[{"data":1,"prerenderedAt":737},["ShallowReactive",2],{"navigation":3,"/api/requests":258,"/api/requests-surround":732},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":168,"api":260,"body":261,"description":726,"extension":727,"links":260,"meta":728,"navigation":729,"path":169,"seo":730,"stem":170,"__hash__":731},"docs/6.api/3.requests/0.index.md",null,{"type":262,"value":263,"toc":718},"minimark",[264,277,280,288,300,333,338,341,413,423,426,430,471,478,482,574,587,591,594,658,667,670,674,681,688,692,695,703,714],[265,266,267,268,272,273,276],"p",{},"A share moves a secret ",[269,270,271],"strong",{},"to"," somebody. A secure request moves one ",[269,274,275],{},"from"," them.",[265,278,279],{},"You create a request, give the person a collect link, and they type the credential into their own browser. Their browser encrypts it to the request's public key before it leaves their machine. You fetch the ciphertext later and open it with a private key we have never held.",[265,281,282,283,287],{},"That is the whole reason this resource exists separately from ",[284,285,286],"a",{"href":143},"shares",": the secret starts on somebody else's keyboard, so no step of the flow can involve you knowing it in advance.",[289,290,293],"callout",{"color":291,"icon":292},"info","i-lucide-lock",[265,294,295,296,299],{},"The collect link contains ",[269,297,298],{},"no key material",". Unlike a share link, it is safe to paste into chat, email or a ticket — the encryption target is the request's public key, which is public by construction. This is why an automation can hand out a collect link and a share link cannot be handed out the same way.",[289,301,304,310],{"color":302,"icon":303},"warning","i-lucide-alert-triangle",[265,305,306,309],{},[269,307,308],{},"Two different links share that path, and they differ only by a fragment."," Truncated in a log, a chat client or a ticket preview, the two are indistinguishable — so if your automation ever holds an access link, treat it with the care you would give a private key, and make sure the value you hand to a human is the one without a fragment.",[311,312,313,321],"ul",{},[314,315,316,317],"li",{},"The collect link you hand out: ",[318,319,320],"code",{},"https://crs.sh/r/\u003Cshort_code>",[314,322,323,324,328,329,332],{},"The owner's ",[325,326,327],"em",{},"access link",": ",[318,330,331],{},"https://crs.sh/r/\u003Cshort_code>#\u003Cseed>"," — that fragment is the private key seed, everything needed to decrypt every submission to the request.",[334,335,337],"h2",{"id":336},"who-holds-which-key","Who holds which key",[265,339,340],{},"This is the part worth getting right before you write any code.",[342,343,344,363],"table",{},[345,346,347],"thead",{},[348,349,350,354,357,360],"tr",{},[351,352,353],"th",{},"Key",[351,355,356],{},"Generated by",[351,358,359],{},"Held by",[351,361,362],{},"Sees the plaintext",[364,365,366,384,399],"tbody",{},[348,367,368,372,378,381],{},[369,370,371],"td",{},"Request public key",[369,373,374,377],{},[269,375,376],{},"You",", the caller",[369,379,380],{},"Sent to us on create, returned on reads",[369,382,383],{},"No — it only encrypts",[348,385,386,389,393,396],{},[369,387,388],{},"Request private key",[369,390,391,377],{},[269,392,376],{},[369,394,395],{},"Never sent to us",[369,397,398],{},"Yes — this is what opens submissions",[348,400,401,404,407,410],{},[369,402,403],{},"Submission ciphertext",[369,405,406],{},"The submitter's browser",[369,408,409],{},"Stored by us, returned to you",[369,411,412],{},"No — we cannot open it",[265,414,415,418,419,422],{},[318,416,417],{},"public_key"," is a P-256 public key, base64url, and it is ",[269,420,421],{},"required"," on this surface. The app tolerates a request without one only for legacy rows; an API caller who omits it would be creating a request that nobody can encrypt to, and would find out when a submitter's browser had nowhere to send the value.",[265,424,425],{},"The private half is yours to keep. In the app it exists as a seed in the owner's access-link fragment or wrapped under their account key; over the API, it exists wherever you put it.",[334,427,429],{"id":428},"the-flow","The flow",[431,432,433,439,451,460,463],"ol",{},[314,434,435,438],{},[269,436,437],{},"Generate a P-256 keypair"," in your own code. Keep the private half.",[314,440,441,446,447,450],{},[269,442,443],{},[284,444,445],{"href":175},"Create the request"," with a title, the fields to ask for, and the public half. You get back a ",[318,448,449],{},"short_code",".",[314,452,453,456,457,459],{},[269,454,455],{},"Assemble the collect link"," — ",[318,458,320],{}," — and send it to the person. As with shares, the API returns a short code rather than a URL, because only you know which origin your recipients use.",[314,461,462],{},"The person fills the form. Their browser encrypts each value to your public key.",[314,464,465,470],{},[269,466,467],{},[284,468,469],{"href":183},"Fetch the submissions"," and decrypt them with your private key.",[265,472,473,474,477],{},"Step 5 is the only read on the whole ",[318,475,476],{},"/v1"," surface that returns content rather than metadata — and it is the metadata-only rule working rather than an exception to it. What comes back is sealed to a key we do not have. We are willing to hand it over precisely because we cannot open it.",[334,479,481],{"id":480},"endpoints","Endpoints",[342,483,484,497],{},[345,485,486],{},[348,487,488,491,494],{},[351,489,490],{},"Method and path",[351,492,493],{},"What it does",[351,495,496],{},"Scope",[364,498,499,514,529,543,560],{},[348,500,501,506,509],{},[369,502,503],{},[318,504,505],{},"POST /v1/requests",[369,507,508],{},"Create a request. Returns a short code.",[369,510,511],{},[318,512,513],{},"requests:write",[348,515,516,521,524],{},[369,517,518],{},[318,519,520],{},"GET /v1/requests",[369,522,523],{},"List the requests this key's account owns, newest first.",[369,525,526],{},[318,527,528],{},"requests:read",[348,530,531,536,539],{},[369,532,533],{},[318,534,535],{},"GET /v1/requests/{shortCode}",[369,537,538],{},"One request's metadata.",[369,540,541],{},[318,542,528],{},[348,544,545,550,556],{},[369,546,547],{},[318,548,549],{},"GET /v1/requests/{shortCode}/submissions",[369,551,552,553,450],{},"The submissions to one request, ",[269,554,555],{},"including ciphertext",[369,557,558],{},[318,559,528],{},[348,561,562,567,570],{},[369,563,564],{},[318,565,566],{},"DELETE /v1/requests/{shortCode}",[369,568,569],{},"Expire an active request, or permanently delete an already-expired one.",[369,571,572],{},[318,573,513],{},[265,575,576,577,579,580,582,583,586],{},"Scopes are matched exactly. ",[318,578,513],{}," does not imply ",[318,581,528],{},", and neither is implied by the ",[318,584,585],{},"shares:*"," scopes — a key that can create shares cannot read submissions unless you granted it that.",[334,588,590],{"id":589},"what-reads-return","What reads return",[265,592,593],{},"Request reads are metadata only, and the shape is deliberately narrow:",[595,596,601],"pre",{"className":597,"code":598,"language":599,"meta":600,"style":600},"language-json shiki shiki-themes github-light github-dark github-dark","{\n  \"short_code\": \"…\",\n  \"expired_at\": \"2026-09-30T12:00:00Z\",\n  \"public_key\": \"…\"\n}\n","json","",[318,602,603,612,628,641,652],{"__ignoreMap":600},[604,605,608],"span",{"class":606,"line":607},"line",1,[604,609,611],{"class":610},"slsVL","{\n",[604,613,615,619,621,625],{"class":606,"line":614},2,[604,616,618],{"class":617},"suiK_","  \"short_code\"",[604,620,328],{"class":610},[604,622,624],{"class":623},"sfrk1","\"…\"",[604,626,627],{"class":610},",\n",[604,629,631,634,636,639],{"class":606,"line":630},3,[604,632,633],{"class":617},"  \"expired_at\"",[604,635,328],{"class":610},[604,637,638],{"class":623},"\"2026-09-30T12:00:00Z\"",[604,640,627],{"class":610},[604,642,644,647,649],{"class":606,"line":643},4,[604,645,646],{"class":617},"  \"public_key\"",[604,648,328],{"class":610},[604,650,651],{"class":623},"\"…\"\n",[604,653,655],{"class":606,"line":654},5,[604,656,657],{"class":610},"}\n",[265,659,660,662,663,666],{},[318,661,417],{}," ",[269,664,665],{},"is"," returned, which is the opposite of how share key material is treated. It is the public half, you supplied it, and you need it back to verify what was stored against what you generated. The private half never existed on our side, so there is nothing else here to withhold.",[265,668,669],{},"Titles, descriptions and field prompts are not returned. Neither is anything about who submitted.",[334,671,673],{"id":672},"ownership","Ownership",[265,675,676,677,680],{},"Every endpoint on this resource checks ownership before anything else, and reports a failure as ",[269,678,679],{},"not found"," rather than forbidden. A key cannot be used to discover that a short code exists on another account.",[265,682,683,684,687],{},"An owner asking about their own ",[269,685,686],{},"expired"," request gets its metadata rather than a 404 — expiry is not the same as absence, and an automation reconciling its own records needs to tell those apart.",[334,689,691],{"id":690},"composition-with-webhooks","Composition with webhooks",[265,693,694],{},"The pairing this resource was built for:",[595,696,701],{"className":697,"code":699,"language":700,"meta":600},[698],"language-text","request.submitted fires\n  → your automation calls GET /v1/requests/{shortCode}/submissions\n  → it decrypts with the private key it holds\n  → it uses a credential a human handed over through a keyless link\n","text",[318,702,699],{"__ignoreMap":600},[265,704,705,706,709,710,713],{},"Before this surface existed, an automation could be ",[325,707,708],{},"told"," a submission had arrived and had no way to fetch it. See ",[284,711,712],{"href":201},"Webhook events"," for the event contract.",[715,716,717],"style",{},"html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":600,"searchDepth":607,"depth":614,"links":719},[720,721,722,723,724,725],{"id":336,"depth":614,"text":337},{"id":428,"depth":614,"text":429},{"id":480,"depth":614,"text":481},{"id":589,"depth":614,"text":590},{"id":672,"depth":614,"text":673},{"id":690,"depth":614,"text":691},"Ask somebody else to hand you a secret, over a link that carries no key and that CredenShare cannot read.","md",{},true,{"title":168,"description":726},"L-tbCrMN6pP6GLNH8ReoG-b3iGusscITPSMxihb3BIE",[733,735],{"title":164,"path":165,"stem":166,"description":734,"children":-1},"Every constant, derivation and byte layout your client needs to produce a share the recipient can actually open.",{"title":174,"path":175,"stem":176,"description":736,"children":-1},"POST /v1/requests — mint a collect link that lets somebody hand you a secret you can decrypt and we cannot.",1788908852451]