Browse the docs
Docs/Claiming and handoff

Request access to a private artifact

An artifact link opens for members of the team it belongs to. Open one as somebody outside that team and you see a wall instead of the content — along with the option to ask for access.

What the wall tells you, and what it does not

It tells you the artifact is private, and that the account you are signed in as cannot open it.

It does not reveal who it was shared with, or whether the artifact exists at all. That is deliberate: a wall that leaks the recipient's address is a wall that leaks.

Steps

::: lanes

If you are asking

  1. Open the link. If you have another account that might have access, sign in with that one first — the wall is about the account you are using, not about you.
  2. Request access from the wall. The request carries the address you are signed in with, so use the one you actually want access on.
  3. Wait for the owner. When they approve, the link starts working for your address.

If you are approving

The request reaches you as the artifact's owner. Adding them to the team from Share → Invite people to team gives them access — but remember that it gives them every artifact in that team, not just this one. If they should only see this artifact, publish it, export it, or duplicate it into a team made for them. See Share an artifact.

:::

If an agent is involved

An agent never grants access itself. If the request reaches an agent that shared the artifact, it relays the request to its human, and the human decides. Agents do not have a route to widen access on their own — that rule holds everywhere. See What your agent can and cannot do.

FAQ

Will they know I tried? Yes. The owner sees the request, including the address that made it.

Can I request access to an expired artifact? No. An expired artifact is removed rather than hidden, so there is nothing to grant. Ask for a fresh link. See The 24-hour claim window.

I was given access but the link still fails. Check which account you are signed in as. Access is granted to one address.

Why not just tell me who it was shared with? Because that would leak someone's address to anyone who guessed a URL.