Share-link gates & export policy
Password, email-domain, and expiry gates on a share link — where they are enforced, what each one actually checks, and why an exported file bypasses all of them.
Every named share link can carry access controls. This page explains exactly what each control checks, where it is enforced, and the one place it does not apply: a downloaded file.
Where gates are enforced
Gates are checked at the serving route — the request that hands the demo to a viewer's browser. The demo bundle itself is never modified to hold a secret. A gate is not "a hard-to-guess URL": the link can be public knowledge and the gate still holds, because the server decides on every request whether to serve, challenge, or refuse.
A link with no gate serves the demo directly. A gated link serves a challenge page first and only releases the demo once the viewer clears it.
The gates
Password
The viewer types a password to watch. Once they clear it, the browser is remembered for the rest of the day, so they aren't re-challenged on every step — the password is entered once per day, per browser. Replacing the password takes effect immediately; browsers that already cleared the old one keep access until their day rolls over.
Email domain
The viewer enters their email address to watch. This is a domain check, not verified identity. DemoMate confirms the address ends in an allowed domain (or is not in a blocked list) and sets a cookie — it does not send a confirmation email, click-through, or otherwise prove the person owns that address. Treat a captured email as "the domain someone typed," not as an authenticated user.
You can run the domain list in two modes:
- Allow only — the address must match one of the listed domains (e.g.
acme.com). - Block — the address must not match any listed domain.
Expiry
A link can expire at an exact instant. After that moment the serving route refuses the demo — expiry is enforced server-side to the instant, in your timezone, not "end of day." A link can also carry no expiry and stay open until you disable it.
Disabling a link
Disabling a link stops it from serving immediately. Existing viewers lose access on their next request; the link can be re-enabled later without regenerating its URL.
Export policy: an exported file is ungated
A single-file .html export is a self-contained, offline copy of the demo. It contains no serving route, so it enforces none of the controls above.
When you export a demo that has at least one enabled gated link, the export step shows this warning and requires you to acknowledge it before the download unlocks:
This demo has protected links. The exported .html file plays offline and bypasses password, email and expiry gates.
You confirm with the checkbox:
I understand — the file itself is ungated
This is deliberate and honest: the file plays anywhere it lands, so anyone you send it to — or anyone they forward it to — can open it without a password, without entering an email, and after the link's expiry has passed. If access control matters, share the link, not the file.