No raw media URLs
Protected files stay private. Clients receive short-lived stream URLs only after entitlement checks.
Security architecture
MusicTap keeps durable media and entitlement decisions server-side. The tag contains an opaque unlock URL; the backend controls the active lease, metadata access, and signed stream URL issuance.
Protected files stay private. Clients receive short-lived stream URLs only after entitlement checks.
Generated tags start inactive. TagWriter must write and read them back before listener scans are enabled.
A new scan of the same physical tag revokes the prior session and creates a fresh lease for the current holder.
Each run is tracked with status, physical serial, write state, verification state, and resource mapping.