Choose Private when only you and selected viewers should be able to watch a YouTube live stream. Use Unlisted only when anyone who receives a forwarded link may watch; it is convenient, but it does not restrict access to named people.
If you are protecting a channel, secure more than the video setting. Protect the associated Google Account, grant collaborators channel permissions instead of sharing sign-in details, and replace a stream key if it may have been exposed.
Choose a visibility setting that fits
YouTube’s visibility choices affect who can watch a video and how it can be found. For a live stream that should be limited to particular people, Private is the appropriate starting point. You can select the people who are allowed to view it; the stream will not be shown in search, and comments are unavailable on private videos. Check YouTube’s visibility guidance for the current details and controls.
Unlisted has a different purpose. It keeps a video out of ordinary search and channel listings, but anyone with the URL can watch and pass that URL to someone else. Public is openly viewable and may appear on your channel and in discovery surfaces. Neither Unlisted nor Private should be treated as a guarantee that nobody can copy, record or otherwise gain access to what a viewer can see.
| Setting | Who can watch | Can a viewer reshare access? | Discoverability | Comments |
|---|---|---|---|---|
| Private | The creator and people selected for sharing | Access is limited to selected viewers, but do not treat the setting as protection against copying what a viewer can see | Not shown in search | Unavailable |
| Unlisted | Anyone with the URL | Yes; the link can be forwarded | Not shown in ordinary search or channel listings | Available |
| Public | Anyone on YouTube | Yes; it is openly viewable | May appear on the channel and in discovery surfaces | Available |
The table describes the distinction that matters most: Private is for selected viewers; Unlisted is for convenient link-based distribution. If you are preparing an all-night devotional broadcast or a local news test that only a few named people should review, choose Private. If the stream is intended for a community and you are comfortable with viewers forwarding the link, Unlisted may suit the distribution plan, but it does not make the audience exclusive.
Set and confirm the visibility for the stream itself before you start. If YouTube creates a replay or archive afterwards, check its visibility too rather than assuming it inherited the setting you intended. For a practical overview of a prerecorded playlist workflow, the guide to live-streaming a video playlist on YouTube can help you plan the content side separately from access control.
Why Unlisted is not access control
A link is a pointer, not a list of approved people. When you send an Unlisted URL to a colleague, that person can pass it on; a later recipient may be able to watch without asking you. YouTube does not require every viewer of an Unlisted video to be individually approved. That is why an unlisted rehearsal link can spread beyond the small group you meant to invite.
This can be useful. For example, a shop owner might send a private-to-the-business preview link to a few staff members and accept that it could be forwarded. If that is the actual requirement, Unlisted avoids making the video publicly discoverable while keeping access simple. But if the stream contains a closed meeting, an internal training session, or a test with material that should only be seen by named accounts, link obscurity is not a substitute for selecting viewers through Private sharing.
The same reasoning applies to a stream key and a video URL: they solve different problems. The visibility setting concerns viewers. A stream key is part of the connection between YouTube and the encoder that sends the broadcast. A key does not decide who is allowed to watch the finished stream, and a Private setting does not secure a Google Account whose owner has lost control of it.
Do not promise yourself that any one setting prevents all copying or access. A person who is allowed to watch can still capture what appears on their screen, and account or production access can create risks beyond the URL. Instead, decide what you need to limit: discoverability, the set of viewers, the ability to start a broadcast, or control of the channel. Use the corresponding control for each.
Secure the Google Account behind the channel
Your YouTube channel is tied to a Google Account, so stream visibility cannot protect it from someone who can sign in as you. If an unauthorised person can access the account, they may be able to change channel settings, alter streams or interfere with your work. Begin with the Google Account security settings, not by changing only the video’s visibility.
Turn on 2-Step Verification and consider using a passkey as the second verification method. YouTube’s channel security guidance recommends a passkey for stronger protection against threats such as phishing. A physical security key is another sign-in factor documented by Google Account Help. These measures protect sign-in; they do not make an Unlisted stream private or decide which viewers can watch.
Use the current account security page to review recovery information and the devices or sessions associated with the account. Remove anything you do not recognise, update recovery details you can no longer access, and use a strong sign-in method that your team can reliably keep available. If you suspect a takeover, recover and secure the Google Account first. Do not assume that changing a stream key alone removes an intruder who still has account access.
For a small team, the owner should secure their own account and ask channel managers to secure theirs as well. An account is only as well protected as the people who can administer the channel. A dedicated security key can be useful for an owner who wants a physical sign-in factor, but it is optional and is not a viewer-access control.
Give collaborators channel permissions, not your password
Sharing the account password may seem like the fastest way to let a helper start or monitor a broadcast. It also gives that person access as you, makes it harder to limit their work, and complicates removing access when a project ends. Use YouTube Studio’s channel permissions to invite each collaborator under a role that matches the work they need to do. YouTube explains the available roles and access controls in its channel permissions guide.
Start with the task, then choose the least access that permits it. Someone who only needs to help with channel content may not need authority to manage permissions or stream settings. A person responsible for production may need more access, but that does not mean every collaborator should receive owner-level control. Read the current role descriptions before inviting anyone, because available capabilities can change.
One distinction matters if a key needs to be replaced: YouTube says only channel Owners and Managers can reset stream keys; Editors cannot. Do not give a person a broader role solely because they might someday need to reset a key. Instead, decide who is trusted to perform that administrative action and ensure that person knows the recovery process. Roles are a way to reduce unnecessary access, not a promise that every action can be safely delegated.
Review the permissions list when someone stops working on the channel, finishes a temporary event or no longer needs their role. Remove their access promptly, and make sure they are not still using shared sign-in details from an earlier arrangement. If you run a 24/7 channel with a separate operator, document who can start, stop or configure the broadcast so that urgent access does not depend on passing passwords around.
Reset a stream key if it may have been exposed
Treat a stream key as confidential. It is part of the connection used by an encoder to send a broadcast to YouTube. If it has appeared in a screen recording, public screenshot, shared document, support conversation or a computer that someone else could access, treat it as potentially exposed rather than trying to judge whether anyone used it.
To respond, a channel Owner or Manager should open YouTube Studio’s Live Control Room and reset the key. YouTube’s stream key guidance describes the key and its role in connecting YouTube with an encoder. After resetting it, replace the saved key in the software or service that sends the broadcast. A reset is not complete operationally until the encoder is using the new key.
If you use OBS or another encoder, update the saved stream settings before your next broadcast and check which key is selected for the new stream. Reusing a saved stream configuration can carry forward an older key, so do not assume that changing it in Studio also updates your encoder. Run a preview or test connection where practical, then confirm that the intended stream is receiving the signal. The guide to monitoring an OBS stream and restarting it when it goes offline covers a different operational problem, but it is useful context for keeping the sending side observable.
A stream key reset addresses the key, not every possible compromise. If you think someone has taken over the Google Account or gained channel permissions, secure the account and review permissions as well. Likewise, changing a password will not necessarily replace a key saved in an encoder; check both sides. Keep keys out of screenshots, public documentation and messages that are not restricted to people who genuinely need them.
Review access before you go live
A short preflight check catches mistakes that a strong password cannot. In Live Control Room, confirm that you are looking at the intended stream, verify its visibility, and check that the correct encoder and key are selected. If the broadcast is restricted, confirm that the invited viewers are the people you meant to select, rather than relying on an old link that may have circulated.
Then check the channel access list. Remove collaborators who have finished their work and confirm that each remaining person still needs their role. Keep owner and manager access limited to trusted people, especially because those roles can perform administrative actions such as resetting a key. Review any shared production documents or screenshots for stream keys or sign-in details before they are reused.
The content itself is part of the review. Check the camera frame, desktop capture, audio and chat for information you did not intend to broadcast. A test screen can reveal a private meeting link, account details, or a conversation heard in the background. Previewing the stream helps you spot such material before viewers see it; it does not guarantee that no one can capture or redistribute content.
A 24/7 stream needs a repeatable routine rather than a single setup-day check. Before changing a playlist, encoder or operator, confirm who has access and whether the stream’s visibility still matches the audience. If you use OBS, the article on routing audio for selective recording may help with production choices, but it is separate from YouTube’s viewer permissions. For continuous broadcasts, a cloud-based workflow such as StreamNeo can remove the specific burden of leaving your own computer running; it does not replace YouTube visibility controls or account and team-access checks.
Keep a simple incident sequence where the people responsible can find it: secure the Google Account if it may be compromised; remove unneeded channel access; reset a possibly exposed key and update the encoder; then verify visibility and the intended stream in Studio. If you cannot confidently regain account control, use Google’s current recovery process before resuming the broadcast. Follow the current instructions in YouTube Studio and Google Account settings, since interface steps can change.
Before committing, compare the operating options on the pricing page. When the file and channel are ready, start free — 24-hour trial, no card.
FAQ
How do I make a YouTube live stream private?
Set the stream’s visibility to Private in the current YouTube Studio controls and select the people who should be able to view it. Confirm the setting for the stream before starting, and check the replay or archive afterwards. Private limits viewing to selected people; it does not guarantee that an authorised viewer cannot copy what they can see.
Is an Unlisted stream private if I do not post the link?
No. Unlisted means that the URL is not ordinarily shown in search or channel listings, but anyone with the link can watch and reshare it. Use it when forwarding the link is acceptable, not when each viewer must be individually selected.
What should I do if my YouTube stream key is compromised?
Ask a channel Owner or Manager to reset the key in YouTube Studio’s Live Control Room, then replace the saved key in the encoder before the next broadcast. Check which key is selected for the new stream rather than assuming saved settings updated automatically. If account access may also be compromised, secure the associated Google Account and review channel permissions.
How do I stop someone accessing my YouTube channel?
If you suspect unauthorised account access, secure and recover the associated Google Account first, including its sign-in and recovery settings. Then review channel permissions, remove access that is no longer needed, and check stream settings and keys. Visibility settings control viewers of a video; they do not remove someone’s access to the channel itself.