> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://contentful.com/developers/docs/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://contentful.com/_mcp/server. Asset keys are used when signing Embargoed Asset URLs. This feature is only enabled on specific plans. Reach out to your Sales representative for more information about feature availability. ## Asset key > **Info** > > Asset key endpoints are currently not available in the OpenAPI specification. Please refer to the legacy documentation or contact support for more information. [Create an asset key](/references/content-management-api/asset-keys/create-an-asset-key) To sign embargoed asset URLs, you need to create an asset key. Secure asset URLs delivered by the CDA, CMA, or CPA will have a host of `(images,assets,videos,downloads).secure.ctfassets.net`. They cannot be accessed without first signing the URL. Signing an embargoed asset URL is accomplished by the following steps: 1. Create an asset key for the space the asset URL belongs to. You must specify an `expiresAt` value, a Unix epoch timestamp in seconds, and this can be no more than 48 hours in the future. 2. Create a JWT with the embargoed asset URL as the `sub` (JWT subject). Sign the JWT with the asset key's `secret`. 3. Affix to the original embargoed asset URL the following query parameters: * `policy` - the asset key's policy * `token` - the JWT created in step 2 4. You may affix other query parameters as well, for example when using the Images API. These do not impact the validity of the signed URL. By default, a signed asset URL will stop functioning after the `expiresAt` value that was specified when creating the asset key. When generating the JWT, you may optionally specify an `exp` (expiry) that will cause the signed URL to be unusable at the specified expiry time. If a per-URL expiry is greater than the `expiresAt` value specified when creating the asset key, the asset key's `expiresAt` value will be used instead. ## API Docs - Asset keys [Create an asset key](https://contentful.com/developers/docs/references/content-management-api/asset-keys/create-an-asset-key.md) ## OpenAPI Specification The raw OpenAPI 3.1 specification for this API is available at: - [OpenAPI JSON](https://contentful.com/developers/docs/openapi.json) - [OpenAPI YAML](https://contentful.com/developers/docs/openapi.yaml)