From the [Share] button on your SOP, you can issue external sharing URLs that can be accessed without requiring a Dive account login. Use this when you want to share SOPs with contractors, business partners, event attendees, and others who don't have Dive accounts.
💡 If you're unsure about the difference between "external sharing URLs and guest permissions," first read SOP sharing externally: usage guide. This one-page resource includes a decision chart and comparison table.
The URL you issue is protected by one or both of the following:
- Expiry date: The URL becomes inaccessible after the specified date
- Password: A password must be entered when viewing
Once issued, you can later change the expiry date, rotate the password, disable, or reactivate the URL. A history records who issued which SOP and when.
Before use: Team activation is required
External sharing is disabled by default for security reasons. To use it, an Owner must enable it in team settings.
- For activation steps, see How to configure and use "External sharing"
After activation, users with the appropriate role can use this feature.
Issue an external sharing URL
- Open the SOP you want to share externally
- Click the [Share] button at the top
- In the modal that appears, open the [External sharing (no login required)] tab
- Turn on [Set expiration] and select the expiry date (the deadline is 23:59 on the specified date)
- If needed, turn on [Protect with password] and enter a password (see details below)
- If needed, turn on [Open from the specified step] and select a step (recipients will start from the chosen step instead of the beginning)
- If needed, enter a Comment (for example, "For XX Corporation," "For the presentation," etc. This will be recorded in the history and audit log)
- Click [Issue URL]. The URL is automatically copied to your clipboard and a QR code is displayed
Below the QR code, you can click [Show print screen] to print the QR code in a print-friendly layout.
Required rules for issuing (expiry date OR password)
When issuing, at least one of the following must be met:
- Expiry date is ON and a date today or later is specified
- Protect with password is ON and a password is entered
You cannot issue a "bare permanent URL" with both turned off. If you want to disable the expiry date (make it permanent), password protection is required.
Protect with password
- Manual entry: You can set any password (up to 64 characters)
- Auto-generate: Click the [Auto-generate] button next to the input field to create an 8-character random password in one click, using easily distinguishable characters (excluding 0/O, 1/l/I, etc.)
- Tell the recipient separately from the URL: For security, it's recommended that you send the password via a different channel than the URL (not in the same email). The password is stored as a PBKDF2 hash and is not stored where guests (recipients) can directly read the plaintext
- After issuing, the display below the URL shows "This URL is password-protected. Password: XXXX" and you can copy just the password from the copy button
Behavior immediately after issuing
- The URL is automatically copied to your clipboard. Paste it directly into email or chat to share
- The QR code is displayed immediately. Use it for on-site scanning at presentations and other events
- If password protection is ON, don't forget to notify the password via a separate channel
Specify language when opening
When you enable the [Open with a specified language] checkbox in the sharing modal, the URL and QR code you issue will specify the display language (29 languages) and translation target when opened. This lets you distribute URLs to overseas bases and foreign staff that open in their language from the start.
The setting only applies when that URL is opened. Viewers can select a different language after opening, and this does not override their usual language settings. For details, see How to print QR codes / copy sharing URLs.
Recipient experience
- Recipients can view the SOP without a Dive account or login — simply by opening the URL
- For password-protected URLs, a [Password-protected] input screen appears immediately after opening. The SOP displays after entering the correct password. An incorrect password prevents access
- When the expiry time (23:59 on the specified date) passes, the URL becomes inaccessible
- When a disabled URL is accessed, it cannot be viewed
View and manage issuing history
Below the [Share] → [External sharing (no login required)] tab of the same SOP, a history (mini-list) of URLs issued for that SOP is displayed.
- Copy URL: Re-copy the same URL from each row in the history
- Show disabled / expired: Toggle with a switch (by default, only active URLs are shown)
- Me / Everyone toggle: Owners and Team Administrators can view URLs issued by all team members
- [Edit / Details]: From the top right of the mini-list, open the full-featured "Issued external sharing URLs" list
Issued external sharing URLs list (full features)
In the full list, you can:
- Copy URL: Copy existing URLs for re-sharing
- Change expiry date: Select a new date/time to extend or shorten the expiry (if making it permanent, password protection is required)
- Change password (rotation): Keep the URL the same but replace the password with a new one. Useful when your recipient changes or there's a potential leak
- Remove password protection: You can remove password protection only from time-limited URLs (permanent URLs cannot have protection removed since the password is the only barrier)
- Disable: Prevent access via that URL going forward (useful for accidental issues or ended partnerships)
- Reactivate: Re-enable a disabled URL (use with date changes if the expiry has passed)
- Filter: Search by SOP name, issuer, or comment; filter by state; toggle between "only me" and "entire team" scope
Note: Issuers, Owners, and Team Administrators can view the configured password (plaintext) from the full list (for re-sharing within your organization and addressing communication gaps). The token that guests (recipients) directly read contains no plaintext — only a PBKDF2 hash is stored.
Audit and compliance
All issuing, disabling, reactivating, expiry changes, and password changes for external sharing URLs are recorded in the Audit log. Because it records who issued which SOP, when, and with what comment, you can use it for your internal operations and audit requirements.
Best practices
- Keep expiry dates short: Set the minimum expiry needed for your use case (the default is 7 days from now)
- Use password protection for sensitive sharing: In addition to an expiry date, protecting with a password means that even if the URL leaks, it cannot be viewed. The trick is to send the password via a separate channel from the URL
- Always password-protect long-term reusable URLs: Permanent URLs require password protection. By rotating just the password periodically, you can keep the URL distribution unchanged while maintaining security
- Comment management: Including the recipient name and purpose in comments when issuing makes the history list easier to distinguish
- Disable when no longer needed: Disabling URLs after presentations end or contracts finish reduces the risk of leaks
- Be careful with sensitive SOPs: The design allows anyone with the URL to access it. Confirm that the content is appropriate for external sharing before issuing