A WordPress draft preview link that works for you may fail for a client because your browser is authenticated and theirs is not. A preview URL is not automatically a public sharing link. Check the intended review workflow, account permissions and link freshness before publishing a private draft as a workaround.
Compare the two access contexts
Record the affected post ID and whether the content is draft, pending, private or already published. Open a fresh preview from the editor, then test with the authorized reviewer's actual account context. Do not send your session cookies or administrator password.
If the reviewer has no account, decide whether the site supports a separate controlled sharing mechanism. A copied browser URL alone may not confer access. The roles and capabilities reference explains why editing and private-content permissions differ between accounts.
Check freshness and redirects
WordPress's preview handler validates a preview nonce for the relevant path. An old tab or altered query string can therefore fail even though the content still exists.
Generate a fresh link using the editor rather than manually constructing preview parameters. Keep the complete link private. If the site redirects between hosts or schemes, inspect whether the required query parameters survive and whether the reviewer ends on the intended site.
| Observation |
Next check |
| Works only for the author |
Reviewer role and intended sharing method |
| Fresh link works, old link fails |
Link validity and the actual preview mechanism |
| Redirect removes parameters |
Canonical redirect handling |
| Preview opens but shows old content |
Saved draft, autosave and cache behavior |
Reviewer context: Approved account or share method. Fresh link: Correct site and draft revision. Signed-out control: Private content remains denied. Sensitive tokens: Not exposed in logs or tickets. Explanatory checklist, not a customer test result.
Protect draft content during the repair
Do not make the post public merely to get approval on confidential copy. Do not remove nonce verification or make all private posts readable. If a supported preview-sharing plugin is already approved, inspect its expiry, revocation and recipient model before using it.
For a client without suitable site access, a sanitized PDF or protected staging review may be more appropriate. Choose the method based on the content's sensitivity and whether the client needs to test live interactions, not just read text.
Ask the host to verify that authenticated or token-bearing previews are not stored in a shared public cache. A preview that works because someone else's private response was cached is a privacy failure, not a successful fix.
Verify both allowed and denied access
Test a fresh permitted review, an unrelated signed-out browser and the documented expiry or revocation behavior of the chosen sharing method. Confirm that the intended draft revision appears and that navigation does not leak other unpublished content.
If the draft itself has lost content, use targeted page recovery. Access troubleshooting cannot reconstruct a missing revision.
For a broken review process, provide the post status, sanitized error and redirect pattern to HandL WP. Remove real preview tokens from screenshots and tickets. Keep a documented review path so the next client approval does not depend on sharing privileged access.
References reviewed October 5, 2026. Examples are explanatory, not customer test results.