
Are Claude Artifacts Public? What the Link Actually Exposes
An artifact is private until you publish it — and a published one is unlisted, not secret. Here's exactly who can see what, and how to share something that stays genuinely restricted.
Short answer: no, not by default — and yes, completely, the moment you publish one. There is no middle setting.
That gap is worth understanding before you publish something with a client's name in it, because "published" in Claude does not mean "shared with the people I chose". It means "anyone holding this URL can open it, with no Claude account required".
The three states an artifact can be in
Private (the default). An artifact lives inside one conversation in your account. Nobody else can reach it. Closing the tab doesn't expose it; neither does the artifact existing for months in your history.
Published (Free, Pro, Max). You click Publish, Claude gives you a public link, and that link works for everyone. No sign-in wall, no allowlist, no expiry you control. Viewers who happen to have Claude accounts can also take a copy and remix it into their own conversation — which is a feature when you're sharing a template and a surprise when you're sharing a draft.
Shared within an organization (Team, Enterprise). On those plans the control is Share rather than Publish, and the link only resolves for members of your own org, who must be signed in. This is the one genuinely access-controlled option Claude offers, and it's unavailable on personal plans.
"Unlisted" is not "private"
The most common misreading is treating a published artifact link like a secret. It isn't a password; it's an address. The realistic exposure is:
- Anyone you send it to can forward it. The link carries no identity, so there is no difference between the person you sent it to and the person they sent it to.
- It travels through everything the link touches. Pasted into a Slack channel, it's readable by that whole channel and by anything indexing it. Pasted into a ticket, it's in the ticket forever.
- Search engines can find it if it's linked anywhere public. Crawlers don't guess URLs, but they absolutely follow them. One link from a public forum post is enough.
- You can't see who opened it. There's no view log, so "did this leak" is a question you can't answer after the fact.
None of that is unusual — it's how unlisted links work everywhere, including Google Docs' "anyone with the link" and Notion's public pages. It only becomes a problem when someone assumes otherwise.
So what's actually safe to publish?
A useful test: would you be comfortable if this URL appeared in a public Slack? If yes, publish freely — a demo, a template, a portfolio piece, a landing page draft. That covers most artifacts.
If no — a client deliverable with pricing in it, an internal dashboard, anything with a real person's data — publishing is the wrong tool, and Claude on a personal plan doesn't offer a right one.
Getting real access control
Two options, depending on what "restricted" means to you.
If you're on Team or Enterprise, use Share instead of Publish. Org-scoped and authenticated — that's genuine access control and it's the correct answer when your audience is your colleagues.
If your audience is outside your org, you need a host that can put a lock on the page. Copy the artifact's code and publish it with a password: the recipient gets a URL like any other, but opening it asks for a password you set. Forwarding the link alone doesn't grant access, which is exactly the property an unlisted link lacks.
That route also gives you the two other things a published artifact can't do: a link you can take down on your own terms, and one that doesn't hand viewers a remix button into your work.
A note on taking it back down
If you do publish and then think better of it, unpublishing is available — but per Anthropic's documentation it's a one-way door: once unpublished, that artifact can't be published again and its stored data is deleted. So "publish it now, lock it down later" isn't a strategy Claude supports. The full behaviour is covered in how to unpublish a Claude artifact.
Checking what you've already exposed
If you've been publishing artifacts and share links for a while and aren't sure what's out there, the anxiety is reasonable and the question is answerable. We built a share-link exposure checker that builds the site: searches for you — it runs entirely in your browser and sends nothing anywhere.
Bottom line: artifacts are private until you publish, and public the instant you do — publicly readable by anyone with the URL, with no way to restrict, revoke gracefully, or audit. That's fine for most things. When it isn't, either use Team/Enterprise Share, or put the page behind a password somewhere you control.
More Posts

CodePen vs dochost: Where Should AI-Generated HTML Live?
CodePen is an editor with a shareable result, while dochost turns finished HTML from ChatGPT or Claude into a clean link that opens as the page itself.

PDF to Markdown, Word to Markdown, and Six More Converters That Run in Your Browser
A set of free document converters that do the work locally in the browser — no upload, no signup — and hand the result straight to a shareable link if you want one.

Claude Skills vs Projects vs Artifacts: What Each One Actually Is
Three Claude features with overlapping names and completely different jobs. Skills are procedures, Projects are context, Artifacts are output — here's how to tell which one you need.
Newsletter
Join the community
Subscribe to our newsletter for the latest news and updates