Skip to content
scroll to zoom · drag to pan

getPrivateTransformUrl

function getPrivateTransformUrl(
asset,
opts,
signingKey,
signOpts): Promise<string | null>;

Defined in: packages/asset-client/src/index.ts:883

The signed URL for a TRANSFORM of a private asset — an arbitrary width, crop or format, not just the sizes that happen to be materialised.

const url = await getPrivateTransformUrl(
asset,
{ width: 1280, format: "webp" },
tenantSigningKey,
{ expiresInSeconds: 300 },
);
// → https://8ok.uk/a/5/t/format=webp,width=1280/<sha>.webp?exp=…&sig=…

Why this exists at all: a private asset that can only be served at the sizes someone already generated is barely a product. The signed tree mirrors the public one, transforms included.

Returns null when opts serialize to an empty DSL — same contract as getTransformUrl, because “no transform requested” is not an error, it just means you wanted getPrivateAssetUrl.

⚠️ Backend only, like every signer here. And note the width is a plain number: a signed URL is a trusted caller, so the edge ladder does not apply — the same rule getSignedTransformUrl already follows.

Parameter Type
asset Pick<AssetDTO, "sha">
opts PrivateTransformOptions
signingKey string
signOpts SignAccessOptions

Promise<string | null>