Deployment bypass
Vercel Deployment Protection requires a Vercel login to open a preview. Reviewers usually don’t have Vercel accounts, so a thread link to a protected preview stops at Vercel’s sign-in page. When you add your Vercel bypass secret to a project, links from Skyelight open the preview directly.
Set it up
The secret applies to the whole project, not to one preview address, so it has its own card below Review Links.
Shareable Links are not accepted
Skyelight refuses Vercel Shareable Links, because they expire after a week. A reviewer who opens an expired link sees an error and may assume the preview is broken. The bypass secret keeps working until you rotate it in Vercel.
What changes for reviewers
Without the secret, a reviewer who opens a thread from an email or the web app sees Vercel’s login and can’t continue.
With the secret, links that Skyelight builds to your protected preview include
an x-vercel-protection-bypass value, and Vercel lets them through. Reviewers
still sign in to Skyelight to leave feedback. The bypass only gets them past
Vercel’s login.
Who can see the secret
Skyelight stores the secret encrypted and never sends it to the review badge on your site. It is included in the links Skyelight opens for workspace members, including reviewers, because those links need it to reach the preview. Anyone who can open your project’s threads can therefore reach the preview. If the secret leaks, generate a new one in Vercel and choose Replace key from the key’s menu in Review Access.
To turn the bypass off, choose Revoke from the key’s menu in Review Access. Links then stop at Vercel’s login again.