Configure Cloudflare Stream signed URLs for private video playback

domain: developers.cloudflare.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Mark the video as requiring signed URLs (requireSignedURLs: true) via the Stream API or dashboard.
  2. For low-volume use, call the video's /token endpoint to mint a token that expires in one hour.
  3. For high-volume use, create a Stream signing key (RSA key pair) and self-sign JWTs instead of calling the token endpoint per view.
  4. Include the signed token when requesting the playback manifest so Cloudflare's edge validates it before serving segments.
  5. Optionally combine with the Allowed Origins setting to restrict which domains can request the manifest.

Known gotchas

Related routes

Configure Cloudflare Stream signed URL tokens with per-viewer accessRules (IP and country) and a downloadable flag for token-gated playback
developers.cloudflare.com · 6 steps · unrated
Configure Mux signed playback URLs with a JWT for private video access
docs.mux.com · 6 steps · unrated
Upload a video to Cloudflare Stream via tus resumable upload
developers.cloudflare.com · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans