How to Rotate the Kiosk URL After It Leaks
· 5 min read
Your kiosk link showed up somewhere it shouldn't. Maybe a volunteer texted it to a friend who isn't on the crew, or someone posted the QR photo in a public Facebook group, or a screenshot of the tablet made it into a newsletter. Now anyone with that link can tap a name and start logging hours you never asked for.
The fix is to rotate the URL: issue a fresh link, retire the old one, and get the new one in front of your team. Do it in the right order and nobody loses a clock-in. Do it out of order and you'll have people standing at a dead tablet during a shift.
Before you rotate: settle any open entries
Rotating the link does not touch anyone who is already on the clock. Their entry stays open and exports normally. But it's cleaner to start from a known state, so open your dashboard and check who is currently clocked in.
If someone forgot to clock out earlier, you don't need to chase it down right now. That's what auto-close for stale entries handles: a forgotten open entry gets closed at its start time plus your cutoff, never at the current moment, so a missed clock-out never inflates the hours. Note the count of people on the clock so you can confirm nothing drops when you rotate.
Rotate the kiosk URL in your workspace
The rotation itself is fast. Sign in as an admin (your magic link, no password), then follow the exact steps in the guide on rotating a leaked kiosk link. In short:
- Go to the kiosk settings for the workspace or location whose link leaked. If you run several locations, rotate only the one that's exposed. The others keep their links.
- Generate a new kiosk URL. The old one stops working the moment the new one is issued. There is no overlap window, which is the point: a leaked link should die immediately.
- Copy the new URL. This is what the tablet and the QR poster will point to from now on.
Rotating the link does not delete a single time entry. Every hour already logged stays put and exports the same way it always did. You are changing the door, not the records behind it.
Reload the tablet so the kiosk stops on the old link
The shared tablet is still holding the old URL in its browser. Open the kiosk on that tablet, paste in the new URL, and load it. If the kiosk runs in a saved bookmark or a home-screen shortcut, replace that shortcut too, or the next person who reboots the tablet will land on the dead link.
Tap a test name and clock in, then clock out, to confirm the new link works end to end. Delete that test entry if you don't want it in your report. If you've never watched the kiosk flow from the worker's side, the live kiosk demo shows exactly what they see when they tap their name.
Reprint the QR poster with the new link
The printed QR code still encodes the old URL. Anyone who scans the poster on the wall now hits a dead link, so this is the part people forget and then wonder why check-ins stopped.
Generate a fresh poster from the new URL using the QR sign-in poster generator. Print it, then physically pull down every copy of the old poster: the one by the door, the one at the sign-in table, the laminated one in the supply closet. If a photo of the old poster is floating around online, that photo is now harmless because the code it shows no longer resolves to a working kiosk.
If workers also clock in from their phones by scanning, tell them to rescan the new poster. The old QR image they saved will fail, which is exactly the behavior you want.
Confirm the old link is actually dead
Don't assume. Verify. Open the old URL in a private or incognito window (so no saved session interferes) and confirm it no longer loads a working kiosk. Scan the old printed QR with your phone and confirm the same. If both are dead and the new link clocks a test worker in and out, the rotation is complete.
Then watch your dashboard for the first shift after the change. The count of people on the clock should match your team, not a stranger who found the link in a group chat. If a name you don't recognize appears, you'll know the leaked link is still live somewhere and you can rotate again.
Cut down the odds of the next leak
You can't stop someone from photographing a poster, but you can make a leak matter less. A few habits help:
- Rotate on a schedule if your crew turns over often, for example at the start of each new event or program season.
- Keep the kiosk link off any public page, printed handout, or shared drive that outsiders can reach.
- Use personal links for anyone who clocks in from their own phone off-site, so a shared kiosk link isn't the only way in.
Because Kangaroo Clock has no per-seat fees and workers never create accounts, rotating a link costs you nothing and locks nobody out. Nothing about the leak or the fix ever depends on a headcount or a password reset, since there are no worker passwords to reset in the first place.
One more reason the leak is contained: the kiosk collects a name and a timestamp, nothing else. There are no screenshots, no location, no activity tracking sitting behind that link for a stranger to find. When you export later, the CSV with its stable column layout still gives you a clean distinct-worker count for payroll or grant reporting, unaffected by the rotation.
Rotate the link, reprint the poster, pull the old copies, verify both are dead. That sequence takes a few minutes and closes the door for good.
Tags: kiosk, qr code, security, how-to
See it in your own setup
No signup needed. Add a few names, share a kiosk URL, watch hours land.