Back to BlogSecurity
The Magic of Signed URLs: Sharing Your Pranks Securely
Security Team
Contributor
Dec 18, 2024
7 min read
Why Signed URLs Beat Public Links
Public links are convenient, but they are also permanent doors left unlocked on the internet. Once a file is public, you can never really control where it goes or who has it. Signed URLs flip that model by giving you short-lived, tightly scoped access instead.
- Access expires automatically after a short time window
- Links can be rotated without re-uploading the file
- You never expose your raw storage bucket URL
- You can log and rate-limit every access attempt
How We Use Them at RoastYourFriend
Every video generated on RoastYourFriend is stored privately. When you want to watch or share it, we create a signed URL that only lives for a limited amount of time and is served through our own streaming endpoint. The person you share it with experiences a fast, simple video player, while your storage layer stays completely hidden.