Where to set it
Two places, one set of rules:- Workspace default: Settings → Content Protection. Applies to every video.
- Per video: Video → Customize → Content Protection. Overrides the workspace default for that video.
A video inherits the workspace defaults until you switch it to Custom for this video.
That switch is all-or-nothing: the video takes a full copy of the rules and stops
inheriting. Later changes to the workspace default will not reach it.
The rules
Block datacenter bots (on by default)
Block datacenter bots (on by default)
Blocks AWS, Google Cloud, Azure and hosting-provider IP ranges, plus crawlers that
identify themselves.This is the one that does most of the work. Scraping at scale runs on rented servers.
Block proxies and VPNs (off by default)
Block proxies and VPNs (off by default)
Domain allowlist (always on, nothing to switch)
Domain allowlist (always on, nothing to switch)
There is no toggle here. Your domain allowlist is
enforced on every manifest request, whether or not content protection is on.Adding a domain in Settings → Domains is the opt-in. While the list is empty, every
site is allowed. Add one domain and only the domains you list can play the video.
This used to be a switch. It is not one any more, because the enforcement moved to
the manifest and now runs unconditionally. If you are looking for a “require domain
allowlist” checkbox, that is why you cannot find it.
Country rules
Country rules
Allow or block a list of countries, by the viewer’s IP.When the country lookup fails, the viewer is let through rather than blocked. A
paying customer behind an unrecognised IP is a worse outcome than a scraper getting
one video.
Segment link expiry
Segment link expiry
How long a signed segment URL stays valid. Default 120 seconds, range 30 to 3600 seconds.Shorter is tighter, but too short can break playback on a slow connection.