[{"data":1,"prerenderedAt":1237},["ShallowReactive",2],{"navigation":3,"/api/authentication":258,"/api/authentication-surround":1232},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":138,"api":260,"body":261,"description":1226,"extension":1227,"links":260,"meta":1228,"navigation":1229,"path":139,"seo":1230,"stem":140,"__hash__":1231},"docs/6.api/1.authentication.md",null,{"type":262,"value":263,"toc":1210},"minimark",[264,273,278,281,291,294,327,330,333,337,348,360,363,367,381,437,440,447,450,464,611,636,656,671,678,684,688,695,775,783,788,802,808,812,821,828,877,891,895,904,908,920,924,927,1006,1017,1024,1033,1077,1090,1094,1099,1102,1113,1127,1134,1137,1141,1147,1196,1203,1206],[265,266,267,268,272],"p",{},"Every request to the CredenShare API carries an API key in the ",[269,270,271],"code",{},"Authorization"," header. There is no session, no cookie and no shared gateway key on this surface — the API key is the only credential, and it is checked on every single request.",[274,275,277],"h2",{"id":276},"the-credential","The credential",[265,279,280],{},"A CredenShare API credential has a fixed prefix and three dot-separated parts:",[282,283,288],"pre",{"className":284,"code":286,"language":287},[285],"language-text","crs_sk_live_\u003CkeyId>.\u003CauthSecret>.\u003CcustodySecret>\n             │       │            └─ custody secret: never transmitted\n             │       └─ auth secret: sent as the bearer credential\n             └─ key id: identifies the key\n","text",[269,289,286],{"__ignoreMap":290},"",[265,292,293],{},"You send the prefix, the key id and the auth secret — the first two parts, nothing more:",[282,295,299],{"className":296,"code":297,"language":298,"meta":290,"style":290},"language-bash shiki shiki-themes github-light github-dark github-dark","curl https://api.credenshare.io/v1/shares \\\n  -H \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"\n","bash",[269,300,301,318],{"__ignoreMap":290},[302,303,306,310,314],"span",{"class":304,"line":305},"line",1,[302,307,309],{"class":308},"shcOC","curl",[302,311,313],{"class":312},"sfrk1"," https://api.credenshare.io/v1/shares",[302,315,317],{"class":316},"suiK_"," \\\n",[302,319,321,324],{"class":304,"line":320},2,[302,322,323],{"class":316},"  -H",[302,325,326],{"class":312}," \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"\n",[265,328,329],{},"The three components are 12, 32 and 32 random bytes, each base64url-encoded without padding. So the value you put in the header is 72 characters long, and the full credential you were shown at creation is 116 characters. Size your storage accordingly.",[265,331,332],{},"Only a SHA-256 hash of the auth secret is stored, and the presented secret is compared in constant time. The full credential is never persisted anywhere — which is why it is displayed exactly once, when the key is created, and can never be retrieved again. If you lose it, revoke the key and mint a new one.",[274,334,336],{"id":335},"never-transmit-the-custody-secret","Never transmit the custody secret",[338,339,342],"callout",{"color":340,"icon":341},"warning","i-lucide-alert-triangle",[265,343,344,345,347],{},"The third part of the credential — the custody secret — must never leave the machine that holds it. Do not put it in the ",[269,346,271],{}," header, in a request body, in a query string or in a log. There is deliberately no field anywhere in the API that accepts it.",[265,349,350,351,354,355,359],{},"The custody secret is not a second password for the server. It is key material your client uses locally: you derive a custody keypair from it as ",[269,352,353],{},"HKDF(custodySecret, \"custody\")"," and register only the ",[356,357,358],"strong",{},"public"," half with CredenShare. The server therefore has no use for the secret half, and by never receiving it we cannot lose it.",[265,361,362],{},"A credential that arrives with all three parts is refused outright — not tolerated, not silently truncated. The attempt is recorded as a key compromise, because the secret has now been transmitted over the network and may exist in logs, proxies and traces along the way. Treat that key as burned: revoke it and mint a replacement.",[274,364,366],{"id":365},"getting-a-key","Getting a key",[265,368,369,370,373,374,376,377,380],{},"Keys are minted in the CredenShare web app, not through the API. Open the account page (",[269,371,372],{},"/user-account","), go to the ",[356,375,246],{}," tab, and find the card headed ",[356,378,379],{},"API keys",".",[382,383,384,391,401,412,422,428],"ol",{},[385,386,387,388,380],"li",{},"Click ",[356,389,390],{},"Create API key",[385,392,393,394,397,398,380],{},"Enter a ",[356,395,396],{},"Name"," (required, up to 256 characters). Use something that identifies the caller, like ",[269,399,400],{},"CI deploy pipeline",[385,402,403,404,407,408,411],{},"Tick the ",[356,405,406],{},"Scopes"," the key needs. The form starts with ",[269,409,410],{},"shares:write"," selected.",[385,413,414,415,418,419,380],{},"Choose a ",[356,416,417],{},"Custody"," level. The form starts on ",[269,420,421],{},"Self",[385,423,387,424,427],{},[356,425,426],{},"Create key",". The full credential appears once, in a highlighted panel.",[385,429,387,430,433,434,380],{},[356,431,432],{},"Copy credential",", store it in your secret manager, then tick the acknowledgement and click ",[356,435,436],{},"Done",[265,438,439],{},"The app registers your custody public key for you, immediately after showing you the credential, while the custody secret is still in memory in your browser. Nothing else in the flow ever sends it.",[338,441,444],{"color":442,"icon":443},"info","i-lucide-info",[265,445,446],{},"An API key cannot manage API keys. Minting, listing and revoking are all on the signed-in app surface only, so a leaked key cannot be used to mint more keys or to widen its own scopes.",[274,448,406],{"id":449},"scopes",[265,451,452,453,455,456,459,460,463],{},"A key carries a set of scopes, chosen at creation and fixed for the life of the key. Matching is exact: there is no hierarchy and no wildcard, so ",[269,454,410],{}," does ",[356,457,458],{},"not"," imply ",[269,461,462],{},"shares:read",". Grant both if the caller needs both. A key can also be created with no scopes at all, in which case every endpoint refuses it.",[465,466,467,483],"table",{},[468,469,470],"thead",{},[471,472,473,477,480],"tr",{},[474,475,476],"th",{},"Scope",[474,478,479],{},"What it gates",[474,481,482],{},"Enforced today",[484,485,486,515,540,560,581,598],"tbody",{},[471,487,488,493,512],{},[489,490,491],"td",{},[269,492,462],{},[489,494,495,498,499,502,503,498,506,498,509],{},[269,496,497],{},"GET /v1/shares",", ",[269,500,501],{},"GET /v1/shares/{shortCode}","; MCP tools ",[269,504,505],{},"list_shares",[269,507,508],{},"get_share",[269,510,511],{},"list_webhooks",[489,513,514],{},"Yes",[471,516,517,521,538],{},[489,518,519],{},[269,520,410],{},[489,522,523,498,526,502,529,498,532,498,535],{},[269,524,525],{},"POST /v1/shares",[269,527,528],{},"DELETE /v1/shares/{shortCode}",[269,530,531],{},"create_share_via_browser",[269,533,534],{},"expire_share",[269,536,537],{},"rotate_webhook_secret",[489,539,514],{},[471,541,542,547,558],{},[489,543,544],{},[269,545,546],{},"requests:read",[489,548,549,498,552,498,555],{},[269,550,551],{},"GET /v1/requests",[269,553,554],{},"GET /v1/requests/{shortCode}",[269,556,557],{},"GET /v1/requests/{shortCode}/submissions",[489,559,514],{},[471,561,562,567,579],{},[489,563,564],{},[269,565,566],{},"requests:write",[489,568,569,498,572,575,576],{},[269,570,571],{},"POST /v1/requests",[269,573,574],{},"DELETE /v1/requests/{shortCode}","; MCP tool ",[269,577,578],{},"request_secret_from",[489,580,514],{},[471,582,583,588,596],{},[489,584,585],{},[269,586,587],{},"stats:read",[489,589,590,575,593],{},[269,591,592],{},"GET /v1/stats",[269,594,595],{},"share_stats",[489,597,514],{},[471,599,600,605,608],{},[489,601,602],{},[269,603,604],{},"webhooks:manage",[489,606,607],{},"Reserved",[489,609,610],{},"No — checked nowhere",[338,612,613],{"color":340,"icon":341},[265,614,615,620,621,623,624,626,627,629,630,632,633,635],{},[356,616,617,619],{},[269,618,604],{}," is a reserved name that nothing currently checks."," Granting it grants no additional access and withholding it denies nothing — do not treat it as a least-privilege boundary. The two webhook tools are gated on ",[269,622,462],{}," and ",[269,625,410],{}," instead, so a key with ",[269,628,410],{}," can rotate a webhook signing secret even without ",[269,631,604],{},", and a key holding only ",[269,634,604],{}," cannot use either webhook tool.",[265,637,638,639,642,643,645,646,649,650,652,653,655],{},"The other five scopes are all enforced. Note in particular that the ",[269,640,641],{},"requests:*"," scopes are ",[356,644,458],{}," implied by the ",[269,647,648],{},"shares:*"," ones: a key that can create shares cannot read a submission unless you granted ",[269,651,546],{}," as well. The reverse also holds — ",[269,654,546],{}," gates the submissions endpoint, which is the only read on the API that returns content.",[265,657,658,659,662,663,666,667,670],{},"When a key is missing a scope the REST API answers ",[269,660,661],{},"403"," with error code ",[269,664,665],{},"78"," and the message ",[269,668,669],{},"You do not have permission to perform this action on this team",". The wording is generic; on this surface it means the key lacks the required scope, not that anything is wrong with your team.",[265,672,673,674,677],{},"The MCP endpoint reports the same condition differently. It answers ",[269,675,676],{},"200"," with a tool result marked as an error, whose text is:",[282,679,682],{"className":680,"code":681,"language":287},[285],"This API key lacks the \"shares:read\" scope, which list_shares requires. Mint a key with that scope.\n",[269,683,681],{"__ignoreMap":290},[274,685,687],{"id":686},"custody-levels","Custody levels",[265,689,690,691,694],{},"Custody is the part of this API most likely to surprise you, and it follows directly from the encryption model: ",[356,692,693],{},"content is encrypted on your side, and the server never sees the key."," A share you create through the API is readable by whoever holds the link fragment — and by nobody else, including you, from your own dashboard, unless you deliberately store a wrapped copy of the item key. Custody is that opt-in.",[465,696,697,712],{},[468,698,699],{},[471,700,701,704,706,709],{},[474,702,703],{},"Level",[474,705,396],{},[474,707,708],{},"What the key can read",[474,710,711],{},"What the caller must do",[484,713,714,736,757],{},[471,715,716,721,726,729],{},[489,717,718],{},[269,719,720],{},"0",[489,722,723],{},[269,724,725],{},"none",[489,727,728],{},"Only content it is handed a link for",[489,730,731,732,735],{},"Omit ",[269,733,734],{},"item_key_wrap",". Sending one is refused.",[471,737,738,743,748,751],{},[489,739,740],{},[269,741,742],{},"1",[489,744,745],{},[269,746,747],{},"self",[489,749,750],{},"Content this key created",[489,752,753,754,756],{},"Register a custody public key, then send ",[269,755,734],{}," on each create",[471,758,759,764,769,772],{},[489,760,761],{},[269,762,763],{},"2",[489,765,766],{},[269,767,768],{},"account",[489,770,771],{},"Everything the account holder can read",[489,773,774],{},"Register a custody public key, then have one of your own devices approve the request",[265,776,777,778,780,781,380],{},"Level ",[269,779,720],{}," is the API's default. The web app's key-creation form defaults to ",[269,782,421],{},[784,785,787],"h3",{"id":786},"level-0-refuses-a-wrap-outright","Level 0 refuses a wrap outright",[265,789,790,791,793,794,797,798,801],{},"At level ",[269,792,720],{}," there is no custody public key, so a wrapped item key could never be unwrapped by anyone. Rather than store something unreadable, the create is refused with ",[269,795,796],{},"400",", error code ",[269,799,800],{},"19",", and this message:",[282,803,806],{"className":804,"code":805,"language":287},[285],"This key has custody level 'none', so an item_key_wrap would never be readable.\nMint a key with custody 'self' or omit the wrap.\n",[269,807,805],{"__ignoreMap":290},[784,809,811],{"id":810},"what-custody-buys-you","What custody buys you",[265,813,814,815,817,818,820],{},"Sending ",[269,816,734],{}," at level ",[269,819,742],{}," or higher is what makes an API-created share readable later from your dashboard. Skip it and the share still works perfectly for its recipient — you simply cannot open it yourself afterwards, because no copy of the item key exists on your side.",[265,822,823,824,827],{},"The create response tells you which happened, in its ",[269,825,826],{},"custody"," field:",[465,829,830,840],{},[468,831,832],{},[471,833,834,837],{},[474,835,836],{},"Value",[474,838,839],{},"Meaning",[484,841,842,854,864],{},[471,843,844,848],{},[489,845,846],{},[269,847,725],{},[489,849,850,851,853],{},"You sent no ",[269,852,734],{},". The share is recipient-only.",[471,855,856,861],{},[489,857,858],{},[269,859,860],{},"stored",[489,862,863],{},"The wrap was saved. The share is readable from your dashboard.",[471,865,866,871],{},[489,867,868],{},[269,869,870],{},"failed",[489,872,873,874,380],{},"The wrap could not be saved. The share exists and the response is still ",[269,875,876],{},"201",[265,878,879,881,882,886,887,890],{},[269,880,870],{}," is reported rather than raised as an error on purpose. By that point the share has already been created, so failing the request would make you retry with a fresh idempotency key and mint a ",[883,884,885],"em",{},"second"," copy of the secret. Storing a wrap also requires that your account has an enrolled zero-knowledge account key and the zero-knowledge plan feature; if either is missing you will see ",[269,888,889],{},"custody: \"failed\""," and should enrol before relying on dashboard readability.",[784,892,894],{"id":893},"reaching-level-1","Reaching level 1",[265,896,897,898,900,901,903],{},"Every key is created at effective level ",[269,899,720],{},", whatever level you asked for, because a non-zero level requires a custody public key and your client cannot produce one until it holds the credential. The level is raised on first use, when you register the public half of ",[269,902,353],{},". The web app does this for you as part of key creation.",[784,905,907],{"id":906},"reaching-level-2","Reaching level 2",[265,909,910,911,913,914,916,917,919],{},"Requesting ",[269,912,768],{}," custody does not grant it. The key is created at ",[269,915,747],{},", the request for level ",[269,918,763],{}," is recorded alongside it, and the effective level rises only after one of your devices performs the grant. That device has to hold your account key unwrapped, and the server cannot stand in for it — which is the whole point. An API key can never perform this approval itself.",[274,921,923],{"id":922},"plans-and-limits","Plans and limits",[265,925,926],{},"API access is a Business and Enterprise capability. It is granted by a plan feature, and every other plan resolves to no access at all rather than to an unlimited default.",[465,928,929,950],{},[468,930,931],{},[471,932,933,936,939,942,945,947],{},[474,934,935],{},"Plan",[474,937,938],{},"API access",[474,940,941],{},"Requests/min",[474,943,944],{},"Burst",[474,946,379],{},[474,948,949],{},"Webhook endpoints",[484,951,952,970,989],{},[471,953,954,957,959,962,964,967],{},[489,955,956],{},"Business (monthly or yearly)",[489,958,514],{},[489,960,961],{},"100",[489,963,676],{},[489,965,966],{},"5",[489,968,969],{},"3",[471,971,972,975,977,980,983,986],{},[489,973,974],{},"Enterprise (monthly or yearly)",[489,976,514],{},[489,978,979],{},"600",[489,981,982],{},"1200",[489,984,985],{},"25",[489,987,988],{},"10",[471,990,991,994,997,1000,1002,1004],{},[489,992,993],{},"Every other plan",[489,995,996],{},"No",[489,998,999],{},"—",[489,1001,999],{},[489,1003,720],{},[489,1005,720],{},[265,1007,1008,1009,1012,1013,1016],{},"Burst is always twice the sustained rate — there is one number to negotiate, not two. Exceeding the rate limit returns ",[269,1010,1011],{},"429"," with a ",[269,1014,1015],{},"Retry-After"," header. Webhooks are gated by the same plan feature as the API; there is no separate webhook entitlement. CredenShare can raise any of these numbers for an individual account or organization.",[265,1018,1019,1020,1023],{},"If a key acts inside an organization, its API access, rate limit and key allowance come from the ",[356,1021,1022],{},"organization's"," plan, not from the plan attached to the individual member.",[265,1025,1026,1027,662,1029,1032],{},"Trying to mint a key on a plan without API access returns ",[269,1028,661],{},[269,1030,1031],{},"98",":",[282,1034,1038],{"className":1035,"code":1036,"language":1037,"meta":290,"style":290},"language-json shiki shiki-themes github-light github-dark github-dark","{\"success\":false,\"message\":\"API access requires a Business or Enterprise plan\",\"error_code\":98}\n","json",[269,1039,1040],{"__ignoreMap":290},[302,1041,1042,1046,1049,1051,1054,1057,1060,1062,1065,1067,1070,1072,1074],{"class":304,"line":305},[302,1043,1045],{"class":1044},"slsVL","{",[302,1047,1048],{"class":316},"\"success\"",[302,1050,1032],{"class":1044},[302,1052,1053],{"class":316},"false",[302,1055,1056],{"class":1044},",",[302,1058,1059],{"class":316},"\"message\"",[302,1061,1032],{"class":1044},[302,1063,1064],{"class":312},"\"API access requires a Business or Enterprise plan\"",[302,1066,1056],{"class":1044},[302,1068,1069],{"class":316},"\"error_code\"",[302,1071,1032],{"class":1044},[302,1073,1031],{"class":316},[302,1075,1076],{"class":1044},"}\n",[265,1078,1079,1080,1082,1083,662,1085,666,1087,380],{},"The ",[356,1081,390],{}," button is visible on every plan, so this error is how a plan without API access finds out. Reaching your plan's key allowance returns ",[269,1084,661],{},[269,1086,961],{},[269,1088,1089],{},"You have reached the API key limit for your plan",[274,1091,1093],{"id":1092},"rotating-and-revoking-a-key","Rotating and revoking a key",[338,1095,1096],{"color":442,"icon":443},[265,1097,1098],{},"Keys do not expire. There is no time-to-live and no expiry date on an API key — it stays usable until you revoke it. If you want keys to turn over on a schedule, that schedule has to be yours.",[265,1100,1101],{},"There is no rotate operation for API keys, and no way to change the scopes or the name of an existing one. Rotation is mint-then-revoke:",[382,1103,1104,1107,1110],{},[385,1105,1106],{},"Create a new key with the same scopes and custody level.",[385,1108,1109],{},"Deploy it. Both keys work at the same time, so there is no window where your caller has no credential.",[385,1111,1112],{},"Confirm the new key is being used, then revoke the old one.",[265,1114,1115,1116,1118,1119,1122,1123,1126],{},"To revoke, open the ",[356,1117,379],{}," card and click ",[356,1120,1121],{},"Revoke"," on that key's row. Each row shows the key's name, a badge for its custody level, and when it was last used — or ",[269,1124,1125],{},"never used"," — which is a good way to find keys nothing depends on before you remove them.",[265,1128,1129,1130,1133],{},"Revocation is immediate. The credential is re-verified from the database on every request and nothing about it is cached, so a revoked key stops working on the next call rather than at the end of some cache window. A revoked key shows a ",[356,1131,1132],{},"Revoked"," badge and no longer counts against your plan's key allowance, so revoking frees a slot right away. Revoking also removes the key's account-custody envelope, so content that key could reach through account custody is no longer reachable through it.",[265,1135,1136],{},"Rotate immediately if the full three-part credential was ever transmitted, pasted into a log or ticket, or committed to a repository.",[274,1138,1140],{"id":1139},"when-authentication-fails","When authentication fails",[265,1142,1143,1144,380],{},"Authentication failures are answered by the gateway, before your request reaches the API, so they do not use CredenShare's normal JSON error envelope. Do not parse them as though they carry a numeric ",[269,1145,1146],{},"error_code",[465,1148,1149,1162],{},[468,1150,1151],{},[471,1152,1153,1156,1159],{},[474,1154,1155],{},"Situation",[474,1157,1158],{},"Status",[474,1160,1161],{},"Body",[484,1163,1164,1182],{},[471,1165,1166,1172,1177],{},[489,1167,1168,1169,1171],{},"No ",[269,1170,271],{}," header",[489,1173,1174],{},[269,1175,1176],{},"401",[489,1178,1179],{},[269,1180,1181],{},"{\"message\":\"Unauthorized\"}",[471,1183,1184,1187,1191],{},[489,1185,1186],{},"Any credential that is not currently usable",[489,1188,1189],{},[269,1190,661],{},[489,1192,1193],{},[269,1194,1195],{},"{\"Message\":\"User is not authorized to access this resource with an explicit deny in an identity-based policy\"}",[265,1197,1198,1199,1202],{},"\"Not currently usable\" deliberately covers every reason at once: a malformed credential, an unknown key id, a wrong auth secret, a revoked key, a credential that carried the custody secret, and a key on an account without API access all produce the identical answer. That uniformity is intentional — a caller who could tell \"this key id does not exist\" from \"this key id exists but is revoked\" could probe for valid key ids. It also means the response cannot tell you ",[883,1200,1201],{},"why"," you were refused, so check the obvious causes in order: the prefix and the two-part shape, then whether the key was revoked, then whether the account's plan includes API access.",[265,1204,1205],{},"One timing detail worth knowing: the credential itself is never cached, but the plan entitlement behind it is cached briefly. A key you have just revoked stops working immediately, while a plan change — including newly granted API access — can take up to 30 seconds to take effect.",[1207,1208,1209],"style",{},"html pre.shiki code .shcOC, html code.shiki .shcOC{--shiki-light:#6F42C1;--shiki-default:#B392F0;--shiki-dark:#B392F0}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}",{"title":290,"searchDepth":305,"depth":320,"links":1211},[1212,1213,1214,1215,1216,1223,1224,1225],{"id":276,"depth":320,"text":277},{"id":335,"depth":320,"text":336},{"id":365,"depth":320,"text":366},{"id":449,"depth":320,"text":406},{"id":686,"depth":320,"text":687,"children":1217},[1218,1220,1221,1222],{"id":786,"depth":1219,"text":787},3,{"id":810,"depth":1219,"text":811},{"id":893,"depth":1219,"text":894},{"id":906,"depth":1219,"text":907},{"id":922,"depth":320,"text":923},{"id":1092,"depth":320,"text":1093},{"id":1139,"depth":320,"text":1140},"How to authenticate requests with a CredenShare API key, and what scopes, custody levels and plan limits control.","md",{},true,{"title":138,"description":1226},"qUEIFYlR_o_Mpx3Gm73lqpoervw2amnmdXzyFLb9_qQ",[1233,1235],{"title":132,"path":133,"stem":134,"description":1234,"children":-1},"The CredenShare REST API — end-to-end encrypted shares, secure requests and usage stats, driven from your own code.",{"title":142,"path":143,"stem":144,"description":1236,"children":-1},"The end-to-end encrypted share resource, and the client-side work a create requires.",1788908850327]