Video & subtitles · Direct Media Downloader
Signed and expiring URLs: why a direct link can stop working tomorrow
· Background
urls security downloads
Many direct links carry signatures and expiry times in their query strings. This post explains how presigned URLs work, why CDNs and storage services use them and how to recognise one before it fails.
The link worked on Friday and returns an error on Monday — the pattern behind most 'broken' direct links
A link can succeed on Friday and return an HTTP error on Monday without the file moving. The query may contain a time-limited authorization whose validity ended between attempts.
ToolAcre reports readable non-success status and notes that the address may have expired, moved, or require sign-in. It does not reinterpret expiry as CORS when an HTTP response is available. Large transfers are especially vulnerable to this timing gap because a valid link can expire after it was shared but before the recipient starts or finishes using it. Long recordings magnify this timing risk because authorization can lapse between sharing, starting, and completing a transfer.
What a signed URL is — a normal file path plus a signature, an expiry and sometimes an allowed IP, all in the query string
A signed URL combines an ordinary resource path with values used by the serving system to verify authorization. These may represent a signature, expiry, credential scope, policy, or client restriction.
Parameter names and encoding are provider-specific. The browser treats them as query data, while the server decides whether their combination is valid at request time. Some schemes bind method or headers as well, so a provider may permit GET yet reject HEAD; only its documented signing algorithm can explain that result. Some providers include method or selected headers in verification, allowing GET while refusing HEAD under the same visible query.
Why storage services and CDNs use them — sharing a private file without making it public or requiring a login
Storage services and CDNs use signed addresses to share a private object without making its path permanently public or attaching an interactive login to every download.
Possession of a live link can therefore be sensitive. Avoid pasting it into untrusted relays, publishing screenshots, or leaving it in shared notes beyond the authorized workflow. Short validity reduces exposure if a link leaks, while revocation and access logs remain provider capabilities rather than functions of the downloaded URL itself. Short validity reduces exposure from leakage, while revocation and access logging remain capabilities of the issuing provider.
Reading the query string — spotting expiry timestamps and signature parameters in common URL shapes
Look for query names suggesting expiry, signature, token, policy, or vendor-prefixed authentication. An epoch-like value may represent a deadline, but documentation is needed before converting it.
ToolAcre’s normalizer deliberately keeps `token`, `expires`, `signature`, and X-Amz-style fields. It removes only known analytics-shaped keys because stripping authorization would change the addressed request. Do not decode or remove unfamiliar parameters casually, because an opaque-looking value can be part of the signed canonical request even when its name is not obvious. Unknown parameters may participate in canonical signing even when their names do not look security-related, so preserve them unchanged.
Worked example: a timestamped storage link — working out when it expires and what the error looks like afterwards
Suppose provider documentation defines an expiry parameter as epoch seconds. Convert it under that documented rule and compare it with current UTC time before starting a large transfer.
After the deadline, the host might return 403, another error, or a redirect; there is no universal response shape. The concrete evidence is the status and body served by that provider, not an invented message. If the host provides a structured error body, preserve it for the owner without publishing the signed address that produced it. Keep any structured error response for the owner while protecting the signed address that generated it from wider disclosure.
What this does not cover — renewing a link, which only the file's owner can do
The downloader cannot renew, resign, refresh, or extend an address. Only the party controlling the source or its authorized sharing system can issue another valid link.
It also does not preserve a signed-in session because credentials are omitted. If access requires account cookies rather than URL authorization, the file is outside this product’s design. Changing a timestamp manually invalidates most signatures because the deadline participates in server verification; that is not an extension mechanism. Changing a timestamp normally invalidates verification because the deadline itself contributes to the signature rather than acting as editable metadata.
Takeaway: download while the link is live — how the Direct Media Downloader's URL check and announced fetch fit an expiring link
Download while an authorized link is live and the file fits the browser workflow. Local validation confirms the initial address meets scheme and host policy, then the explicit request lets the origin evaluate its signature.
The host announcement does not disclose whether the token remains valid. Check link can test reachability with HEAD, but some providers handle HEAD differently from GET, so it is not a renewal or guarantee. For archival workflows, coordinate link issuance with the transfer window and verify the saved bytes before deleting the sender’s authoritative copy. Coordinate issuance with the planned transfer window, then verify the completed asset before retiring the sender’s authoritative copy.