[{"data":1,"prerenderedAt":1410},["ShallowReactive",2],{"navigation":3,"/api/shares/create":258,"/api/shares/create-surround":1405},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":148,"api":260,"body":261,"description":1399,"extension":1400,"links":260,"meta":1401,"navigation":1402,"path":149,"seo":1403,"stem":150,"__hash__":1404},"docs/6.api/2.shares/1.create.md",null,{"type":262,"value":263,"toc":1380},"minimark",[264,275,283,291,296,302,323,326,329,333,525,538,546,549,561,564,570,572,578,581,588,590,596,603,615,617,623,626,629,661,664,670,672,681,738,743,747,859,863,869,923,990,1006,1010,1054,1062,1066,1080,1091,1094,1098,1101,1140,1156,1160,1338,1342,1349,1356,1359,1376],[265,266,272],"pre",{"className":267,"code":269,"language":270,"meta":271},[268],"language-text","POST /v1/shares\n","text","",[273,274,269],"code",{"__ignoreMap":271},[276,277,278,279,282],"p",{},"Requires the ",[273,280,281],{},"shares:write"," scope. Creates a share from ciphertext your client produced, and returns the short code you use to assemble the recipient link.",[276,284,285,286,290],{},"If you have not read the ",[287,288,289],"a",{"href":143},"end-to-end flow",", start there — four of the five steps in a create happen on your side, and this page only covers the request itself.",[292,293,295],"h2",{"id":294},"the-idempotency-key-header-is-required","The Idempotency-Key header is required",[265,297,300],{"className":298,"code":299,"language":270,"meta":271},[268],"Idempotency-Key: deploy-42\n",[273,301,299],{"__ignoreMap":271},[303,304,307],"callout",{"color":305,"icon":306},"warning","i-lucide-alert-triangle",[276,308,309,310,314,315,318,319,322],{},"This header is ",[311,312,313],"strong",{},"mandatory",", not optional. A create without it is refused with a ",[273,316,317],{},"400"," and ",[273,320,321],{},"error_code"," 104.",[276,324,325],{},"It is required because a retried automation must not duplicate a secret. A second share is a second copy of a credential in the world, with its own link and its own audit trail, that your caller does not know exists.",[276,327,328],{},"Any unique string you can reproduce on retry will do. The value is scoped to your API key, so it cannot collide with another customer's, and it is retained for 24 hours.",[292,330,332],{"id":331},"request-fields","Request fields",[334,335,336,355],"table",{},[337,338,339],"thead",{},[340,341,342,346,349,352],"tr",{},[343,344,345],"th",{},"Field",[343,347,348],{},"Type",[343,350,351],{},"Required",[343,353,354],{},"Notes",[356,357,358,379,393,411,425,440,454,468,483,497,511],"tbody",{},[340,359,360,366,369,372],{},[361,362,363],"td",{},[273,364,365],{},"title",[361,367,368],{},"string",[361,370,371],{},"yes",[361,373,374,375,378],{},"Max 256 characters. ",[311,376,377],{},"Visible to CredenShare"," — it is metadata, not encrypted content.",[340,380,381,386,388,390],{},[361,382,383],{},[273,384,385],{},"data",[361,387,368],{},[361,389,371],{},[361,391,392],{},"Your ciphertext. See below.",[340,394,395,400,402,404],{},[361,396,397],{},[273,398,399],{},"encryption_type",[361,401,368],{},[361,403,371],{},[361,405,406,407,410],{},"Exactly one accepted value: ",[273,408,409],{},"e2ee-aes256-gcm",".",[340,412,413,418,420,422],{},[361,414,415],{},[273,416,417],{},"access_token",[361,419,368],{},[361,421,371],{},[361,423,424],{},"Derived from the content key. See below.",[340,426,427,432,434,437],{},[361,428,429],{},[273,430,431],{},"description",[361,433,368],{},[361,435,436],{},"no",[361,438,439],{},"Max 1024 characters. Also visible to CredenShare.",[340,441,442,447,449,451],{},[361,443,444],{},[273,445,446],{},"passcode_verifier",[361,448,368],{},[361,450,436],{},[361,452,453],{},"A derived verifier, never the passcode. See below.",[340,455,456,461,463,465],{},[361,457,458],{},[273,459,460],{},"expired_at",[361,462,368],{},[361,464,436],{},[361,466,467],{},"When the share stops working. Accepted formats below.",[340,469,470,475,478,480],{},[361,471,472],{},[273,473,474],{},"access_counts_left",[361,476,477],{},"integer",[361,479,436],{},[361,481,482],{},"View limit, from 1 to 10000.",[340,484,485,490,492,494],{},[361,486,487],{},[273,488,489],{},"timed_view",[361,491,477],{},[361,493,436],{},[361,495,496],{},"Seconds the content stays visible once opened, from 5 to 86400.",[340,498,499,504,506,508],{},[361,500,501],{},[273,502,503],{},"organization_id",[361,505,368],{},[361,507,436],{},[361,509,510],{},"Omit it. The organization is taken from the key, and a value that disagrees is refused — see below.",[340,512,513,518,520,522],{},[361,514,515],{},[273,516,517],{},"item_key_wrap",[361,519,368],{},[361,521,436],{},[361,523,524],{},"Makes the share readable from your dashboard later. See below.",[303,526,529],{"color":527,"icon":528},"info","i-lucide-info",[276,530,531,534,535,537],{},[311,532,533],{},"The organization comes from the key, not the request."," A key minted for a team creates\ninside that team automatically. If you send an ",[273,536,503],{}," that matches, it is accepted;\nif you send one that does not, the create is refused rather than quietly filed somewhere else.\nA key with no team binding cannot attribute a share to one at all.",[276,539,540,541,318,543,545],{},"Keep secrets out of ",[273,542,365],{},[273,544,431],{},". Those two fields are exactly the ones we can read.",[547,548,385],"h3",{"id":385},[276,550,551,553,554,557,558,410],{},[273,552,385],{}," is standard base64 of ",[273,555,556],{},"salt(16) || iv(12) || ciphertext+tag",", as described in the ",[287,559,560],{"href":143},"flow",[276,562,563],{},"CredenShare stores and serves this string verbatim. It is not parsed, not re-encoded and not encrypted again — there is no server-side encryption step on this path, because the content arrived already encrypted.",[276,565,566,567,410],{},"Nothing validates its internal structure either, so a malformed blob is accepted on create and fails only when a recipient tries to open it. Verify a new integration by opening one of its shares, not by trusting the ",[273,568,569],{},"201",[547,571,417],{"id":417},[265,573,576],{"className":574,"code":575,"language":270,"meta":271},[268],"access_token = base64url(HKDF-SHA256(contentKey, \"\", \"access\", 32))\n",[273,577,575],{"__ignoreMap":271},[276,579,580],{},"This is the value the recipient must present to read the share, and it is what binds a link to its content. Their browser recomputes it from the key in the URL fragment, so you do not send it to the recipient separately.",[276,582,583,584,587],{},"CredenShare stores only ",[273,585,586],{},"SHA-256"," of the token's trimmed value. The token itself is not retained, and it is not a decryption key — possession of it proves possession of the link and nothing more.",[547,589,446],{"id":446},[265,591,594],{"className":592,"code":593,"language":270,"meta":271},[268],"passcode_verifier = base64url(HKDF-SHA256(utf8(passcode), \"\", \"verify\", 32))\n",[273,595,593],{"__ignoreMap":271},[276,597,598,599,602],{},"Send the ",[311,600,601],{},"verifier",", never the passcode itself. The passcode is mixed into the derivation of your content key, so handing us the passcode would hand us a component of that key — which is the whole thing this design exists to avoid. The verifier is one-way, so the server can check an attempt without gaining the ability to decrypt.",[276,604,605,606,608,609,318,612,614],{},"Passcode protection is a plan feature. A create carrying a ",[273,607,446],{}," on a plan without view protection is refused with a ",[273,610,611],{},"403",[273,613,321],{}," 53.",[547,616,517],{"id":517},[276,618,619,620,622],{},"An API-created share is normally readable only from its link, because only the link carries the key. ",[273,621,517],{}," is how you keep a copy readable from your dashboard: it is the content key wrapped to your own key's custody public key.",[276,624,625],{},"Only you can compute it. The wrap is made to the custody keypair derived from the third part of your credential, which never leaves your machine, so we can store it without being able to open it.",[276,627,628],{},"Two conditions apply:",[630,631,632,655],"ul",{},[633,634,635,636,639,640,643,644,647,648,650,651,654],"li",{},"Your API key must be at custody level ",[273,637,638],{},"self"," or ",[273,641,642],{},"account",". A key at custody level ",[273,645,646],{},"none"," sending a wrap gets a ",[273,649,317],{}," with the message ",[273,652,653],{},"This key has custody level 'none', so an item_key_wrap would never be readable. Mint a key with custody 'self' or omit the wrap."," It is refused rather than dropped on purpose — a silently ignored wrap means discovering months later that the content was never reachable.",[633,656,657,658,410],{},"Your account must have a zero-knowledge account key enrolled, and the zero-knowledge plan feature. When that is not the case the share is still created and the response reports ",[273,659,660],{},"\"custody\": \"failed\"",[276,662,663],{},"The subject of the wrap is always the acting API key, taken from the verified credential. There is no request field for it and no way to name a different one.",[276,665,666,667,669],{},"Omit ",[273,668,517],{}," when the caller keeps the link and nothing else needs to read the item.",[547,671,460],{"id":460},[276,673,674,676,677,680],{},[273,675,460],{}," is a datetime, not a duration. Values like ",[273,678,679],{},"24h"," are rejected.",[334,682,683,693],{},[337,684,685],{},[340,686,687,690],{},[343,688,689],{},"Format",[343,691,692],{},"Example",[356,694,695,705,718,728],{},[340,696,697,700],{},[361,698,699],{},"RFC 3339 with fractional seconds",[361,701,702],{},[273,703,704],{},"2026-09-01T00:00:00.123456789Z",[340,706,707,710],{},[361,708,709],{},"RFC 3339 with a zone or offset",[361,711,712,639,715],{},[273,713,714],{},"2026-09-01T00:00:00Z",[273,716,717],{},"2026-09-01T02:00:00+02:00",[340,719,720,723],{},[361,721,722],{},"Date and time with no zone",[361,724,725],{},[273,726,727],{},"2026-09-01T00:00:00",[340,729,730,733],{},[361,731,732],{},"Date only",[361,734,735],{},[273,736,737],{},"2026-09-01",[276,739,740,741,410],{},"A value with no timezone is interpreted as UTC. An unparseable value is a ",[273,742,317],{},[292,744,746],{"id":745},"request","Request",[265,748,752],{"className":749,"code":750,"language":751,"meta":271,"style":271},"language-bash shiki shiki-themes github-light github-dark github-dark","curl -X POST https://api.credenshare.io/v1/shares \\\n  -H \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\" \\\n  -H \"Idempotency-Key: deploy-42\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"title\": \"Deploy credentials\",\n    \"encryption_type\": \"e2ee-aes256-gcm\",\n    \"data\": \"oKGio6SlpqeoqaqrrK2ur7CxsrO0tba3uLm6u...\",\n    \"access_token\": \"d2DJ6L1GBXjLD-YhpdyVxJQNkLOHIovvBRUbSMcZf0A\",\n    \"expired_at\": \"2026-09-01T00:00:00Z\",\n    \"access_counts_left\": 1\n  }'\n","bash",[273,753,754,777,788,798,808,817,823,829,835,841,847,853],{"__ignoreMap":271},[755,756,759,763,767,771,774],"span",{"class":757,"line":758},"line",1,[755,760,762],{"class":761},"shcOC","curl",[755,764,766],{"class":765},"suiK_"," -X",[755,768,770],{"class":769},"sfrk1"," POST",[755,772,773],{"class":769}," https://api.credenshare.io/v1/shares",[755,775,776],{"class":765}," \\\n",[755,778,780,783,786],{"class":757,"line":779},2,[755,781,782],{"class":765},"  -H",[755,784,785],{"class":769}," \"Authorization: Bearer crs_sk_live_\u003CkeyId>.\u003CauthSecret>\"",[755,787,776],{"class":765},[755,789,791,793,796],{"class":757,"line":790},3,[755,792,782],{"class":765},[755,794,795],{"class":769}," \"Idempotency-Key: deploy-42\"",[755,797,776],{"class":765},[755,799,801,803,806],{"class":757,"line":800},4,[755,802,782],{"class":765},[755,804,805],{"class":769}," \"Content-Type: application/json\"",[755,807,776],{"class":765},[755,809,811,814],{"class":757,"line":810},5,[755,812,813],{"class":765},"  -d",[755,815,816],{"class":769}," '{\n",[755,818,820],{"class":757,"line":819},6,[755,821,822],{"class":769},"    \"title\": \"Deploy credentials\",\n",[755,824,826],{"class":757,"line":825},7,[755,827,828],{"class":769},"    \"encryption_type\": \"e2ee-aes256-gcm\",\n",[755,830,832],{"class":757,"line":831},8,[755,833,834],{"class":769},"    \"data\": \"oKGio6SlpqeoqaqrrK2ur7CxsrO0tba3uLm6u...\",\n",[755,836,838],{"class":757,"line":837},9,[755,839,840],{"class":769},"    \"access_token\": \"d2DJ6L1GBXjLD-YhpdyVxJQNkLOHIovvBRUbSMcZf0A\",\n",[755,842,844],{"class":757,"line":843},10,[755,845,846],{"class":769},"    \"expired_at\": \"2026-09-01T00:00:00Z\",\n",[755,848,850],{"class":757,"line":849},11,[755,851,852],{"class":769},"    \"access_counts_left\": 1\n",[755,854,856],{"class":757,"line":855},12,[755,857,858],{"class":769},"  }'\n",[292,860,862],{"id":861},"success-response","Success response",[276,864,865,868],{},[273,866,867],{},"201 Created",", with exactly three keys:",[265,870,874],{"className":871,"code":872,"language":873,"meta":271,"style":271},"language-json shiki shiki-themes github-light github-dark github-dark","{\n  \"short_code\": \"a1b2c3d4\",\n  \"expired_at\": \"2026-09-01T00:00:00Z\",\n  \"custody\": \"none\"\n}\n","json",[273,875,876,882,896,908,918],{"__ignoreMap":271},[755,877,878],{"class":757,"line":758},[755,879,881],{"class":880},"slsVL","{\n",[755,883,884,887,890,893],{"class":757,"line":779},[755,885,886],{"class":765},"  \"short_code\"",[755,888,889],{"class":880},": ",[755,891,892],{"class":769},"\"a1b2c3d4\"",[755,894,895],{"class":880},",\n",[755,897,898,901,903,906],{"class":757,"line":790},[755,899,900],{"class":765},"  \"expired_at\"",[755,902,889],{"class":880},[755,904,905],{"class":769},"\"2026-09-01T00:00:00Z\"",[755,907,895],{"class":880},[755,909,910,913,915],{"class":757,"line":800},[755,911,912],{"class":765},"  \"custody\"",[755,914,889],{"class":880},[755,916,917],{"class":769},"\"none\"\n",[755,919,920],{"class":757,"line":810},[755,921,922],{"class":880},"}\n",[334,924,925,935],{},[337,926,927],{},[340,928,929,931,933],{},[343,930,345],{},[343,932,348],{},[343,934,354],{},[356,936,937,949,967],{},[340,938,939,944,946],{},[361,940,941],{},[273,942,943],{},"short_code",[361,945,368],{},[361,947,948],{},"The share's public identifier. Use it to build the link, and as the path parameter on the other endpoints.",[340,950,951,955,958],{},[361,952,953],{},[273,954,460],{},[361,956,957],{},"string or null",[361,959,960,961,964,965,410],{},"RFC 3339, or ",[273,962,963],{},"null"," when you sent no ",[273,966,460],{},[340,968,969,974,976],{},[361,970,971],{},[273,972,973],{},"custody",[361,975,368],{},[361,977,978,979,889,981,983,984,639,987,410],{},"What happened to ",[273,980,517],{},[273,982,646],{},", ",[273,985,986],{},"stored",[273,988,989],{},"failed",[303,991,992],{"color":527,"icon":528},[276,993,994,995,998,999,1002,1003,410],{},"There is no ",[273,996,997],{},"url"," field and no ",[273,1000,1001],{},"id"," field. The response returns a short code because a link would have to contain the content key, which CredenShare never receives. Assemble the link yourself as ",[273,1004,1005],{},"https://crs.sh/{short_code}#1{base64url(contentKey)}",[547,1007,1009],{"id":1008},"the-custody-field","The custody field",[334,1011,1012,1022],{},[337,1013,1014],{},[340,1015,1016,1019],{},[343,1017,1018],{},"Value",[343,1020,1021],{},"Meaning",[356,1023,1024,1036,1045],{},[340,1025,1026,1030],{},[361,1027,1028],{},[273,1029,646],{},[361,1031,1032,1033,1035],{},"No ",[273,1034,517],{}," was sent.",[340,1037,1038,1042],{},[361,1039,1040],{},[273,1041,986],{},[361,1043,1044],{},"The wrap was persisted. The share is readable from your dashboard.",[340,1046,1047,1051],{},[361,1048,1049],{},[273,1050,989],{},[361,1052,1053],{},"The share exists, but the wrap could not be stored. The share is readable only from its link.",[276,1055,1056,1058,1059,1061],{},[273,1057,989],{}," comes back with a ",[273,1060,569],{},", not an error. By the time the wrap is attempted the share already exists, so reporting a failure would make you retry with a fresh idempotency key and mint a second copy of the secret. The wrap is additive: losing it costs dashboard visibility, not the share.",[292,1063,1065],{"id":1064},"idempotent-replay","Idempotent replay",[276,1067,1068,1069,1072,1073,1076,1077,1079],{},"Repeating a create with an ",[273,1070,1071],{},"Idempotency-Key"," that has already completed returns ",[273,1074,1075],{},"200 OK"," — not ",[273,1078,569],{}," — with the first call's response body verbatim, including the same short code.",[276,1081,1082,1083,1086,1087,1090],{},"The request body is fingerprinted with SHA-256 over the ",[311,1084,1085],{},"raw bytes"," received. A retry must therefore be byte-identical: reformatted JSON or reordered keys count as a different body and are refused with a ",[273,1088,1089],{},"409",", even when the meaning is unchanged. Send the same serialized bytes you sent the first time.",[276,1092,1093],{},"Claims are scoped to your API key and expire after 24 hours.",[292,1095,1097],{"id":1096},"order-of-checks","Order of checks",[276,1099,1100],{},"A create runs its checks in a fixed order, and stops at the first failure. This matters when you are debugging a status code you did not expect:",[1102,1103,1104,1110,1115,1118,1121,1124,1132,1137],"ol",{},[633,1105,1106,1107,1109],{},"Scope — is ",[273,1108,281],{}," on the key?",[633,1111,1112,1114],{},[273,1113,1071],{}," — is the header present?",[633,1116,1117],{},"JSON — does the body parse?",[633,1119,1120],{},"Field validation — are the required fields present and within their limits?",[633,1122,1123],{},"Plan share allowance — do you have shares left this period?",[633,1125,1126,1128,1129,1131],{},[273,1127,399],{}," — is it ",[273,1130,409],{},"?",[633,1133,1134,1136],{},[273,1135,517],{}," — is the key's custody level high enough?",[633,1138,1139],{},"Idempotency claim.",[276,1141,1142,1143,1145,1146,1149,1150,1152,1153,1155],{},"So a request that sends the wrong ",[273,1144,399],{}," ",[311,1147,1148],{},"while your plan's share allowance is spent"," returns the ",[273,1151,611],{}," for the allowance, not the ",[273,1154,317],{}," for the encryption type. Fix the earlier check first and the later one will surface.",[292,1157,1159],{"id":1158},"errors","Errors",[334,1161,1162,1176],{},[337,1163,1164],{},[340,1165,1166,1169,1173],{},[343,1167,1168],{},"Status",[343,1170,1171],{},[273,1172,321],{},[343,1174,1175],{},"When",[356,1177,1178,1191,1205,1225,1235,1248,1258,1271,1284,1297,1312,1323],{},[340,1179,1180,1182,1185],{},[361,1181,317],{},[361,1183,1184],{},"104",[361,1186,1187,1188,1190],{},"The ",[273,1189,1071],{}," header is missing or blank.",[340,1192,1193,1195,1198],{},[361,1194,317],{},[361,1196,1197],{},"19",[361,1199,1200,1201,1204],{},"Field validation failed. ",[273,1202,1203],{},"additional_data"," maps each rejected field to a message.",[340,1206,1207,1209,1211],{},[361,1208,317],{},[361,1210,1197],{},[361,1212,1213,1215,1216,1218,1219,1221,1222,1224],{},[273,1214,399],{}," is not ",[273,1217,409],{},", or an ",[273,1220,517],{}," was sent by a ",[273,1223,646],{},"-custody key. Both carry their own message.",[340,1226,1227,1229,1232],{},[361,1228,317],{},[361,1230,1231],{},"—",[361,1233,1234],{},"The body is not valid JSON.",[340,1236,1237,1239,1242],{},[361,1238,611],{},[361,1240,1241],{},"78",[361,1243,1244,1245,1247],{},"The key lacks the ",[273,1246,281],{}," scope.",[340,1249,1250,1252,1255],{},[361,1251,611],{},[361,1253,1254],{},"61",[361,1256,1257],{},"Your plan's share allowance is spent. API creates count against the same allowance the dashboard enforces.",[340,1259,1260,1262,1265],{},[361,1261,611],{},[361,1263,1264],{},"53",[361,1266,1267,1268,1270],{},"A gated feature was requested without the plan for it, such as ",[273,1269,446],{}," without view protection.",[340,1272,1273,1275,1278],{},[361,1274,1089],{},[361,1276,1277],{},"105",[361,1279,1280,1281,1283],{},"This ",[273,1282,1071],{}," was already used with a different request body.",[340,1285,1286,1288,1291],{},[361,1287,1089],{},[361,1289,1290],{},"106",[361,1292,1293,1294,1296],{},"An earlier request with this ",[273,1295,1071],{}," has not finished.",[340,1298,1299,1302,1305],{},[361,1300,1301],{},"429",[361,1303,1304],{},"107",[361,1306,1307,1308,1311],{},"Rate limit exceeded. ",[273,1309,1310],{},"Retry-After"," gives the seconds to wait, and is never below 1.",[340,1313,1314,1317,1320],{},[361,1315,1316],{},"500",[361,1318,1319],{},"24 or 45",[361,1321,1322],{},"The account or team behind the plan lookup could not be read.",[340,1324,1325,1328,1331],{},[361,1326,1327],{},"503",[361,1329,1330],{},"108",[361,1332,1333,1334,1337],{},"Your entitlements could not be resolved, so we cannot tell whether this create is within your allowance. ",[311,1335,1336],{},"Nothing was created."," Retry — a failed billing lookup is deliberately not treated as permission to exceed a cap.",[292,1339,1341],{"id":1340},"team-shares-and-quota","Team shares and quota",[276,1343,1344,1345,1348],{},"A key can act inside a team. When it does, the plan consulted for the share allowance is the ",[311,1346,1347],{},"team's"," plan, not the key holder's own account — a seat member of a paying team is judged against the team.",[276,1350,1351,1352,1355],{},"API creates consume the same monthly share allowance as the dashboard. The API is not a way around a plan limit. ",[273,1353,1354],{},"max_shares = -1"," on a plan means unlimited.",[292,1357,194],{"id":1358},"webhooks",[276,1360,1361,1362,1365,1366,1368,1369,983,1371,318,1373,1375],{},"A successful create emits the ",[273,1363,1364],{},"share.created"," event to your webhook endpoints, carrying ",[273,1367,943],{}," plus ",[273,1370,365],{},[273,1372,503],{},[273,1374,460],{}," where those are set. The payload is metadata only; ciphertext, keys, tokens and fragments are never included in any webhook body.",[1377,1378,1379],"style",{},"html pre.shiki code .shcOC, html code.shiki .shcOC{--shiki-light:#6F42C1;--shiki-default:#B392F0;--shiki-dark:#B392F0}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}",{"title":271,"searchDepth":758,"depth":779,"links":1381},[1382,1383,1390,1391,1394,1395,1396,1397,1398],{"id":294,"depth":779,"text":295},{"id":331,"depth":779,"text":332,"children":1384},[1385,1386,1387,1388,1389],{"id":385,"depth":790,"text":385},{"id":417,"depth":790,"text":417},{"id":446,"depth":790,"text":446},{"id":517,"depth":790,"text":517},{"id":460,"depth":790,"text":460},{"id":745,"depth":779,"text":746},{"id":861,"depth":779,"text":862,"children":1392},[1393],{"id":1008,"depth":790,"text":1009},{"id":1064,"depth":779,"text":1065},{"id":1096,"depth":779,"text":1097},{"id":1158,"depth":779,"text":1159},{"id":1340,"depth":779,"text":1341},{"id":1358,"depth":779,"text":194},"POST /v1/shares — store ciphertext you encrypted yourself and get back a short code.","md",{},true,{"title":148,"description":1399},"InS_lBrCb6L1K7Pn0x4a7VCkld9hxWH1BKcTmIoxH2I",[1406,1408],{"title":142,"path":143,"stem":144,"description":1407,"children":-1},"The end-to-end encrypted share resource, and the client-side work a create requires.",{"title":152,"path":153,"stem":154,"description":1409,"children":-1},"GET /v1/shares — page through the shares your key created, metadata only.",1788908851823]