Answer
GitBook lets you publish a space as Public while keeping some versions as drafts. To block those draft URLs for unauthenticated visitors you must enable the "Allow draft access" toggle in the space’s visibility settings. If the toggle is off, draft links return a 403 error even when the space is public.
Why It Works
When a space is set to Public, GitBook’s UI still requires the draft access flag to expose any draft content. The flag is a per‑space setting, not a global feature, so you can keep the rest of the space public while protecting drafts.
Step‑by‑Step Workflow
- Log in to the GitBook admin console.
- Navigate to the target space.
- Open the
Settings > Visibility panel.
- Set
Visibility to Public.
- Toggle "Allow draft access" ON.
- Save changes and wait a few seconds for propagation.
- Test the draft URL in an incognito window. It should now be inaccessible to unauthenticated users.
API‑Based Verification
If you prefer to confirm via the REST API, use a token that includes the draft scope:
curl -H "Authorization: Bearer <token>" \
https://api.gitbook.com/v1/spaces/<spaceId>/drafts
A 200 OK response means the draft is publicly accessible; a 403 Forbidden indicates the toggle is still off.
Things to Watch Out For
- Enabling draft access exposes unfinished or unreviewed content to all visitors. Review drafts before toggling.
- Draft URLs can be indexed by search engines unless blocked via
robots.txt or meta tags.
- Changing visibility may affect integrations that rely on the space being private.
Future Features?
There is no announced “Hide drafts from public” toggle in a separate release; the existing setting is the intended mechanism. Check the GitBook roadmap or community forum for updates.
Missing Diagnostic Detail
Does the space have at least one published version? If the space has never been published, it remains a private draft and the public toggle will have no effect. Confirm that a version has been published before enabling draft access.