[{"data":1,"prerenderedAt":733},["ShallowReactive",2],{"navigation":3,"/api/requests/submissions":258,"/api/requests/submissions-surround":728},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":182,"api":260,"body":261,"description":722,"extension":723,"links":260,"meta":724,"navigation":725,"path":183,"seo":726,"stem":184,"__hash__":727},"docs/6.api/3.requests/3.submissions.md",null,{"type":262,"value":263,"toc":713},"minimark",[264,275,292,297,300,307,310,314,347,351,357,465,475,496,503,507,519,527,530,571,574,581,585,588,595,599,688,692,698,709],[265,266,272],"pre",{"className":267,"code":269,"language":270,"meta":271},[268],"language-text","GET /v1/requests/{shortCode}/submissions\n","text","",[273,274,269],"code",{"__ignoreMap":271},[276,277,278,279,282,283,287,288,291],"p",{},"Requires the ",[273,280,281],{},"requests:read"," scope. This is the ",[284,285,286],"strong",{},"only"," read on the ",[273,289,290],{},"/v1"," surface that returns content.",[293,294,296],"h2",{"id":295},"why-this-endpoint-is-allowed-to-return-content","Why this endpoint is allowed to return content",[276,298,299],{},"Everywhere else, an API read returns metadata, because a bearer key skips the proof-of-work and captcha challenges that guard the anonymous recipient page — exposing recipient reads to a key would turn the API into an enumeration bypass.",[276,301,302,303,306],{},"This endpoint is not an exception to that rule; it is the rule working. Each submission is sealed to the ",[284,304,305],{},"request's"," public key. The private half never reached us: it lives as a seed in the owner's access-link fragment, or wrapped under their account key. We hand back something we cannot open, to the party who can.",[276,308,309],{},"That is what makes an ephemeral automation possible. A runner derives its keypair, is granted the account key once, and can then unwrap every submission it is handed without keeping any local state.",[293,311,313],{"id":312},"request","Request",[265,315,319],{"className":316,"code":317,"language":318,"meta":271,"style":271},"language-bash shiki shiki-themes github-light github-dark github-dark","curl https://api.credenshare.io/v1/requests/a1b2c3d4/submissions \\\n  -H \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"\n","bash",[273,320,321,338],{"__ignoreMap":271},[322,323,326,330,334],"span",{"class":324,"line":325},"line",1,[322,327,329],{"class":328},"shcOC","curl",[322,331,333],{"class":332},"sfrk1"," https://api.credenshare.io/v1/requests/a1b2c3d4/submissions",[322,335,337],{"class":336},"suiK_"," \\\n",[322,339,341,344],{"class":324,"line":340},2,[322,342,343],{"class":336},"  -H",[322,345,346],{"class":332}," \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"\n",[293,348,350],{"id":349},"success-response","Success response",[276,352,353,356],{},[273,354,355],{},"200 OK",":",[265,358,362],{"className":359,"code":360,"language":361,"meta":271,"style":271},"language-json shiki shiki-themes github-light github-dark github-dark","{\n  \"submissions\": [\n    {\n      \"short_code\": \"e5f6g7h8\",\n      \"created_at\": \"2026-09-03T14:22:11Z\",\n      \"data\": \"\u003Cbase64 ciphertext>\",\n      \"encryption_type\": \"e2ee-aes256-gcm\"\n    }\n  ],\n  \"count\": 1\n}\n","json",[273,363,364,370,378,384,399,412,425,436,442,448,459],{"__ignoreMap":271},[322,365,366],{"class":324,"line":325},[322,367,369],{"class":368},"slsVL","{\n",[322,371,372,375],{"class":324,"line":340},[322,373,374],{"class":336},"  \"submissions\"",[322,376,377],{"class":368},": [\n",[322,379,381],{"class":324,"line":380},3,[322,382,383],{"class":368},"    {\n",[322,385,387,390,393,396],{"class":324,"line":386},4,[322,388,389],{"class":336},"      \"short_code\"",[322,391,392],{"class":368},": ",[322,394,395],{"class":332},"\"e5f6g7h8\"",[322,397,398],{"class":368},",\n",[322,400,402,405,407,410],{"class":324,"line":401},5,[322,403,404],{"class":336},"      \"created_at\"",[322,406,392],{"class":368},[322,408,409],{"class":332},"\"2026-09-03T14:22:11Z\"",[322,411,398],{"class":368},[322,413,415,418,420,423],{"class":324,"line":414},6,[322,416,417],{"class":336},"      \"data\"",[322,419,392],{"class":368},[322,421,422],{"class":332},"\"\u003Cbase64 ciphertext>\"",[322,424,398],{"class":368},[322,426,428,431,433],{"class":324,"line":427},7,[322,429,430],{"class":336},"      \"encryption_type\"",[322,432,392],{"class":368},[322,434,435],{"class":332},"\"e2ee-aes256-gcm\"\n",[322,437,439],{"class":324,"line":438},8,[322,440,441],{"class":368},"    }\n",[322,443,445],{"class":324,"line":444},9,[322,446,447],{"class":368},"  ],\n",[322,449,451,454,456],{"class":324,"line":450},10,[322,452,453],{"class":336},"  \"count\"",[322,455,392],{"class":368},[322,457,458],{"class":336},"1\n",[322,460,462],{"class":324,"line":461},11,[322,463,464],{"class":368},"}\n",[276,466,467,470,471,474],{},[273,468,469],{},"count"," is the number of entries in ",[273,472,473],{},"submissions",", which is not necessarily the number of submissions the request received — see the next section.",[276,476,477,480,481,484,485,487,488,491,492,495],{},[273,478,479],{},"data"," is ciphertext. Decrypt it with the private key matching the ",[273,482,483],{},"public_key"," you supplied on create. ",[273,486,473],{}," is always an array; a request nobody has filled in yet returns ",[273,489,490],{},"[]"," and ",[273,493,494],{},"count: 0",".",[276,497,498,499,502],{},"Each submission has its own ",[273,500,501],{},"short_code",", distinct from the request's.",[293,504,506],{"id":505},"legacy-submissions-are-skipped-and-counted","Legacy submissions are skipped, and counted",[508,509,512],"callout",{"color":510,"icon":511},"warning","i-lucide-alert-triangle",[276,513,514,515,518],{},"Submissions that are ",[284,516,517],{},"not"," client-encrypted are omitted from the response rather than returned.",[276,520,521,522,526],{},"A request that predates end-to-end encryption may hold submissions stored under the older server-side encryption types. For those rows the server ",[523,524,525],"em",{},"can"," decrypt, so returning them would make this the one place in the product where a bearer-authenticated call yields readable secrets. They are skipped.",[276,528,529],{},"The omission is named in the response rather than merely logged:",[265,531,533],{"className":359,"code":532,"language":361,"meta":271,"style":271},"{\n  \"submissions\": [],\n  \"count\": 0,\n  \"skipped_not_end_to_end_encrypted\": 2\n}\n",[273,534,535,539,546,557,567],{"__ignoreMap":271},[322,536,537],{"class":324,"line":325},[322,538,369],{"class":368},[322,540,541,543],{"class":324,"line":340},[322,542,374],{"class":336},[322,544,545],{"class":368},": [],\n",[322,547,548,550,552,555],{"class":324,"line":380},[322,549,453],{"class":336},[322,551,392],{"class":368},[322,553,554],{"class":336},"0",[322,556,398],{"class":368},[322,558,559,562,564],{"class":324,"line":386},[322,560,561],{"class":336},"  \"skipped_not_end_to_end_encrypted\"",[322,563,392],{"class":368},[322,565,566],{"class":336},"2\n",[322,568,569],{"class":324,"line":401},[322,570,464],{"class":368},[276,572,573],{},"The key is present only when the count is greater than zero. Without it you would see fewer submissions than your dashboard shows and have no way to learn why. If you see it, retrieve those submissions through the app instead.",[276,575,576,577,580],{},"Check ",[273,578,579],{},"encryption_type"," on each entry you do receive; every returned row is client-encrypted, but reading the field rather than assuming keeps your client correct if another client-side type is added later.",[293,582,584],{"id":583},"ownership","Ownership",[276,586,587],{},"Ownership is checked twice: once in the handler before anything else runs, and again inside the export path against the viewing user. Submissions are the most sensitive thing this API can return, so the check is not delegated to a service that might later relax it for the recipient path.",[276,589,590,591,594],{},"A short code on another account returns ",[273,592,593],{},"404",", the same as a short code that does not exist.",[293,596,598],{"id":597},"errors","Errors",[600,601,602,620],"table",{},[603,604,605],"thead",{},[606,607,608,612,617],"tr",{},[609,610,611],"th",{},"Status",[609,613,614],{},[273,615,616],{},"error_code",[609,618,619],{},"When",[621,622,623,639,652,662,677],"tbody",{},[606,624,625,629,632],{},[626,627,628],"td",{},"400",[626,630,631],{},"44",[626,633,634,635,638],{},"No short code in the path. ",[273,636,637],{},"GET /v1/requests/submissions"," is not a bulk read.",[606,640,641,644,647],{},[626,642,643],{},"403",[626,645,646],{},"78",[626,648,649,650,495],{},"The key lacks ",[273,651,281],{},[606,653,654,656,659],{},[626,655,593],{},[626,657,658],{},"70",[626,660,661],{},"No such request on this account.",[606,663,664,667,670],{},[626,665,666],{},"429",[626,668,669],{},"107",[626,671,672,673,676],{},"Rate limit exceeded. ",[273,674,675],{},"Retry-After"," gives the seconds to wait.",[606,678,679,682,685],{},[626,680,681],{},"500",[626,683,684],{},"11",[626,686,687],{},"The submissions could not be read.",[293,689,691],{"id":690},"composition","Composition",[265,693,696],{"className":694,"code":695,"language":270,"meta":271},[268],"request.submitted fires\n  → GET /v1/requests/{shortCode}/submissions\n  → decrypt with your private key\n  → use the credential\n",[273,697,695],{"__ignoreMap":271},[276,699,700,701,704,705,495],{},"Subscribing to ",[273,702,703],{},"request.submitted"," is cheaper and faster than polling this endpoint. See ",[706,707,708],"a",{"href":201},"Webhook events",[710,711,712],"style",{},"html pre.shiki code .shcOC, html code.shiki .shcOC{--shiki-light:#6F42C1;--shiki-default:#B392F0;--shiki-dark:#B392F0}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}",{"title":271,"searchDepth":325,"depth":340,"links":714},[715,716,717,718,719,720,721],{"id":295,"depth":340,"text":296},{"id":312,"depth":340,"text":313},{"id":349,"depth":340,"text":350},{"id":505,"depth":340,"text":506},{"id":583,"depth":340,"text":584},{"id":597,"depth":340,"text":598},{"id":690,"depth":340,"text":691},"GET /v1/requests/{shortCode}/submissions — the ciphertext somebody submitted, which only you can open.","md",{},true,{"title":182,"description":722},"RXX65V48n6JgC82Zx6B8rgIK_3cCilidxEFdQo2-V24",[729,731],{"title":178,"path":179,"stem":180,"description":730,"children":-1},"GET /v1/requests and GET /v1/requests/{shortCode} — the requests your account owns, as metadata.",{"title":186,"path":187,"stem":188,"description":732,"children":-1},"DELETE /v1/requests/{shortCode} — close a collect link, and on a second call remove it for good.",1788908852894]