[{"data":1,"prerenderedAt":1171},["ShallowReactive",2],{"navigation":3,"/api/shares":258,"/api/shares-surround":1166},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":142,"api":260,"body":261,"description":1160,"extension":1161,"links":260,"meta":1162,"navigation":1163,"path":143,"seo":1164,"stem":144,"__hash__":1165},"docs/6.api/2.shares/0.index.md",null,{"type":262,"value":263,"toc":1145},"minimark",[264,268,271,288,293,304,307,310,354,372,377,384,388,391,489,609,629,633,640,654,671,675,681,691,700,704,711,762,765,771,786,791,795,798,805,808,812,916,925,929,935,938,941,944,950,957,963,966,976,982,988,992,995,998,1007,1011,1021,1031,1106,1112,1119,1122,1136,1141],[265,266,267],"p",{},"A share is a piece of content that your client encrypts before it reaches CredenShare. The API stores and serves the ciphertext you hand it, and never holds the key that opens it.",[265,269,270],{},"That one fact shapes every endpoint on this resource. It is also why creating a share is more work than a single request, so read this page before the endpoint pages.",[272,273,276],"callout",{"color":274,"icon":275},"info","i-lucide-lock",[265,277,278,279,283,284,287],{},"The API does not accept plaintext. ",[280,281,282],"code",{},"encryption_type"," has exactly one accepted value, ",[280,285,286],{},"e2ee-aes256-gcm",", and there is no flag, opt-in or per-account exception. A server cannot encrypt what it never sees.",[289,290,292],"h2",{"id":291},"the-end-to-end-flow","The end-to-end flow",[272,294,296],{"color":274,"icon":295},"i-lucide-package",[265,297,298,299,303],{},"Four of these five steps happen in your code. The ",[300,301,302],"a",{"href":221},"official SDKs"," do all five — reach for this section when you are implementing them yourself.",[265,305,306],{},"A create is a five-step operation, and only one of those steps is a request to us.",[265,308,309],{},"These are the primitives you need:",[311,312,313,326],"table",{},[314,315,316],"thead",{},[317,318,319,323],"tr",{},[320,321,322],"th",{},"Primitive",[320,324,325],{},"Parameters",[327,328,329,338,346],"tbody",{},[317,330,331,335],{},[332,333,334],"td",{},"Hash",[332,336,337],{},"SHA-256",[317,339,340,343],{},[332,341,342],{},"KDF",[332,344,345],{},"HKDF-SHA-256 (RFC 5869), extract-and-expand",[317,347,348,351],{},[332,349,350],{},"AEAD",[332,352,353],{},"AES-256-GCM, 96-bit IV, 128-bit tag",[265,355,356,359,360,362,363,366,367,371],{},[280,357,358],{},"HKDF-SHA256(ikm, salt, info, len)"," below takes ",[280,361,274],{}," as UTF-8 bytes. Where a salt is shown as ",[280,364,365],{},"\"\"",", pass a ",[368,369,370],"strong",{},"zero-length byte string",". Do not substitute a non-zero placeholder — that changes the derived key and your ciphertext will not decrypt.",[373,374,376],"h3",{"id":375},"_1-generate-a-content-key","1. Generate a content key",[265,378,379,380,383],{},"The content key is ",[368,381,382],{},"32 random bytes"," from a cryptographically secure source. It is the only thing that can decrypt the share, and CredenShare never receives it.",[373,385,387],{"id":386},"_2-build-the-field-array","2. Build the field array",[265,389,390],{},"The plaintext is a JSON array of field objects:",[392,393,398],"pre",{"className":394,"code":395,"language":396,"meta":397,"style":397},"language-json shiki shiki-themes github-light github-dark github-dark","[\n  { \"key\": \"Database password\", \"value\": \"s3cr3t\", \"type\": \"password\" },\n  { \"key\": \"Host\", \"value\": \"db.internal.example\", \"type\": \"text\" }\n]\n","json","",[280,399,400,409,450,483],{"__ignoreMap":397},[401,402,405],"span",{"class":403,"line":404},"line",1,[401,406,408],{"class":407},"slsVL","[\n",[401,410,412,415,419,422,426,429,432,434,437,439,442,444,447],{"class":403,"line":411},2,[401,413,414],{"class":407},"  { ",[401,416,418],{"class":417},"suiK_","\"key\"",[401,420,421],{"class":407},": ",[401,423,425],{"class":424},"sfrk1","\"Database password\"",[401,427,428],{"class":407},", ",[401,430,431],{"class":417},"\"value\"",[401,433,421],{"class":407},[401,435,436],{"class":424},"\"s3cr3t\"",[401,438,428],{"class":407},[401,440,441],{"class":417},"\"type\"",[401,443,421],{"class":407},[401,445,446],{"class":424},"\"password\"",[401,448,449],{"class":407}," },\n",[401,451,453,455,457,459,462,464,466,468,471,473,475,477,480],{"class":403,"line":452},3,[401,454,414],{"class":407},[401,456,418],{"class":417},[401,458,421],{"class":407},[401,460,461],{"class":424},"\"Host\"",[401,463,428],{"class":407},[401,465,431],{"class":417},[401,467,421],{"class":407},[401,469,470],{"class":424},"\"db.internal.example\"",[401,472,428],{"class":407},[401,474,441],{"class":417},[401,476,421],{"class":407},[401,478,479],{"class":424},"\"text\"",[401,481,482],{"class":407}," }\n",[401,484,486],{"class":403,"line":485},4,[401,487,488],{"class":407},"]\n",[311,490,491,504],{},[314,492,493],{},[317,494,495,498,501],{},[320,496,497],{},"Member",[320,499,500],{},"Required",[320,502,503],{},"Notes",[327,505,506,523,535,575,591],{},[317,507,508,513,516],{},[332,509,510],{},[280,511,512],{},"key",[332,514,515],{},"yes",[332,517,518,519,522],{},"The field's visible ",[368,520,521],{},"label"," — what the recipient reads.",[317,524,525,530,532],{},[332,526,527],{},[280,528,529],{},"value",[332,531,515],{},[332,533,534],{},"The field's content.",[317,536,537,542,544],{},[332,538,539],{},[280,540,541],{},"type",[332,543,515],{},[332,545,546,547,428,550,428,553,428,556,428,559,428,562,565,566,568,569,571,572,574],{},"One of ",[280,548,549],{},"text",[280,551,552],{},"password",[280,554,555],{},"date",[280,557,558],{},"multiline",[280,560,561],{},"markdown",[280,563,564],{},"source_code",". Decides how the recipient's page renders it: ",[280,567,552],{}," is masked behind a reveal, ",[280,570,564],{}," is syntax-highlighted, ",[280,573,561],{}," is rendered.",[317,576,577,582,585],{},[332,578,579],{},[280,580,581],{},"selectedProgrammingLanguage",[332,583,584],{},"no",[332,586,587,588,590],{},"Language hint for ",[280,589,564],{},".",[317,592,593,598,600],{},[332,594,595],{},[280,596,597],{},"filename",[332,599,584],{},[332,601,602,603,605,606,608],{},"For ",[280,604,564],{}," and ",[280,607,561],{},", offers the recipient a download using this name.",[272,610,613],{"color":611,"icon":612},"warning","i-lucide-alert-triangle",[265,614,615,616,618,619,428,621,624,625,628],{},"The label member is ",[280,617,512],{},". It is not ",[280,620,521],{},[280,622,623],{},"name"," or ",[280,626,627],{},"title"," — those are ignored silently. A share built with the wrong member name still encrypts, still posts, still decrypts and still renders, with every field label blank and nothing anywhere reporting an error.",[373,630,632],{"id":631},"_3-encrypt","3. Encrypt",[392,634,638],{"className":635,"code":637,"language":549,"meta":397},[636],"language-text","salt       = 16 random bytes\niv         = 12 random bytes\nkey        = HKDF-SHA256(contentKey, salt, \"content\", 32)\nciphertext = AES-256-GCM(key, iv, utf8(JSON.stringify(fields)))\n\ndata       = base64(salt || iv || ciphertext+tag)\n",[280,639,637],{"__ignoreMap":397},[265,641,642,645,646,649,650,653],{},[280,643,644],{},"data"," uses ",[368,647,648],{},"standard"," base64 with padding: it travels in a JSON body, never in a URL. AES-GCM output is ",[280,651,652],{},"ciphertext || tag"," in a single buffer; if your AEAD returns them separately, concatenate in that order.",[265,655,656,657,659,660,663,664,667,668,670],{},"If the share has a passcode, the ",[280,658,274],{}," string becomes ",[280,661,662],{},"content|\u003Cpasscode>"," instead of ",[280,665,666],{},"content",". The passcode is mixed into ",[280,669,274],{},", never into the salt.",[373,672,674],{"id":673},"_4-derive-the-access-token","4. Derive the access token",[392,676,679],{"className":677,"code":678,"language":549,"meta":397},[636],"access_token = base64url(HKDF-SHA256(contentKey, \"\", \"access\", 32))\n",[280,680,678],{"__ignoreMap":397},[265,682,683,684,687,688,690],{},"The salt is empty on purpose, so the recipient's browser can reproduce this value from the link fragment alone with nothing stored. CredenShare stores only a hash of the token, and HKDF's domain separation means the ",[280,685,686],{},"access"," output tells us nothing about the ",[280,689,666],{}," output.",[265,692,693,696,697,590],{},[280,694,695],{},"base64url"," here is URL-safe base64 with ",[368,698,699],{},"no padding",[373,701,703],{"id":702},"_5-post-the-ciphertext-then-assemble-the-link-yourself","5. POST the ciphertext, then assemble the link yourself",[265,705,706,707,710],{},"Send the create request with an ",[280,708,709],{},"Idempotency-Key"," header. You get back a short code:",[392,712,714],{"className":394,"code":713,"language":396,"meta":397,"style":397},"{\n  \"short_code\": \"a1b2c3d4\",\n  \"expired_at\": \"2026-09-01T00:00:00Z\",\n  \"custody\": \"none\"\n}\n",[280,715,716,721,734,746,756],{"__ignoreMap":397},[401,717,718],{"class":403,"line":404},[401,719,720],{"class":407},"{\n",[401,722,723,726,728,731],{"class":403,"line":411},[401,724,725],{"class":417},"  \"short_code\"",[401,727,421],{"class":407},[401,729,730],{"class":424},"\"a1b2c3d4\"",[401,732,733],{"class":407},",\n",[401,735,736,739,741,744],{"class":403,"line":452},[401,737,738],{"class":417},"  \"expired_at\"",[401,740,421],{"class":407},[401,742,743],{"class":424},"\"2026-09-01T00:00:00Z\"",[401,745,733],{"class":407},[401,747,748,751,753],{"class":403,"line":485},[401,749,750],{"class":417},"  \"custody\"",[401,752,421],{"class":407},[401,754,755],{"class":424},"\"none\"\n",[401,757,759],{"class":403,"line":758},5,[401,760,761],{"class":407},"}\n",[265,763,764],{},"The recipient link is the short code plus the content key in the URL fragment:",[392,766,769],{"className":767,"code":768,"language":549,"meta":397},[636],"https://crs.sh/{short_code}#1{base64url(contentKey)}\n",[280,770,768],{"__ignoreMap":397},[265,772,773,774,777,778,781,782,785],{},"The fragment is ",[368,775,776],{},"bare",": a single version character ",[280,779,780],{},"1",", then the base64url key, with no ",[280,783,784],{},"k="," prefix. Browsers never transmit a fragment to a server, which is how the key reaches the recipient without reaching us.",[272,787,788],{"color":611,"icon":612},[265,789,790],{},"You are the only party who can build a working link. If you lose the content key between step 1 and step 5, nobody can open that share — including you and including CredenShare. There is no recovery; create the share again.",[289,792,794],{"id":793},"why-the-response-contains-no-url","Why the response contains no URL",[265,796,797],{},"The create response returns a short code, not a link, and this is deliberate rather than an omission.",[265,799,800,801,804],{},"A working link contains the content key. CredenShare has never had that key, so there is nothing we could put in a ",[280,802,803],{},"url"," field that would actually open the share. Returning a keyless link would be worse than returning none: it would look correct and fail at the moment the recipient used it.",[265,806,807],{},"The same reasoning removes several things you might expect elsewhere on this resource. No endpoint returns share content, and no endpoint returns anything from which a link could be reconstructed.",[289,809,811],{"id":810},"endpoints","Endpoints",[311,813,814,830],{},[314,815,816],{},[317,817,818,821,824,827],{},[320,819,820],{},"Method",[320,822,823],{},"Path",[320,825,826],{},"Scope",[320,828,829],{},"Purpose",[327,831,832,854,876,896],{},[317,833,834,839,844,849],{},[332,835,836],{},[280,837,838],{},"POST",[332,840,841],{},[280,842,843],{},"/v1/shares",[332,845,846],{},[280,847,848],{},"shares:write",[332,850,851,853],{},[300,852,148],{"href":149}," from ciphertext you produced",[317,855,856,861,865,870],{},[332,857,858],{},[280,859,860],{},"GET",[332,862,863],{},[280,864,843],{},[332,866,867],{},[280,868,869],{},"shares:read",[332,871,872,875],{},[300,873,874],{"href":153},"List your shares",", metadata only",[317,877,878,882,887,891],{},[332,879,880],{},[280,881,860],{},[332,883,884],{},[280,885,886],{},"/v1/shares/{shortCode}",[332,888,889],{},[280,890,869],{},[332,892,893],{},[300,894,895],{"href":157},"Retrieve one share's metadata",[317,897,898,903,907,911],{},[332,899,900],{},[280,901,902],{},"DELETE",[332,904,905],{},[280,906,886],{},[332,908,909],{},[280,910,848],{},[332,912,913,915],{},[300,914,160],{"href":161}," now",[265,917,918,919,921,922,924],{},"Scopes are matched by exact string. There is no hierarchy: ",[280,920,848],{}," does not imply ",[280,923,869],{},", so a key that both creates and lists needs both scopes.",[289,926,928],{"id":927},"base-url","Base URL",[392,930,933],{"className":931,"code":932,"language":549,"meta":397},[636],"https://api.credenshare.io/v1\n",[280,934,932],{"__ignoreMap":397},[265,936,937],{},"Every path on this page is relative to that base.",[289,939,138],{"id":940},"authentication",[265,942,943],{},"Every request carries a bearer credential:",[392,945,948],{"className":946,"code":947,"language":549,"meta":397},[636],"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\n",[280,949,947],{"__ignoreMap":397},[265,951,952,953,956],{},"An API credential issued to you has ",[368,954,955],{},"three"," dot-separated parts:",[392,958,961],{"className":959,"code":960,"language":549,"meta":397},[636],"crs_sk_live_\u003CkeyId>.\u003CauthSecret>.\u003CcustodySecret>\n",[280,962,960],{"__ignoreMap":397},[265,964,965],{},"Send only the first two. The third part derives your custody keypair locally and must never be transmitted — a request carrying all three is refused outright, and that credential should be treated as disclosed and rotated.",[265,967,968,969,972,973,590],{},"API access is a Business and Enterprise capability. On a plan without it, minting a key is refused with ",[280,970,971],{},"error_code"," 98 and the message ",[280,974,975],{},"API access requires a Business or Enterprise plan",[265,977,978,979,981],{},"Keys are minted in the dashboard, under ",[368,980,246],{}," on your account page. There is no API endpoint that creates, lists or revokes keys: a leaked key that could mint more keys would be a far worse leak than one that cannot.",[265,983,984,985,987],{},"See ",[300,986,138],{"href":139}," for scopes, custody levels and rate limits in full.",[289,989,991],{"id":990},"reading-content-back","Reading content back",[265,993,994],{},"There is no content-read endpoint on this API, for your own shares or anyone else's.",[265,996,997],{},"The recipient read path is anonymous and protected by proof-of-work and a captcha. Bearer authentication skips both, so exposing that path to an API key would turn the API into a way to enumerate short codes. A key reads only metadata, and only for what your account owns.",[265,999,1000,1001,1006],{},"If you want an API-created share to be readable later from your dashboard rather than only from the link, send an ",[300,1002,1003],{"href":149},[280,1004,1005],{},"item_key_wrap"," on the create.",[289,1008,1010],{"id":1009},"response-and-error-shape","Response and error shape",[265,1012,1013,1014,1016,1017,1020],{},"Successful responses are bare JSON objects — there is no ",[280,1015,644],{}," wrapper and no ",[280,1018,1019],{},"meta"," block.",[265,1022,1023,1024,1027,1028,1030],{},"Errors use one envelope, with an ",[368,1025,1026],{},"integer"," ",[280,1029,971],{},":",[392,1032,1034],{"className":394,"code":1033,"language":396,"meta":397,"style":397},"{\n  \"success\": false,\n  \"message\": \"Validation failed\",\n  \"error_code\": 19,\n  \"additional_data\": {\n    \"data\": \"data is a required field\"\n  }\n}\n",[280,1035,1036,1040,1052,1064,1076,1084,1095,1101],{"__ignoreMap":397},[401,1037,1038],{"class":403,"line":404},[401,1039,720],{"class":407},[401,1041,1042,1045,1047,1050],{"class":403,"line":411},[401,1043,1044],{"class":417},"  \"success\"",[401,1046,421],{"class":407},[401,1048,1049],{"class":417},"false",[401,1051,733],{"class":407},[401,1053,1054,1057,1059,1062],{"class":403,"line":452},[401,1055,1056],{"class":417},"  \"message\"",[401,1058,421],{"class":407},[401,1060,1061],{"class":424},"\"Validation failed\"",[401,1063,733],{"class":407},[401,1065,1066,1069,1071,1074],{"class":403,"line":485},[401,1067,1068],{"class":417},"  \"error_code\"",[401,1070,421],{"class":407},[401,1072,1073],{"class":417},"19",[401,1075,733],{"class":407},[401,1077,1078,1081],{"class":403,"line":758},[401,1079,1080],{"class":417},"  \"additional_data\"",[401,1082,1083],{"class":407},": {\n",[401,1085,1087,1090,1092],{"class":403,"line":1086},6,[401,1088,1089],{"class":417},"    \"data\"",[401,1091,421],{"class":407},[401,1093,1094],{"class":424},"\"data is a required field\"\n",[401,1096,1098],{"class":403,"line":1097},7,[401,1099,1100],{"class":407},"  }\n",[401,1102,1104],{"class":403,"line":1103},8,[401,1105,761],{"class":407},[265,1107,1108,1111],{},[280,1109,1110],{},"additional_data"," carries a map of JSON field name to message on a validation failure, and is absent otherwise. There is no request id.",[265,1113,1114,1115,1118],{},"One class of failure does ",[368,1116,1117],{},"not"," use that envelope. A request with a missing or unusable credential is refused before it reaches the API, and the body is the gateway's own, not ours. Handle it by status code rather than by parsing the body.",[265,1120,1121],{},"An unknown key, a revoked key and a key with the wrong secret are deliberately indistinguishable to the caller: telling them apart would let anyone holding no credential at all learn which key ids exist. Your logs are the place to diagnose a credential; the response is not.",[265,1123,1124,1125,1128,1129,1132,1133,590],{},"Every response carries ",[280,1126,1127],{},"Access-Control-Allow-Origin: *",". The only rate-limit header the API emits is ",[280,1130,1131],{},"Retry-After",", and only on a ",[280,1134,1135],{},"429",[265,1137,1138,1139,590],{},"Every code you can receive is listed in ",[300,1140,216],{"href":217},[1142,1143,1144],"style",{},"html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":397,"searchDepth":404,"depth":411,"links":1146},[1147,1154,1155,1156,1157,1158,1159],{"id":291,"depth":411,"text":292,"children":1148},[1149,1150,1151,1152,1153],{"id":375,"depth":452,"text":376},{"id":386,"depth":452,"text":387},{"id":631,"depth":452,"text":632},{"id":673,"depth":452,"text":674},{"id":702,"depth":452,"text":703},{"id":793,"depth":411,"text":794},{"id":810,"depth":411,"text":811},{"id":927,"depth":411,"text":928},{"id":940,"depth":411,"text":138},{"id":990,"depth":411,"text":991},{"id":1009,"depth":411,"text":1010},"The end-to-end encrypted share resource, and the client-side work a create requires.","md",{},true,{"title":142,"description":1160},"-0kaR6L24SOhiWgFzpCkMZM7LicJMGqkONTSB053Njg",[1167,1169],{"title":138,"path":139,"stem":140,"description":1168,"children":-1},"How to authenticate requests with a CredenShare API key, and what scopes, custody levels and plan limits control.",{"title":148,"path":149,"stem":150,"description":1170,"children":-1},"POST /v1/shares — store ciphertext you encrypted yourself and get back a short code.",1788908851512]