# getPrivateAssetUrl

```ts
function getPrivateAssetUrl(
   asset, 
   preset, 
   signingKey, 
opts): Promise<string>;
```

Defined in: packages/asset-client/src/index.ts:844

The signed URL for one preset of a PRIVATE asset — what every refusal above
points at.

```ts
// On your BACKEND, once you have decided this viewer may see it:
const url = await getPrivateAssetUrl(asset, "lg", tenantSigningKey, {
  expiresInSeconds: 300,
});
```

It works on a public asset too — `/a/` is a different door onto the same
object — but there is no reason to pay for it: a public URL is cacheable at
the edge and costs nothing, a signed one is neither.

⚠️ **Backend only.** Handing the signing key to a browser lets any visitor
mint URLs for every private asset the tenant owns, which is the whole
property the private tree exists to provide.

⚠️ Needs [setTenantId](/api/nitida/asset-client/functions/settenantid/) (or a `NitidaClient` with `tenantId`), like
every variant URL builder: the tenant segment is base36 and part of what the
signature covers, so a missing tenant does not produce a wrong URL — it
produces an unsignable one.

## Parameters

| Parameter | Type |
| ------ | ------ |
| `asset` | [`Pick`](/api/nitida/sdk/react/-internal-/type-aliases/pick/)\<[`AssetDTO`](/api/nitida/asset-client/type-aliases/assetdto/), `"sha"`\> & [`OriginalHints`](/api/nitida/asset-client/-internal-/type-aliases/originalhints/) |
| `preset` | [`VariantPreset`](/api/nitida/asset-client/type-aliases/variantpreset/) |
| `signingKey` | `string` |
| `opts` | [`SignAccessOptions`](/api/nitida/asset-client/type-aliases/signaccessoptions/) |

## Returns

`Promise`\<`string`\>