[{"data":1,"prerenderedAt":918},["ShallowReactive",2],{"navigation":3,"/guides/secure-requests":258,"/guides/secure-requests-surround":913},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":48,"api":260,"body":261,"description":907,"extension":908,"links":260,"meta":909,"navigation":910,"path":49,"seo":911,"stem":50,"__hash__":912},"docs/2.guides/6.secure-requests.md",null,{"type":262,"value":263,"toc":885},"minimark",[264,268,273,293,304,308,311,314,318,324,345,350,357,424,431,434,438,445,491,494,505,508,520,523,527,530,540,546,550,553,573,577,584,628,632,647,650,653,688,691,695,706,712,716,719,745,755,759,765,772,775,785,798,801,805,812,818,825,828,832,835,849,852,856,863,869,872,875],[265,266,267],"p",{},"A secure request is a form you send to somebody so they can hand you a credential, instead of you handing one to them.",[269,270,272],"h2",{"id":271},"business-and-enterprise-only","Business and Enterprise only",[265,274,275,276,280,281,285,286,289,290,292],{},"Secure requests are gated on the ",[277,278,279],"code",{},"secure_requests"," entitlement, which only ",[282,283,284],"strong",{},"Business"," and ",[282,287,288],{},"Enterprise"," carry — monthly and yearly alike. On every other plan the app does not explain the absence: the ",[282,291,48],{}," item is simply missing from the sidebar and from the command palette. If you cannot find it, that is your plan, not a fault.",[265,294,295,296,300,301,303],{},"Everything on this page is the owner's side of the feature. The person filling the form in has their own page: ",[297,298,299],"a",{"href":53},"Receiving a secure request",". The REST equivalent is documented separately under ",[297,302,168],{"href":169},".",[269,305,307],{"id":306},"when-to-use-one-instead-of-a-share","When to use one instead of a share",[265,309,310],{},"Use a share when the secret is already yours and you need to move it to somebody. Use a secure request when the secret is theirs and you need it moved to you — a client's API key, a contractor's licence key, a vendor's SFTP password.",[265,312,313],{},"The difference that matters is which way the encryption points. With a share, you hold the key and the recipient gets it in the link. With a request, the submitter's browser encrypts to a public key belonging to the request, and only you can open the result. That is why the link you hand out carries no key material and can safely go into a ticket, a channel or an email thread — where a share link could not.",[269,315,317],{"id":316},"creating-one","Creating one",[265,319,320,323],{},[282,321,322],{},"Secure Requests → New Request"," opens the form. It is created in whichever workspace you are currently in — the badge in the modal header names it — so switch to the team first if the request belongs to the team.",[325,326,327,339],"ul",{},[328,329,330,333,334,338],"li",{},[282,331,332],{},"Title"," is required and accepts up to 255 characters. It is what the submitter sees at the top of the form, and it becomes the title of each submission (\"Response to: ",[335,336,337],"em",{},"your title","\").",[328,340,341,344],{},[282,342,343],{},"Description"," is optional; it renders under the title as instructions for the submitter.",[346,347,349],"h3",{"id":348},"defining-the-fields","Defining the fields",[265,351,352,353,356],{},"Under ",[282,354,355],{},"Requested Fields"," you list what you are asking for, one row per item. Every row needs a name — the create is refused with \"All fields must have a name\" otherwise — and each carries a type:",[358,359,360,373],"table",{},[361,362,363],"thead",{},[364,365,366,370],"tr",{},[367,368,369],"th",{},"Type",[367,371,372],{},"What the submitter gets",[374,375,376,385,393,401,409,416],"tbody",{},[364,377,378,382],{},[379,380,381],"td",{},"Text",[379,383,384],{},"A single-line box",[364,386,387,390],{},[379,388,389],{},"Password",[379,391,392],{},"A masked single-line box",[364,394,395,398],{},[379,396,397],{},"Date",[379,399,400],{},"A date picker",[364,402,403,406],{},[379,404,405],{},"Multiline",[379,407,408],{},"A three-row text area",[364,410,411,414],{},[379,412,413],{},"Markdown",[379,415,408],{},[364,417,418,421],{},[379,419,420],{},"Source Code",[379,422,423],{},"A four-row monospaced text area",[265,425,426,427,430],{},"Drag a row by its grip to reorder; the order you set is the order the submitter sees. On Business and Enterprise the number of fields per request is unlimited, so the ",[282,428,429],{},"Add Field"," button never runs out.",[265,432,433],{},"Fields are asked, never answered in advance: a request has no notion of a pre-filled default value, and any default value carried by a template is ignored.",[269,435,437],{"id":436},"the-two-links","The two links",[265,439,440,441,444],{},"Creating the request produces ",[282,442,443],{},"two"," links from the same short code, and they are not interchangeable. The success screen labels them plainly:",[358,446,447,460],{},[361,448,449],{},[364,450,451,454,457],{},[367,452,453],{},"Panel",[367,455,456],{},"What it is",[367,458,459],{},"What to do with it",[374,461,462,478],{},[364,463,464,469,475],{},[379,465,466],{},[282,467,468],{},"Collect link — send this out",[379,470,471,474],{},[277,472,473],{},"https://crs.sh/r/\u003Ccode>"," — no key material at all",[379,476,477],{},"Give it to whoever is submitting. It also carries a QR code. It lets people submit and never lets them read",[364,479,480,485,488],{},[379,481,482],{},[282,483,484],{},"Access link — save this for yourself",[379,486,487],{},"A longer form of the same URL, carrying your key",[379,489,490],{},"Keep it. It is what decrypts every submission",[265,492,493],{},"Sending the access link to a submitter would hand them the ability to read every submission to that request. Saving only the collect link leaves you unable to read any.",[495,496,499],"callout",{"color":497,"icon":498},"warning","i-lucide-alert-triangle",[265,500,501,504],{},[282,502,503],{},"The access link is not recoverable."," Its key never leaves your browser — it is not transmitted to us, it is not stored on the request, and no screen shows it a second time. Save it somewhere durable before you close the modal. Support cannot reissue it, and neither can anyone else.",[265,506,507],{},"Two things soften that, and neither is a substitute for saving the link:",[325,509,510,513],{},[328,511,512],{},"The seed is cached in the browser that created the request, so submissions open there without your being asked for anything. Clearing site data discards it.",[328,514,515,516,519],{},"If you have set up ",[297,517,518],{"href":45},"zero-knowledge custody",", the seed is also wrapped to your account key at creation — and, for a team request, to the team key — so your other activated devices resolve it without the link.",[265,521,522],{},"Editing a request never regenerates the keypair, so your access link keeps working afterwards. Title, description, expiry, submission cap, fields and the protection settings can all be changed; the key cannot.",[269,524,526],{"id":525},"request-lifetime-and-submission-cap","Request lifetime and submission cap",[265,528,529],{},"Two controls decide when the form stops accepting anything.",[265,531,532,535,536,539],{},[282,533,534],{},"Expires On"," is an absolute date and time. The ",[282,537,538],{},"Quick Set"," buttons fill in 7, 14, 30 or 90 days ahead at 12:00. Leaving the date empty defaults to 30 days from creation. After it passes the link stops accepting submissions; submissions already received are unaffected.",[265,541,542,545],{},[282,543,544],{},"Max Submissions"," is off by default, which means unlimited. The slider runs to 100 and the number box beside it accepts up to 5000. The cap counts every submission the request has ever taken, including ones that have since expired — deleting or expiring a submission does not free a slot.",[269,547,549],{"id":548},"request-security","Request security",[265,551,552],{},"Three optional controls sit between the submitter and the form:",[325,554,555,561,567],{},[328,556,557,560],{},[282,558,559],{},"Password protect form"," — a passcode the submitter must enter before the fields appear. Send it through a different channel from the link. It is stored encrypted and can never be displayed back to you; on a later edit, leaving the box blank keeps the current password and unticking the checkbox clears it.",[328,562,563,566],{},[282,564,565],{},"Secure view prompt"," — a markdown message shown before the form opens, up to 500 characters. Use it for compliance wording or handling instructions.",[328,568,569,572],{},[282,570,571],{},"Submitter must be logged in"," — restricts submissions to signed-in CredenShare accounts, which attributes each submission to an email address rather than an IP.",[269,574,576],{"id":575},"what-each-submission-becomes","What each submission becomes",[265,578,579,580,583],{},"Every submission creates a share that only you can read, and the ",[282,581,582],{},"Submitted Data Settings"," section decides how that share behaves. These settings are applied server-side from the request, so a submitter cannot skip them.",[325,585,586,595,617,623],{},[328,587,588,285,591,594],{},[282,589,590],{},"Unit",[282,592,593],{},"Duration"," set how long the submission stays readable: hours up to 24, days up to 31, or months up to 3. The default is 7 days.",[328,596,597,600,601,604,605,608,609,612,613,616],{},[282,598,599],{},"Expire from"," chooses when the clock starts. ",[282,602,603],{},"Creation"," counts from the moment the submitter sends it. ",[282,606,607],{},"First View"," does not start the countdown until ",[335,610,611],{},"you"," first open the submission — the expiry is stamped at that moment, so an unopened submission sits at \"Expires ",[335,614,615],{},"n"," days after first view\" until you look at it.",[328,618,619,622],{},[282,620,621],{},"Password protect share"," adds a passcode you must enter before the submission opens.",[328,624,625,627],{},[282,626,565],{}," adds a confirmation gate, with an optional message of up to 500 characters, before the content is displayed — useful when you might be sharing your screen.",[269,629,631],{"id":630},"field-templates","Field templates",[265,633,634,635,638,639,642,643,646],{},"If you build the same request repeatedly, save the field set as a ",[282,636,637],{},"field template"," of kind ",[335,640,641],{},"secure request"," and pick it from the selector at the top of the create modal. The selector only appears when your plan includes ",[277,644,645],{},"field_templates"," and at least one template of that kind exists in your current context — team templates in a team, your own personal templates otherwise.",[265,648,649],{},"A template supplies the field names and types, and can also preset the submission cap, the form password flag, the login requirement, the secure view prompt and its message, and the submitted-share expiry. Anything it sets can be overridden before you create the request, and the small X beside the selector clears the applied template, returning the form to a single empty field.",[265,651,652],{},"Two ceilings apply, both from your plan:",[358,654,655,665],{},[361,656,657],{},[364,658,659,661,663],{},[367,660],{},[367,662,284],{},[367,664,288],{},[374,666,667,678],{},[364,668,669,672,675],{},[379,670,671],{},"Templates (per team, and per user for personal ones)",[379,673,674],{},"25",[379,676,677],{},"100",[364,679,680,683,686],{},[379,681,682],{},"Fields in one template",[379,684,685],{},"30",[379,687,685],{},[265,689,690],{},"The count cap is checked when you create a template, and the app refuses with \"Your plan's field template limit has been reached.\"",[269,692,694],{"id":693},"what-the-submitter-sees","What the submitter sees",[265,696,697,698,701,702,705],{},"They open the collect link, clear any gate you configured, and get the title, the description and one box per field, plus a panel headed ",[282,699,700],{},"How your submission is protected"," stating the lifetime you chose and whether the countdown starts at submission or at your first open. Every box has to be filled in. Pressing ",[282,703,704],{},"Submit Securely"," encrypts the answers in their browser before anything is sent, and they land on \"Submitted Successfully!\". No account is needed unless you required a login.",[265,707,708,709,711],{},"If the request has expired, hit its cap, or been deleted, all three look identical from their side: \"This request is no longer available\". Full detail is on ",[297,710,299],{"href":53}," — that page is written for them, so it is the one to forward when somebody is stuck.",[269,713,715],{"id":714},"how-you-are-told-about-a-submission","How you are told about a submission",[265,717,718],{},"Two notifications, with different triggers:",[325,720,721,735],{},[328,722,723,726,727,730,731,734],{},[282,724,725],{},"In-app."," Every submission raises a notification reading \"New response submitted by ",[335,728,729],{},"submitter"," for request ",[335,732,733],{},"title","\", linking to the request's page. This one is not optional.",[328,736,737,740,741,744],{},[282,738,739],{},"Email."," Sent to your account address only when ",[282,742,743],{},"Notify me on submission"," is ticked, which it is by default. Untick it for a high-volume form.",[265,746,747,750,751,754],{},[335,748,749],{},"Submitter"," is the person's email address when they were signed in, and ",[277,752,753],{},"guest"," when they were not.",[269,756,758],{"id":757},"reading-submissions","Reading submissions",[265,760,761,762,764],{},"Open the request from the ",[282,763,48],{}," list to see every submission it has taken, newest first, with the submitter, the time, the expiry and the submission's own short code. The eye icon opens one in place.",[265,766,767,768,771],{},"The first time you open an end-to-end encrypted submission on a device that has neither the cached seed nor zero-knowledge custody, the viewer stops at ",[282,769,770],{},"Access link needed"," and asks you to paste the access link you saved. Paste the whole URL; it is cached on that device afterwards. A link belonging to a different request is refused rather than silently producing nothing.",[265,773,774],{},"Two further gates can precede that, if you configured them on the submitted share: the secure view prompt, then the passcode.",[495,776,779],{"color":777,"icon":778},"info","i-lucide-info",[265,780,781,784],{},[282,782,783],{},"Only the account that created the request can open its submissions."," Ownership is checked server-side against the request's creator; team administrators are not an exception, and get \"Not authorized to export this request\" — \"You can only export requests you've created.\" A team administrator does see the request itself in the team list, but not its submissions: listing them is owner-only as well.",[265,786,787,790,791,793,794,797],{},[282,788,789],{},"Export"," offers CSV and JSON for the whole request. It covers active submissions only — with none available it refuses with \"No submissions to export\" and \"Expired submissions are not exportable because their content is scrubbed.\" It does not apply your access-link seed, so rows it cannot read are dropped from the file and the result is reported as \"Exported ",[335,792,615],{}," of ",[335,795,796],{},"m"," submissions\" with \"Some submissions could not be decrypted.\" For end-to-end encrypted submissions, open them one at a time in the viewer instead.",[265,799,800],{},"A value you copy out of a submission is wiped from the clipboard 30 seconds later. The wipe reads the clipboard back first and only clears it if it still holds that value, so in a browser that blocks clipboard reads nothing is wiped.",[269,802,804],{"id":803},"expiry-and-scrubbing","Expiry and scrubbing",[265,806,807,808,811],{},"Submissions are shares, and they expire like shares. When one expires its content is scrubbed permanently — not archived, and not recoverable by us or by you — and the row moves to an audit trail that keeps who submitted, when, and the submission's title and short code, never the content. The list marks it ",[277,809,810],{},"expired",", the eye icon is disabled, and hovering the date gives the exact timestamp.",[265,813,814,815,817],{},"The request reaching its own ",[282,816,534],{}," date only closes the form. The submissions carry on to their own expiries.",[265,819,820,821,824],{},"Using the delete control is different. On either tab it moves ",[282,822,823],{},"every"," live submission into the audit trail before it touches the request, so expiring a request scrubs its submissions there and then rather than leaving them on their own clocks. Read or export what you need first.",[265,826,827],{},"Open a request whose own row has gone and the page says so plainly: \"The secure request has expired or been deleted, so its title, fields, and link can't be shown. Past submissions are still listed below as an audit trail — their content has expired and is no longer recoverable.\"",[269,829,831],{"id":830},"expiring-and-deleting-a-request","Expiring and deleting a request",[265,833,834],{},"The delete control means two different things depending on which tab you are on, and the confirmation dialog says which:",[325,836,837,843],{},[328,838,839,842],{},[282,840,841],{},"Active tab — \"Expire request now?\""," The request stops accepting submissions and moves to your Expired list. The dialog says submissions already received \"stay available in the audit trail\": the audit rows do stay, but their content is scrubbed at the same moment.",[328,844,845,848],{},[282,846,847],{},"Expired tab — \"Delete expired request?\""," The row is permanently removed. This cannot be undone.",[265,850,851],{},"Either way the submissions' content goes, so export or read anything you still need before you use the control.",[269,853,855],{"id":854},"submissions-count-against-your-allowance","Submissions count against your allowance",[265,857,858,859,862],{},"Every submission creates a share, and that share is charged to ",[282,860,861],{},"your"," plan's allowance, not the submitter's — they may not even have an account. A request answered by twenty people is twenty shares against your month. That bites on Business, whose allowance is 500 shares per billing month. Enterprise is unlimited, so a request there cannot exhaust one.",[265,864,865,866,303],{},"The check runs against the request owner's subscription, or the team's when the request belongs to a team. Expired and deleted submissions still count, exactly as expired shares do; see ",[297,867,868],{"href":75},"Plans and share allowance",[265,870,871],{},"When the allowance is spent the submission is refused server-side and the submitter sees only \"Failed to submit. Please try again.\" — they are not told why, and nothing reaches you. If people report failing submissions on a request that used to work, check your remaining allowance first.",[873,874],"hr",{},[495,876,878],{"color":777,"icon":877},"i-lucide-arrow-right",[265,879,880,881,303],{},"Something here not matching what you see? Write to ",[297,882,884],{"href":883},"mailto:support@credenshare.io","support@credenshare.io",{"title":886,"searchDepth":887,"depth":888,"links":889},"",1,2,[890,891,892,896,897,898,899,900,901,902,903,904,905,906],{"id":271,"depth":888,"text":272},{"id":306,"depth":888,"text":307},{"id":316,"depth":888,"text":317,"children":893},[894],{"id":348,"depth":895,"text":349},3,{"id":436,"depth":888,"text":437},{"id":525,"depth":888,"text":526},{"id":548,"depth":888,"text":549},{"id":575,"depth":888,"text":576},{"id":630,"depth":888,"text":631},{"id":693,"depth":888,"text":694},{"id":714,"depth":888,"text":715},{"id":757,"depth":888,"text":758},{"id":803,"depth":888,"text":804},{"id":830,"depth":888,"text":831},{"id":854,"depth":888,"text":855},"Collect a credential from somebody else — how to build the form, which of the two links to send, and how to read what comes back.","md",{},true,{"title":48,"description":907},"F_EiUqupNNGTICzQMaYvOgOkxmMxr5e4Xgmua_IO-wI",[914,916],{"title":44,"path":45,"stem":46,"description":915,"children":-1},"How the account passphrase, per-device activation and device linking let you reach your own encrypted shares from a second device — and what each way of replacing a key costs you.",{"title":52,"path":53,"stem":54,"description":917,"children":-1},"Someone sent you a CredenShare link asking for a password or key. What the link is, what happens to what you type, and who can read it.",1788908846768]