Control workspace visibility
A nonprivate workspace can be read through its access link. Private workspace restricts access to its signed-in owner.
- Free
- Requires account ownership
- Pro
- Requires account ownership
- Self-hosted
- Requires account ownership
Access and editing controls
| Workspace state | Who can read it? | What the control changes |
|---|---|---|
| Shared, nonprivate workspace | People who obtain its access link | The link provides access to the saved content. |
| Private account-owned workspace | Its signed-in owner | Other users cannot read it through the workspace API. |
| Locked workspace | Its existing readers | Locking restricts who can add versions, rather than who can read. |
| Community Library entry | Public readers | Publication makes the example discoverable in the Library. |
The owner can change privacy and locking for an account-owned workspace that is not a Library entry. Anonymous workspaces do not have an account owner who can apply those controls.
Make an account-owned workspace private
- Sign in to the account that owns the workspace.
- Open Workspace actions on your account page, or Manage Workspace in the saved workspace.
- Enable Private workspace.
- Open its access link in a signed-out browser session.
- Verify that the saved content is unavailable there.
If the control is unavailable, verify ownership and whether the workspace is a Library entry. Changing visibility does not remove copies that another person already obtained.
The Read-only editor control restricts edits by other people. It does not make the workspace private.
Choose the mode before saving
Save Mode sets the initial access and editing rules for new account-owned workspaces.
- Open Settings, then General and Saving & sharing.
- Set Save Mode to Public, Locked, or Private.
- Save a new workspace.
- Verify its access and editing controls before sharing the link.
Locked permits readers but restricts edits. Private restricts access to the signed-in owner. The preference applies to new workspaces, including forks. It does not change existing workspace permissions. Change save mode in a workspace menu or save dialog opens the same preference.
Workspace contents
A saved workspace can contain more than a pattern. Its test strings, substitutions, unit tests, and other saved inputs can contain sensitive data. Before saving or sharing, replace real logs, customer information, and credentials with synthetic examples.
Copy Shareable Link embeds editor fields in a URL. The private workspace control does not protect data copied into a separate URL. Deleting a saved workspace also does not remove independent copies of that URL.
Network operations
Matching workers run in the browser. Saving, account actions, and API or MCP requests involve the service. An MCP client can send workspace content to other services according to that client's configuration. The public privacy policy governs the public service.
A self-hosted deployment uses its own service and account configuration. Its network and operational scope are described separately in Enterprise network guidance.