Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A simple image URL points to an image or image-delivery endpoint without a signature. A signed URL is created by a provider with authentication material that it validates, either to authorize temporary access to an otherwise private image or to protect delivery parameters such as transformation options. Signing does not generate the image: generation, storage, transformation and authorization are separate steps.

What simple and signed image URLs do

A URL is an address used to request a resource. For image workflows, that resource might be a generated file in object storage or an image-delivery endpoint that can resize or otherwise transform a stored image.

Simple or public URL

A simple URL has no URL signature. If the image or endpoint is public, anyone able to reach the address can generally request it. The URL may still contain ordinary query parameters, such as transformation choices; without a signature, whether those can be changed depends on the service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Signed URL

A signed URL includes provider-generated authentication material. The provider validates it according to its own rules. The signature may authorize a request to a private object for a limited time, or establish that transformation parameters have not been altered. These are related patterns, not one universal format or signing algorithm.

A signed URL is not a secret once delivered to a browser or another client. Anyone who obtains a usable bearer-style URL may be able to use it within its scope and validity. Google Cloud Storage says anyone who knows a signed URL can access the resource until it expires or the signing key is rotated (Google Cloud Storage signed URLs).

Choose the URL type for the access you need

Approach What it does Good fit Main trade-off
Simple/public image URL Identifies a public image or delivery endpoint, potentially with transformation parameters. Public pages, galleries, or assets that do not need access restrictions. Anyone who can reach the URL can generally request the resource; supported parameters may be changeable.
Signed transformation URL Validates a provider-specific signature that protects the URL or its transformation parameters. Image delivery where clients should not freely alter transformation controls. Parameters must follow that provider’s signing rules; a changed URL may need a new signature.
Signed or presigned storage URL Grants whoever possesses the URL permission to perform a limited action on a private object. Temporary downloads or direct uploads without making the object broadly public. It is a bearer credential, and expiry, permitted operation, request details, and signing credentials constrain it.
CDN signed URL Authorizes delivery of a protected resource through a content-delivery network. Protected content that still needs CDN delivery. URL construction, key setup, parameter ordering, and expiry are provider-specific.

Decide whether the asset should be public, what exact action a recipient needs, whether the signature protects parameters or grants object access, and how long access should last. Also consider whether a browser can receive the final URL directly or must request it from your backend, and how the provider handles delivery and caching.

How to deliver a generated image privately

Use this sequence regardless of which provider you select. The signing step must use the provider’s supported SDK, client library, or documented signing procedure; there is no portable signature you can calculate once and use across services.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Generate and store the image. Complete image synthesis separately, then save the result in the storage or delivery service you intend to use.
  2. Choose its visibility. If anyone may view the image, a public URL may be enough. Use signing when you need access control or protection against changes to delivery parameters.
  3. Authorize on your backend. Check that the requesting user may access the image. Generate a URL scoped to the narrowest practical resource and action, with the shortest useful lifetime.
  4. Keep signing secrets server-side. Store keys in backend secrets, not browser JavaScript, a public repository, or a request that an untrusted client can control. Cloudflare’s private-image guidance likewise says to generate signed URLs server-side to protect the signing key (Cloudflare Serve private images).
  5. Send the URL over HTTPS. Provide it only to the intended client. Forwarding the URL forwards its access capability.
  6. Use the request exactly as signed. Do not alter query parameters, HTTP method, or required headers afterward. If the request needs to change, generate a fresh URL following the provider’s canonicalization rules.
  7. Test expiry and key changes. Check the chosen service’s behavior in your environment, including what happens when underlying credentials expire or keys are rotated.

Provider-specific signing rules and expiration

Signed URLs are not interchangeable. Their lifetimes and required request details depend on the service and sometimes on how you create the URL.

Google Cloud Storage

Google Cloud Storage V4 signed URLs have a maximum expiration of 604800 seconds (seven days), according to its current documentation accessed in 2026; this limit applies to that signing system, not signed URLs generally. The documentation also limits these URLs to Cloud Storage XML API endpoints. See Google Cloud Storage’s signed URL documentation.

Amazon S3

AWS checks expiration when the HTTP request is made. A URL signed with temporary credentials may stop working when those credentials expire, are revoked, deleted, or deactivated, even if its requested end time is later. AWS says the request parameters—including method, headers, and query string—must match. Its current documentation accessed in 2026 gives a console duration of 1 minute to 12 hours and a CLI/SDK maximum of seven days; those are S3-specific limits, not universal defaults. See AWS S3 presigned URLs.

Google Cloud CDN

Cloud CDN describes signed URLs as temporary access for whoever possesses the URL and recommends the shortest useful lifetime. Its custom URL parameters are case-sensitive and must be ordered as documented. See Google Cloud CDN signed URLs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Imgix

Imgix uses signatures to prevent unauthorized changes to URL parameters; if parameters change, the URL must be re-signed. Its expires parameter is a separate expiration control. Because that parameter can be changed in a query string, Imgix recommends signing assets that use it and recommends client libraries for application-scale URL security. See Imgix Securing Assets.

Cloudflare Images

Cloudflare Images’ documentation, last updated August 26, 2026, says private images require a signed URL token unless the requested variant is configured to allow public access. The signing key should remain server-side. See Cloudflare’s private-image instructions.

Rank #4
API Security in Action
  • API Security in Action
  • Manning Publications
  • ABIS BOOK

Amazon CloudFront

CloudFront says adding a query string after signing causes an HTTP 403 response. Construct the final URL before signing and follow the exact rules for the distribution and signing method. See AWS CloudFront signed URLs.

Common failures and practical fixes

  • 403 or access denied: Confirm the URL has not been edited after signing, the requested object and operation are covered, the key is configured correctly, and any required headers and method match. CloudFront specifically rejects a query string appended after signing.
  • URL expired earlier than expected: Check both the URL’s expiry and the lifetime or status of the credentials used to sign it. In S3, temporary credentials can end access before the URL’s requested end time.
  • Transformation request rejected: Compare every parameter and its ordering or case with the provider’s signing requirements, then create a new signature for the exact final URL.
  • Private image appears public: Check whether the object itself or a particular delivery variant allows public access, and ensure the application is not returning an unrestricted URL.
  • Link works for the recipient but leaks when forwarded: Treat it as a credential. Reduce the expiration, limit the scope, and avoid placing it in public logs or pages.
  • Signature visible in client code: Do not ship the signing key or signing logic that requires the key to untrusted clients. Move URL generation to a backend and return only the authorized URL.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

For capturing a webpage as an image or PDF—not generating synthetic art—ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns a PNG, JPEG, WebP, or PDF. Its capture flow can accept cookie or consent banners and remove more than 60 known consent platforms, newsletter popups, and chat widgets; those steps can each be turned off. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, with the outcome identified in response headers. AI agents can use its MCP server tools, including take_screenshot, get_page_info, and capture_pdf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Here is a cURL request that saves a webpage capture as WebP:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options and formats, and sign up for 1,000 free screenshots a month with no card.

Keep the security model simple

Use public URLs for genuinely public images. Use provider-specific signing only when it solves a defined need: limiting access to an object or preventing unauthorized changes to delivery parameters. Keep keys on the server, use narrow scopes and short lifetimes, and treat every signed link as a credential that can be forwarded.

Frequently Asked Questions

Does a signed URL create or generate an image?

No. It controls authorization or validates delivery parameters for an image that has already been generated or stored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I reuse one signed URL with a different image service?

No. The signature format and validation rules are provider-specific.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.