sendhey puts a real access gate in front of anything your AI produced — a shared password, a verified email, or a restriction to named people or company domains — before a recipient ever sees the content. Publish through the MCP connector or the dashboard, choose the gate, and send the link; nothing about the artifact is visible or fetchable until access succeeds.
Layer document approval on top of an email gate when you need more than access control: the recipient formally acknowledges the exact document version they were shown, verified by a one-time email code. That's a recorded acknowledgement, not an electronic signature, and we make no claim about its legal effect.
Every challenge is document-first: the recipient sees a plain, sendhey-owned placeholder and the access prompt beside it — never the real filename, title, thumbnail, text, image, chart, or any other content-derived detail. The actual bundle is not fetched until access succeeds, so a curious recipient (or anyone who intercepts the page before the gate) learns nothing about what's behind it. That's a genuine difference from tools that blur a live preview of the real content — blur is a visual treatment, not a privacy boundary, and it still means the content was already fetched.
From a connected agent, pass a policy object to publish_page or create_link — for example an email gate with verification is {"audience":{"kind":"email","validate":true,"verify":"otp"}}. From the dashboard, pick the gate from the publish form's first step. Either way the gate applies immediately and can be changed or removed later without a new link.
Yes — switch from open to password, add an email check, or move to a restricted list at any time from the link's settings; the same URL keeps working under the new rule.
No. A blurred thumbnail would mean the real content was already fetched before access succeeded. The placeholder shown instead carries no filename, title, thumbnail, text, or other content-derived detail at all — that's the point of a document-first gate.
A password is only as good as how it's shared — send it over a separate channel from the link itself if that matters for the artifact. Email verification confirms an inbox, not a person's identity. Restricting to a company domain relies on the recipient's own email address, not a directory you control. For view-level tracking on top of any of these gates, see tracking who opened your shared reports; for the pillar overview see sharing AI-generated work with clients. Reference the exact policy shape at the MCP reference. Consultancies gating every client deliverable this way should also see client delivery for AI consultancies.
Free 14-day Pro trial starts when you publish your first link. No card.
See pricing for plan limits.
Written by Marcel Seibold, founder of sendhey.
About · Privacy · Legal notice · Report illegal content · Terms · DSA