The decision
A paid archive under a public directory is available to anyone who knows or guesses the URL. Moving the buy button does not change that. Store the archive outside public assets and use a server route that verifies entitlement before returning it. A download link is sensitive if possession alone grants access.
A worked example
The launch kit stores its ZIP in a private product directory. The download route validates the checkout session and current charge state, then streams the file with private, no-store caching and a download filename. The public free scorecard lives in a separate samples directory and remains accessible without payment.
How to put it into practice
- Separate free samples from paid assets in the filesystem and deployment artifact.
- Validate the product, payment status, and refund state for every protected download.
- Return controlled errors without exposing internal file paths or provider details.
- Test the built deployment bundle, because local file access does not guarantee the archive is packaged in production.
A failure to plan for
A permanent bearer link can be shared. For stronger account-level access, bind purchases to authenticated users and rotate or expire download credentials. Choose the design based on the product rather than promising impossible prevention of copying.
Try it on your project
Request the old public archive URL and verify it is unavailable. Then test the protected route without a token, with an unpaid token, and with a valid paid test fixture. Check response caching and referrer headers.
Keep the next step small
Use the free demand scorecard or planning tools to make your assumptions explicit. The $19 launch kit brings the blueprint and seven editable worksheets together.