ShortFreeURL for Enterprise
Single sign-on, team separation, per-link permissions and data you can export.
At scale a link platform stops being a marketing convenience and becomes shared infrastructure. The questions change: who can create links on which domain, who can repoint a link that is printed on a million units, how access is revoked, and how the data reaches your warehouse.
Identity and access
SAML 2.0 single sign-on works with the usual identity providers, so joining and leaving follow your existing process rather than a separate user list. Roles run from owner and admin through standard user to read-only.
Per-link permissions cover the cases roles cannot: a specific link that must not be edited by anyone outside a named group, regardless of their general role.
- SAML 2.0 SSO with standard identity providers
- Owner, admin, user and read-only roles
- Per-link permissions independent of role
- Team-scoped API tokens
Organisational structure
An organisation holds multiple teams. Each team has its own domains, folders, members and reporting scope, which maps onto business units, regions or brands without those groups seeing each other's work.
Folder defaults push conventions down to the point of creation, so a link made by someone in a regional team inherits the right domain, tagging and status code without a policy document.
- Multiple teams inside one organisation
- Per-team domains, folders and members
- Folder and domain-level defaults
- Membership across teams from a single account
Governance of live links
The risk at scale is not creating links, it is changing them. A link printed on packaging, embedded in shipped software or used in a regulated communication needs to be protected from casual edits. Per-link permissions and read-only roles handle that directly.
Where a link genuinely must be withdrawn, editing the destination or expiring it takes effect immediately for new requests, so a communication can be redirected to a notice page without waiting for a page to be taken down.
- Locked links protected from edits
- Immediate redirect or expiry when a link must be withdrawn
- Fallback destinations rather than dead ends
- Domain-level 404 recovery
Data, privacy and retention
IP hiding and truncation keep full addresses out of the click log, retention windows are configurable, a DPA is available, and everything exports — aggregates and raw events alike.
Because export is complete, evidence for an internal review or a regulator does not depend on our reporting screens, and leaving the platform never means losing history.
- IP hiding and configurable retention
- DPA available
- Full export of links, settings and analytics
- Aggregates retained after raw events age out
Integration with your systems
The REST API covers everything the dashboard does, with published rate limits and bulk endpoints. Webhooks stream click events, signed and retried, into your own pipeline so the data lands in your warehouse rather than staying in a vendor dashboard.
Conversion tracking joins clicks to outcomes server-side through a click identifier, which fits backend systems rather than requiring a client-side tag.
- REST API with full feature parity and bulk endpoints
- Signed, retried webhooks
- Server-side conversion reporting with values
- Integrations including Zapier, Make, Slack and GitHub Actions
Reliability and migration
Redirects are served from a cache-first path independent of the dashboard, so link resolution is not coupled to the availability of the application people log into. Status codes are configurable per link, folder or domain.
Consolidating from several tools is a supported operation: CSV and XLSX import, a dedicated Bitly path that preserves short codes, and bulk editing to normalise domains and tagging afterwards.
- Redirect path independent of the dashboard
- 301, 302, 307 or 308 per link, folder or domain
- CSV, XLSX and Bitly import
- Bulk normalisation of domains and tagging after migration
Questions
Do you support SAML single sign-on?
Yes, SAML 2.0 with the common identity providers, so access follows your joiner and leaver process.
Can we stop specific links from being edited?
Yes. Per-link permissions restrict editing independently of a user's general role.
How do we get click data into our warehouse?
Signed webhooks for streaming, reporting endpoints for scheduled pulls, and CSV export for backfill.
Can we control what click data is stored?
Yes, through IP hiding or truncation and configurable retention windows, with a DPA available.
How are business units kept separate?
Each becomes a team with its own domains, folders, members and reporting scope, inside one organisation.
What happens to redirects during maintenance?
They continue. The redirect path is separate from the dashboard application by design.
Bring every team onto one link layer, with the controls to match.
Start Free — no credit card
The free plan includes 1,000 links, 6 custom domains and 50,000 tracked clicks a month, free forever. Choose a free subdomain from six shared domains. Paid plans start at $4 a month when you outgrow it, and you keep everything you have built.

