Link access and sharing
Every Aozumi app sits behind a gateway that decides who may open it. You choose the audience, and you can change it, share it, or take it back at any time.
The three settings
| Setting | Who can open the app | CLI flag |
|---|---|---|
| Public | Anyone with the link. Production only. | --public |
| Team | Members of your Aozumi workspace. | --team |
| Private | Only people you invite or give a share link. | --private |
Public access exposes the running site only: never the source code, the workspace, the deploy controls or other environments.
Defaults
- Console import from GitHub: you choose a first audience. “Anyone with the link” is preselected; “Only me” and “Specific people” both mean private.
- CLI: a new site asks once in a terminal, defaulting to private, and is private when there is no terminal. See CLI link access.
- AI agent (MCP): the
importtool defaults to your team; the agent can choose “Only me” or “Specific people” instead.
Change link access
Open the app's Access tab and choose who can open the production link. From the CLI, deploy with --public, --team or --private. Making an app public or team-visible needs a workspace role that can manage apps, and every change is recorded in the audit log.
Invitations and roles
Invite people by email from Share or the Access tab. App invitations grant one of two roles: viewer, who can use the app, or builder, who can also change it. App access and workspace membership are separate, so someone who only needs to use your app does not need access to your other apps or settings.
Access requests
When someone without access opens a private app, they can ask for access. People who manage the app see the request and approve or deny it; approved people get access without you sending a separate invite.
Questions
- Is my link public?
- Only if the app's link access is set to public. In the console's GitHub import, "Anyone with the link" is preselected as the first audience, so change it before importing if the app is not for everyone. New CLI sites are private unless you choose otherwise, and apps imported by an AI agent default to your workspace team. Only the Production environment can be public. You can change the setting at any time.
- What does a public Aozumi app expose?
- Only the running site. Public access never exposes the source code, the workspace, the deploy controls or other environments.
- How do I stop someone from opening my app?
- Turn off the share link they used, remove their invitation or membership, or change the app's link access to team or private. Changes apply to new requests through Aozumi's gateway.
Checked against the product on .