Support

Keep your calendar link private

Your pipeline calendar URL is a capability link — whoever holds it can read your saved opportunities. How to rotate it if it leaks.

The calendar subscribe URL for your pipeline is a capability link. Possession is permission — anyone holding it can read the titles and deadlines of everything you have saved, with no login.

This is not a flaw. Every calendar subscription on every platform works this way, because calendar clients cannot log in on your behalf. It just means the URL needs handling like a password.

Why it matters here

Your pipeline is competitive information. It shows what your organization is going after, what stage each pursuit is at, and when. For a business bidding on contracts, that is genuinely sensitive.

Where these leak

In roughly this order:

  • Pasted into a shared Google Doc or Notion page
  • Attached to a support ticket or bug report
  • Sent in a group chat so a colleague can subscribe too
  • Included in a screenshot of a calendar settings screen
  • Left in a browser session on a shared machine

If it leaks, rotate it

You can rotate the calendar token. This revokes the existing URL immediately and issues a new one.

Anyone still subscribed to the old URL stops receiving updates — including you, on your own devices. After rotating you need to re-subscribe everywhere you had it.

That inconvenience is the point: revocation is real rather than cosmetic.

Good practice

Do not share one URL across a team. If several people need the deadlines, put them on a shared team calendar that you control, and keep the OpenGrants feed on one account.

Rotate when someone leaves. A departing colleague’s subscribed calendar keeps working otherwise.

Rotate if you are unsure. It costs a re-subscribe and nothing else.

Stop Reading About Grants. Start Winning Them.

Search every open opportunity, get matched by eligibility, and track every deadline in one workspace.