Token authentication for CDN downloads and video

Gate cached Cloud CDN objects with secure tokens so paid downloads, pre-load depots and premium video are not freely shareable.

A cached object is still a public object if the URL is enough. Paid installers, embargoed video and pre-load game depots need a token at the edge so unauthorised clients never reach cache or origin.

Gate the hit

Cloud CDN checks the token before serving from cache. Origin is not bothered by unauthorised GETs. Authorised users still hit 210+ PoPs.

Expiry matches the product

Rental windows, pre-load windows and one-time downloads need different lifetimes. Short expiry limits leaked URL reuse.

Public and private on one distribution

Marketing pages stay public. /downloads and /hls paths require tokens. Path policy, not a second CDN.

Not a replacement for login

The application still mints the URL after it checks entitlements. The CDN enforces the URL. Billing stays in the app.

Frequently Asked Questions

Token authentication is enforced at Cloud CDN. You can still validate at origin; the edge rejects bad tokens first.

Yes. Segment URLs can require a token so playlists are not freely redistributed.

Short expiry limits reuse. Rotate secrets and purge if a long-lived token was exposed.

Put this on Cloud CDN.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.