[{"data":1,"prerenderedAt":1353},["ShallowReactive",2],{"navigation":3,"/api":258,"/api-surround":1348},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":132,"api":260,"body":261,"description":1342,"extension":1343,"links":260,"meta":1344,"navigation":1345,"path":133,"seo":1346,"stem":134,"__hash__":1347},"docs/6.api/0.index.md",null,{"type":262,"value":263,"toc":1333},"minimark",[264,268,287,303,308,319,322,329,332,335,368,379,386,392,396,410,417,567,571,752,765,768,794,802,805,809,816,829,876,879,978,990,1020,1030,1042,1112,1130,1139,1143,1155,1209,1212,1273,1276,1290,1300,1304,1324,1329],[265,266,267],"p",{},"The CredenShare API lets you work with shares and secure requests from your own code — CI pipelines, provisioning scripts, internal tools. It works on ciphertext you encrypt yourself, so the service stores your secret without ever being able to read it.",[265,269,270,271,275,276,279,280,283,284,286],{},"There are three resources: ",[272,273,274],"a",{"href":143},"shares"," send a secret to somebody, ",[272,277,278],{"href":169},"secure requests"," collect one from them, and ",[272,281,282],{"href":191},"stats"," reports usage. The same account can also be driven by an AI assistant through the hosted ",[272,285,212],{"href":213},".",[288,289,292],"callout",{"color":290,"icon":291},"info","i-lucide-package",[265,293,294,298,299,302],{},[295,296,297],"strong",{},"Working in Node, Python, Go or Rust?"," The ",[272,300,301],{"href":221},"official SDKs"," perform the encryption, derive the tokens and assemble the link for you, so you pass plaintext fields and get back a finished link. This reference is what you need if you are implementing the wire format yourself, or working in another language.",[304,305,307],"h2",{"id":306},"base-url","Base URL",[309,310,316],"pre",{"className":311,"code":313,"language":314,"meta":315},[312],"language-text","https://api.credenshare.io/v1\n","text","",[317,318,313],"code",{"__ignoreMap":315},[265,320,321],{},"Every path on this page is relative to that base. There is no version header and no stage segment in the path.",[265,323,324,325,328],{},"A development host, ",[317,326,327],{},"https://api-dev.credenshare.io/v1",", runs the same code if you want somewhere to rehearse against before pointing at production. The rest of this documentation uses the canonical base URL only.",[304,330,138],{"id":331},"authentication",[265,333,334],{},"Send your API key as a bearer token:",[309,336,340],{"className":337,"code":338,"language":339,"meta":315,"style":315},"language-bash shiki shiki-themes github-light github-dark github-dark","curl https://api.credenshare.io/v1/shares \\\n  -H \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"\n","bash",[317,341,342,359],{"__ignoreMap":315},[343,344,347,351,355],"span",{"class":345,"line":346},"line",1,[343,348,350],{"class":349},"shcOC","curl",[343,352,354],{"class":353},"sfrk1"," https://api.credenshare.io/v1/shares",[343,356,358],{"class":357},"suiK_"," \\\n",[343,360,362,365],{"class":345,"line":361},2,[343,363,364],{"class":357},"  -H",[343,366,367],{"class":353}," \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"\n",[265,369,370,371,374,375,378],{},"A full credential has ",[295,372,373],{},"three"," dot-separated parts — ",[317,376,377],{},"crs_sk_live_\u003CkeyId>.\u003CauthSecret>.\u003CcustodySecret>",". Only the first two are ever transmitted. The third part is a client-side secret used to derive your custody keypair; a credential that arrives with all three parts is refused outright and the key must be rotated.",[265,380,381,382,385],{},"Keys are minted in the dashboard under ",[295,383,384],{},"Account → Security",", and the credential is displayed exactly once. There is no API route that creates, rotates or revokes keys: a leaked key that could mint more keys would be a far worse leak, so key management stays session-authenticated.",[265,387,388,389,391],{},"See ",[272,390,138],{"href":139}," for scopes, custody levels and the key lifecycle.",[304,393,395],{"id":394},"the-encryption-model-read-this-first","The encryption model — read this first",[288,397,400],{"color":398,"icon":399},"warning","i-lucide-alert-triangle",[265,401,402,405,406,409],{},[295,403,404],{},"This API cannot accept a plaintext secret, and it cannot return a share link."," Both are consequences of the encryption model, not gaps in the interface. Code written on the assumption that you can ",[317,407,408],{},"POST"," a password and get a URL back will fail on its first call.",[265,411,412,413,416],{},"CredenShare shares are encrypted in the client. The content key is never sent to the server — it travels to the recipient in the ",[295,414,415],{},"URL fragment"," of the share link, and browsers do not transmit the fragment to the origin. That single fact shapes the whole API:",[418,419,420,500,512,539,545],"ul",{},[421,422,423,426,427,430,431,434,435,438,439,442,443],"li",{},[295,424,425],{},"You encrypt before you call."," ",[317,428,429],{},"data"," is your ciphertext, stored byte-for-byte. ",[317,432,433],{},"encryption_type"," must be the literal string ",[317,436,437],{},"e2ee-aes256-gcm","; any other value, including the server-side encryption types used elsewhere in the product, is refused with a ",[317,440,441],{},"400",":",[309,444,448],{"className":445,"code":446,"language":447,"meta":315,"style":315},"language-json shiki shiki-themes github-light github-dark github-dark","{\n  \"success\": false,\n  \"message\": \"The API accepts end-to-end encrypted content only. Encrypt client-side and send encryption_type=e2ee-aes256-gcm.\",\n  \"error_code\": 19\n}\n","json",[317,449,450,456,470,483,494],{"__ignoreMap":315},[343,451,452],{"class":345,"line":346},[343,453,455],{"class":454},"slsVL","{\n",[343,457,458,461,464,467],{"class":345,"line":361},[343,459,460],{"class":357},"  \"success\"",[343,462,463],{"class":454},": ",[343,465,466],{"class":357},"false",[343,468,469],{"class":454},",\n",[343,471,473,476,478,481],{"class":345,"line":472},3,[343,474,475],{"class":357},"  \"message\"",[343,477,463],{"class":454},[343,479,480],{"class":353},"\"The API accepts end-to-end encrypted content only. Encrypt client-side and send encryption_type=e2ee-aes256-gcm.\"",[343,482,469],{"class":454},[343,484,486,489,491],{"class":345,"line":485},4,[343,487,488],{"class":357},"  \"error_code\"",[343,490,463],{"class":454},[343,492,493],{"class":357},"19\n",[343,495,497],{"class":345,"line":496},5,[343,498,499],{"class":454},"}\n",[421,501,502,508,509,511],{},[295,503,504,505,286],{},"You must supply an ",[317,506,507],{},"access_token"," It is derived by your client from the content key. The server stores only a SHA-256 hash of it and cannot recompute it; the recipient's browser presents the same token when it opens the share. A create without ",[317,510,507],{}," fails validation.",[421,513,514,521,522,525,526,532,535,536,538],{},[295,515,516,517,520],{},"The create response has no ",[317,518,519],{},"url"," field."," It returns a ",[317,523,524],{},"short_code",". You assemble the link, because only you hold the key:",[309,527,530],{"className":528,"code":529,"language":314,"meta":315},[312],"https://crs.sh/\u003Cshort_code>#\u003Ckey material your client appends>\n",[317,531,529],{"__ignoreMap":315},[533,534],"br",{},"There is nothing the API could put in a ",[317,537,519],{}," field that would open, so it does not offer one.",[421,540,541,544],{},[295,542,543],{},"There is no endpoint that reads share content."," A bearer key skips the proof-of-work and captcha challenges that guard the anonymous recipient page, so exposing recipient reads to a key would turn the API into an enumeration bypass. Reads through the API return metadata only.",[421,546,547,550,551,554,555,558,559,562,563,566],{},[295,548,549],{},"API-created shares are not readable from the dashboard unless you say so."," Send an ",[317,552,553],{},"item_key_wrap"," on create — a wrap of the content key to your key's custody public key — and the share becomes recoverable from your account later. This requires a key minted with custody ",[317,556,557],{},"self"," or higher; a wrap sent by a key with custody ",[317,560,561],{},"none"," is refused rather than ignored. Omit the wrap and the ciphertext is openable only by whoever holds the link. The ",[317,564,565],{},"custody"," field in the create response reports which happened.",[304,568,570],{"id":569},"endpoints","Endpoints",[572,573,574,590],"table",{},[575,576,577],"thead",{},[578,579,580,584,587],"tr",{},[581,582,583],"th",{},"Method and path",[581,585,586],{},"What it does",[581,588,589],{},"Scope",[591,592,593,609,624,638,652,667,682,696,710,724,739],"tbody",{},[578,594,595,601,604],{},[596,597,598],"td",{},[317,599,600],{},"POST /v1/shares",[596,602,603],{},"Create a share from ciphertext. Returns a short code.",[596,605,606],{},[317,607,608],{},"shares:write",[578,610,611,616,619],{},[596,612,613],{},[317,614,615],{},"GET /v1/shares",[596,617,618],{},"List the shares this key created, newest first. Metadata only.",[596,620,621],{},[317,622,623],{},"shares:read",[578,625,626,631,634],{},[596,627,628],{},[317,629,630],{},"GET /v1/shares/{shortCode}",[596,632,633],{},"One share's metadata. Consumes no view and runs no passcode check.",[596,635,636],{},[317,637,623],{},[578,639,640,645,648],{},[596,641,642],{},[317,643,644],{},"DELETE /v1/shares/{shortCode}",[596,646,647],{},"Expire a share your account owns.",[596,649,650],{},[317,651,608],{},[578,653,654,659,662],{},[596,655,656],{},[317,657,658],{},"POST /v1/requests",[596,660,661],{},"Create a secure request. Returns a short code for a collect link.",[596,663,664],{},[317,665,666],{},"requests:write",[578,668,669,674,677],{},[596,670,671],{},[317,672,673],{},"GET /v1/requests",[596,675,676],{},"List the requests your account owns, newest first. Metadata only.",[596,678,679],{},[317,680,681],{},"requests:read",[578,683,684,689,692],{},[596,685,686],{},[317,687,688],{},"GET /v1/requests/{shortCode}",[596,690,691],{},"One request's metadata.",[596,693,694],{},[317,695,681],{},[578,697,698,703,706],{},[596,699,700],{},[317,701,702],{},"GET /v1/requests/{shortCode}/submissions",[596,704,705],{},"The submissions to one request, including ciphertext.",[596,707,708],{},[317,709,681],{},[578,711,712,717,720],{},[596,713,714],{},[317,715,716],{},"DELETE /v1/requests/{shortCode}",[596,718,719],{},"Expire an active request, or delete an already-expired one.",[596,721,722],{},[317,723,666],{},[578,725,726,731,734],{},[596,727,728],{},[317,729,730],{},"GET /v1/stats",[596,732,733],{},"Share counts and a 14-day view history. Figures only.",[596,735,736],{},[317,737,738],{},"stats:read",[578,740,741,746,749],{},[596,742,743],{},[317,744,745],{},"POST /v1/mcp",[596,747,748],{},"The hosted MCP server. JSON-RPC 2.0, not REST.",[596,750,751],{},"Per tool",[265,753,754,755,757,758,757,760,762,763,286],{},"That is the whole surface. Full detail is on ",[272,756,142],{"href":143},", ",[272,759,168],{"href":169},[272,761,190],{"href":191}," and ",[272,764,212],{"href":213},[265,766,767],{},"Two things follow from the table that are easy to miss:",[418,769,770,780],{},[421,771,772,777,778,286],{},[295,773,774,776],{},[317,775,702],{}," is the one read that returns content."," Everything else is metadata. It is not an exception to the encryption model — submissions come back sealed to a key you generated and we never received. See ",[272,779,182],{"href":183},[421,781,782,787,788,791,792,286],{},[295,783,784,786],{},[317,785,716],{}," is not idempotent."," The first call expires; a second call on an already-expired request permanently deletes it, submissions included. The share ",[317,789,790],{},"DELETE"," has no such second behaviour. See ",[272,793,186],{"href":187},[288,795,797],{"color":290,"icon":796},"i-lucide-info",[265,798,799,800,286],{},"Webhook endpoints are created and re-pointed in the dashboard, not through this API — an API key must not be able to redirect your event stream. The delivery contract, signing and event catalogue are documented under ",[272,801,194],{"href":195},[265,803,804],{},"Short codes are opaque. Do not parse them, and do not assume a length or character set.",[304,806,808],{"id":807},"response-shapes","Response shapes",[265,810,811,812,815],{},"Successes and errors are shaped ",[295,813,814],{},"differently"," on this surface. Handle both.",[265,817,818,821,822,824,825,828],{},[295,819,820],{},"Successes"," are bare JSON objects. There is no ",[317,823,429],{}," wrapper, no ",[317,826,827],{},"meta"," block and no request id.",[309,830,832],{"className":445,"code":831,"language":447,"meta":315,"style":315},"{\n  \"short_code\": \"…\",\n  \"expired_at\": \"2026-09-03T12:00:00Z\",\n  \"custody\": \"stored\"\n}\n",[317,833,834,838,850,862,872],{"__ignoreMap":315},[343,835,836],{"class":345,"line":346},[343,837,455],{"class":454},[343,839,840,843,845,848],{"class":345,"line":361},[343,841,842],{"class":357},"  \"short_code\"",[343,844,463],{"class":454},[343,846,847],{"class":353},"\"…\"",[343,849,469],{"class":454},[343,851,852,855,857,860],{"class":345,"line":472},[343,853,854],{"class":357},"  \"expired_at\"",[343,856,463],{"class":454},[343,858,859],{"class":353},"\"2026-09-03T12:00:00Z\"",[343,861,469],{"class":454},[343,863,864,867,869],{"class":345,"line":485},[343,865,866],{"class":357},"  \"custody\"",[343,868,463],{"class":454},[343,870,871],{"class":353},"\"stored\"\n",[343,873,874],{"class":345,"line":496},[343,875,499],{"class":454},[265,877,878],{},"The list endpoint returns two keys:",[309,880,882],{"className":445,"code":881,"language":447,"meta":315,"style":315},"{\n  \"shares\": [\n    { \"short_code\": \"…\", \"expired_at\": \"2026-09-03T12:00:00Z\" }\n  ],\n  \"pagination\": { \"page\": 1, \"limit\": 25, \"total_pages\": 4, \"total\": 87 }\n}\n",[317,883,884,888,896,920,925,973],{"__ignoreMap":315},[343,885,886],{"class":345,"line":346},[343,887,455],{"class":454},[343,889,890,893],{"class":345,"line":361},[343,891,892],{"class":357},"  \"shares\"",[343,894,895],{"class":454},": [\n",[343,897,898,901,904,906,908,910,913,915,917],{"class":345,"line":472},[343,899,900],{"class":454},"    { ",[343,902,903],{"class":357},"\"short_code\"",[343,905,463],{"class":454},[343,907,847],{"class":353},[343,909,757],{"class":454},[343,911,912],{"class":357},"\"expired_at\"",[343,914,463],{"class":454},[343,916,859],{"class":353},[343,918,919],{"class":454}," }\n",[343,921,922],{"class":345,"line":485},[343,923,924],{"class":454},"  ],\n",[343,926,927,930,933,936,938,941,943,946,948,951,953,956,958,961,963,966,968,971],{"class":345,"line":496},[343,928,929],{"class":357},"  \"pagination\"",[343,931,932],{"class":454},": { ",[343,934,935],{"class":357},"\"page\"",[343,937,463],{"class":454},[343,939,940],{"class":357},"1",[343,942,757],{"class":454},[343,944,945],{"class":357},"\"limit\"",[343,947,463],{"class":454},[343,949,950],{"class":357},"25",[343,952,757],{"class":454},[343,954,955],{"class":357},"\"total_pages\"",[343,957,463],{"class":454},[343,959,960],{"class":357},"4",[343,962,757],{"class":454},[343,964,965],{"class":357},"\"total\"",[343,967,463],{"class":454},[343,969,970],{"class":357},"87",[343,972,919],{"class":454},[343,974,976],{"class":345,"line":975},6,[343,977,499],{"class":454},[265,979,980,982,983,986,987,442],{},[317,981,790],{}," is the one success that carries an envelope, and it returns ",[317,984,985],{},"200"," with a body — not ",[317,988,989],{},"204",[309,991,993],{"className":445,"code":992,"language":447,"meta":315,"style":315},"{ \"success\": true, \"message\": \"ok\" }\n",[317,994,995],{"__ignoreMap":315},[343,996,997,1000,1003,1005,1008,1010,1013,1015,1018],{"class":345,"line":346},[343,998,999],{"class":454},"{ ",[343,1001,1002],{"class":357},"\"success\"",[343,1004,463],{"class":454},[343,1006,1007],{"class":357},"true",[343,1009,757],{"class":454},[343,1011,1012],{"class":357},"\"message\"",[343,1014,463],{"class":454},[343,1016,1017],{"class":353},"\"ok\"",[343,1019,919],{"class":454},[265,1021,1022,1023,1026,1027,286],{},"Every ",[317,1024,1025],{},"expired_at"," is either an RFC 3339 string or JSON ",[317,1028,1029],{},"null",[265,1031,1032,1035,1036,426,1039,442],{},[295,1033,1034],{},"Errors"," use a flat envelope with an ",[295,1037,1038],{},"integer",[317,1040,1041],{},"error_code",[309,1043,1045],{"className":445,"code":1044,"language":447,"meta":315,"style":315},"{\n  \"success\": false,\n  \"message\": \"Validation failed\",\n  \"error_code\": 19,\n  \"additional_data\": {\n    \"encryption_type\": \"\u003Cwhy this field was rejected>\"\n  }\n}\n",[317,1046,1047,1051,1061,1072,1083,1091,1101,1107],{"__ignoreMap":315},[343,1048,1049],{"class":345,"line":346},[343,1050,455],{"class":454},[343,1052,1053,1055,1057,1059],{"class":345,"line":361},[343,1054,460],{"class":357},[343,1056,463],{"class":454},[343,1058,466],{"class":357},[343,1060,469],{"class":454},[343,1062,1063,1065,1067,1070],{"class":345,"line":472},[343,1064,475],{"class":357},[343,1066,463],{"class":454},[343,1068,1069],{"class":353},"\"Validation failed\"",[343,1071,469],{"class":454},[343,1073,1074,1076,1078,1081],{"class":345,"line":485},[343,1075,488],{"class":357},[343,1077,463],{"class":454},[343,1079,1080],{"class":357},"19",[343,1082,469],{"class":454},[343,1084,1085,1088],{"class":345,"line":496},[343,1086,1087],{"class":357},"  \"additional_data\"",[343,1089,1090],{"class":454},": {\n",[343,1092,1093,1096,1098],{"class":345,"line":975},[343,1094,1095],{"class":357},"    \"encryption_type\"",[343,1097,463],{"class":454},[343,1099,1100],{"class":353},"\"\u003Cwhy this field was rejected>\"\n",[343,1102,1104],{"class":345,"line":1103},7,[343,1105,1106],{"class":454},"  }\n",[343,1108,1110],{"class":345,"line":1109},8,[343,1111,499],{"class":454},[265,1113,1114,1115,1117,1118,1121,1122,1125,1126,1129],{},"Branch on ",[317,1116,1041],{},", not on ",[317,1119,1120],{},"message"," — messages are prose and may be reworded. ",[317,1123,1124],{},"additional_data"," is present on validation failures, where it maps each rejected JSON field name to a human-readable reason. See ",[272,1127,1128],{"href":217},"Errors and rate limits"," for the full code table.",[288,1131,1132],{"color":290,"icon":796},[265,1133,1134,1135,1138],{},"Authentication failures are the exception to both shapes: they are produced by the gateway before your request reaches the API, so they do not use the error envelope at all. ",[272,1136,1128],{"href":1137},"/api/errors-and-limits#authentication-failures"," shows exactly what you get.",[304,1140,1142],{"id":1141},"idempotency","Idempotency",[265,1144,1145,426,1147,1150,1151,1154],{},[317,1146,600],{},[295,1148,1149],{},"requires"," an ",[317,1152,1153],{},"Idempotency-Key"," request header. It exists because a retried create that is not recognised as a retry mints a second copy of a secret.",[309,1156,1158],{"className":337,"code":1157,"language":339,"meta":315,"style":315},"curl -X POST https://api.credenshare.io/v1/shares \\\n  -H \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\" \\\n  -H \"Idempotency-Key: deploy-2026-09-03-db-password\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{ ... }'\n",[317,1159,1160,1174,1183,1192,1201],{"__ignoreMap":315},[343,1161,1162,1164,1167,1170,1172],{"class":345,"line":346},[343,1163,350],{"class":349},[343,1165,1166],{"class":357}," -X",[343,1168,1169],{"class":353}," POST",[343,1171,354],{"class":353},[343,1173,358],{"class":357},[343,1175,1176,1178,1181],{"class":345,"line":361},[343,1177,364],{"class":357},[343,1179,1180],{"class":353}," \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"",[343,1182,358],{"class":357},[343,1184,1185,1187,1190],{"class":345,"line":472},[343,1186,364],{"class":357},[343,1188,1189],{"class":353}," \"Idempotency-Key: deploy-2026-09-03-db-password\"",[343,1191,358],{"class":357},[343,1193,1194,1196,1199],{"class":345,"line":485},[343,1195,364],{"class":357},[343,1197,1198],{"class":353}," \"Content-Type: application/json\"",[343,1200,358],{"class":357},[343,1202,1203,1206],{"class":345,"line":496},[343,1204,1205],{"class":357},"  -d",[343,1207,1208],{"class":353}," '{ ... }'\n",[265,1210,1211],{},"Choose the value yourself — anything non-blank. Reuse semantics:",[572,1213,1214,1224],{},[575,1215,1216],{},[578,1217,1218,1221],{},[581,1219,1220],{},"Situation",[581,1222,1223],{},"Result",[591,1225,1226,1238,1248,1261],{},[578,1227,1228,1231],{},[596,1229,1230],{},"Header missing or whitespace only",[596,1232,1233,757,1235,1237],{},[317,1234,441],{},[317,1236,1041],{}," 104",[578,1239,1240,1243],{},[596,1241,1242],{},"Key reused, request body byte-identical, first call finished",[596,1244,1245,1247],{},[317,1246,985],{}," with the first call's stored response body, replayed verbatim",[578,1249,1250,1253],{},[596,1251,1252],{},"Key reused, request body differs by even one byte",[596,1254,1255,757,1258,1260],{},[317,1256,1257],{},"409",[317,1259,1041],{}," 105",[578,1262,1263,1266],{},[596,1264,1265],{},"Key reused while the first call is still in flight",[596,1267,1268,757,1270,1272],{},[317,1269,1257],{},[317,1271,1041],{}," 106",[265,1274,1275],{},"Two details decide whether a retry is recognised:",[418,1277,1278,1284],{},[421,1279,1280,1283],{},[295,1281,1282],{},"What is hashed is the raw request body, byte for byte"," — a SHA-256 of exactly the bytes you sent. A retry that re-serialises the same object with different key ordering, different whitespace, or a different float formatting hashes differently, and is refused as a reuse rather than replayed. To retry safely, send the identical byte string; build the body once, keep it, and resend it.",[421,1285,1286,1289],{},[295,1287,1288],{},"Keys are scoped to the API key that used them, and retained for 24 hours."," After 24 hours the same value is a fresh key. Two different API keys may use the same value without colliding.",[265,1291,1292,1293,1295,1296,1299],{},"Note that a successful replay returns ",[317,1294,985],{},", not the original ",[317,1297,1298],{},"201",". Treat both as success.",[304,1301,1303],{"id":1302},"plans","Plans",[265,1305,1306,1307,762,1310,1313,1314,762,1317,1319,1320,1323],{},"API access is a ",[295,1308,1309],{},"Business",[295,1311,1312],{},"Enterprise"," capability. On any other plan the entitlement resolves to off, and minting a key is refused with ",[317,1315,1316],{},"403",[317,1318,1041],{}," 98, ",[317,1321,1322],{},"\"API access requires a Business or Enterprise plan\"",". An unset rate limit is treated as no access rather than as unlimited, so an older plan that predates the feature does not inherit it.",[265,1325,1326,1327,286],{},"Request-rate limits, the plan share allowance and every error code are on ",[272,1328,1128],{"href":217},[1330,1331,1332],"style",{},"html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .shcOC, html code.shiki .shcOC{--shiki-light:#6F42C1;--shiki-default:#B392F0;--shiki-dark:#B392F0}",{"title":315,"searchDepth":346,"depth":361,"links":1334},[1335,1336,1337,1338,1339,1340,1341],{"id":306,"depth":361,"text":307},{"id":331,"depth":361,"text":138},{"id":394,"depth":361,"text":395},{"id":569,"depth":361,"text":570},{"id":807,"depth":361,"text":808},{"id":1141,"depth":361,"text":1142},{"id":1302,"depth":361,"text":1303},"The CredenShare REST API — end-to-end encrypted shares, secure requests and usage stats, driven from your own code.","md",{},true,{"title":132,"description":1342},"HtCiRk3zzYWIkh7p-kNQ04GVTjrqtpKm04nBTIQd4EI",[1349,1351],{"title":127,"path":128,"stem":129,"description":1350,"children":-1},"Every refusal the app can show you, keyed on the exact wording, with what it means and what to do about it.",{"title":138,"path":139,"stem":140,"description":1352,"children":-1},"How to authenticate requests with a CredenShare API key, and what scopes, custody levels and plan limits control.",1788908845932]