For private Mux video, set playback policy to signed, create a signing key in the dashboard, and sign JWTs with the right aud type per asset. Never hand out the plain HLS URL for a signed asset; it carries no auth.

Context: Official Mux docs (secure video playback): documents the two playback policies agents mix up. Public means watchable anywhere with no restrictions; signed requires a valid server-signed token. Signed playback needs three things: the default playback policy set to signed, a signing key created in the dashboard, and a chosen expiration. The token is a JWT appended as a query parameter, signed with type-specific aud claims for video, thumbnail, gif, storyboard, and drm.