Skip to main content

Secure URL

By default, the URLs we generate for call recordings and logs do not expire, allowing you to easily share the links with other people. However, if security is a concern and you want to prevent unauthorized access in case the URL is leaked, you can opt in for secure URLs. Secure URLs expire after the configured duration. The default is 24 hours; you can choose from 1 minute to 7 days.

How to Opt In

You can opt in to secure URLs at any time:
  1. Open the agent editor and expand Security & fallback settings. For a conversation flow, select Global settings first.
  2. Turn on Opt In Secure URLs.
  3. Set Expiration Time. Leave it at 24 hours or choose a duration from 1 minute to 7 days.
Through the API, set opt_in_signed_url to true and use signed_url_expiration_ms to configure the duration in milliseconds. Leaving the duration unset uses 86,400,000 ms (24 hours).
Opt In Secure URLs switch shown off in the security settings panel.

Enable Opt In Secure URLs to reveal the expiration setting.

What Happens When You Opt In

  • Every time you request the URLs of your call’s recording and log, we will generate a URL with a signature that expires after the configured duration (24 hours by default).
  • Accessing the resource after the signed URL expires will be denied.
  • Files created before secure URLs were enabled will still be generated without signatures.

What Happens When You Opt Out After Opt In

  • Files created while secure URLs were enabled will continue to generate signed URLs using the duration stored with that call (24 hours by default) whenever you request their URLs, even after you opt out.
  • Only files created after you opt out will generate non-expiring URLs.