Skip to content
All insights

What Is a One-Time Link and When to Use One

On this page
  1. What a one-time link actually is
  2. When to use a one-time link
  3. One-time links, revocation and the difference between them
  4. How 99 Data Rooms handles one-time and controlled links
  5. Try controlled links for free
  6. Sources

What is a one-time link? It is a share link designed to work once, or for one specific person, and then stop. Instead of a URL that anyone can open, forward and reopen indefinitely, a one-time link is tied to a single recipient or a single use, so that once it has served its purpose it cannot be reused by whoever gets hold of it later. That single design choice removes the biggest weakness of ordinary file sharing: the link that keeps working long after you meant it to. This guide explains what a one-time link actually is, how it differs from a normal share link, when it is the right tool, and how 99 Data Rooms uses the idea to keep sensitive documents under control.

If you have ever emailed a Dropbox or Google Drive link and then realised you had no idea who else it might reach, you already understand the problem a one-time link solves, and why we argue there is one thing a Dropbox link simply cannot do. Sensitive documents, an NDA, a term sheet, a set of accounts, an offer letter, should not travel on links that outlive their purpose. Below we cover the mechanics, the use cases, and the honest limits.

A one-time link is a share URL with a built-in expiry condition based on use rather than only on time. The most common form is single-use: the link opens the document once and then deactivates, so a forwarded copy is a dead end. A closely related form is per-recipient: each person you share with gets their own distinct link tied to their verified identity, so even if the link is passed on, the next person cannot open it without passing the same identity check.

Contrast that with an ordinary share link, the kind most consumer file tools generate by default. A standard link is effectively a public door with a long, hard-to-guess address. Anyone who has the URL can open it, reopen it, and forward it, and the document keeps rendering for all of them until you remember to go back and switch the link off, if the tool even lets you. There is no natural end. That is fine for a holiday photo album and genuinely dangerous for a cap table.

The point of a one-time link is to make "shared" mean "shared with one person, once" rather than "published to anyone who ends up holding the URL". It closes the gap between who you intended to reach and who can actually get in. It is one of a family of controls, alongside expiry dates, access gates and revocation, that turn a bare link into a controlled one. If you want the broader picture of how access control fits together, our gating and access-control page is the place to start.

A one-time link earns its place whenever a document is sensitive, time-bound, or meant for exactly one recipient. Here are the situations where it is clearly the right call.

Sending something confidential to a single named person. If you are sharing a contract, an NDA, financial statements or an offer letter with one individual, a per-recipient one-time link means only they can open it, and a forward does not silently widen your audience. This is the everyday case, and it is where the difference from an email attachment is starkest, because an attachment is copied the instant it is downloaded, which is why we call the email attachment the riskiest way to send a contract.

Sharing during a negotiation or a deal. When you send a term sheet or draft agreement that is likely to change, you do not want the first version circulating forever. A single-use link keeps the document from becoming a permanent, forwardable artefact, and it pairs naturally with version control so that superseded drafts genuinely go away.

Distributing something on a deadline. A one-time link supports the discipline of "this is available now, for you, and not indefinitely". It is a close cousin of link expiry, and the two are often used together. Deciding how long any link should remain usable is its own small skill, which we cover in how long a share link should stay live.

Where a one-time link is overkill: genuinely public material, marketing collateral, or documents you actively want people to forward. Do not reach for single-use controls on a file whose whole purpose is to spread. The tool should match the sensitivity. For anything covered by a confidentiality obligation, though, single-use or per-recipient links are the sensible default, and they work best alongside a signed NDA, which our explainer on what an NDA is and when you need one unpacks.

A common point of confusion: is a one-time link the same as revocation? They are related but not identical, and understanding the difference helps you use both well.

A one-time link controls access at the moment of sharing. You decide, in advance, that this link should work once or for one person, and the system enforces that automatically. It is a rule set at the start.

Revocation controls access after the fact. Even a link you intended to leave open can be switched off at any moment, including while someone is mid-read, so access ends the instant you decide it should. It is an action you take later. We cover the mechanics on our one-click revocation page, and the practical guide to pulling a document back sits in how to un-send a document you already shared.

The two work as a pair. A one-time link handles the predictable case ("this is for one use") without you having to remember anything. Revocation handles the unpredictable case ("circumstances changed, cut it off now"). Between them, you never have a document that keeps opening for people you can no longer see or control. The honest limit worth stating: neither control stops a person from screenshotting or photographing what they have already been allowed to see in the seconds it is on screen. Access control decides who gets in and for how long; it does not turn a viewer into someone who cannot use their own eyes. For that reason, sensitive material should combine one-time links with tracking and, where it matters, watermarking, so that a leak is at least traceable.

In 99 Data Rooms, controlled links are the default way documents move, not an advanced setting you have to hunt for. When you share a document from a room, you share a tracked, revocable link rather than an attachment. You can issue one link per recipient, tied to a verified email and a one-time code, so the person opening the file is the person you meant to reach, and a forward simply hits the same identity gate. You can set an expiry so the link stops working after a chosen point, and you can revoke any link in one click, even mid-scroll, if something changes.

The links do not sit in isolation. A document can be drafted from vetted England and Wales clauses using the AI Legal Drafting feature, which assembles vetted clauses and never invents them, placed in a room, gated so only verified viewers get in, shared as a controlled link, tracked with page-by-page analytics that distinguish a raw visit from a verified viewer, watermarked on the Business tier, and revoked in one click. The one-time or per-recipient link is simply the entry point to that whole controlled journey. Because everything is UK-hosted in London with no third-party viewer trackers, the link you send stays inside a system you can actually see and control, which is the entire point.

A one-time link turns "I shared a file" into "I shared it with one person, once, and I can pull it back". In 99 Data Rooms every share is a tracked, revocable, per-recipient link by default, with gating, analytics and one-click revocation built in. The free tier is a real tier, not a trial: three rooms, twenty-five active links, forever, no card required. Start for free, send a controlled link, and see how different it feels from firing off an attachment. The platform is in beta and improving fast, but controlled sharing already works exactly as it should.

Sources

Questions, answered
What is the difference between a one-time link and a normal share link?

A normal share link works for anyone who holds the URL, reopens indefinitely, and can be forwarded freely until you manually disable it. A one-time link is designed to work once, or for a single verified recipient, so a forwarded copy is a dead end. It closes the gap between who you meant to reach and who can actually get in.

Does a one-time link stop someone screenshotting my document?

No. Access control decides who can open a file and for how long; it cannot stop a person from photographing or screenshotting what they have already been allowed to see. That is why sensitive documents should pair a controlled link with tracking and, where it matters, watermarking, so a leak is at least traceable.

Is a one-time link the same as revoking access?

Not quite. A one-time link is a rule set in advance (work once, or for one person). Revocation is an action taken later (switch this off now, even mid-read). They complement each other, and 99 Data Rooms offers both, as covered on our revocation page and in how to un-send a document.

When should I not use a one-time link?

When the document is meant to be public or shared widely, such as marketing material you want forwarded. Single-use controls are for sensitive, time-bound, or single-recipient documents, not for content whose purpose is to spread.

Can I set how long a link stays usable?

Yes. In 99 Data Rooms you can set an expiry on a link and revoke it at any time. Choosing a sensible expiry is its own decision, which we walk through in how long a share link should stay live.

Keep reading