[{"data":1,"prerenderedAt":1467},["ShallowReactive",2],{"navigation":3,"/api/errors-and-limits":258,"/api/errors-and-limits-surround":1462},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":216,"api":260,"body":261,"description":1456,"extension":1457,"links":260,"meta":1458,"navigation":1459,"path":217,"seo":1460,"stem":218,"__hash__":1461},"docs/6.api/7.errors-and-limits.md",null,{"type":262,"value":263,"toc":1441},"minimark",[264,268,273,276,370,438,455,472,476,483,780,785,788,893,896,907,957,964,967,988,991,995,1012,1050,1066,1070,1098,1107,1110,1117,1120,1162,1165,1200,1203,1207,1214,1257,1265,1270,1284,1287,1290,1293,1306,1324,1331,1350,1366,1379,1382,1397,1401,1415,1418,1437],[265,266,267],"p",{},"Everything the API refuses, and how to tell the refusals apart.",[269,270,272],"h2",{"id":271},"the-error-envelope","The error envelope",[265,274,275],{},"Every error produced by the API itself uses one flat envelope:",[277,278,283],"pre",{"className":279,"code":280,"language":281,"meta":282,"style":282},"language-json shiki shiki-themes github-light github-dark github-dark","{\n  \"success\": false,\n  \"message\": \"Validation failed\",\n  \"error_code\": 19,\n  \"additional_data\": {\n    \"encryption_type\": \"\u003Cwhy this field was rejected>\"\n  }\n}\n","json","",[284,285,286,295,311,325,338,347,358,364],"code",{"__ignoreMap":282},[287,288,291],"span",{"class":289,"line":290},"line",1,[287,292,294],{"class":293},"slsVL","{\n",[287,296,298,302,305,308],{"class":289,"line":297},2,[287,299,301],{"class":300},"suiK_","  \"success\"",[287,303,304],{"class":293},": ",[287,306,307],{"class":300},"false",[287,309,310],{"class":293},",\n",[287,312,314,317,319,323],{"class":289,"line":313},3,[287,315,316],{"class":300},"  \"message\"",[287,318,304],{"class":293},[287,320,322],{"class":321},"sfrk1","\"Validation failed\"",[287,324,310],{"class":293},[287,326,328,331,333,336],{"class":289,"line":327},4,[287,329,330],{"class":300},"  \"error_code\"",[287,332,304],{"class":293},[287,334,335],{"class":300},"19",[287,337,310],{"class":293},[287,339,341,344],{"class":289,"line":340},5,[287,342,343],{"class":300},"  \"additional_data\"",[287,345,346],{"class":293},": {\n",[287,348,350,353,355],{"class":289,"line":349},6,[287,351,352],{"class":300},"    \"encryption_type\"",[287,354,304],{"class":293},[287,356,357],{"class":321},"\"\u003Cwhy this field was rejected>\"\n",[287,359,361],{"class":289,"line":360},7,[287,362,363],{"class":293},"  }\n",[287,365,367],{"class":289,"line":366},8,[287,368,369],{"class":293},"}\n",[371,372,373,386],"table",{},[374,375,376],"thead",{},[377,378,379,383],"tr",{},[380,381,382],"th",{},"Field",[380,384,385],{},"Notes",[387,388,389,403,413,428],"tbody",{},[377,390,391,397],{},[392,393,394],"td",{},[284,395,396],{},"success",[392,398,399,400,402],{},"Always ",[284,401,307],{}," on an error.",[377,404,405,410],{},[392,406,407],{},[284,408,409],{},"message",[392,411,412],{},"Prose, meant for a human reading a log. Some are fixed strings, some are written for the specific refusal. Do not branch on it.",[377,414,415,420],{},[392,416,417],{},[284,418,419],{},"error_code",[392,421,422,423,427],{},"An ",[424,425,426],"strong",{},"integer",". This is the field to branch on.",[377,429,430,435],{},[392,431,432],{},[284,433,434],{},"additional_data",[392,436,437],{},"Omitted unless the refusal has structured detail. On a validation failure it maps each rejected JSON field name to a reason.",[265,439,440,441,444,445,448,449,454],{},"There is no ",[284,442,443],{},"data"," wrapper, no ",[284,446,447],{},"meta"," block, no request id, and no string error code. Successful responses are shaped differently — see ",[450,451,453],"a",{"href":452},"/api#response-shapes","Response shapes",".",[456,457,460],"callout",{"color":458,"icon":459},"warning","i-lucide-alert-triangle",[265,461,462,463,466,467,471],{},"Authentication failures do ",[424,464,465],{},"not"," use this envelope. They are produced by the gateway before your request reaches the API. See ",[450,468,470],{"href":469},"#authentication-failures","Authentication failures"," below.",[269,473,475],{"id":474},"error-codes","Error codes",[265,477,478,479,482],{},"These are the codes reachable on ",[284,480,481],{},"/v1",". Codes are stable; messages are not.",[371,484,485,498],{},[374,486,487],{},[377,488,489,492,495],{},[380,490,491],{},"Code",[380,493,494],{},"HTTP",[380,496,497],{},"What triggers it",[387,499,500,555,586,599,618,630,644,659,676,686,699,717,736,746,756,766],{},[377,501,502,504,507],{},[392,503,335],{},[392,505,506],{},"400",[392,508,509,510,513,514,513,516,513,519,522,523,525,526,529,530,533,534,536,537,540,541,544,545,548,549,551,552,554],{},"Validation failed. A required field is missing (",[284,511,512],{},"title",", ",[284,515,443],{},[284,517,518],{},"encryption_type",[284,520,521],{},"access_token","), ",[284,524,512],{}," exceeds 256 characters, ",[284,527,528],{},"description"," exceeds 1024, ",[284,531,532],{},"expired_at"," does not parse, ",[284,535,518],{}," is anything other than ",[284,538,539],{},"e2ee-aes256-gcm",", or an ",[284,542,543],{},"item_key_wrap"," was sent by a key whose custody level is ",[284,546,547],{},"none",". ",[284,550,434],{}," names the offending fields; the last two cases carry a written explanation in ",[284,553,409],{}," instead.",[377,556,557,560,562],{},[392,558,559],{},"44",[392,561,506],{},[392,563,564,567,568,571,572,513,575,578,579,581,582,585],{},[284,565,566],{},"\"Cannot parse request params\""," — the request body is not valid JSON, a ",[284,569,570],{},"DELETE"," arrived without a short code, or you used a method other than ",[284,573,574],{},"POST",[284,576,577],{},"GET"," or ",[284,580,570],{}," on a ",[284,583,584],{},"/v1/shares"," path.",[377,587,588,591,593],{},[392,589,590],{},"104",[392,592,506],{},[392,594,595,598],{},[284,596,597],{},"\"An Idempotency-Key header is required on this request\""," — the header was missing or whitespace only on a create.",[377,600,601,604,607],{},[392,602,603],{},"105",[392,605,606],{},"409",[392,608,609,610,613,614,617],{},"The ",[284,611,612],{},"Idempotency-Key"," has already been used with a ",[424,615,616],{},"different"," request body.",[377,619,620,623,625],{},[392,621,622],{},"106",[392,624,606],{},[392,626,609,627,629],{},[284,628,612],{}," is in flight — an earlier request using it has not finished.",[377,631,632,635,638],{},[392,633,634],{},"1",[392,636,637],{},"404",[392,639,640,643],{},[284,641,642],{},"\"Share not found\""," — unknown short code, already expired, or owned by another account. The three are deliberately indistinguishable so short codes cannot be probed.",[377,645,646,649,652],{},[392,647,648],{},"53",[392,650,651],{},"403",[392,653,654,655,658],{},"Plan upgrade required. Raised when ",[284,656,657],{},"passcode_verifier"," is sent on a plan without view protection, or when the organization the key acts in has no owner linked to an active subscription.",[377,660,661,664,666],{},[392,662,663],{},"61",[392,665,651],{},[392,667,668,671,672,454],{},[284,669,670],{},"\"You have reached limit of your share creation.\""," — the plan's share allowance is spent. See ",[450,673,675],{"href":674},"#share-allowance","Share allowance",[377,677,678,681,683],{},[392,679,680],{},"76",[392,682,651],{},[392,684,685],{},"The share is marked owner-only and the caller is not its owner.",[377,687,688,691,693],{},[392,689,690],{},"78",[392,692,651],{},[392,694,695,698],{},[284,696,697],{},"\"You do not have permission to perform this action on this team\""," — the key does not carry the scope the endpoint requires. Despite the wording, this is a scope problem, not a team problem.",[377,700,701,704,707],{},[392,702,703],{},"107",[392,705,706],{},"429",[392,708,709,712,713,454],{},[284,710,711],{},"\"Rate limit exceeded\"",". See ",[450,714,716],{"href":715},"#rate-limits","Rate limits",[377,718,719,722,725],{},[392,720,721],{},"11",[392,723,724],{},"500",[392,726,727,728,732,733,735],{},"Unexpected internal failure. Retry it — and if it was a create, retry with the ",[729,730,731],"em",{},"same"," ",[284,734,612],{},", which is what stops a second copy of the secret being minted.",[377,737,738,741,743],{},[392,739,740],{},"24",[392,742,724],{},[392,744,745],{},"The user record behind the key could not be read while resolving your plan.",[377,747,748,751,753],{},[392,749,750],{},"42",[392,752,724],{},[392,754,755],{},"The share was found but could not be expired.",[377,757,758,761,763],{},[392,759,760],{},"45",[392,762,724],{},[392,764,765],{},"The organization behind the key could not be read while resolving your plan.",[377,767,768,771,774],{},[392,769,770],{},"108",[392,772,773],{},"503",[392,775,776,777,779],{},"The billing lookup needed to check your share allowance failed or came back empty. This is deliberately a ",[284,778,773],{}," and not an allow: retry it.",[781,782,784],"h3",{"id":783},"codes-from-key-management","Codes from key management",[265,786,787],{},"Key management happens in the dashboard rather than through this API, so you will normally meet these in the interface. The codes are listed here so they can be looked up.",[371,789,790,800],{},[374,791,792],{},[377,793,794,796,798],{},[380,795,491],{},[380,797,494],{},[380,799,497],{},[387,801,802,816,829,842,855,865,875],{},[377,803,804,807,810],{},[392,805,806],{},"10",[392,808,809],{},"401",[392,811,812,815],{},[284,813,814],{},"\"Login required\""," — the management call had no session.",[377,817,818,821,823],{},[392,819,820],{},"98",[392,822,651],{},[392,824,825,828],{},[284,826,827],{},"\"API access requires a Business or Enterprise plan\""," — minting a key on a plan without API access.",[377,830,831,834,836],{},[392,832,833],{},"99",[392,835,637],{},[392,837,838,841],{},[284,839,840],{},"\"API key not found\""," — unknown key id, or a key belonging to another account. Both give the same answer on purpose.",[377,843,844,847,849],{},[392,845,846],{},"100",[392,848,651],{},[392,850,851,854],{},[284,852,853],{},"\"You have reached the API key limit for your plan\""," — the plan's key allowance is fully used. Revoking a key frees its slot immediately.",[377,856,857,860,862],{},[392,858,859],{},"101",[392,861,506],{},[392,863,864],{},"A requested scope is outside the supported set.",[377,866,867,870,872],{},[392,868,869],{},"102",[392,871,506],{},[392,873,874],{},"The key name was empty.",[377,876,877,880,882],{},[392,878,879],{},"103",[392,881,506],{},[392,883,884,885,513,888,513,890,454],{},"The requested custody level is not one of ",[284,886,887],{},"0",[284,889,634],{},[284,891,892],{},"2",[269,894,716],{"id":895},"rate-limits",[265,897,898,899,902,903,906],{},"Limits are expressed in ",[424,900,901],{},"requests per minute, sustained",", with a burst ceiling of exactly ",[424,904,905],{},"twice"," the sustained rate. There is one number to configure per account; the burst follows from it.",[371,908,909,922],{},[374,910,911],{},[377,912,913,916,919],{},[380,914,915],{},"Plan",[380,917,918],{},"Sustained",[380,920,921],{},"Burst",[387,923,924,935,946],{},[377,925,926,929,932],{},[392,927,928],{},"Business",[392,930,931],{},"100 req/min",[392,933,934],{},"200",[377,936,937,940,943],{},[392,938,939],{},"Enterprise",[392,941,942],{},"600 req/min",[392,944,945],{},"1200",[377,947,948,951,954],{},[392,949,950],{},"Everything else",[392,952,953],{},"No API access",[392,955,956],{},"—",[265,958,959,960,963],{},"The sustained rate comes from your plan's ",[284,961,962],{},"api_rate_limit_rpm"," entitlement. A negotiated per-account limit can be set and overrides the plan value, so if your contract says something different, your contract is what applies. An account with no rate limit granted has no API access at all — an unset value means zero, never unlimited.",[265,965,966],{},"Two things are worth knowing about how requests are counted:",[968,969,970,977],"ul",{},[971,972,973,976],"li",{},[424,974,975],{},"Two buckets are checked on every request"," — one for the API key, one for the account — and the stricter of the two decides. Minting more keys does not multiply your allowance; ten keys on a 100 rpm account share 100 rpm.",[971,978,979,982,983,985,986,454],{},[424,980,981],{},"Every request that reaches the shares endpoints counts",", including ones that then fail a scope check or validation. A tight retry loop on a ",[284,984,506],{}," will eventually earn you a ",[284,987,706],{},[265,989,990],{},"There is no daily, weekly or monthly request quota anywhere in the API. Rate is the only request-side limit.",[781,992,994],{"id":993},"the-429-response","The 429 response",[277,996,1000],{"className":997,"code":998,"language":999,"meta":282,"style":282},"language-http shiki shiki-themes github-light github-dark github-dark","HTTP/1.1 429 Too Many Requests\nRetry-After: 12\n","http",[284,1001,1002,1007],{"__ignoreMap":282},[287,1003,1004],{"class":289,"line":290},[287,1005,1006],{},"HTTP/1.1 429 Too Many Requests\n",[287,1008,1009],{"class":289,"line":297},[287,1010,1011],{},"Retry-After: 12\n",[277,1013,1015],{"className":279,"code":1014,"language":281,"meta":282,"style":282},"{ \"success\": false, \"message\": \"Rate limit exceeded\", \"error_code\": 107 }\n",[284,1016,1017],{"__ignoreMap":282},[287,1018,1019,1022,1025,1027,1029,1031,1034,1036,1038,1040,1043,1045,1047],{"class":289,"line":290},[287,1020,1021],{"class":293},"{ ",[287,1023,1024],{"class":300},"\"success\"",[287,1026,304],{"class":293},[287,1028,307],{"class":300},[287,1030,513],{"class":293},[287,1032,1033],{"class":300},"\"message\"",[287,1035,304],{"class":293},[287,1037,711],{"class":321},[287,1039,513],{"class":293},[287,1041,1042],{"class":300},"\"error_code\"",[287,1044,304],{"class":293},[287,1046,703],{"class":300},[287,1048,1049],{"class":293}," }\n",[265,1051,1052,1055,1056,1059,1060,1062,1063,1065],{},[284,1053,1054],{},"Retry-After"," is in ",[424,1057,1058],{},"whole seconds"," and is never ",[284,1061,887],{}," — the smallest value emitted is ",[284,1064,634],{},". It is the time until the stricter of your two buckets has a token available, so it is the longer of the two waits, not an average. Wait at least that long before retrying; the buckets refill continuously rather than resetting on a fixed window boundary, so retrying earlier will simply be refused again.",[781,1067,1069],{"id":1068},"there-are-no-rate-limit-headers","There are no rate-limit headers",[456,1071,1072],{"color":458,"icon":459},[265,1073,1074,1075,1077,1078,513,1081,513,1084,1087,1088,1091,1092,1094,1095,1097],{},"The API does ",[424,1076,465],{}," emit ",[284,1079,1080],{},"X-RateLimit-Limit",[284,1082,1083],{},"X-RateLimit-Remaining",[284,1085,1086],{},"X-RateLimit-Reset",", or any other ",[284,1089,1090],{},"X-RateLimit-*"," header. The only rate-limit header on this surface is ",[284,1093,1054],{},", and it appears only on a ",[284,1096,706],{},". If you have written a client that reads those headers to pace itself, it is reading nothing.",[265,1099,1100,1101,1103,1104,1106],{},"There is also no usage or quota endpoint to poll. To stay inside your limit, track your own send rate against the sustained figure for your plan, and treat a ",[284,1102,706],{}," with ",[284,1105,1054],{}," as the authoritative signal to back off.",[269,1108,675],{"id":1109},"share-allowance",[265,1111,1112,1113,1116],{},"Request rate is not the only ceiling. Your plan also caps how many shares you may have created in the current period, and ",[424,1114,1115],{},"shares created through the API draw on the same allowance as shares created in the dashboard"," — there is one pool, not two. The number the dashboard shows as remaining shares is the number the API is working against.",[265,1118,1119],{},"When the allowance is spent, a create is refused:",[277,1121,1123],{"className":279,"code":1122,"language":281,"meta":282,"style":282},"{\n  \"success\": false,\n  \"message\": \"You have reached limit of your share creation.\",\n  \"error_code\": 61\n}\n",[284,1124,1125,1129,1139,1149,1158],{"__ignoreMap":282},[287,1126,1127],{"class":289,"line":290},[287,1128,294],{"class":293},[287,1130,1131,1133,1135,1137],{"class":289,"line":297},[287,1132,301],{"class":300},[287,1134,304],{"class":293},[287,1136,307],{"class":300},[287,1138,310],{"class":293},[287,1140,1141,1143,1145,1147],{"class":289,"line":313},[287,1142,316],{"class":300},[287,1144,304],{"class":293},[287,1146,670],{"class":321},[287,1148,310],{"class":293},[287,1150,1151,1153,1155],{"class":289,"line":327},[287,1152,330],{"class":300},[287,1154,304],{"class":293},[287,1156,1157],{"class":300},"61\n",[287,1159,1160],{"class":289,"line":340},[287,1161,369],{"class":293},[265,1163,1164],{},"Three details matter in practice:",[968,1166,1167,1182,1188],{},[971,1168,1169,1172,1173,1175,1176,1178,1179,1181],{},[424,1170,1171],{},"The allowance is checked before the encryption-type check."," On an exhausted plan a create that is also wrong in some other way — plaintext ",[284,1174,518],{},", for example — comes back as this ",[284,1177,651],{},", not as the ",[284,1180,506],{}," you were expecting. Fix the allowance first, then re-read the error.",[971,1183,1184,1187],{},[424,1185,1186],{},"When your key acts inside an organization, the organization's allowance is what applies",", not the individual member's. A seat member of a paying team is judged by the team's plan.",[971,1189,1190,1193,1194,1196,1197,1199],{},[424,1191,1192],{},"A failed billing lookup is a refusal, not an allow."," If the plan cannot be resolved, the create fails with ",[284,1195,773],{}," and ",[284,1198,419],{}," 108. Retry it; do not treat it as a permanent denial.",[265,1201,1202],{},"Plans whose share allowance is unlimited are never refused for this reason.",[269,1204,1206],{"id":1205},"key-and-webhook-allowances","Key and webhook allowances",[265,1208,1209,1210,1213],{},"Two further ceilings come from your plan. Unlike the share allowance, these count what exists ",[424,1211,1212],{},"right now"," rather than what you have created this period, so revoking a key or deleting an endpoint frees its slot immediately.",[371,1215,1216,1228],{},[374,1217,1218],{},[377,1219,1220,1222,1225],{},[380,1221,915],{},[380,1223,1224],{},"API keys",[380,1226,1227],{},"Webhook endpoints",[387,1229,1230,1240,1249],{},[377,1231,1232,1234,1237],{},[392,1233,928],{},[392,1235,1236],{},"5",[392,1238,1239],{},"3",[377,1241,1242,1244,1247],{},[392,1243,939],{},[392,1245,1246],{},"25",[392,1248,806],{},[377,1250,1251,1253,1255],{},[392,1252,950],{},[392,1254,887],{},[392,1256,887],{},[265,1258,1259,1260,1103,1262,1264],{},"Minting a key beyond the allowance returns ",[284,1261,651],{},[284,1263,419],{}," 100. There is no equivalent API error for webhooks, because endpoints are created in the dashboard rather than through this API — you meet that ceiling there.",[265,1266,1267],{},[424,1268,1269],{},"The two are counted on different scopes, which only shows up on a team:",[968,1271,1272,1278],{},[971,1273,1274,1277],{},[424,1275,1276],{},"Webhook endpoints are counted across the organization"," when your key acts inside one. A five-person team on Business shares three endpoints between them, not three each.",[971,1279,1280,1283],{},[424,1281,1282],{},"API keys are counted per user."," Each member of that same team holds their own allowance of five.",[265,1285,1286],{},"A negotiated per-account override beats the plan value for either, the same way it does for the rate limit.",[269,1288,470],{"id":1289},"authentication-failures",[265,1291,1292],{},"Authentication is settled at the gateway, before your request reaches the API. That means authentication failures do not use the error envelope, and there are exactly two shapes.",[265,1294,1295,1302,1303,1305],{},[424,1296,1297,1298,1301],{},"No ",[284,1299,1300],{},"Authorization"," header at all"," — ",[284,1304,809],{},":",[277,1307,1309],{"className":279,"code":1308,"language":281,"meta":282,"style":282},"{ \"message\": \"Unauthorized\" }\n",[284,1310,1311],{"__ignoreMap":282},[287,1312,1313,1315,1317,1319,1322],{"class":289,"line":290},[287,1314,1021],{"class":293},[287,1316,1033],{"class":300},[287,1318,304],{"class":293},[287,1320,1321],{"class":321},"\"Unauthorized\"",[287,1323,1049],{"class":293},[265,1325,1326,1302,1329,1305],{},[424,1327,1328],{},"A credential that cannot currently be used",[284,1330,651],{},[277,1332,1334],{"className":279,"code":1333,"language":281,"meta":282,"style":282},"{ \"Message\": \"User is not authorized to access this resource with an explicit deny in an identity-based policy\" }\n",[284,1335,1336],{"__ignoreMap":282},[287,1337,1338,1340,1343,1345,1348],{"class":289,"line":290},[287,1339,1021],{"class":293},[287,1341,1342],{"class":300},"\"Message\"",[287,1344,304],{"class":293},[287,1346,1347],{"class":321},"\"User is not authorized to access this resource with an explicit deny in an identity-based policy\"",[287,1349,1049],{"class":293},[265,1351,1352,1353,1356,1357,1360,1361,578,1363,1365],{},"Note the capital ",[284,1354,1355],{},"M"," in ",[284,1358,1359],{},"Message"," on the second one, and that neither body carries ",[284,1362,396],{},[284,1364,419],{},". Parsing either as the standard envelope will fail.",[456,1367,1370],{"color":1368,"icon":1369},"info","i-lucide-info",[265,1371,1372,1375,1376,1378],{},[424,1373,1374],{},"A bad credential is not distinguishable from a permissions failure."," Every one of these produces that same ",[284,1377,651],{},": a malformed token, an unknown key, a revoked key, a credential sent with its custody secret still attached, and a perfectly valid key on an account whose plan does not carry API access.",[265,1380,1381],{},"That is deliberate — a response that differed by cause would let anyone probe which key ids exist — but it does mean the response cannot tell you what went wrong. When you meet it, check in the dashboard, in this order: the key still exists and is not revoked; you are sending only the first two parts of the credential; and the account is on a plan with API access.",[265,1383,1384,1385,1388,1389,1103,1391,1393,1394,1396],{},"One useful discriminator: ",[424,1386,1387],{},"if you got the error envelope, your credential is fine."," A missing scope is not an authentication failure — it reaches the API and comes back as ",[284,1390,651],{},[284,1392,419],{}," 78. So an envelope means you authenticated and were refused for some other reason; a bare ",[284,1395,1359],{}," body means you did not authenticate.",[781,1398,1400],{"id":1399},"timing","Timing",[968,1402,1403,1409],{},[971,1404,1405,1408],{},[424,1406,1407],{},"Revocation is immediate."," The credential is verified on every single request, with no caching, so a revoked key stops working on its next call.",[971,1410,1411,1414],{},[424,1412,1413],{},"Entitlement changes take up to 30 seconds."," The answer to \"does this account have API access, and at what rate\" is cached briefly, and denials are cached too. An account that has just been upgraded, or just had a negotiated limit applied, can keep seeing the old answer for up to half a minute. Wait, then retry.",[1416,1417],"hr",{},[456,1419,1421],{"color":1368,"icon":1420},"i-lucide-arrow-right",[265,1422,1423,1424,1430,1431,1436],{},"Rate limits are per key and scale with your plan. ",[450,1425,1429],{"href":1426,"rel":1427},"https://credenshare.io/pricing",[1428],"nofollow","See the limits by tier",", or ",[450,1432,1435],{"href":1433,"rel":1434},"https://credenshare.io/enterprise",[1428],"get in touch"," if you need a higher ceiling.",[1438,1439,1440],"style",{},"html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":282,"searchDepth":290,"depth":297,"links":1442},[1443,1444,1447,1451,1452,1453],{"id":271,"depth":297,"text":272},{"id":474,"depth":297,"text":475,"children":1445},[1446],{"id":783,"depth":313,"text":784},{"id":895,"depth":297,"text":716,"children":1448},[1449,1450],{"id":993,"depth":313,"text":994},{"id":1068,"depth":313,"text":1069},{"id":1109,"depth":297,"text":675},{"id":1205,"depth":297,"text":1206},{"id":1289,"depth":297,"text":470,"children":1454},[1455],{"id":1399,"depth":313,"text":1400},"The error envelope, every error code you can hit, request-rate limits, and what an authentication failure actually looks like.","md",{},true,{"title":216,"description":1456},"o0sbRCSZmgTTaBRL5I3zAqQFpIOUQOlJ2GuOzvE_-Fo",[1463,1465],{"title":212,"path":213,"stem":214,"description":1464,"children":-1},"Connect an AI assistant to CredenShare over the Model Context Protocol, without a plaintext secret ever reaching the model.",{"title":220,"path":221,"stem":222,"description":1466,"children":-1},"Official CredenShare clients for Node, Python, Go and Rust — they perform the encryption, so you pass plaintext and get back a link.",1788908850654]