[{"data":1,"prerenderedAt":1804},["ShallowReactive",2],{"navigation":3,"/api/webhooks/events":258,"/api/webhooks/events-surround":1799},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":200,"api":260,"body":261,"description":1793,"extension":1794,"links":260,"meta":1795,"navigation":1796,"path":201,"seo":1797,"stem":202,"__hash__":1798},"docs/6.api/5.webhooks/1.events.md",null,{"type":262,"value":263,"toc":1776},"minimark",[264,268,271,276,515,542,555,560,567,575,579,584,625,638,642,645,674,678,700,711,719,723,994,1000,1049,1077,1092,1096,1109,1382,1400,1406,1414,1417,1434,1447,1452,1457,1522,1531,1535,1538,1629,1632,1676,1685,1741,1745,1756,1759,1772],[265,266,267],"p",{},"There are nineteen event codes. The set is closed: you choose which of them an\nendpoint receives, and a code outside this list is refused when you save the\nselection rather than stored and quietly ignored.",[265,269,270],{},"Each endpoint has its own selection, and saving a selection replaces the previous\none wholesale — the events you tick are the events the endpoint has, not events\nadded to what it had before.",[272,273,275],"h2",{"id":274},"event-codes","Event codes",[277,278,279,292],"table",{},[280,281,282],"thead",{},[283,284,285,289],"tr",{},[286,287,288],"th",{},"Event",[286,290,291],{},"Fires when",[293,294,295,311,321,331,345,359,374,384,393,407,421,431,441,451,461,471,485,495,505],"tbody",{},[283,296,297,304],{},[298,299,300],"td",{},[301,302,303],"code",{},"share.created",[298,305,306,307,310],{},"A share is created, from the app or the API. A submission to a secure request does not fire this — it fires ",[301,308,309],{},"request.submitted"," instead.",[283,312,313,318],{},[298,314,315],{},[301,316,317],{},"share.viewed",[298,319,320],{},"A recipient successfully opens the share and its content is returned.",[283,322,323,328],{},[298,324,325],{},[301,326,327],{},"share.expired",[298,329,330],{},"A share reaches the end of its life, either because the periodic sweep found it expired or because a read did.",[283,332,333,338],{},[298,334,335],{},[301,336,337],{},"share.deleted",[298,339,340,341,344],{},"The owner deletes the share, from the app or with ",[301,342,343],{},"DELETE /v1/shares/{shortCode}",".",[283,346,347,352],{},[298,348,349],{},[301,350,351],{},"share.access_denied",[298,353,354,355,358],{},"Someone tries to open a share and is refused for a reason CredenShare can attribute — see ",[301,356,357],{},"reason"," below.",[283,360,361,366],{},[298,362,363],{},[301,364,365],{},"user.emergency_expire",[298,367,368,369,373],{},"The owner force-expires everything. ",[370,371,372],"strong",{},"One event for the whole batch",", not one per share — see below.",[283,375,376,381],{},[298,377,378],{},[301,379,380],{},"request.created",[298,382,383],{},"You create a secure request. The request's field definitions are deliberately not included.",[283,385,386,390],{},[298,387,388],{},[301,389,309],{},[298,391,392],{},"Someone submits an answer to your secure request.",[283,394,395,400],{},[298,396,397],{},[301,398,399],{},"request.expired",[298,401,402,403,406],{},"An active secure request is closed. The first ",[301,404,405],{},"DELETE /v1/requests/{shortCode}"," fires this.",[283,408,409,414],{},[298,410,411],{},[301,412,413],{},"request.deleted",[298,415,416,417,420],{},"A secure request is permanently removed, submissions included. A second ",[301,418,419],{},"DELETE"," on an already-expired request fires this.",[283,422,423,428],{},[298,424,425],{},[301,426,427],{},"org.member_added",[298,429,430],{},"An invited member accepts the invitation. Not when the invitation is sent.",[283,432,433,438],{},[298,434,435],{},[301,436,437],{},"org.member_removed",[298,439,440],{},"A member is removed from the organization.",[283,442,443,448],{},[298,444,445],{},[301,446,447],{},"zk.device_linked",[298,449,450],{},"A device is linked to your zero-knowledge account.",[283,452,453,458],{},[298,454,455],{},[301,456,457],{},"zk.device_revoked",[298,459,460],{},"A linked device is revoked.",[283,462,463,468],{},[298,464,465],{},[301,466,467],{},"zk.team_key_granted",[298,469,470],{},"An admin grants a team key to a member.",[283,472,473,478],{},[298,474,475],{},[301,476,477],{},"zk.rotated",[298,479,480,481,484],{},"The account key itself is rotated. ",[301,482,483],{},"destructive"," says whether everything already stored was orphaned.",[283,486,487,492],{},[298,488,489],{},[301,490,491],{},"api_key.created",[298,493,494],{},"An API key is minted on the account.",[283,496,497,502],{},[298,498,499],{},[301,500,501],{},"api_key.revoked",[298,503,504],{},"An API key is revoked.",[283,506,507,512],{},[298,508,509],{},[301,510,511],{},"api_key.custody_granted",[298,513,514],{},"An API key is granted the ability to decrypt what the account can.",[516,517,520],"callout",{"color":518,"icon":519},"info","i-lucide-shield-alert",[265,521,522,533,534,536,537,528,539,541],{},[370,523,524,525,528,529,532],{},"The ",[301,526,527],{},"api_key.*"," and ",[301,530,531],{},"zk.*"," events are the ones a security team wants."," A credential appearing on a production account at 03:00, or gaining custody, is the signal worth alerting on. Subscribe to ",[301,535,491],{},", ",[301,538,511],{},[301,540,477],{}," if you are wiring this into monitoring rather than into a product feature.",[265,543,544,528,547,550,551,554],{},[301,545,546],{},"share.downloaded",[301,548,549],{},"share.exploded"," are ",[370,552,553],{},"not"," event codes, despite appearing in some older notes. The set above is closed: naming a code outside it is refused when you create the subscription rather than stored and silently never fired.",[556,557,559],"h3",{"id":558},"useremergency_expire-is-one-event-for-the-batch","user.emergency_expire is one event for the batch",[265,561,562,563,566],{},"Force-expiring an account's shares fires a single event carrying ",[301,564,565],{},"expired_count",", not one event per share. That is deliberate: a per-share event would mean a delivery storm at exactly the moment somebody is dealing with an incident, and the individual short codes are not the useful part of that signal.",[265,568,569,570,574],{},"If you need to know ",[571,572,573],"em",{},"which"," shares went, reconcile against your own records — the event tells you how many and when.",[556,576,578],{"id":577},"requestexpired-and-requestdeleted-are-two-outcomes-of-one-call","request.expired and request.deleted are two outcomes of one call",[265,580,581,583],{},[301,582,405],{}," behaves differently depending on the request's state, and the event follows what actually happened rather than what was asked for:",[277,585,586,595],{},[280,587,588],{},[283,589,590,593],{},[286,591,592],{},"Call",[286,594,288],{},[293,596,597,612],{},[283,598,599,608],{},[298,600,601,603,604,607],{},[301,602,419],{}," on an ",[370,605,606],{},"active"," request",[298,609,610],{},[301,611,399],{},[283,613,614,621],{},[298,615,616,603,618,607],{},[301,617,419],{},[370,619,620],{},"already-expired",[298,622,623],{},[301,624,413],{},[265,626,627,628,631,632,634,635,344],{},"Both payloads carry only ",[301,629,630],{},"short_code",". If you are watching for destruction rather than closure, ",[301,633,413],{}," is the one that means the submissions are gone. See ",[636,637,186],"a",{"href":187},[272,639,641],{"id":640},"who-receives-an-event","Who receives an event",[265,643,644],{},"Endpoints belong to an account, and an event goes to the endpoints of the account\nthat owns the thing the event is about — not to whoever triggered it. So:",[646,647,648,657,662,669],"ul",{},[649,650,651,652,528,654,656],"li",{},"Share events go to the share's owner, including ",[301,653,317],{},[301,655,351],{},", which are caused by a recipient.",[649,658,659,661],{},[301,660,309],{}," goes to the request's owner, not to the person who submitted.",[649,663,664,528,666,668],{},[301,665,427],{},[301,667,437],{}," go to the organization's owner.",[649,670,671,673],{},[301,672,467],{}," goes to the admin who granted the key. The member who received it is not notified through webhooks.",[272,675,677],{"id":676},"the-delivery-payload","The delivery payload",[265,679,680,681,684,685,688,689,692,693,528,696,699],{},"The body is a flat JSON object. ",[301,682,683],{},"event"," holds the event code; the remaining keys\nname the object involved, and are strings apart from the five noted in the field\nreference below. There is no wrapper object, and no ",[301,686,687],{},"id"," or ",[301,690,691],{},"timestamp"," inside\nthe body — the delivery id and the event code arrive in the\n",[301,694,695],{},"X-CredenShare-Delivery",[301,697,698],{},"X-CredenShare-Event"," headers.",[265,701,702,703,706,707,710],{},"Optional fields are ",[370,704,705],{},"omitted",", not sent as ",[301,708,709],{},"null",". Write your handler to treat\na missing key as absent rather than expecting every key on every delivery.",[265,712,713,714,718],{},"Payloads are metadata only. No delivery ever carries shared content, a link\nfragment, a key, a passcode or an access token — see\n",[636,715,717],{"href":716},"/api/webhooks#payloads-carry-metadata-only","Payloads carry metadata only"," for why.",[556,720,722],{"id":721},"fields-by-event","Fields by event",[277,724,725,736],{},[280,726,727],{},[283,728,729,731],{},[286,730,288],{},[286,732,733,734],{},"Fields besides ",[301,735,683],{},[293,737,738,759,775,792,802,814,824,838,855,865,875,888,901,912,926,939,949,972,984],{},[283,739,740,744],{},[298,741,742],{},[301,743,303],{},[298,745,746,536,748,751,752,751,755,758],{},[301,747,630],{},[301,749,750],{},"title","?, ",[301,753,754],{},"organization_id",[301,756,757],{},"expired_at","?",[283,760,761,765],{},[298,762,763],{},[301,764,317],{},[298,766,767,536,769,751,771,751,773,758],{},[301,768,630],{},[301,770,750],{},[301,772,754],{},[301,774,757],{},[283,776,777,781],{},[298,778,779],{},[301,780,327],{},[298,782,783,785,786,788,789],{},[301,784,630],{},", then either ",[301,787,750],{},"? or ",[301,790,791],{},"expired_on",[283,793,794,798],{},[298,795,796],{},[301,797,337],{},[298,799,800],{},[301,801,630],{},[283,803,804,808],{},[298,805,806],{},[301,807,351],{},[298,809,810,536,812],{},[301,811,630],{},[301,813,357],{},[283,815,816,820],{},[298,817,818],{},[301,819,365],{},[298,821,822],{},[301,823,565],{},[283,825,826,830],{},[298,827,828],{},[301,829,380],{},[298,831,832,536,834,751,836,758],{},[301,833,630],{},[301,835,750],{},[301,837,754],{},[283,839,840,844],{},[298,841,842],{},[301,843,309],{},[298,845,846,536,848,536,851,751,853,758],{},[301,847,630],{},[301,849,850],{},"secure_request_short_code",[301,852,750],{},[301,854,754],{},[283,856,857,861],{},[298,858,859],{},[301,860,399],{},[298,862,863],{},[301,864,630],{},[283,866,867,871],{},[298,868,869],{},[301,870,413],{},[298,872,873],{},[301,874,630],{},[283,876,877,881],{},[298,878,879],{},[301,880,427],{},[298,882,883,536,885],{},[301,884,754],{},[301,886,887],{},"email",[283,889,890,894],{},[298,891,892],{},[301,893,437],{},[298,895,896,536,898],{},[301,897,754],{},[301,899,900],{},"user_id",[283,902,903,907],{},[298,904,905],{},[301,906,447],{},[298,908,909],{},[301,910,911],{},"link_code",[283,913,914,918],{},[298,915,916],{},[301,917,457],{},[298,919,920,536,923],{},[301,921,922],{},"envelope_id",[301,924,925],{},"kind?",[283,927,928,932],{},[298,929,930],{},[301,931,467],{},[298,933,934,536,936],{},[301,935,754],{},[301,937,938],{},"target_user_id",[283,940,941,945],{},[298,942,943],{},[301,944,477],{},[298,946,947],{},[301,948,483],{},[283,950,951,955],{},[298,952,953],{},[301,954,491],{},[298,956,957,536,960,536,963,536,966,536,969],{},[301,958,959],{},"key_id",[301,961,962],{},"name",[301,964,965],{},"scopes",[301,967,968],{},"custody_level",[301,970,971],{},"custody_level_requested",[283,973,974,978],{},[298,975,976],{},[301,977,501],{},[298,979,980,536,982],{},[301,981,959],{},[301,983,357],{},[283,985,986,990],{},[298,987,988],{},[301,989,511],{},[298,991,992],{},[301,993,959],{},[265,995,996,997,999],{},"Fields marked ",[301,998,758],{}," are present only when they have a value.",[516,1001,1004,1021],{"color":1002,"icon":1003},"warning","i-lucide-alert-triangle",[265,1005,1006,1017,1018,1020],{},[370,1007,1008,1009,1011,1012,1014,1015,344],{},"On ",[301,1010,491],{},", alert on ",[301,1013,971],{},", not ",[301,1016,968],{}," A monitor watching ",[301,1019,968],{}," for \"something asked for the ability to read everything\" would never fire.",[646,1022,1023,1038,1043],{},[649,1024,1025,1027,1028,1034,1035,1037],{},[301,1026,968],{}," is ",[370,1029,1030,1031],{},"always ",[301,1032,1033],{},"0"," on this event, and truthfully so: a key cannot hold a non-zero custody level until a public key has been registered for it, and the client cannot register one until it holds the credential — which does not exist until after this event fires. So a key that asked for full account custody still reports ",[301,1036,1033],{}," here.",[649,1039,1040,1042],{},[301,1041,971],{}," is the argument the caller passed, and it is the security-relevant intent.",[649,1044,1045,1046,1048],{},"The actual grant arrives later, as a separate ",[301,1047,511],{}," event.",[516,1050,1052],{"color":518,"icon":1051},"i-lucide-info",[265,1053,1054,1056,1057,1059,1060,1062,1063,528,1065,1067,1068,1071,1072,1074,1075,344],{},[301,1055,327],{}," has two shapes. When the periodic sweep detects the expiry you\nget ",[301,1058,630],{}," and, if the share had one, ",[301,1061,750],{},". When a read detects it you\nget ",[301,1064,630],{},[301,1066,791],{}," with the value ",[301,1069,1070],{},"read",", and no ",[301,1073,750],{},". Handle\nboth: require nothing but ",[301,1076,630],{},[265,1078,1079,1080,1082,1083,1085,1086,1088,1089,1091],{},"The two organization events also differ from each other: ",[301,1081,427],{},"\nidentifies the member by ",[301,1084,887],{},", while ",[301,1087,437],{}," identifies them by\n",[301,1090,900],{},". Read each one on its own terms.",[556,1093,1095],{"id":1094},"field-reference","Field reference",[265,1097,1098,1099,536,1101,536,1103,536,1105,528,1107,344],{},"Most fields are JSON strings. Five are not, and they are marked below — a handler that coerces everything to a string will mangle ",[301,1100,565],{},[301,1102,483],{},[301,1104,965],{},[301,1106,968],{},[301,1108,971],{},[277,1110,1111,1121],{},[280,1112,1113],{},[283,1114,1115,1118],{},[286,1116,1117],{},"Field",[286,1119,1120],{},"Notes",[293,1122,1123,1132,1141,1150,1159,1172,1186,1200,1214,1225,1235,1246,1256,1272,1283,1298,1316,1328,1339,1353,1369],{},[283,1124,1125,1129],{},[298,1126,1127],{},[301,1128,683],{},[298,1130,1131],{},"Always present. One of the nineteen codes above.",[283,1133,1134,1138],{},[298,1135,1136],{},[301,1137,630],{},[298,1139,1140],{},"The short code of the share, submission or secure request the event concerns.",[283,1142,1143,1147],{},[298,1144,1145],{},[301,1146,750],{},[298,1148,1149],{},"The object's title. Omitted when it has none.",[283,1151,1152,1156],{},[298,1153,1154],{},[301,1155,754],{},[298,1157,1158],{},"The organization the object belongs to. Omitted for personal objects.",[283,1160,1161,1165],{},[298,1162,1163],{},[301,1164,757],{},[298,1166,1167,1168,1171],{},"The share's expiry, as an RFC 3339 timestamp such as ",[301,1169,1170],{},"2026-09-03T17:00:00Z",". Omitted when the share has no expiry.",[283,1173,1174,1178],{},[298,1175,1176],{},[301,1177,791],{},[298,1179,1180,1181,1183,1184,344],{},"Only on ",[301,1182,327],{},", and only from the read path. Always the value ",[301,1185,1070],{},[283,1187,1188,1192],{},[298,1189,1190],{},[301,1191,357],{},[298,1193,1008,1194,1196,1197,1199],{},[301,1195,351],{},", one of the five values below. On ",[301,1198,501],{},", free text describing why.",[283,1201,1202,1206],{},[298,1203,1204],{},[301,1205,850],{},[298,1207,1180,1208,1210,1211,1213],{},[301,1209,309],{},". The secure request that the submission answers; ",[301,1212,630],{}," on the same delivery is the submission itself.",[283,1215,1216,1220],{},[298,1217,1218],{},[301,1219,887],{},[298,1221,1180,1222,1224],{},[301,1223,427],{},". The email address of the member who accepted.",[283,1226,1227,1231],{},[298,1228,1229],{},[301,1230,900],{},[298,1232,1180,1233,344],{},[301,1234,437],{},[283,1236,1237,1241],{},[298,1238,1239],{},[301,1240,911],{},[298,1242,1180,1243,1245],{},[301,1244,447],{},". The code used for the pairing.",[283,1247,1248,1252],{},[298,1249,1250],{},[301,1251,922],{},[298,1253,1180,1254,344],{},[301,1255,457],{},[283,1257,1258,1263],{},[298,1259,1260],{},[301,1261,1262],{},"kind",[298,1264,1180,1265,1267,1268,1271],{},[301,1266,457],{},". Currently always ",[301,1269,1270],{},"device"," — see below.",[283,1273,1274,1278],{},[298,1275,1276],{},[301,1277,938],{},[298,1279,1180,1280,1282],{},[301,1281,467],{},". The member who was granted the key.",[283,1284,1285,1289],{},[298,1286,1287],{},[301,1288,565],{},[298,1290,1180,1291,1293,1294,1297],{},[301,1292,365],{},". ",[370,1295,1296],{},"A number",", not a string: how many shares the batch expired.",[283,1299,1300,1304],{},[298,1301,1302],{},[301,1303,483],{},[298,1305,1180,1306,1293,1308,1311,1312,1315],{},[301,1307,477],{},[370,1309,1310],{},"A boolean."," ",[301,1313,1314],{},"true"," means everything already stored was orphaned by the rotation.",[283,1317,1318,1322],{},[298,1319,1320],{},[301,1321,959],{},[298,1323,1324,1325,1327],{},"On the three ",[301,1326,527],{}," events. The key's id — never any part of the credential itself.",[283,1329,1330,1334],{},[298,1331,1332],{},[301,1333,962],{},[298,1335,1180,1336,1338],{},[301,1337,491],{},". The name the key was given so it can be told apart in a list.",[283,1340,1341,1345],{},[298,1342,1343],{},[301,1344,965],{},[298,1346,1180,1347,1293,1349,1352],{},[301,1348,491],{},[370,1350,1351],{},"An array of strings",", the scopes the key was minted with.",[283,1354,1355,1359],{},[298,1356,1357],{},[301,1358,968],{},[298,1360,1180,1361,1293,1363,1365,1366,1368],{},[301,1362,491],{},[370,1364,1296],{},", and always ",[301,1367,1033],{}," — see the warning above.",[283,1370,1371,1375],{},[298,1372,1373],{},[301,1374,971],{},[298,1376,1180,1377,1293,1379,1381],{},[301,1378,491],{},[370,1380,1296],{},": the custody level the caller asked for. This is the one to alert on.",[516,1383,1384],{"color":518,"icon":1051},[265,1385,1386,1388,1389,1391,1392,1394,1395,1397,1398,344],{},[301,1387,357],{}," is the one field name that means different things on different events. On ",[301,1390,351],{}," it is one of five fixed values you can branch on; on ",[301,1393,501],{}," it is free text meant for a human. Branch on ",[301,1396,683],{}," before you interpret ",[301,1399,357],{},[556,1401,1403,1404],{"id":1402},"values-of-kind","Values of ",[301,1405,1262],{},[265,1407,1408,1410,1411,1413],{},[301,1409,1262],{}," names what was revoked. Today it is always ",[301,1412,1270],{},": the revocation behind this event\ndeletes device envelopes only, so no other value can currently reach you. It is sent as an\nexplicit statement rather than left implied, so a future envelope type does not change the\nmeaning of a payload that never said which kind it meant.",[265,1415,1416],{},"Two properties worth coding against:",[646,1418,1419,1425],{},[649,1420,1421,1424],{},[370,1422,1423],{},"Treat it as optional."," It is read before the revocation, because afterwards the row is\ngone, and a failed lookup omits the field rather than blocking the revocation. Do not fail\nclosed on its absence.",[649,1426,1427,1430,1431,1433],{},[370,1428,1429],{},"Do not switch exhaustively on it."," Handle ",[301,1432,1270],{},", and ignore values you do not\nrecognise rather than erroring.",[516,1435,1436],{"color":518,"icon":1051},[265,1437,1438,1439,1442,1443,1446],{},"Revoking an ",[370,1440,1441],{},"API key's"," custody wrap is a different operation and currently emits ",[370,1444,1445],{},"no\nevent at all",". If you are watching for credentials losing access to encrypted content, this\nevent will not tell you about it.",[556,1448,1403,1450],{"id":1449},"values-of-reason",[301,1451,357],{},[265,1453,1454,1456],{},[301,1455,351],{}," carries exactly one of these strings:",[277,1458,1459,1470],{},[280,1460,1461],{},[283,1462,1463,1467],{},[286,1464,1465],{},[301,1466,357],{},[286,1468,1469],{},"Meaning",[293,1471,1472,1482,1492,1502,1512],{},[283,1473,1474,1479],{},[298,1475,1476],{},[301,1477,1478],{},"Passcode does not match",[298,1480,1481],{},"A passcode was supplied and was wrong.",[283,1483,1484,1489],{},[298,1485,1486],{},[301,1487,1488],{},"Passcode required",[298,1490,1491],{},"The share is passcode-protected and none was supplied.",[283,1493,1494,1499],{},[298,1495,1496],{},[301,1497,1498],{},"Login required",[298,1500,1501],{},"The share requires a signed-in recipient.",[283,1503,1504,1509],{},[298,1505,1506],{},[301,1507,1508],{},"You do not have permission to perform this action on this team",[298,1510,1511],{},"The reader is not permitted to act in that team.",[283,1513,1514,1519],{},[298,1515,1516],{},[301,1517,1518],{},"You don't have permission to access this share",[298,1520,1521],{},"The reader is signed in but is not an allowed recipient.",[265,1523,1524,1525,1527,1528,1530],{},"An unknown short code does ",[370,1526,553],{}," fire ",[301,1529,351],{},". That is\ndeliberate: a wrong access token and a code that never existed look the same from\nthe outside, so emitting on it would turn anyone guessing at short codes into a\nflood of notifications for you.",[272,1532,1534],{"id":1533},"example-deliveries","Example deliveries",[265,1536,1537],{},"A share created with a title, an expiry, and an owning organization. Values are\nillustrative:",[1539,1540,1545],"pre",{"className":1541,"code":1542,"language":1543,"meta":1544,"style":1544},"language-json shiki shiki-themes github-light github-dark github-dark","{\n  \"event\": \"share.created\",\n  \"short_code\": \"9kQ2vX7mB4\",\n  \"title\": \"Staging database password\",\n  \"organization_id\": \"4d1c9e2a-8b57-4f31-9a6e-2c0f7b8d1e34\",\n  \"expired_at\": \"2026-09-03T17:00:00Z\"\n}\n","json","",[301,1546,1547,1556,1573,1586,1599,1612,1623],{"__ignoreMap":1544},[1548,1549,1552],"span",{"class":1550,"line":1551},"line",1,[1548,1553,1555],{"class":1554},"slsVL","{\n",[1548,1557,1559,1563,1566,1570],{"class":1550,"line":1558},2,[1548,1560,1562],{"class":1561},"suiK_","  \"event\"",[1548,1564,1565],{"class":1554},": ",[1548,1567,1569],{"class":1568},"sfrk1","\"share.created\"",[1548,1571,1572],{"class":1554},",\n",[1548,1574,1576,1579,1581,1584],{"class":1550,"line":1575},3,[1548,1577,1578],{"class":1561},"  \"short_code\"",[1548,1580,1565],{"class":1554},[1548,1582,1583],{"class":1568},"\"9kQ2vX7mB4\"",[1548,1585,1572],{"class":1554},[1548,1587,1589,1592,1594,1597],{"class":1550,"line":1588},4,[1548,1590,1591],{"class":1561},"  \"title\"",[1548,1593,1565],{"class":1554},[1548,1595,1596],{"class":1568},"\"Staging database password\"",[1548,1598,1572],{"class":1554},[1548,1600,1602,1605,1607,1610],{"class":1550,"line":1601},5,[1548,1603,1604],{"class":1561},"  \"organization_id\"",[1548,1606,1565],{"class":1554},[1548,1608,1609],{"class":1568},"\"4d1c9e2a-8b57-4f31-9a6e-2c0f7b8d1e34\"",[1548,1611,1572],{"class":1554},[1548,1613,1615,1618,1620],{"class":1550,"line":1614},6,[1548,1616,1617],{"class":1561},"  \"expired_at\"",[1548,1619,1565],{"class":1554},[1548,1621,1622],{"class":1568},"\"2026-09-03T17:00:00Z\"\n",[1548,1624,1626],{"class":1550,"line":1625},7,[1548,1627,1628],{"class":1554},"}\n",[265,1630,1631],{},"A refused read of that same share:",[1539,1633,1635],{"className":1541,"code":1634,"language":1543,"meta":1544,"style":1544},"{\n  \"event\": \"share.access_denied\",\n  \"short_code\": \"9kQ2vX7mB4\",\n  \"reason\": \"Passcode does not match\"\n}\n",[301,1636,1637,1641,1652,1662,1672],{"__ignoreMap":1544},[1548,1638,1639],{"class":1550,"line":1551},[1548,1640,1555],{"class":1554},[1548,1642,1643,1645,1647,1650],{"class":1550,"line":1558},[1548,1644,1562],{"class":1561},[1548,1646,1565],{"class":1554},[1548,1648,1649],{"class":1568},"\"share.access_denied\"",[1548,1651,1572],{"class":1554},[1548,1653,1654,1656,1658,1660],{"class":1550,"line":1575},[1548,1655,1578],{"class":1561},[1548,1657,1565],{"class":1554},[1548,1659,1583],{"class":1568},[1548,1661,1572],{"class":1554},[1548,1663,1664,1667,1669],{"class":1550,"line":1588},[1548,1665,1666],{"class":1561},"  \"reason\"",[1548,1668,1565],{"class":1554},[1548,1670,1671],{"class":1568},"\"Passcode does not match\"\n",[1548,1673,1674],{"class":1550,"line":1601},[1548,1675,1628],{"class":1554},[265,1677,1678,1679,1681,1682,1684],{},"A submission to a secure request. ",[301,1680,630],{}," is the submitted share;\n",[301,1683,850],{}," is the request it answers:",[1539,1686,1688],{"className":1541,"code":1687,"language":1543,"meta":1544,"style":1544},"{\n  \"event\": \"request.submitted\",\n  \"short_code\": \"T4hL8sD1nW\",\n  \"secure_request_short_code\": \"R7bK2mP9xQ\",\n  \"title\": \"Onboarding credentials\"\n}\n",[301,1689,1690,1694,1705,1716,1728,1737],{"__ignoreMap":1544},[1548,1691,1692],{"class":1550,"line":1551},[1548,1693,1555],{"class":1554},[1548,1695,1696,1698,1700,1703],{"class":1550,"line":1558},[1548,1697,1562],{"class":1561},[1548,1699,1565],{"class":1554},[1548,1701,1702],{"class":1568},"\"request.submitted\"",[1548,1704,1572],{"class":1554},[1548,1706,1707,1709,1711,1714],{"class":1550,"line":1575},[1548,1708,1578],{"class":1561},[1548,1710,1565],{"class":1554},[1548,1712,1713],{"class":1568},"\"T4hL8sD1nW\"",[1548,1715,1572],{"class":1554},[1548,1717,1718,1721,1723,1726],{"class":1550,"line":1588},[1548,1719,1720],{"class":1561},"  \"secure_request_short_code\"",[1548,1722,1565],{"class":1554},[1548,1724,1725],{"class":1568},"\"R7bK2mP9xQ\"",[1548,1727,1572],{"class":1554},[1548,1729,1730,1732,1734],{"class":1550,"line":1601},[1548,1731,1591],{"class":1561},[1548,1733,1565],{"class":1554},[1548,1735,1736],{"class":1568},"\"Onboarding credentials\"\n",[1548,1738,1739],{"class":1550,"line":1614},[1548,1740,1628],{"class":1554},[272,1742,1744],{"id":1743},"handling-unknown-codes","Handling unknown codes",[265,1746,1747,1748,1751,1752,1755],{},"The nineteen codes above are the whole set today, and you cannot subscribe to\nanything outside it. Still, write your handler so that a code it does not\nrecognise is logged and acknowledged with a ",[301,1749,1750],{},"2xx"," rather than treated as an\nerror: a ",[301,1753,1754],{},"4xx"," on an unrecognised event ends that delivery with no retry, and if\nthe set is ever extended you would rather find out from your logs than from a\ngap.",[1757,1758],"hr",{},[516,1760,1762],{"color":518,"icon":1761},"i-lucide-arrow-right",[265,1763,1764,1765,1771],{},"Need an event that is not on this list? ",[636,1766,1770],{"href":1767,"rel":1768},"https://credenshare.io/contact",[1769],"nofollow","Tell us what you are building"," — the set is closed today, and what goes into it next is driven by what integrators ask for.",[1773,1774,1775],"style",{},"html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":1544,"searchDepth":1551,"depth":1558,"links":1777},[1778,1782,1783,1791,1792],{"id":274,"depth":1558,"text":275,"children":1779},[1780,1781],{"id":558,"depth":1575,"text":559},{"id":577,"depth":1575,"text":578},{"id":640,"depth":1558,"text":641},{"id":676,"depth":1558,"text":677,"children":1784},[1785,1786,1787,1789],{"id":721,"depth":1575,"text":722},{"id":1094,"depth":1575,"text":1095},{"id":1402,"depth":1575,"text":1788},"Values of kind",{"id":1449,"depth":1575,"text":1790},"Values of reason",{"id":1533,"depth":1558,"text":1534},{"id":1743,"depth":1558,"text":1744},"The nineteen webhook event codes, when each one fires, and the exact fields of a delivery payload.","md",{},true,{"title":200,"description":1793},"sB4Mn3bzY407BCe2UghKEGp4tsTsKwyjIBqAAHXvOhE",[1800,1802],{"title":194,"path":195,"stem":196,"description":1801,"children":-1},"How CredenShare delivers event notifications to your endpoint, how to verify a delivery, and what an API key can and cannot do with webhooks.",{"title":204,"path":205,"stem":206,"description":1803,"children":-1},"How CredenShare signs every webhook delivery, and how to verify one correctly.",1788908853215]