Use require_auth for anything customer-facing instead of relying on obscured URLs. Store the meeting_token per participant and treat it like a password - anyone with the token can join.

Context: Tavus supports authenticated private conversations (official docs). Set require_auth to true when creating the conversation. The response then includes a meeting_token - join links must carry that token, otherwise participants cannot enter. Magic Canvas cards only render if the preview feature is enabled on the account; the app talks to production (https://tavusapi.com) only.