Private source boundary
Provider credentials and private media sources stay on trusted servers instead of being exposed to the browser.
Unpirator sits between your authorization decision and media delivery. Your app keeps control of users and content; the playback layer handles short-lived protected access.
Provider credentials and private media sources stay on trusted servers instead of being exposed to the browser.
Access is short-lived, scoped and revocable instead of becoming a reusable public media link.
Protected playback always binds the authenticated viewer email to a stable application device ID; plan-enabled watermarking can display that trusted identity during playback.
Track, limit, block or revoke devices when the purchased plan includes those capabilities.
Control simultaneous playback when concurrent-stream enforcement is enabled for the customer plan.
Inspect active and recent sessions, usage and security events from the customer workspace.
How it works
The protected path starts from your own backend decision and stays server-led until the media gateway authorizes delivery.
Your database remains the source of truth for content and the viewer's entitlement to watch it.
Your backend authenticates the viewer, resolves their email from trusted server-side auth state and checks access before Unpirator creates playback.
The concrete protection features enabled by the customer's plan are applied to the playback session.
The browser receives short-lived protected playback instead of provider credentials or a permanent private source URL.
Where it fits