How to create a secure client portal for document sharing

Use a Restricted Room link to share client documents, verify approved inboxes, update files, and remove access when the project ends.

02:11 min

Before you start

  • You need a HummingDeck account on Pro or Business, an existing Room, and the email addresses or company domains you want to admit. Restricted access starts on Pro; clients verify their email without creating a HummingDeck account.
  • Prepare any replacement document in the same file type as the original, up to 100 MB. Replace keeps existing links and Room placements, but is unavailable while the document has an active Proposal link with response controls.
  • The optional custom-domain and API workflow uses Business. API access must be enabled for your workspace before you can create links or update their access lists through the API.

Follow the steps

  1. Start from your client's Room

    Open the Room containing your client's documents and next steps. If you have not built it yet, follow the file-sharing tutorial below to create the Room and arrange its documents before setting up Restricted access.

  2. Create a Restricted link

    Choose Create share link, then Restricted. Under Allowed recipients, add each person's email address. Optionally add the client's company under Allowed domains to admit anyone who verifies an inbox at that exact domain. Add subdomains separately and use individual addresses for personal email providers. Access mode is fixed per link, so create a new Restricted link rather than changing an existing open link.

  3. Send the link and verify the client experience

    Generate the link, copy its URL, and send it to your client. The client enters an approved email and follows the access link sent to that inbox; the access link expires after 15 minutes and should be kept private. An unlisted address receives the same on-screen message without an access email. Email verification confirms control of an approved inbox.

  4. Review verified visits

    Open the Room's Activity tab to review visits and the email that verified each one. Use this to follow recorded document activity for the approved inboxes. Verification establishes inbox access and allowlist membership; it does not establish legal identity or decision authority.

  5. Replace a file while keeping the portal link

    Open the document in your Library, choose Replace, select the new file, and confirm Replace Document. Keep the same file type, wait for processing to finish, and check the preview. Existing document links, Room placements, access settings, and activity history remain. Keep a source copy before replacement because the previous file is not retained for restoration, and tell your client about material changes.

  6. Remove a recipient or switch the link off

    Open Link settings and remove the person's allowed email. Their next visit must meet the updated access rules. If an allowed company domain still admits them, replace that domain rule with the individual email addresses of people who should retain access. At the end of the project, switch Link active off to close entry through that link for everyone. Review other Room links separately when ending access to the whole project.

  7. Optionally use your domain and the API

    On Business, connect your own subdomain for client-facing share links. With API access enabled for your workspace, use the HummingDeck REST API to create Restricted Room links and update their allowed email addresses and company domains. Review the access list before sharing each link.

Transcript

Read the transcript

00:00A secure place for a client's files

Here's how to give a client one secure place for their files. Only the people you list can get in, you can update a file without sending a new link, and you can take access away when the work is done.

00:15Start from a Room

A client portal in HummingDeck is a Room: the documents, the next steps, a video and your booking calendar, behind one link. If you haven't built one yet, the previous video shows how.

00:29Choose who can get in

Choose Create share link, then Restricted. Add the people who should get in, here Sarah from Northstar and Jordan, a freelancer on the project. Then allow the company's domain, so anyone with a Northstar email can request access. Everyone on the list confirms their email before the portal opens.

00:53Your client confirms their email

Sarah opens the link and enters her email. HummingDeck sends her a one-time access link that expires in fifteen minutes. She clicks it, and she's in. If the link is forwarded to someone who isn't on the list, they see the same message, but no access link is sent. In the room's activity, each visit shows the email that confirmed it.

01:21Update a file, keep the link

When a file changes, replace it instead of sending a new one. Open it in your library, choose Replace, and pick the new version. The portal link stays the same, and the history is kept.

01:36Remove access

When someone leaves the project, remove them from the list. Jordan's next visit stops at the email check. And when the project ends, switch the link off.

01:51On Business: your domain and the API

On Business, share links can use your own subdomain, and the HummingDeck API can create these links and update who's on the list. Set up your own client portal with the link below.