Skip to content
RoundMeet

Three ways to keep strangers out of your meeting

A meeting link is a URL, and a URL travels. RoundMeet gives you three separate controls — the access token in the invite, a password lock on the room, and a lobby that makes you approve each person by name. Here is what each one actually stops.

Founder & Platform Engineer, RoundMeet · Builds and operates the RoundMeet stack end to end — Jitsi/WebRTC media, the Django API, and the React meeting client.

7 min read

The uncomfortable thing about a video meeting link is that it is a URL. It gets pasted into a group chat, forwarded to somebody who could not make it, and copied into a calendar invite that syncs to three other calendars. None of that is a breach; it is what links are for. It just means "the link is private" cannot be the whole plan.

RoundMeet has three controls for this, and they answer three genuinely different questions. This post is about which one to reach for.

Where the controls live

All three are in one place. In a meeting, open the More (⋮) menu in the control bar and choose Security.

If you are not the host, that panel says so — *"This meeting's security is managed by the host"* — and shows nothing else. That is deliberate. A participant who can see which protections are off knows exactly which door to try.

1. The access token: proof you were invited

Every meeting has an access token, shown at the top of the Security panel with a Copy button next to it.

It is not a password you type at a prompt. It is the part of the invite that says *this person was invited*, and it travels with the link you share. Its job is to stop someone who guessed or scraped a room name from walking in.

That makes it a good default and a weak boundary. It protects against a stranger who never had the invite; it does nothing at all once the invite itself has been forwarded — and the whole reason the other two controls exist is that invites get forwarded constantly, usually with the best intentions.

Use the Copy button rather than retyping it. It is the most commonly mistyped thing in the panel.

2. The password lock: a shared secret at the door

In the Security panel, Password lock has a text field and a Lock button. Type a password, press Lock, and the room is locked; the panel then reads *"This room is locked with a password"* and offers Remove password instead.

Anyone joining from that point on has to enter it. That is the important qualifier:

A password is the right control when you can get the secret to the right people over a *different channel* from the link. Sent in the same message as the link, it adds a step and no security whatsoever: whoever forwards one forwards both.

Two practical notes. Set the password before you announce the meeting, not in the first minute, or the early arrivals will be locked out by a lock you added while they were joining. And pick something you can say out loud on a phone call — a password that has to be spelled character by character over a bad line costs more time than it saves.

3. The lobby: you approve each person by name

Lobby (waiting room) is a single toggle. Turn it on and nobody joins directly any more. They land in a waiting state, and their name appears in your Security panel with two buttons: Admit and Deny.

This is the only one of the three that lets you *see who is asking before you decide*. The other two are locks — the right key opens them and there is no judgement involved. The lobby is a door with a person behind it.

That makes it the correct choice whenever the meeting has people from outside your organisation in it: an interview, a client call, a class where you know the roll, anything where a name you do not recognise is itself the signal. It is also the only control that helps against the one failure the others cannot touch — a link forwarded to someone who *was* trusted and no longer is.

The cost is real, though: someone has to be watching the panel. If you are presenting to forty people, admitting them one at a time while you talk is not workable, and the latecomer knocking at minute twenty will sit there. For large sessions, prefer the password, or turn the lobby off once the meeting has properly started.

Which one should you use?

SituationReach for
Internal stand-up, same team every dayThe access token in the invite is enough
Client or partner callLobby — you want to see the names
Interview or one-to-oneLobby
Class with a known rollLobby at the start, off once the class has begun
Webinar or all-hands, dozens joining at oncePassword, shared over a different channel
Anything you are recordingLobby, so nobody joins after the announcement without being seen
The link has definitely leakedPassword lock, then re-share the invite

They stack, and stacking is normal. A token plus a lobby is the everyday combination for meetings with outsiders in them. All three at once is not paranoid, just slow.

The part no control covers

Everything above governs *joining*. Once someone is in the room, the questions are different, and they have different answers:

  • Someone is in and should not be. Open the Participants panel and remove them. Then lock the room so they cannot walk back in.
  • You are recording. Say so out loud. Everyone sees the red REC badge and hears the chime, but the badge is a notification, not consent — see how recording works.
  • Someone is disrupting the meeting. Mute them from the Participants panel; that is faster than removing them and usually enough.

Does locking the room kick out people who are already in it?

No. The lock applies at the door, to anyone joining afterwards. To remove someone already in the meeting, use the Participants panel.

Can I use a password and a lobby together?

Yes. They are independent controls and both apply — a joiner enters the password and then waits for you to admit them.

Where do participants type the password?

They are prompted for it as they join, before they reach the room. There is nothing they need to do in advance.

If I turn the lobby on mid-meeting, what happens to people already inside?

Nothing. They stay. The lobby only holds people who arrive after you enable it.

Can participants see whether the lobby or a password is on?

Not from the Security panel — it only shows them that the host manages security. They find out at the door, which is where it matters.

I locked the room and now I cannot remember the password.

Open the Security panel and press Remove password, then set a new one. The host can always clear it; there is no recovery flow because none is needed.

The short version

The access token proves an invite. A password proves a shared secret. The lobby proves you looked at the name. Pick the one that matches what you are actually worried about — and if you are worried about a forwarded link, only the lobby helps.

About Astik Gabani

Founder & Platform Engineer, RoundMeet · Builds and operates the RoundMeet stack end to end — Jitsi/WebRTC media, the Django API, and the React meeting client.

Astik builds and runs RoundMeet: the WebRTC media tier, the Django control plane that mints room tokens, and the React client people actually meet in. He writes here about how the platform works, from the operator's side of it.

More from Astik Gabani →