Skip to content
scroll to zoom · drag to pan

getPrivateAssetUrl

function getPrivateAssetUrl(
asset,
preset,
signingKey,
opts): Promise<string>;

Defined in: packages/asset-client/src/index.ts:844

The signed URL for one preset of a PRIVATE asset — what every refusal above points at.

// On your BACKEND, once you have decided this viewer may see it:
const url = await getPrivateAssetUrl(asset, "lg", tenantSigningKey, {
expiresInSeconds: 300,
});

It works on a public asset too — /a/ is a different door onto the same object — but there is no reason to pay for it: a public URL is cacheable at the edge and costs nothing, a signed one is neither.

⚠️ Backend only. Handing the signing key to a browser lets any visitor mint URLs for every private asset the tenant owns, which is the whole property the private tree exists to provide.

⚠️ Needs setTenantId (or a NitidaClient with tenantId), like every variant URL builder: the tenant segment is base36 and part of what the signature covers, so a missing tenant does not produce a wrong URL — it produces an unsignable one.

Parameter Type
asset Pick<AssetDTO, "sha"> & OriginalHints
preset VariantPreset
signingKey string
opts SignAccessOptions

Promise<string>