Signed links and extended download security
Requirements
- Extended download security is an optional add on. Contact Passcreator if you don't see this option. The Signed link generator tab only appears under Tools for accounts with the feature enabled.
Steps
Enable extended download security on a template
- Open your template and go to the Distribution tab.
- Turn on Enable extended download security.
Once enabled, the panel shows two settings.
- Signing secret is the shared secret that computes the signatures. You copy it but cannot edit it directly, and users without edit rights see it masked. Regenerate creates a new secret, and all links signed with the current secret stop working immediately. With Use custom secret you set your own secret of 16 to 128 characters, for example to match a secret already deployed in your systems.
- Additional properties included in the signature defines which values the signature covers. Passcreator always offers Pass ID and UUID, plus the additional properties of the template except checkboxes. If a signed value changes on a pass later, links signed before become invalid. The pass ID and UUID never change, so they're the safest choice.
Generate a signed link
- Open the profile menu at the bottom of the sidebar and choose Tools.
- Select the Signed link generator tab. Its description reads "Create download links with a security signature for templates that use extended download security. Only links with a valid signature can open the download page of a pass."
- Choose the Template. If the feature isn't enabled on it yet, the tool tells you so and offers an Open distribution settings link.
- Enter the Pass link or pass ID. Paste the full download link of a pass or only its ID.
- Under "How long should the link be valid?" pick Unlimited, 1 hour, 24 hours, 7 days, 30 days or Until a specific date.
The tool shows Your signed link, optionally as a QR code. For expiring links it adds the hint "This link stops working on {date}."
You also generate a signed link for one pass directly while editing it. The Edit Pass dialog of such templates has a Signed download link section with the same validity options and a Generate new link button. Links you created earlier stay valid until their own expiration date.
Validate a link
The Validate a link section of the tool checks any download link you paste. For a valid link it reports "This link is valid." and adds the expiration. That is either "It stays valid until {date}" or "It has no expiration date." For an invalid link it reports "This link is not valid." and names the reason. Reasons are a missing sig parameter, an invalid signature, a malformed expires timestamp or an expired link. Use it to verify links your own systems produce.
Signing links in your own systems
Your backend signs links itself, so you send out download links without calling Passcreator. The For developers section of the tool documents the algorithm and shows ready made code examples in PHP, JavaScript and Python that match the configuration of the selected template. In short, the algorithm has four parts.
- The signature is an
HMAC-SHA256over the optional expiration timestamp plus the values of the selected fields. Passcreator joins them with line breaks and sorts them by field ID. The reserved IDs arepassIdanduuid. - Passcreator encodes the result as
base64urland appends it to the link as the GET parametersig. - The
expiresparameter carries the expiration as a unix timestamp in seconds. - The key is the Signing secret of the template from its distribution settings.
Next step
Continue withPass download pages and localizationChecked 2026-08-20 · Documentation
