Media2URL
Share with workspace access

Private links for files that should stay inside a workspace

Sometimes sending someone the URL should not be enough to open the file. A draft for your team or a client project may only make sense for people who already have access to the workspace where that file belongs.

A Media2URL Private link works that way. The recipient opens the link while signed in, and access depends on whether their account can use the workspace that owns the file.

The workflow

What the sender and recipient do

The link is only one part of this workflow. The file also belongs to a workspace, and the recipient needs the right account access before the private file can open.

That makes Private different from sending an ordinary hidden or unlisted URL.

  1. 1. Put the file in the right workspace

    Save the supported file inside the personal or team workspace that should control it. This matters because Private access follows the workspace that owns the asset.

  2. 2. Change the access mode to Private

    Open the file's access settings and choose Private where that option is available. Someone knowing the URL is not enough by itself. Their signed-in account also needs access to the owning workspace.

  3. 3. Send the link

    Send the available link to the person who needs the file. When they open it, Media2URL checks the access attached to their account and workspace rather than treating possession of the URL as permission.

  4. 4. Change access later

    Access can change when the project changes. A permitted workspace administrator can update a member's role or remove that member, while the file link can also be disabled separately. None of those actions automatically means the stored asset itself has been deleted.

Authorisation model

Private means workspace-authorised access

A Private link is still a link, but the URL is not the complete access credential.

The recipient also needs a signed-in Media2URL account that is allowed to use the workspace behind the file. If the same URL is forwarded to someone who does not have that workspace access, the forwarded URL alone should not give them the same result as an authorised member.

This makes Private useful when access should follow an existing project or team membership instead of being granted simply because someone received a URL.

Access comparisons

Private, Unlisted and Password Protected are not the same

Link modeWhat gives someone access
PublicThe working URL itself
UnlistedPossession of the URL
Password ProtectedThe URL plus the required password check
PrivateThe URL plus authorised signed-in workspace access

An Unlisted link is useful when you do not want normal public discovery but anyone with the working URL may still use it. Private is different because workspace authorisation remains part of the request.

Password protection solves another problem. It gives access to someone who knows the password, while Private access is tied to the recipient's workspace account.

When Private makes more sense than a password

A password can work well when the recipient is outside your Media2URL workspace and you simply need another access check before the file opens.

Private access fits better when the people already belong to a workspace and their access should follow that membership. You do not need to send another shared password to every team member just to let them use a file they are already authorised to see.

If the person should lose access when they leave the project, workspace-based Private access can also be easier to manage than remembering which passwords were shared with whom.

When Private is probably the wrong choice

Private access is not the best fit when the recipient does not have a Media2URL account or should not become part of the workspace.

A client who only needs one temporary review link may be better served by a password or expiry setting where those controls are available. A public website asset clearly should not be set to Private if anonymous visitors need to load it.

Choose Private because workspace membership matters, not simply because the word “private” sounds safer.

Workspace role vs file access

Being allowed into a workspace does not mean every member has the same controls. Workspace roles (Owner, Admin, Editor, Viewer) decide management abilities inside your Team Workspaces, while Private link access validates membership.

Forwarding does not transfer membership

If an authorised member sends the Private URL to someone outside the workspace, possession of the URL alone does not grant access. However, authorized members can still copy content they legitimately receive.

Private access with an end date

Workspace membership answers who should open the file; Expiring Links answer how long. Combine them during client approval cycles so review links close after deadlines.

Removing a member should not remove the team's file

Imagine a designer uploads product images to a client workspace and leaves the project a month later. Removing that person changes their future access, but does not delete shared library assets for everyone else.

File deletion remains a separate decision in your Media Library.

Disable the link when the file should stop being shared

Sometimes team members should remain in the project, but one particular draft file should no longer be accessible via its previous URL.

Disabling the file link stops delivery without modifying anyone's broader workspace membership or deleting the asset.

Decision framework

Which sharing mode would I choose?

SituationBetter starting point
Image on a public websitePublic
Link should only be known by selected recipientsUnlisted
External recipient should enter a shared passwordPassword Protected
Existing workspace members should open the filePrivate
Workspace members only need the file for a limited periodPrivate + Expiry

These are practical examples rather than fixed rules. The actual options available depend on your account and the file being shared. Check full options in Security & Access.

Practical use

Where Private links fit naturally

Design review

A designer uploads a draft banner into the client workspace. The reviewer is already a member, so the file can stay Private instead of creating another public review URL.

Internal PDF

A project document needs to remain available to the team for several months. Private access makes more sense than repeatedly sending the file as an attachment whenever someone needs it.

Contractor access

A contractor joins the project for a limited period. Their workspace membership gives them access to the private project files they need. When the work ends, removing that membership changes their future workspace access without deleting the files for everyone else.

Old project draft

The team still needs the workspace, but one outdated draft should stop opening from an old link. Disable that link rather than removing every member from the project.

Private is an access rule, not a different file type

Making a file Private does not turn the image, PDF, video or other asset into another file format. The underlying asset still belongs to the Media2URL library. What changes is the access rule around delivery. The recipient now needs the workspace authorisation required by that Private link before the supported file can be opened.

Access boundaries

What Private access does not change

  • It does not make an authorised recipient unable to copy the content. The access rule controls delivery through Media2URL.
  • It does not delete the file when a member is removed. Membership and stored assets have separate controls.
  • It does not replace normal upload rules. The file still needs to follow the same account and acceptable-use requirements.
  • It does not work for someone who cannot use the owning workspace. Confirm that the intended recipient has the correct account access before depending on the link.
Questions about this workflow

Frequently asked questions

Yes. Private workspace access is designed for a recipient who is signed in to an account with access to the workspace that owns the file. Simply receiving the URL should not be treated as enough permission to open the Private asset.

No. An Unlisted link mainly depends on possession of the URL. Private access also checks the recipient's workspace authorisation. Forwarding an Unlisted URL can therefore have a different result from forwarding a Private one.

Yes, where expiry controls are available for the asset and account. Private access determines who can use the link, while expiry determines how long the link remains active.

The removed person loses the workspace access associated with that membership. The shared assets remain in the workspace unless they are separately deleted through the available file-management controls.

No. Password-protected access asks the recipient for a shared password. Private access relies on the signed-in account's permission to use the owning workspace. Use the option that fits how you already manage the recipient.

The forwarded URL alone should not give another person the workspace permission they are missing. The new recipient still needs the required account access. An authorised person can still copy or redistribute content after receiving it, so Private access should not be treated as control over what happens outside the Media2URL delivery path.

Private changes the access behaviour rather than turning the asset into a completely different file. The current file and link controls determine how its supported outputs behave after the access mode changes.

Usually not when ordinary website visitors need to load the image without signing in. Private access is better suited to files meant for authorised workspace members. Use the normal Image to Link or other public delivery workflow when the media belongs on a public page.

Next steps

Explore related workspace and access tools