[{"data":1,"prerenderedAt":1605},["ShallowReactive",2],{"navigation":3,"/api/mcp":258,"/api/mcp-surround":1600},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":212,"api":260,"body":261,"description":1594,"extension":1595,"links":260,"meta":1596,"navigation":1597,"path":213,"seo":1598,"stem":214,"__hash__":1599},"docs/6.api/6.mcp.md",null,{"type":262,"value":263,"toc":1571},"minimark",[264,268,280,283,291,296,306,309,312,315,318,375,378,392,395,444,447,452,463,470,601,605,612,680,689,787,794,801,820,824,913,926,936,939,942,1126,1129,1207,1211,1214,1308,1316,1318,1321,1327,1330,1367,1374,1378,1381,1384,1387,1390,1395,1398,1425,1429,1431,1434,1440,1443,1448,1455,1469,1473,1476,1484,1493,1495,1498,1500,1503,1506,1512,1523,1527,1532,1537,1540,1544,1559,1567],[265,266,267],"p",{},"CredenShare hosts an MCP server so an AI assistant can do the work around a credential handoff — asking someone for a secret, listing what exists, expiring something, rotating a webhook signing secret — without ever handling a plaintext secret itself.",[269,270,273],"callout",{"color":271,"icon":272},"info","i-lucide-info",[265,274,275,279],{},[276,277,278],"strong",{},"No SDK wraps this surface."," A case-insensitive search for MCP returns nothing in all four client repositories. MCP is also the only programmatic route to two capabilities the SDKs do not reach at all — asking someone for a secret, and browser-assisted share creation — as well as the only way to list webhook endpoints or rotate a signing secret.",[265,281,282],{},"That constraint shapes every tool on the surface. No tool accepts the contents of a secret as an argument, because that would put the secret in the model's context and in our logs. No tool returns the contents of one, for the same reason in the other direction. And CredenShare cannot decrypt its own storage, so metadata-only is a property of the system here rather than a restriction waiting to be lifted.",[265,284,285,286,290],{},"The consequence is worth knowing before you start: the most useful tool on this server is the one that hands the last step to a human. See ",[287,288,289],"code",{},"create_share_via_browser"," below.",[292,293,295],"h2",{"id":294},"endpoint","Endpoint",[297,298,303],"pre",{"className":299,"code":301,"language":302},[300],"language-text","POST https://api.credenshare.io/v1/mcp\n","text",[287,304,301],{"__ignoreMap":305},"",[265,307,308],{},"One URL, one HTTP method. The transport is MCP's Streamable HTTP in stateless mode: one POST carries one JSON-RPC 2.0 request and gets one JSON response back. There is no SSE stream, no session id, and no long-lived connection — every request is complete on its own, which is what lets a serverless function serve it.",[265,310,311],{},"Point your MCP client at that URL with a bearer credential. Nothing else is negotiated.",[292,313,138],{"id":314},"authentication",[265,316,317],{},"The MCP server uses the same API keys as the REST API, in the standard header:",[297,319,323],{"className":320,"code":321,"language":322,"meta":305,"style":305},"language-bash shiki shiki-themes github-light github-dark github-dark","curl -sS https://api.credenshare.io/v1/mcp \\\n  -H \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/list\"}'\n","bash",[287,324,325,345,356,366],{"__ignoreMap":305},[326,327,330,334,338,342],"span",{"class":328,"line":329},"line",1,[326,331,333],{"class":332},"shcOC","curl",[326,335,337],{"class":336},"suiK_"," -sS",[326,339,341],{"class":340},"sfrk1"," https://api.credenshare.io/v1/mcp",[326,343,344],{"class":336}," \\\n",[326,346,348,351,354],{"class":328,"line":347},2,[326,349,350],{"class":336},"  -H",[326,352,353],{"class":340}," \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"",[326,355,344],{"class":336},[326,357,359,361,364],{"class":328,"line":358},3,[326,360,350],{"class":336},[326,362,363],{"class":340}," \"Content-Type: application/json\"",[326,365,344],{"class":336},[326,367,369,372],{"class":328,"line":368},4,[326,370,371],{"class":336},"  -d",[326,373,374],{"class":340}," '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/list\"}'\n",[265,376,377],{},"Keys are created from your CredenShare account settings and the secret is shown exactly once. The API cannot mint keys, and your plan must include API access.",[269,379,382],{"color":380,"icon":381},"warning","i-lucide-alert-triangle",[265,383,384,387,388,391],{},[276,385,386],{},"Send only the first two parts of your credential."," The value you were shown has three: ",[287,389,390],{},"crs_sk_live_\u003CkeyId>.\u003CauthSecret>.\u003CcustodySecret>",". The third part is the custody secret and must never leave your machine. A credential that arrives with all three parts is refused outright, and the key is then treated as compromised — rotate it.",[265,393,394],{},"Authentication is settled before the JSON-RPC layer is reached, so a rejected request comes back as an HTTP error whose body is not a JSON-RPC envelope:",[396,397,398,411],"table",{},[399,400,401],"thead",{},[402,403,404,408],"tr",{},[405,406,407],"th",{},"Situation",[405,409,410],{},"Response",[412,413,414,433],"tbody",{},[402,415,416,424],{},[417,418,419,420,423],"td",{},"No ",[287,421,422],{},"Authorization"," header",[417,425,426,429,430],{},[287,427,428],{},"401"," with ",[287,431,432],{},"{\"message\":\"Unauthorized\"}",[402,434,435,438],{},[417,436,437],{},"A credential that does not verify",[417,439,440,443],{},[287,441,442],{},"403"," with an access-denied message",[265,445,446],{},"A revoked key is deliberately indistinguishable from one that never existed. Nothing in the response can be used to work out which key ids are real.",[448,449,451],"h3",{"id":450},"scopes","Scopes",[265,453,454,455,458,459,462],{},"Every tool requires exactly one scope, listed in the tool table below. Scopes are matched as exact strings and there is no hierarchy: ",[287,456,457],{},"shares:write"," does not imply ",[287,460,461],{},"shares:read",". Mint the key with every scope the tools you intend to call require.",[265,464,465,466,469],{},"A call with a valid credential but a missing scope is not an HTTP error. It comes back as a tool result marked ",[287,467,468],{},"isError",", because the call was well-formed and the answer is final:",[297,471,475],{"className":472,"code":473,"language":474,"meta":305,"style":305},"language-json shiki shiki-themes github-light github-dark github-dark","{\n  \"jsonrpc\": \"2.0\",\n  \"id\": 3,\n  \"result\": {\n    \"content\": [\n      {\n        \"type\": \"text\",\n        \"text\": \"This API key lacks the \\\"shares:write\\\" scope, which expire_share requires. Mint a key with that scope.\"\n      }\n    ],\n    \"isError\": true\n  }\n}\n","json",[287,476,477,483,497,509,517,526,532,545,566,572,578,589,595],{"__ignoreMap":305},[326,478,479],{"class":328,"line":329},[326,480,482],{"class":481},"slsVL","{\n",[326,484,485,488,491,494],{"class":328,"line":347},[326,486,487],{"class":336},"  \"jsonrpc\"",[326,489,490],{"class":481},": ",[326,492,493],{"class":340},"\"2.0\"",[326,495,496],{"class":481},",\n",[326,498,499,502,504,507],{"class":328,"line":358},[326,500,501],{"class":336},"  \"id\"",[326,503,490],{"class":481},[326,505,506],{"class":336},"3",[326,508,496],{"class":481},[326,510,511,514],{"class":328,"line":368},[326,512,513],{"class":336},"  \"result\"",[326,515,516],{"class":481},": {\n",[326,518,520,523],{"class":328,"line":519},5,[326,521,522],{"class":336},"    \"content\"",[326,524,525],{"class":481},": [\n",[326,527,529],{"class":328,"line":528},6,[326,530,531],{"class":481},"      {\n",[326,533,535,538,540,543],{"class":328,"line":534},7,[326,536,537],{"class":336},"        \"type\"",[326,539,490],{"class":481},[326,541,542],{"class":340},"\"text\"",[326,544,496],{"class":481},[326,546,548,551,553,556,559,561,563],{"class":328,"line":547},8,[326,549,550],{"class":336},"        \"text\"",[326,552,490],{"class":481},[326,554,555],{"class":340},"\"This API key lacks the ",[326,557,558],{"class":336},"\\\"",[326,560,457],{"class":340},[326,562,558],{"class":336},[326,564,565],{"class":340}," scope, which expire_share requires. Mint a key with that scope.\"\n",[326,567,569],{"class":328,"line":568},9,[326,570,571],{"class":481},"      }\n",[326,573,575],{"class":328,"line":574},10,[326,576,577],{"class":481},"    ],\n",[326,579,581,584,586],{"class":328,"line":580},11,[326,582,583],{"class":336},"    \"isError\"",[326,585,490],{"class":481},[326,587,588],{"class":336},"true\n",[326,590,592],{"class":328,"line":591},12,[326,593,594],{"class":481},"  }\n",[326,596,598],{"class":328,"line":597},13,[326,599,600],{"class":481},"}\n",[292,602,604],{"id":603},"protocol","Protocol",[265,606,607,608,611],{},"Four JSON-RPC methods are implemented. Anything else returns ",[287,609,610],{},"-32601",".",[396,613,614,624],{},[399,615,616],{},[402,617,618,621],{},[405,619,620],{},"Method",[405,622,623],{},"Result",[412,625,626,636,646,670],{},[402,627,628,633],{},[417,629,630],{},[287,631,632],{},"initialize",[417,634,635],{},"Server identity and capabilities",[402,637,638,643],{},[417,639,640],{},[287,641,642],{},"ping",[417,644,645],{},"An empty object",[402,647,648,653],{},[417,649,650],{},[287,651,652],{},"tools/list",[417,654,655,658,659,662,663,666,667],{},[287,656,657],{},"{\"tools\":[…]}",", where each entry has ",[287,660,661],{},"name",", ",[287,664,665],{},"description"," and ",[287,668,669],{},"inputSchema",[402,671,672,677],{},[417,673,674],{},[287,675,676],{},"tools/call",[417,678,679],{},"The tool's result",[265,681,682,684,685,688],{},[287,683,632],{}," advertises protocol version ",[287,686,687],{},"2025-06-18",". The value is fixed — the server does not echo the version the client asked for.",[297,690,692],{"className":472,"code":691,"language":474,"meta":305,"style":305},"{\n  \"jsonrpc\": \"2.0\",\n  \"id\": 1,\n  \"result\": {\n    \"protocolVersion\": \"2025-06-18\",\n    \"capabilities\": { \"tools\": {} },\n    \"serverInfo\": { \"name\": \"credenshare\", \"version\": \"1.0.0\" }\n  }\n}\n",[287,693,694,698,708,719,725,737,751,779,783],{"__ignoreMap":305},[326,695,696],{"class":328,"line":329},[326,697,482],{"class":481},[326,699,700,702,704,706],{"class":328,"line":347},[326,701,487],{"class":336},[326,703,490],{"class":481},[326,705,493],{"class":340},[326,707,496],{"class":481},[326,709,710,712,714,717],{"class":328,"line":358},[326,711,501],{"class":336},[326,713,490],{"class":481},[326,715,716],{"class":336},"1",[326,718,496],{"class":481},[326,720,721,723],{"class":328,"line":368},[326,722,513],{"class":336},[326,724,516],{"class":481},[326,726,727,730,732,735],{"class":328,"line":519},[326,728,729],{"class":336},"    \"protocolVersion\"",[326,731,490],{"class":481},[326,733,734],{"class":340},"\"2025-06-18\"",[326,736,496],{"class":481},[326,738,739,742,745,748],{"class":328,"line":528},[326,740,741],{"class":336},"    \"capabilities\"",[326,743,744],{"class":481},": { ",[326,746,747],{"class":336},"\"tools\"",[326,749,750],{"class":481},": {} },\n",[326,752,753,756,758,761,763,766,768,771,773,776],{"class":328,"line":534},[326,754,755],{"class":336},"    \"serverInfo\"",[326,757,744],{"class":481},[326,759,760],{"class":336},"\"name\"",[326,762,490],{"class":481},[326,764,765],{"class":340},"\"credenshare\"",[326,767,662],{"class":481},[326,769,770],{"class":336},"\"version\"",[326,772,490],{"class":481},[326,774,775],{"class":340},"\"1.0.0\"",[326,777,778],{"class":481}," }\n",[326,780,781],{"class":328,"line":547},[326,782,594],{"class":481},[326,784,785],{"class":328,"line":568},[326,786,600],{"class":481},[265,788,789,790,793],{},"The result also carries an ",[287,791,792],{},"instructions"," string, which clients that surface it will display. It states up front that no tool returns a secret, so a model does not go looking for one.",[265,795,796,797,800],{},"Only the ",[287,798,799],{},"tools"," capability is advertised. There are no resources, no prompts, and deliberately no sampling: a security product asking the client's model to generate something on its behalf has no use here.",[265,802,803,804,807,808,811,812,815,816,819],{},"A ",[276,805,806],{},"notification"," — a request with no ",[287,809,810],{},"id"," — produces no response body at all: HTTP ",[287,813,814],{},"202"," and nothing else. Clients send ",[287,817,818],{},"notifications/initialized"," on every session, and answering it is a protocol violation that some clients surface to the user as an error.",[448,821,823],{"id":822},"errors","Errors",[396,825,826,839],{},[399,827,828],{},[402,829,830,833,836],{},[405,831,832],{},"Code",[405,834,835],{},"Message",[405,837,838],{},"When",[412,840,841,859,884,898],{},[402,842,843,848,853],{},[417,844,845],{},[287,846,847],{},"-32700",[417,849,850],{},[287,851,852],{},"invalid JSON",[417,854,855,856,611],{},"The request body could not be parsed. The parser's own message is in ",[287,857,858],{},"data",[402,860,861,866,871],{},[417,862,863],{},[287,864,865],{},"-32600",[417,867,868],{},[287,869,870],{},"not a JSON-RPC 2.0 request",[417,872,873,876,877,879,880,883],{},[287,874,875],{},"jsonrpc"," is not ",[287,878,493],{},", or ",[287,881,882],{},"method"," is empty",[402,885,886,890,895],{},[417,887,888],{},[287,889,610],{},[417,891,892],{},[287,893,894],{},"unknown method: \u003Cname>",[417,896,897],{},"Not one of the four methods above",[402,899,900,905,910],{},[417,901,902],{},[287,903,904],{},"-32603",[417,906,907],{},[287,908,909],{},"could not encode response",[417,911,912],{},"The server could not serialise its own response",[265,914,915,916,919,920,922,923,925],{},"Every JSON-RPC error is carried on HTTP ",[287,917,918],{},"200",". A JSON-RPC error says the call was malformed; the HTTP layer still succeeded in carrying that answer. So an HTTP status other than ",[287,921,918],{}," or ",[287,924,814],{}," is a transport or authentication problem, never a protocol one.",[265,927,928,929,932,933,935],{},"Problems with a tool's arguments do not come back as ",[287,930,931],{},"-32602"," either. They come back as tool results marked ",[287,934,468],{},". The distinction matters in practice: a business-rule refusal returned as a protocol error looks to a model like a transport fault worth retrying, when it is really a final answer.",[292,937,938],{"id":799},"Tools",[265,940,941],{},"Eight tools, with the scope each one requires:",[396,943,944,960],{},[399,945,946],{},[402,947,948,951,954,957],{},[405,949,950],{},"Tool",[405,952,953],{},"What it does",[405,955,956],{},"Arguments",[405,958,959],{},"Scope",[412,961,962,991,1011,1035,1055,1073,1091,1107],{},[402,963,964,969,972,986],{},[417,965,966],{},[287,967,968],{},"request_secret_from",[417,970,971],{},"Creates a secure request and returns a collect link to give to the person who holds the secret",[417,973,974,977,978,981,982,985],{},[287,975,976],{},"title"," (string, required), ",[287,979,980],{},"fields"," (array of string, required), ",[287,983,984],{},"expires_in_days"," (integer, optional)",[417,987,988],{},[287,989,990],{},"requests:write",[402,992,993,997,1000,1007],{},[417,994,995],{},[287,996,289],{},[417,998,999],{},"Returns a link that opens a pre-composed share for a human to fill in. Creates nothing server-side",[417,1001,1002,977,1004,1006],{},[287,1003,976],{},[287,1005,980],{}," (array of string, required)",[417,1008,1009],{},[287,1010,457],{},[402,1012,1013,1018,1021,1031],{},[417,1014,1015],{},[287,1016,1017],{},"list_shares",[417,1019,1020],{},"Lists the shares on the account, newest first. Metadata only",[417,1022,1023,1026,1027,1030],{},[287,1024,1025],{},"limit"," (integer, optional, 1–100, default 25), ",[287,1028,1029],{},"page"," (integer, optional, 1-based)",[417,1032,1033],{},[287,1034,461],{},[402,1036,1037,1042,1045,1051],{},[417,1038,1039],{},[287,1040,1041],{},"get_share",[417,1043,1044],{},"Looks up one share by short code. Metadata only",[417,1046,1047,1050],{},[287,1048,1049],{},"short_code"," (string, required)",[417,1052,1053],{},[287,1054,461],{},[402,1056,1057,1062,1065,1069],{},[417,1058,1059],{},[287,1060,1061],{},"expire_share",[417,1063,1064],{},"Expires a share immediately. Irreversible",[417,1066,1067,1050],{},[287,1068,1049],{},[417,1070,1071],{},[287,1072,457],{},[402,1074,1075,1080,1083,1086],{},[417,1076,1077],{},[287,1078,1079],{},"share_stats",[417,1081,1082],{},"Reports how many shares are active and expired, total views, and a 14-day daily view history. Figures only",[417,1084,1085],{},"None",[417,1087,1088],{},[287,1089,1090],{},"stats:read",[402,1092,1093,1098,1101,1103],{},[417,1094,1095],{},[287,1096,1097],{},"list_webhooks",[417,1099,1100],{},"Lists the account's webhook endpoints, the events each is subscribed to, and whether it is enabled",[417,1102,1085],{},[417,1104,1105],{},[287,1106,461],{},[402,1108,1109,1114,1117,1122],{},[417,1110,1111],{},[287,1112,1113],{},"rotate_webhook_secret",[417,1115,1116],{},"Issues a new signing secret for an endpoint and returns it once",[417,1118,1119,1050],{},[287,1120,1121],{},"endpoint_id",[417,1123,1124],{},[287,1125,457],{},[265,1127,1128],{},"A call looks like this:",[297,1130,1132],{"className":320,"code":1131,"language":322,"meta":305,"style":305},"curl -sS https://api.credenshare.io/v1/mcp \\\n  -H \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"jsonrpc\": \"2.0\",\n    \"id\": 2,\n    \"method\": \"tools/call\",\n    \"params\": {\n      \"name\": \"list_shares\",\n      \"arguments\": { \"limit\": 10 }\n    }\n  }'\n",[287,1133,1134,1144,1152,1160,1167,1172,1177,1182,1187,1192,1197,1202],{"__ignoreMap":305},[326,1135,1136,1138,1140,1142],{"class":328,"line":329},[326,1137,333],{"class":332},[326,1139,337],{"class":336},[326,1141,341],{"class":340},[326,1143,344],{"class":336},[326,1145,1146,1148,1150],{"class":328,"line":347},[326,1147,350],{"class":336},[326,1149,353],{"class":340},[326,1151,344],{"class":336},[326,1153,1154,1156,1158],{"class":328,"line":358},[326,1155,350],{"class":336},[326,1157,363],{"class":340},[326,1159,344],{"class":336},[326,1161,1162,1164],{"class":328,"line":368},[326,1163,371],{"class":336},[326,1165,1166],{"class":340}," '{\n",[326,1168,1169],{"class":328,"line":519},[326,1170,1171],{"class":340},"    \"jsonrpc\": \"2.0\",\n",[326,1173,1174],{"class":328,"line":528},[326,1175,1176],{"class":340},"    \"id\": 2,\n",[326,1178,1179],{"class":328,"line":534},[326,1180,1181],{"class":340},"    \"method\": \"tools/call\",\n",[326,1183,1184],{"class":328,"line":547},[326,1185,1186],{"class":340},"    \"params\": {\n",[326,1188,1189],{"class":328,"line":568},[326,1190,1191],{"class":340},"      \"name\": \"list_shares\",\n",[326,1193,1194],{"class":328,"line":574},[326,1195,1196],{"class":340},"      \"arguments\": { \"limit\": 10 }\n",[326,1198,1199],{"class":328,"line":580},[326,1200,1201],{"class":340},"    }\n",[326,1203,1204],{"class":328,"line":591},[326,1205,1206],{"class":340},"  }'\n",[448,1208,1210],{"id":1209},"results-are-prose-not-json","Results are prose, not JSON",[265,1212,1213],{},"Every tool returns a single block of text:",[297,1215,1217],{"className":472,"code":1216,"language":474,"meta":305,"style":305},"{\n  \"jsonrpc\": \"2.0\",\n  \"id\": 2,\n  \"result\": {\n    \"content\": [\n      {\n        \"type\": \"text\",\n        \"text\": \"3 share(s) total, page 1 of 1:\\n\\n  a1b2c3  Staging deploy credentials  (no expiry)\\n\"\n      }\n    ]\n  }\n}\n",[287,1218,1219,1223,1233,1244,1250,1256,1260,1270,1291,1295,1300,1304],{"__ignoreMap":305},[326,1220,1221],{"class":328,"line":329},[326,1222,482],{"class":481},[326,1224,1225,1227,1229,1231],{"class":328,"line":347},[326,1226,487],{"class":336},[326,1228,490],{"class":481},[326,1230,493],{"class":340},[326,1232,496],{"class":481},[326,1234,1235,1237,1239,1242],{"class":328,"line":358},[326,1236,501],{"class":336},[326,1238,490],{"class":481},[326,1240,1241],{"class":336},"2",[326,1243,496],{"class":481},[326,1245,1246,1248],{"class":328,"line":368},[326,1247,513],{"class":336},[326,1249,516],{"class":481},[326,1251,1252,1254],{"class":328,"line":519},[326,1253,522],{"class":336},[326,1255,525],{"class":481},[326,1257,1258],{"class":328,"line":528},[326,1259,531],{"class":481},[326,1261,1262,1264,1266,1268],{"class":328,"line":534},[326,1263,537],{"class":336},[326,1265,490],{"class":481},[326,1267,542],{"class":340},[326,1269,496],{"class":481},[326,1271,1272,1274,1276,1279,1282,1285,1288],{"class":328,"line":547},[326,1273,550],{"class":336},[326,1275,490],{"class":481},[326,1277,1278],{"class":340},"\"3 share(s) total, page 1 of 1:",[326,1280,1281],{"class":336},"\\n\\n",[326,1283,1284],{"class":340},"  a1b2c3  Staging deploy credentials  (no expiry)",[326,1286,1287],{"class":336},"\\n",[326,1289,1290],{"class":340},"\"\n",[326,1292,1293],{"class":328,"line":568},[326,1294,571],{"class":481},[326,1296,1297],{"class":328,"line":574},[326,1298,1299],{"class":481},"    ]\n",[326,1301,1302],{"class":328,"line":580},[326,1303,594],{"class":481},[326,1305,1306],{"class":328,"line":591},[326,1307,600],{"class":481},[265,1309,1310,1311,1315],{},"That is a deliberate choice, not an oversight. A model reads prose at least as well as it reads JSON, and prose lets each result say what it does ",[1312,1313,1314],"em",{},"not"," contain — a model that expects a secret back and receives a link will otherwise try again a different way, or apologise to the user for a failure that never happened. Read these strings; do not parse them as a data format.",[292,1317,289],{"id":289},[265,1319,1320],{},"This tool creates nothing. No share, no short code, no stored row. It returns a link:",[297,1322,1325],{"className":1323,"code":1324,"language":302},[300],"https://app.credenshare.io/?compose=\u003Cbase64url>\n",[287,1326,1324],{"__ignoreMap":305},[265,1328,1329],{},"The encoded part is base64url of a title and a list of field names — labels only, never values:",[297,1331,1333],{"className":472,"code":1332,"language":474,"meta":305,"style":305},"{ \"title\": \"Staging deploy credentials\", \"fields\": [\"Username\", \"Password\"] }\n",[287,1334,1335],{"__ignoreMap":305},[326,1336,1337,1340,1343,1345,1348,1350,1353,1356,1359,1361,1364],{"class":328,"line":329},[326,1338,1339],{"class":481},"{ ",[326,1341,1342],{"class":336},"\"title\"",[326,1344,490],{"class":481},[326,1346,1347],{"class":340},"\"Staging deploy credentials\"",[326,1349,662],{"class":481},[326,1351,1352],{"class":336},"\"fields\"",[326,1354,1355],{"class":481},": [",[326,1357,1358],{"class":340},"\"Username\"",[326,1360,662],{"class":481},[326,1362,1363],{"class":340},"\"Password\"",[326,1365,1366],{"class":481},"] }\n",[265,1368,1369,1370,1373],{},"Opening that link opens the CredenShare app with the share already composed: title and field names filled in, values blank. The person types the values, their browser encrypts them, and the finished share link is shown to ",[276,1371,1372],{},"them",", on that page.",[448,1375,1377],{"id":1376},"why-it-works-this-way","Why it works this way",[265,1379,1380],{},"There are two things a hosted server cannot do, and this shape is what remains once you accept both.",[265,1382,1383],{},"It cannot receive the plaintext. Passing a secret as a tool argument puts it in the model's context and in our logs, which is precisely what this product exists to avoid.",[265,1385,1386],{},"It cannot hand back the finished link either — and this is the part that surprises people. A CredenShare share link carries the decryption key in its URL fragment. Returning that link to the caller would put the key in the model's context and undo the whole arrangement, even though nothing that looked like a secret was ever passed around.",[265,1388,1389],{},"Both problems disappear if the human does the last step. So what the assistant produces here is an invitation, not an artefact.",[269,1391,1392],{"color":271,"icon":272},[265,1393,1394],{},"Expect no share link back. The tool's own result says so explicitly, so a well-behaved assistant tells the person to copy the link from the page instead of reporting a failure that did not happen.",[265,1396,1397],{},"A few practical consequences:",[1399,1400,1401,1405,1412,1415,1418],"ul",{},[1402,1403,1404],"li",{},"Give the link to someone who has a CredenShare account — it opens the web app's create-share screen.",[1402,1406,1407,1408,1411],{},"Whoever opens the link creates the share on ",[276,1409,1410],{},"their"," account. The link carries only a title and field names; there is nothing in it that ties the result back to your API key.",[1402,1413,1414],{},"Because the share is created through the app, the normal plan limits apply at that moment, in that person's session.",[1402,1416,1417],{},"The prefill is shape-checked on arrival, because it comes from a URL somebody was handed: the title is truncated to 256 characters and at most 30 field names are accepted. A malformed parameter opens nothing at all.",[1402,1419,1420,1421,1424],{},"The prefill is consumed once, and the ",[287,1422,1423],{},"compose"," parameter is then stripped from the URL.",[292,1426,1428],{"id":1427},"notes-on-the-other-tools","Notes on the other tools",[448,1430,968],{"id":968},[265,1432,1433],{},"Creates a secure request and returns a collect link:",[297,1435,1438],{"className":1436,"code":1437,"language":302},[300],"https://crs.sh/r/\u003Cshort_code>\n",[287,1439,1437],{"__ignoreMap":305},[265,1441,1442],{},"Give that link to the person who holds the secret. Each field you name is presented to them as a masked password field, in the order you listed them, because these are credentials rather than free text. The link carries no decryption key, so it is safe to send over chat, a ticket, or email — and what they submit through it is never returned to the assistant and never appears in a tool result.",[265,1444,1445,1447],{},[287,1446,984],{}," is optional; without it, the request uses your account's default.",[265,1449,1450,1451,1454],{},"If you have a webhook endpoint subscribed to ",[287,1452,1453],{},"request.submitted",", it fires when they submit.",[269,1456,1458],{"color":380,"icon":1457},"i-lucide-shield-alert",[265,1459,1460,1463,1464,1468],{},[276,1461,1462],{},"A request created this way is not end-to-end encrypted."," End-to-end collection depends on\nan X25519 public key generated in the owner's browser, and a hosted server has no way to\nproduce one — so submissions to a request created here are sent over TLS and encrypted on\nCredenShare's servers, where CredenShare can read them. That is the same position as a\n",[1465,1466,1467],"a",{"href":252},"Slack share",". If you need collection we cannot read, create the request\nin the CredenShare app instead, where your browser generates the keypair.",[448,1470,1472],{"id":1471},"list_shares-and-get_share","list_shares and get_share",[265,1474,1475],{},"Both are metadata only, because there is no content for them to return.",[265,1477,1478,1480,1481,1483],{},[287,1479,1017],{}," lists shares newest first — short code, title and expiry, one per line, preceded by a total and page count when there is more than one page. A ",[287,1482,1025],{}," outside 1–100 falls back to 25 rather than failing the call.",[265,1485,1486,1488,1489,1492],{},[287,1487,1041],{}," looks up a single short code and reports whether it exists on the account and whether it has expired. It does not consume a view, does not evaluate a passcode, and does not return content. Reading metadata also does not ",[1312,1490,1491],{},"act"," on expiry — polling your own share must not be the thing that deletes it. A short code belonging to another account reports as not found rather than as forbidden, so the tool cannot be used to find out which codes exist elsewhere.",[448,1494,1061],{"id":1061},[265,1496,1497],{},"Expires a share immediately so its link stops working. This is irreversible: afterwards the content cannot be recovered by anyone, including CredenShare. It is worth having the assistant confirm with the user before calling it. A short code that is not on the account is reported as such, and nothing is changed.",[448,1499,1079],{"id":1079},[265,1501,1502],{},"Takes no arguments. Reports how many shares the account has active and expired, how many times they have been viewed in total, and daily view counts for the last 14 days.",[265,1504,1505],{},"Figures only — no titles, no short codes, and nothing about who viewed anything. It is the safest tool on the server to grant, and the one most likely to be what somebody actually wants when they ask an assistant \"how are we using CredenShare?\".",[265,1507,1508,1509,1511],{},"It requires ",[287,1510,1090],{},", which no other tool uses. A key minted for the share tools will not have it, and the model will be told so rather than silently getting nothing.",[265,1513,1514,1515,1518,1519,1522],{},"On a team account the figures are the ",[276,1516,1517],{},"organization's",", not the individual member's — the same rule the ",[1465,1520,1521],{"href":191},"REST endpoint"," follows, and for the same reason: a seat member has no meaningful figures of their own.",[448,1524,1526],{"id":1525},"list_webhooks-and-rotate_webhook_secret","list_webhooks and rotate_webhook_secret",[265,1528,1529,1531],{},[287,1530,1097],{}," takes no arguments and returns each endpoint's URL, id, subscribed event codes, and whether it is enabled. It never returns a signing secret.",[265,1533,1534,1536],{},[287,1535,1113],{}," is the one tool that returns a secret value of any kind: the endpoint's new signing secret, in the result text, shown once. That is defensible only because the value did not exist until the call and is worthless without the endpoint itself. The previous secret keeps verifying for 24 hours, and during that window every delivery is signed with both secrets, so a receiver can be updated without dropping anything.",[265,1538,1539],{},"Store the new secret before the conversation ends — it cannot be shown again. And rotate only once per window: only one previous secret is retained, so rotating twice inside the 24 hours drops the oldest, and a receiver still on it starts failing immediately.",[292,1541,1543],{"id":1542},"rate-limits","Rate limits",[265,1545,1546,1547,1550,1551,1554,1555,1558],{},"The MCP endpoint is not rate limited today. The ",[287,1548,1549],{},"/v1"," REST endpoints are: they enforce a per-key and per-account budget derived from your plan, and answer ",[287,1552,1553],{},"429"," with a ",[287,1556,1557],{},"Retry-After"," header when a caller exceeds it.",[265,1560,1561,1562,666,1564,1566],{},"Treat the absence as a property of the current deployment rather than a guarantee. Handle ",[287,1563,1553],{},[287,1565,1557],{}," in your client anyway, so that bringing the MCP endpoint under the same budget does not break it.",[1568,1569,1570],"style",{},"html pre.shiki code .shcOC, html code.shiki .shcOC{--shiki-light:#6F42C1;--shiki-default:#B392F0;--shiki-dark:#B392F0}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}",{"title":305,"searchDepth":329,"depth":347,"links":1572},[1573,1574,1577,1580,1583,1586,1593],{"id":294,"depth":347,"text":295},{"id":314,"depth":347,"text":138,"children":1575},[1576],{"id":450,"depth":358,"text":451},{"id":603,"depth":347,"text":604,"children":1578},[1579],{"id":822,"depth":358,"text":823},{"id":799,"depth":347,"text":938,"children":1581},[1582],{"id":1209,"depth":358,"text":1210},{"id":289,"depth":347,"text":289,"children":1584},[1585],{"id":1376,"depth":358,"text":1377},{"id":1427,"depth":347,"text":1428,"children":1587},[1588,1589,1590,1591,1592],{"id":968,"depth":358,"text":968},{"id":1471,"depth":358,"text":1472},{"id":1061,"depth":358,"text":1061},{"id":1079,"depth":358,"text":1079},{"id":1525,"depth":358,"text":1526},{"id":1542,"depth":347,"text":1543},"Connect an AI assistant to CredenShare over the Model Context Protocol, without a plaintext secret ever reaching the model.","md",{},true,{"title":212,"description":1594},"nBNnhoticX_nXqcbK2knHs9iSenLpe_96nWfGEwWtNA",[1601,1603],{"title":208,"path":209,"stem":210,"description":1602,"children":-1},"The request CredenShare sends, what counts as success, the retry schedule, and how to recover a delivery that failed.",{"title":216,"path":217,"stem":218,"description":1604,"children":-1},"The error envelope, every error code you can hit, request-rate limits, and what an authentication failure actually looks like.",1788908850366]