Skip to content
scroll to zoom · drag to pan

MAX_SIGNED_URL_TTL_SECONDS

const MAX_SIGNED_URL_TTL_SECONDS: number;

Defined in: packages/asset-client/dist/index.d.ts:72

The longest life a signed URL may claim: 7 days.

⚠️ Must equal MAX_SIGNED_TRANSFORM_TTL_SECONDS on the origin and MAX_SIGNED_URL_TTL_SECONDS in the CDN worker — one policy, three runtimes, pinned in all three suites. Both verifiers refuse anything longer, so a bigger number here would only mint a URL that 401s.

Why there is a ceiling at all: expiresInSeconds was validated as “> 0” and nothing else, so { expiresInSeconds: 315_360_000 } produced a ten-year link that every check called valid. “Has an expiry” and “expires” are different properties, and only the second makes a leaked link die.