# Wowza Streaming Engine SecureToken uses ambiguous URL formats to access the same underlying asset

**URL:** <https://community.wowza.com/t/wowza-streaming-engine-securetoken-uses-ambiguous-url-formats-to-access-the-same-underlying-asset/102825>\
**Category:** Wowza Streaming Engine\
**Created:** [April 21, 2026, 6:11pm UTC](https://community.wowza.com/t/wowza-streaming-engine-securetoken-uses-ambiguous-url-formats-to-access-the-same-underlying-asset/102825 "2026-04-21T18:11:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Vanhoucke](https://avatars.discourse-cdn.com/v4/letter/j/74df32/32.png) [@John\_Vanhoucke](https://community.wowza.com/u/John_Vanhoucke)\
**Post date:** [April 21, 2026, 6:11pm UTC](https://community.wowza.com/t/wowza-streaming-engine-securetoken-uses-ambiguous-url-formats-to-access-the-same-underlying-asset/102825/1 "2026-04-21T18:11:02Z")

</div>

In the Wowza Streaming Engine SecureToken implementation, the stream path is used to generate the digest. However, the same media asset can be accessed through multiple URL variants, for example:

- `http://server/vod/_definst_/sample.mp4/playlist.m3u8`

- `http://server/vod/mp4:sample.mp4/playlist.m3u8`

- `http://server/vod/sample.mp4/playlist.m3u8`

If I generate the digest using `vod/sample.mp4`, internally Wowza may resolve the request to `vod/_definst_/sample.mp4` use this path to digest the streams, i can’t play it, so I must using different path to digest, very confusing to serve the stream.

My goal is to protect the asset `sample.mp4`. I plan to implement a custom authentication module that verifies signed access to the asset. If I perform this validation in `onHTTPCupertinoStreamingSessionCreate`, will this provide sufficient protection for playback across all HLS requests?

---

<div class="post-metadata">

**Author:** ![Jason\_Hilton](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/jason_hilton/32/437_2.png) [@Jason\_Hilton](https://community.wowza.com/u/Jason_Hilton)\
**Post date:** [April 23, 2026, 9:48am UTC](https://community.wowza.com/t/wowza-streaming-engine-securetoken-uses-ambiguous-url-formats-to-access-the-same-underlying-asset/102825/2 "2026-04-23T09:48:05Z")

</div>

Hi John,  
Using onHTTPCupertinoStreamingSessionCreate should work. However, what you’re describing with Secure Token should work correctly anyway as the Wowza Streaming Engine software should be applying the token against the same URL that the player uses.

If this is not happening (server switches to a different URL), I recommend creating a ticket so the Technical Support Team can investigate further.  
[Open a support ticket](https://www.wowza.com/support/open-ticket)

Regards,  
**Jason Hilton**  
Senior Technical Support Engineer  
**WOWZA** | _The **solution** you start with, the **partner** you scale with._

[**Manage your Support cases online**](https://urldefense.com/v3/ __https://portal.wowza.com/account/support__ ;!!GFN0sa3rsbfR8OLyAw!b21Ye3sPxunm4p5NSvmBLvIcMnA6OS9j4Q6GGF5By3Zd2KpmqFACOzAHUWnC8Y2Wwq_lhoVkvzxWGfdtbeYvJI9QnQ$)  
**Bookmark our** [**FAQ page**](https://urldefense.com/v3/ __https://support.wowza.com/hc/en-us__ ;!!GFN0sa3rsbfR8OLyAw!b21Ye3sPxunm4p5NSvmBLvIcMnA6OS9j4Q6GGF5By3Zd2KpmqFACOzAHUWnC8Y2Wwq_lhoVkvzxWGfdtbeZS3JTgtA$)  
**Bookmark our** [**Status page**](https://urldefense.com/v3/ __https://status.wowza.com/__ ;!!GFN0sa3rsbfR8OLyAw!b21Ye3sPxunm4p5NSvmBLvIcMnA6OS9j4Q6GGF5By3Zd2KpmqFACOzAHUWnC8Y2Wwq_lhoVkvzxWGfdtbebL9JPWqQ$)  
 ![|182x66.9749984741211](https://api-na1.hubspot.com/filemanager/api/v2/files/205037197227/signed-url-redirect?portalId=229276)
