---
name: mux-video-paywall
description: Put Mux video behind a paywall. Use for subscription, pay-per-view, rental, course, or members-only video; locking down videos that are currently public; or auditing an existing gated integration.
---

# Mux video paywall

Read https://www.mux.com/docs/prompts/video-paywall.md?ref=skill for the canonical procedure. In a browser, open https://www.mux.com/docs/prompts/video-paywall and expand **View the full agent instructions**. If the prompt is unavailable, identify the missing reference before implementing API operations from memory.

Start at **Start with the request**. Determine whether the task is application development, protecting existing videos, or auditing an integration. Resolve the listed choices from the user and project context, then ask only for missing choices that change the work. Use the API, MCP, CLI, repository, or computer-use capabilities available in the environment, along with the project's existing authentication and billing providers.

Follow the prompt for signing keys, signed playback IDs, playback restrictions, token issuance, player integration, previews, and DRM. Its critical distinctions are:

- The application decides who has paid; Mux enforces it through signed playback. The entitlement check on the token endpoint is the paywall.
- Signing keys are separate from API access tokens, and the private key is returned only at creation. Keep it in the server's secret store.
- Playback, thumbnail, storyboard, and DRM license requests each need their own token, and options for a signed playback ID belong in the token's claims instead of the URL.
- A token stays valid until it expires, even after a cancellation, and an expired token stops playback that is already in progress.
- A video remains public until its public playback ID is deleted. Deleting one breaks existing embeds, so confirm with the user first.

When protecting an existing library, save each asset's old and new playback IDs so another invocation can resume the migration. When auditing, work read-only until the user approves changes.

Use **Verify the result** for the handoff. Distinguish code and configuration that were prepared from gating that was actually tested with a paying and a non-paying viewer. Report anything that still needs credentials, a test purchase, DRM onboarding, or target devices.
