[{"data":1,"prerenderedAt":1192},["ShallowReactive",2],{"navigation":3,"/api/webhooks":258,"/api/webhooks-surround":1187},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":194,"api":260,"body":261,"description":1181,"extension":1182,"links":260,"meta":1183,"navigation":1184,"path":195,"seo":1185,"stem":196,"__hash__":1186},"docs/6.api/5.webhooks/0.index.md",null,{"type":262,"value":263,"toc":1167},"minimark",[264,273,289,294,301,342,364,367,372,375,394,397,401,407,491,516,519,523,526,552,564,568,575,578,582,597,604,607,610,632,644,688,694,697,756,762,765,845,851,855,862,865,927,930,933,969,979,982,990,994,997,1034,1037,1041,1127,1133,1141,1144,1163],[265,266,267,268,272],"p",{},"A webhook delivery is an HTTP ",[269,270,271],"code",{},"POST"," that CredenShare sends to a URL you own when\nsomething happens in your account — a share is created, a recipient opens one, a\nmember joins your organization. The body is a small, flat JSON object describing\nthe event. It never contains the shared content itself.",[274,275,278],"callout",{"color":276,"icon":277},"info","i-lucide-info",[265,279,280,284,285,288],{},[281,282,283],"strong",{},"Webhook endpoints are managed in the app, not through the API."," The API has no\nroute for creating, editing, re-pointing or deleting an endpoint — there is no\n",[269,286,287],{},"POST /v1/webhooks",", and no equivalent under any other path. An API key's only\nwebhook powers are to list your endpoints and to rotate an endpoint's signing\nsecret, both through the hosted MCP server.",[290,291,293],"h2",{"id":292},"where-endpoints-are-managed","Where endpoints are managed",[265,295,296,297,300],{},"Add and remove endpoints in the app, under ",[281,298,299],{},"Account → Security → Webhooks",":",[302,303,304,312,323,330,336],"ol",{},[305,306,307,308,311],"li",{},"Choose ",[281,309,310],{},"Add webhook endpoint",".",[305,313,314,315,318,319,322],{},"Enter the ",[281,316,317],{},"Endpoint URL",". It must be ",[269,320,321],{},"https"," and must resolve to a public address.",[305,324,325,326,329],{},"Optionally add a ",[281,327,328],{},"Description"," (up to 256 characters).",[305,331,332,333,311],{},"Tick the events you want. The selection defaults to ",[269,334,335],{},"share.created",[305,337,307,338,341],{},[281,339,340],{},"Add endpoint",". The signing secret is displayed once — copy it, confirm you have saved it, and close the dialog.",[265,343,344,345,348,349,352,353,348,356,359,360,363],{},"Each endpoint then offers ",[281,346,347],{},"Deliveries",", ",[281,350,351],{},"Disable","/",[281,354,355],{},"Enable",[281,357,358],{},"Rotate secret","\nand ",[281,361,362],{},"Remove",". The delivery log shows the event, status, attempt count, response\ncode and time for recent deliveries, and lets you replay one.",[265,365,366],{},"Removing an endpoint is permanent: it deletes the endpoint's event selection and\nits whole delivery log with it, and cannot be undone.",[368,369,371],"h3",{"id":370},"what-an-api-key-can-do","What an API key can do",[265,373,374],{},"Through the hosted MCP server, an API key can:",[376,377,378,384],"ul",{},[305,379,380,383],{},[269,381,382],{},"list_webhooks"," — list your endpoints with their id, URL, events and enabled state. It never returns a signing secret.",[305,385,386,389,390,393],{},[269,387,388],{},"rotate_webhook_secret"," — rotate one endpoint's signing secret, given its ",[269,391,392],{},"endpoint_id",". The new secret is returned once.",[265,395,396],{},"That is the whole of it. Listing and rotating cannot redirect your event stream\nanywhere; creating and re-pointing can, which is exactly why they are not\nreachable with an API key. A stolen key that could re-point a webhook would turn\none leaked credential into an ongoing feed of your event metadata.",[290,398,400],{"id":399},"what-a-delivery-looks-like","What a delivery looks like",[265,402,403,404,406],{},"CredenShare sends ",[269,405,271],{}," to your URL with these headers:",[408,409,410,423],"table",{},[411,412,413],"thead",{},[414,415,416,420],"tr",{},[417,418,419],"th",{},"Header",[417,421,422],{},"Value",[424,425,426,439,451,463,473],"tbody",{},[414,427,428,434],{},[429,430,431],"td",{},[269,432,433],{},"Content-Type",[429,435,436],{},[269,437,438],{},"application/json",[414,440,441,446],{},[429,442,443],{},[269,444,445],{},"User-Agent",[429,447,448],{},[269,449,450],{},"CredenShare-Webhooks/1",[414,452,453,458],{},[429,454,455],{},[269,456,457],{},"X-CredenShare-Event",[429,459,460,461],{},"The event code, for example ",[269,462,335],{},[414,464,465,470],{},[429,466,467],{},[269,468,469],{},"X-CredenShare-Delivery",[429,471,472],{},"The delivery's id (a UUID). The same value repeats on every retry of that delivery.",[414,474,475,480],{},[429,476,477],{},[269,478,479],{},"X-CredenShare-Signature",[429,481,482,485,486],{},[269,483,484],{},"t=\u003Cunix seconds>,v1=\u003Chex>"," — see ",[487,488,490],"a",{"href":489},"#verifying-a-delivery","Verifying a delivery",[265,492,493,494,497,498,501,502,501,505,508,509,512,513,515],{},"The body is a flat JSON object with an ",[269,495,496],{},"event"," key and a handful of string\nfields. There is no envelope: no ",[269,499,500],{},"data",", no ",[269,503,504],{},"object",[269,506,507],{},"id"," or ",[269,510,511],{},"timestamp","\ninside the body. The delivery id and event code travel in the headers above. See\nthe ",[487,514,200],{"href":201}," for every event code and its fields.",[265,517,518],{},"Deliveries are queued when the event happens and sent by a worker that runs once\na minute, so a delivery normally arrives within about a minute of the event\nrather than synchronously with the action that caused it. Queuing a delivery can\nnever fail the action itself.",[290,520,522],{"id":521},"payloads-carry-metadata-only","Payloads carry metadata only",[265,524,525],{},"A payload names the object an event concerns — a short code, a title, an\norganization id — and stops there. It never carries shared content, a URL\nfragment, a decryption key, a passcode, an access token or a signing secret.",[265,527,528,529,348,531,348,534,537,538,348,541,348,544,547,548,551],{},"This is not a policy that could be relaxed later; it is what the product can do.\nContent is encrypted in the sender's browser, and the decryption key lives in the\nlink fragment, which never reaches CredenShare's servers. There is no plaintext on\nthe server to put into a webhook, and the keys ",[269,530,500],{},[269,532,533],{},"fragment",[269,535,536],{},"key",",\n",[269,539,540],{},"content",[269,542,543],{},"secret",[269,545,546],{},"passcode"," and ",[269,549,550],{},"access_token"," are refused outright before a\ndelivery is queued.",[265,553,554,555,559,560,563],{},"The practical consequence: a webhook tells you ",[556,557,558],"em",{},"that"," something happened and to\n",[556,561,562],{},"which"," share. To act on the content itself, you still need the link and its\nfragment.",[290,565,567],{"id":566},"the-signing-secret","The signing secret",[265,569,570,571,574],{},"Each endpoint has one signing secret, a string beginning ",[269,572,573],{},"whsec_",". It is shown\nonce, when the endpoint is created, and again each time you rotate it.",[265,576,577],{},"CredenShare cannot show it to you a second time. The secret is derived on demand\nfrom a master key plus the endpoint's id and secret version; only hashes are\nstored. If you lose it, rotate to get a new one.",[368,579,581],{"id":580},"rotation","Rotation",[265,583,584,585,588,589,592,593,596],{},"Rotating bumps the endpoint's secret version and issues a new secret. For 24\nhours afterwards, every delivery is signed ",[281,586,587],{},"twice"," — once with the new secret\nand once with the previous one — so two ",[269,590,591],{},"v1="," values appear in the signature\nheader, and a receiver that accepts any matching ",[269,594,595],{},"v1"," keeps working while you\nroll your configuration.",[274,598,601],{"color":599,"icon":600},"warning","i-lucide-triangle-alert",[265,602,603],{},"Only one previous secret is retained. Rotating twice inside the same 24-hour\nwindow drops the oldest, and a receiver still holding the original secret starts\nfailing immediately.",[290,605,490],{"id":606},"verifying-a-delivery",[265,608,609],{},"Verify every delivery before you act on it. The signature header looks like this:",[611,612,617],"pre",{"className":613,"code":614,"language":615,"meta":616,"style":616},"language-bash shiki shiki-themes github-light github-dark github-dark","X-CredenShare-Signature: t=1756270800,v1=3f9c1a2b4d6e8f0a1c3e5d7b9f1a3c5e7d9b1f3a5c7e9d1b3f5a7c9e1d3b5f7a\n","bash","",[269,618,619],{"__ignoreMap":616},[620,621,624,628],"span",{"class":622,"line":623},"line",1,[620,625,627],{"class":626},"shcOC","X-CredenShare-Signature:",[620,629,631],{"class":630},"sfrk1"," t=1756270800,v1=3f9c1a2b4d6e8f0a1c3e5d7b9f1a3c5e7d9b1f3a5c7e9d1b3f5a7c9e1d3b5f7a\n",[265,633,634,637,638,640,641,643],{},[269,635,636],{},"t"," is the Unix time in seconds at which that attempt was signed. Each ",[269,639,595],{}," is a\nlowercase hex HMAC-SHA256 over the timestamp, a single ",[269,642,311],{},", and the raw request\nbody:",[611,645,647],{"className":613,"code":646,"language":615,"meta":616,"style":616},"signed_payload = \"\u003Ct>\" + \".\" + \u003Craw body bytes>\n",[269,648,649],{"__ignoreMap":616},[620,650,651,654,657,660,663,666,668,672,675,678,681,685],{"class":622,"line":623},[620,652,653],{"class":626},"signed_payload",[620,655,656],{"class":630}," =",[620,658,659],{"class":630}," \"\u003Ct>\"",[620,661,662],{"class":630}," +",[620,664,665],{"class":630}," \".\"",[620,667,662],{"class":630},[620,669,671],{"class":670},"so5gQ"," \u003C",[620,673,674],{"class":630},"raw",[620,676,677],{"class":630}," body",[620,679,680],{"class":630}," byte",[620,682,684],{"class":683},"slsVL","s",[620,686,687],{"class":670},">\n",[265,689,690,691,693],{},"The ",[269,692,311],{}," is not decoration — without it, different timestamp and body pairs could\nproduce the same input.",[265,695,696],{},"To verify:",[302,698,699,706,719,728,733,750],{},[305,700,701,702,705],{},"Read the ",[281,703,704],{},"raw body bytes exactly as received",". Do not parse the JSON and re-serialize it before hashing — the bytes on the wire are what was signed, and their key order and spacing are not guaranteed to match what your serializer would produce.",[305,707,708,709,711,712,715,716,718],{},"Split the header value on commas. Take ",[269,710,636],{},", and take ",[281,713,714],{},"every"," ",[269,717,595],{}," value, not just the first or the last.",[305,720,721,722,724,725,727],{},"Reject the delivery if ",[269,723,636],{}," is missing or if there is no ",[269,726,595],{}," value.",[305,729,721,730,732],{},[269,731,636],{}," differs from your own clock by more than 300 seconds in either direction.",[305,734,735,736,739,740,742,743,746,747,749],{},"Compute ",[269,737,738],{},"hex(HMAC-SHA256(secret, signed_payload))",", where ",[269,741,543],{}," is the ",[281,744,745],{},"full"," issued string including the ",[269,748,573],{}," prefix — not the characters after it, and not a decoded form of it.",[305,751,752,753,755],{},"Compare your result against each ",[269,754,595],{}," value using a constant-time comparison. Accept the delivery if any one of them matches.",[265,757,758,759,761],{},"Step 2 matters during a rotation window, when two ",[269,760,595],{}," values are present. Code\nthat reads only one of them will reject roughly half of what arrives.",[265,763,764],{},"An illustrative recomputation at the shell:",[611,766,768],{"className":613,"code":767,"language":615,"meta":616,"style":616},"# $TS     — the t value from the signature header\n# $BODY   — the request body exactly as received\n# $SECRET — the full secret, including the whsec_ prefix\nprintf '%s.%s' \"$TS\" \"$BODY\" \\\n  | openssl dgst -sha256 -hmac \"$SECRET\" -hex\n",[269,769,770,776,782,788,817],{"__ignoreMap":616},[620,771,772],{"class":622,"line":623},[620,773,775],{"class":774},"sCsY4","# $TS     — the t value from the signature header\n",[620,777,779],{"class":622,"line":778},2,[620,780,781],{"class":774},"# $BODY   — the request body exactly as received\n",[620,783,785],{"class":622,"line":784},3,[620,786,787],{"class":774},"# $SECRET — the full secret, including the whsec_ prefix\n",[620,789,791,795,798,801,804,807,809,812,814],{"class":622,"line":790},4,[620,792,794],{"class":793},"suiK_","printf",[620,796,797],{"class":630}," '%s.%s'",[620,799,800],{"class":630}," \"",[620,802,803],{"class":683},"$TS",[620,805,806],{"class":630},"\"",[620,808,800],{"class":630},[620,810,811],{"class":683},"$BODY",[620,813,806],{"class":630},[620,815,816],{"class":793}," \\\n",[620,818,820,823,826,829,832,835,837,840,842],{"class":622,"line":819},5,[620,821,822],{"class":670},"  |",[620,824,825],{"class":626}," openssl",[620,827,828],{"class":630}," dgst",[620,830,831],{"class":793}," -sha256",[620,833,834],{"class":793}," -hmac",[620,836,800],{"class":630},[620,838,839],{"class":683},"$SECRET",[620,841,806],{"class":630},[620,843,844],{"class":793}," -hex\n",[265,846,847,848,850],{},"Each attempt is signed at the moment it is sent, so a retry of the same delivery\narrives with a different ",[269,849,636],{}," and a different signature over an identical body.\nVerify each attempt on its own, and do not cache a signature.",[290,852,854],{"id":853},"retries-and-failures","Retries and failures",[265,856,857,858,861],{},"Any ",[269,859,860],{},"2xx"," response counts as success. Your handler has 10 seconds to answer —\nacknowledge first and do your work afterwards, or the attempt is recorded as a\ntimeout.",[265,863,864],{},"A failed attempt is retried, up to six attempts in total:",[408,866,867,877],{},[411,868,869],{},[414,870,871,874],{},[417,872,873],{},"Attempt",[417,875,876],{},"Sent",[424,878,879,887,895,903,911,919],{},[414,880,881,884],{},[429,882,883],{},"1",[429,885,886],{},"Within about a minute of the event",[414,888,889,892],{},[429,890,891],{},"2",[429,893,894],{},"1 minute after attempt 1",[414,896,897,900],{},[429,898,899],{},"3",[429,901,902],{},"5 minutes after attempt 2",[414,904,905,908],{},[429,906,907],{},"4",[429,909,910],{},"25 minutes after attempt 3",[414,912,913,916],{},[429,914,915],{},"5",[429,917,918],{},"2 hours 5 minutes after attempt 4",[414,920,921,924],{},[429,922,923],{},"6",[429,925,926],{},"6 hours after attempt 5",[265,928,929],{},"Six attempts span roughly 8 hours 36 minutes from the first.",[265,931,932],{},"What is and is not retried:",[376,934,935,952],{},[305,936,937,938,348,941,348,944,947,948,951],{},"Retried: timeouts, connection errors, any ",[269,939,940],{},"5xx",[269,942,943],{},"408 Request Timeout",[269,945,946],{},"429 Too Many Requests",", and ",[269,949,950],{},"3xx"," responses (redirects are never followed, so a redirect counts as a failure).",[305,953,954,955,958,959,348,962,508,965,968],{},"Not retried: any other ",[269,956,957],{},"4xx",". A ",[269,960,961],{},"400",[269,963,964],{},"404",[269,966,967],{},"410"," ends that delivery immediately, however many attempts remain. A handler that rejects a body it does not recognise will therefore drop events quietly rather than fill your log with retries.",[265,970,971,972,975,976,978],{},"A delivery that exhausts its attempts is marked dead and stays in the endpoint's\ndelivery log. Replay it from the app once your receiver is fixed. A replay sends\nthe original payload again under a ",[281,973,974],{},"new"," delivery id, so a receiver that\nde-duplicates on ",[269,977,469],{}," will treat it as new.",[265,980,981],{},"An endpoint can also be disabled for you, in which case it stops receiving\nimmediately until you re-enable it:",[376,983,984,987],{},[305,985,986],{},"Its target resolved to a private or otherwise blocked address at delivery time.",[305,988,989],{},"The master signing key changed, so the secret you hold can no longer verify anything. An endpoint in that state has to be re-created.",[290,991,993],{"id":992},"endpoint-limits","Endpoint limits",[265,995,996],{},"Webhooks are part of the same entitlement as API access, so they come with the\nBusiness and Enterprise plans:",[408,998,999,1009],{},[411,1000,1001],{},[414,1002,1003,1006],{},[417,1004,1005],{},"Plan",[417,1007,1008],{},"Endpoints",[424,1010,1011,1018,1026],{},[414,1012,1013,1016],{},[429,1014,1015],{},"Business",[429,1017,899],{},[414,1019,1020,1023],{},[429,1021,1022],{},"Enterprise",[429,1024,1025],{},"10",[414,1027,1028,1031],{},[429,1029,1030],{},"Every other plan",[429,1032,1033],{},"0 — webhooks are not included",[265,1035,1036],{},"The cap counts the endpoints on your account, disabled ones included. Disabling\nan endpoint does not free a slot; removing it does.",[290,1038,1040],{"id":1039},"url-requirements","URL requirements",[408,1042,1043,1053],{},[411,1044,1045],{},[414,1046,1047,1050],{},[417,1048,1049],{},"Rule",[417,1051,1052],{},"Detail",[424,1054,1055,1073,1109,1119],{},[414,1056,1057,1062],{},[429,1058,1059,1061],{},[269,1060,321],{}," only",[429,1063,1064,1065,1068,1069,1072],{},"The URL must begin with ",[269,1066,1067],{},"https://",". Plain ",[269,1070,1071],{},"http"," is refused.",[414,1074,1075,1078],{},[429,1076,1077],{},"Public addresses only",[429,1079,1080,1081,348,1084,348,1087,348,1090,348,1093,348,1096,1099,1100,348,1103,547,1106,311],{},"A hostname that resolves to a loopback, private, link-local, carrier-NAT, documentation or multicast address is refused — ",[269,1082,1083],{},"localhost",[269,1085,1086],{},"127.0.0.1",[269,1088,1089],{},"10.x",[269,1091,1092],{},"172.16–31.x",[269,1094,1095],{},"192.168.x",[269,1097,1098],{},"169.254.x",", and the IPv6 equivalents ",[269,1101,1102],{},"::1",[269,1104,1105],{},"fc00::/7",[269,1107,1108],{},"fe80::/10",[414,1110,1111,1114],{},[429,1112,1113],{},"Any port",[429,1115,1116,1118],{},[269,1117,321],{}," on a non-standard port is accepted.",[414,1120,1121,1124],{},[429,1122,1123],{},"No redirects",[429,1125,1126],{},"Redirects are never followed. Register the final destination, not something that forwards to it.",[265,1128,1129,1130,1132],{},"The address check runs again before ",[281,1131,714],{}," delivery, not only when you add the\nendpoint. That is deliberate: an endpoint whose DNS later pointed inward would\notherwise become a way to make CredenShare's servers reach a private network. If\na target resolves somewhere blocked at delivery time, that delivery is dropped\nand the endpoint is disabled. A hostname that does not resolve at all when you\nadd it is accepted, and gets checked the same way at delivery.",[274,1134,1135],{"color":599,"icon":600},[265,1136,1137,1140],{},[281,1138,1139],{},"An endpoint's URL cannot be changed after it is created."," To send events\nsomewhere else, add a new endpoint and remove the old one. The new endpoint has\nits own signing secret and its own delivery log; nothing carries over.",[1142,1143],"hr",{},[274,1145,1147],{"color":276,"icon":1146},"i-lucide-arrow-right",[265,1148,1149,1150,1156,1157,1162],{},"Webhooks are available on every paid plan. ",[487,1151,1155],{"href":1152,"rel":1153},"https://credenshare.io/pricing",[1154],"nofollow","See what each tier includes",", or ",[487,1158,1161],{"href":1159,"rel":1160},"https://credenshare.io/enterprise",[1154],"talk to us"," if you need delivery guarantees or an event we do not emit yet.",[1164,1165,1166],"style",{},"html pre.shiki code .shcOC, html code.shiki .shcOC{--shiki-light:#6F42C1;--shiki-default:#B392F0;--shiki-dark:#B392F0}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .so5gQ, html code.shiki .so5gQ{--shiki-light:#D73A49;--shiki-default:#F97583;--shiki-dark:#F97583}html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}html pre.shiki code .sCsY4, html code.shiki .sCsY4{--shiki-light:#6A737D;--shiki-default:#6A737D;--shiki-dark:#6A737D}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}",{"title":616,"searchDepth":623,"depth":778,"links":1168},[1169,1172,1173,1174,1177,1178,1179,1180],{"id":292,"depth":778,"text":293,"children":1170},[1171],{"id":370,"depth":784,"text":371},{"id":399,"depth":778,"text":400},{"id":521,"depth":778,"text":522},{"id":566,"depth":778,"text":567,"children":1175},[1176],{"id":580,"depth":784,"text":581},{"id":606,"depth":778,"text":490},{"id":853,"depth":778,"text":854},{"id":992,"depth":778,"text":993},{"id":1039,"depth":778,"text":1040},"How CredenShare delivers event notifications to your endpoint, how to verify a delivery, and what an API key can and cannot do with webhooks.","md",{},true,{"title":194,"description":1181},"WiYJ_xJMCA1TKD5mEQ86D1bBcHT4lY7boGwtp6oWkj0",[1188,1190],{"title":190,"path":191,"stem":192,"description":1189,"children":-1},"GET /v1/stats — the account's share counts and a 14-day view history, without paging the whole share list.",{"title":200,"path":201,"stem":202,"description":1191,"children":-1},"The nineteen webhook event codes, when each one fires, and the exact fields of a delivery payload.",1788908853049]