[{"data":1,"prerenderedAt":893},["ShallowReactive",2],{"navigation":3,"/guides/securepaste":258,"/guides/securepaste-surround":888},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":56,"api":260,"body":261,"description":882,"extension":883,"links":260,"meta":884,"navigation":885,"path":57,"seo":886,"stem":58,"__hash__":887},"docs/2.guides/8.securepaste.md",null,{"type":262,"value":263,"toc":867},"minimark",[264,268,273,289,292,324,328,343,346,352,355,367,370,374,380,383,386,390,396,402,407,414,418,434,472,483,487,493,498,505,509,512,531,537,548,552,567,570,596,599,715,721,727,732,738,742,745,811,821,835,839,842,850,860],[265,266,267],"p",{},"SecurePaste is a paste tool for text you should not put in a pastebin: config files, log excerpts, keys, blocks of code. It comes in two versions — a public one that needs no account, and a version inside the app for signed-in users.",[269,270,272],"h2",{"id":271},"the-public-tool","The public tool",[265,274,275,276,283,284,288],{},"Open ",[277,278,282],"a",{"href":279,"rel":280},"https://paste.credenshare.io",[281],"nofollow","paste.credenshare.io"," and you get an editor straight away. There is no sign-up, no sign-in and no plan check. Type or paste your content, press ",[285,286,287],"strong",{},"Create Paste",", and copy the link off the success screen.",[265,290,291],{},"Three things are worth knowing before you use it:",[293,294,295,307,318],"ul",{},[296,297,298,301,302,306],"li",{},[285,299,300],{},"It is free and sits outside every plan allowance."," An anonymous paste is not attributed to an account, so it never draws on the ",[277,303,305],{"href":304},"/api/errors-and-limits#share-allowance","share allowance"," of any plan — not even if you happen to be signed in to CredenShare in another tab. The public tool deliberately does not attach your session.",[296,308,309,312,313,317],{},[285,310,311],{},"The expiry is fixed at 24 hours."," It is stated on the page, not offered as a control. Choosing a lifetime is an account feature; see ",[277,314,316],{"href":315},"#the-signed-in-version","the signed-in version"," below.",[296,319,320,323],{},[285,321,322],{},"The link opens once by default."," That setting is a checkbox, so you can turn it off, but it starts on.",[269,325,327],{"id":326},"burn-after-reading","Burn after reading",[265,329,330,331,333,334,338,339,342],{},"The ",[285,332,327],{}," checkbox is on by default. With it on, the settings row reads ",[335,336,337],"code",{},"Opens once, expires in 24h","; with it off, ",[335,340,341],{},"Expires in 24 hours"," and the link keeps working until the expiry.",[265,344,345],{},"The success screen repeats the warning where it matters most:",[347,348,349],"blockquote",{},[265,350,351],{},"This link opens once. Opening it expires it — so don't open it yourself to check.",[265,353,354],{},"Take that literally. There is no preview, no owner's copy and no dashboard entry — opening the link to see whether it worked is the same act as the recipient opening it.",[356,357,360],"callout",{"color":358,"icon":359},"info","i-lucide-info",[265,361,362,363,366],{},"An ordinary link preview will ",[285,364,365],{},"not"," burn it. The decryption key lives in a part of the link that a plain HTTP fetch never receives, and a read is refused without a token derived from that key. An unfurler in Slack, or an email scanner that fetches the URL, gets nothing and consumes nothing.",[265,368,369],{},"The 24-hour expiry still applies underneath. It is the backstop for a link nobody ever opens.",[269,371,373],{"id":372},"password","Password",[265,375,376,377,379],{},"Tick ",[285,378,373],{}," and type one, and the recipient must enter it before the content will open.",[265,381,382],{},"The password is not a lock bolted on top of the ciphertext — it is folded into the key derivation, alongside the key in the link. A paste with a password cannot be read with the link alone, and cannot be read with the password alone. Send them through different channels.",[265,384,385],{},"On the public tool the password is available to everyone, because there is no plan to check. On the signed-in page it is gated — see below.",[269,387,389],{"id":388},"what-is-encrypted-and-what-is-not","What is encrypted, and what is not",[265,391,392,393,395],{},"The paste body is encrypted in your browser with AES-256-GCM before anything is sent. CredenShare stores ciphertext and cannot read it. That holds on every plan and on the public tool alike; see ",[277,394,251],{"href":252},".",[265,397,330,398,401],{},[285,399,400],{},"title is not encrypted",". The public tool says so under the field:",[347,403,404],{},[265,405,406],{},"Visible to CredenShare — keep secrets in the paste itself.",[265,408,409,410,413],{},"The title exists so a paste can be listed in a dashboard, which means the server has to be able to read it. Leave it blank and the paste is titled ",[335,411,412],{},"SecurePaste — \u003Ctoday's date>",". Never put the secret, the hostname, the account name or the customer's name in the title.",[269,415,417],{"id":416},"code-and-markdown","Code and Markdown",[265,419,420,421,424,425,428,429,424,432,395],{},"Two formats, chosen with the toggle above the editor. The public tool labels them ",[285,422,423],{},"Code"," and ",[285,426,427],{},"Markdown","; the signed-in page labels the same pair ",[285,430,431],{},"Source Code",[285,433,427],{},[435,436,437,450],"table",{},[438,439,440],"thead",{},[441,442,443,447],"tr",{},[444,445,446],"th",{},"Format",[444,448,449],{},"What it does",[451,452,453,463],"tbody",{},[441,454,455,460],{},[456,457,458],"td",{},[285,459,423],{},[456,461,462],{},"Line numbers in the editor, plus syntax highlighting for the languages the editor carries a highlighter for. A language picker sits beside the toggle.",[441,464,465,469],{},[456,466,467],{},[285,468,427],{},[456,470,471],{},"Markdown highlighting in the editor.",[265,473,474,475,478,479,482],{},"The language list is the same on both SecurePaste surfaces: 46 entries — ",[285,476,477],{},"Plain Text"," plus 45 languages and formats, from Bash and Dockerfile through to YAML. The language you pick becomes the field's label for the recipient — ",[335,480,481],{},"Code (javascript)",", for example — who sees the content in a read-only, line-numbered block. Markdown is delivered as Markdown source, not rendered into a formatted document.",[269,484,486],{"id":485},"download-filename","Download filename",[265,488,330,489,492],{},[285,490,491],{},"Filename"," field is optional, up to 255 characters. On the public tool its placeholder describes what it does:",[347,494,495],{},[265,496,497],{},"Filename (optional) — e.g. notes.md, adds a Download button for viewers",[265,499,500,501,504],{},"Set it and a download button appears beside the copy action on the recipient's view, tooltipped ",[335,502,503],{},"Download as \u003Cyour filename>",", saving the paste under that exact name. Leave it blank and there is no download button — the recipient copies the text instead. The filename travels inside the encrypted blob, so unlike the title it is not visible to us.",[269,506,508],{"id":507},"can-i-delete-a-paste","Can I delete a paste?",[265,510,511],{},"Not from anywhere you can reach. An anonymous paste has no owner, so there is no dashboard entry, no edit screen and no revoke button. Once it exists you have two options:",[513,514,515,525],"ol",{},[296,516,517,520,521,524],{},[285,518,519],{},"Open the link yourself."," If burn-after-reading was on, opening it spends the single view and the link is dead from that moment. Because a public paste is never marked owner-only, the view page also carries a ",[285,522,523],{},"Delete the Secure Share Forever"," button under the content — which is the only way to end a paste early when you turned burn-after-reading off.",[296,526,527,530],{},[285,528,529],{},"Wait."," After 24 hours it expires and the content is permanently deleted.",[265,532,533,534,395],{},"Anyone opening the link after either of those sees ",[285,535,536],{},"This share is no longer available",[356,538,541],{"color":539,"icon":540},"warning","i-lucide-alert-triangle",[265,542,543,544,547],{},"If you pasted a live credential to the wrong person, or into a channel you did not mean to, ",[285,545,546],{},"rotate the credential",". Do that first and treat the paste's expiry as housekeeping. You cannot prove the paste was not read before you got to it, and expiry does not undo a copy the recipient already made.",[269,549,551],{"id":550},"the-signed-in-version","The signed-in version",[265,553,554,555,558,559,562,563,566],{},"Signed-in users get SecurePaste inside the app, at ",[285,556,557],{},"app.credenshare.io/secure-paste",". It is the same editor with a settings panel unlocked — the ",[285,560,561],{},"Settings"," button opens a drawer headed ",[285,564,565],{},"Paste Settings"," — and it produces a normal share rather than an anonymous one.",[265,568,569],{},"What changes:",[293,571,572,578,584,590],{},[296,573,574,577],{},[285,575,576],{},"It counts against your plan's share allowance",", exactly like a share created from the dashboard. Free is 3 per day; Solo 50, Basic 100, Plus 200 and Business 500 per billing month; Enterprise unlimited. Expired and deleted pastes still count.",[296,579,580,583],{},[285,581,582],{},"It appears in your Shares list",", so you can see it, and end it without opening it. The list's delete action expires and scrubs the paste; the record moves to Expired Shares.",[296,585,586,589],{},[285,587,588],{},"You choose the expiry."," Presets of 1h, 24h, 3d, 7d, 14d and 30d, or the slider — hours up to 24, days up to 31, or months up to 12. The default is 24 hours.",[296,591,592,595],{},[285,593,594],{},"A Team workspace is honoured."," Create a paste with a team selected and it belongs to the team, is judged against the team's plan, and appears in the team's list.",[265,597,598],{},"The settings panel adds:",[435,600,601,613],{},[438,602,603],{},[441,604,605,608,610],{},[444,606,607],{},"Setting",[444,609,449],{},[444,611,612],{},"Plan",[451,614,615,628,640,652,664,676,688,703],{},[441,616,617,622,625],{},[456,618,619],{},[285,620,621],{},"Max Views",[456,623,624],{},"Caps how many opens the paste allows, then destroys it. Off means unlimited; switching it on defaults to 10. Set it to 1 for the public tool's burn-after-reading behaviour.",[456,626,627],{},"All plans",[441,629,630,634,637],{},[456,631,632],{},[285,633,373],{},[456,635,636],{},"A passcode the recipient must enter. Folded into the encryption, as on the public tool.",[456,638,639],{},"Solo and above",[441,641,642,647,650],{},[456,643,644],{},[285,645,646],{},"Failed attempts",[456,648,649],{},"Destroys the paste after 1–10 wrong password entries. Only offered once a password is set.",[456,651,639],{},[441,653,654,659,662],{},[456,655,656],{},[285,657,658],{},"Timed View",[456,660,661],{},"Hides the content again 15–180 seconds after it is unlocked.",[456,663,627],{},[441,665,666,671,674],{},[456,667,668],{},[285,669,670],{},"Secure View Prompt",[456,672,673],{},"A Markdown message, up to 500 characters, shown before the content unlocks.",[456,675,639],{},[441,677,678,683,686],{},[456,679,680],{},[285,681,682],{},"Require Login",[456,684,685],{},"Only signed-in CredenShare accounts can view. Each view is attributed to a username rather than an IP.",[456,687,627],{},[441,689,690,695,701],{},[456,691,692],{},[285,693,694],{},"Require MFA",[456,696,697,698,700],{},"The viewer's account must have two-factor authentication on. Needs ",[285,699,682],{},"; the switch is disabled until that is on.",[456,702,627],{},[441,704,705,710,713],{},[456,706,707],{},[285,708,709],{},"Only Owner Delete",[456,711,712],{},"Off by default, which is what puts the self-destruct button on the recipient's screen. Turn it on so only you can destroy the paste.",[456,714,627],{},[265,716,717,718,720],{},"A gated row shows a plan lock and its switch is disabled. A Free account has no ",[285,719,373],{}," on this page — the one setting where the public tool is less restricted than the signed-in one.",[265,722,723,726],{},[285,724,725],{},"Create Another"," clears everything you typed and every secret, while the policy settings — expiry, view limits, login and MFA requirements — deliberately carry over so you can create a batch under one policy. The success screen says so:",[347,728,729],{},[265,730,731],{},"Creating another paste keeps your expiry and protection settings. The content, title, filename, description and any passcode are always cleared.",[265,733,734,737],{},[285,735,736],{},"Reset",", at the top of the Paste Settings drawer, drops the carried-over settings too.",[269,739,741],{"id":740},"hostnames","Hostnames",[265,743,744],{},"Four hostnames turn up around SecurePaste. They are not interchangeable.",[435,746,747,757],{},[438,748,749],{},[441,750,751,754],{},[444,752,753],{},"Host",[444,755,756],{},"What it serves",[451,758,759,768,781,798],{},[441,760,761,765],{},[456,762,763],{},[335,764,282],{},[456,766,767],{},"The public SecurePaste editor. This is the canonical address, and the one to bookmark or send to someone who needs to create a paste.",[441,769,770,775],{},[456,771,772],{},[335,773,774],{},"paste.crs.sh",[456,776,777,778,780],{},"The same editor on the short domain. Identical content; it declares ",[335,779,282],{}," as canonical.",[441,782,783,788],{},[456,784,785],{},[335,786,787],{},"crs.sh",[456,789,790,791,794,795,797],{},"Where finished links live. A SecurePaste link is ",[335,792,793],{},"https://crs.sh/\u003Cshort code>#\u003Ckey>",". This host serves recipient pages only — ",[335,796,787],{}," on its own redirects to the app.",[441,799,800,805],{},[456,801,802],{},[335,803,804],{},"app.credenshare.io",[456,806,807,808,395],{},"The app, including the signed-in SecurePaste at ",[335,809,810],{},"/secure-paste",[265,812,813,814,817,818,395],{},"The legacy path ",[335,815,816],{},"app.credenshare.io/secure-paste-public"," still resolves; it redirects to ",[335,819,820],{},"https://paste.credenshare.io/",[356,822,823],{"color":358,"icon":359},[265,824,825,826,828,829,831,832,395],{},"The link you send is a ",[335,827,787],{}," link, not a ",[335,830,282],{}," one. That is expected — you create on the paste host and the recipient opens on the short one. A link that arrived incomplete has lost its key and can never be decrypted; see ",[277,833,834],{"href":124},"Link not working",[269,836,838],{"id":837},"if-a-paste-will-not-create","If a paste will not create",[265,840,841],{},"The public tool runs a captcha and a proof-of-work check before it will accept a paste, because it is an unauthenticated endpoint. When the captcha fails you get:",[347,843,844,847],{},[265,845,846],{},"Verification Failed",[265,848,849],{},"Captcha verification failed. Please refresh and try again.",[265,851,852,853,855,856,859],{},"Refresh the page and try once more. Pressing ",[285,854,287],{}," with an empty editor gives ",[285,857,858],{},"Please enter some content"," instead.",[861,862],"docs-cta",{"buttonLabel":863,"buttonTo":864,"description":865,"title":866},"View Plans & Pricing","https://credenshare.io/pricing","Signing in adds expiry control, view limits and a list of everything you have sent. Paid plans add an access trail.","Need pastes you can manage?",{"title":868,"searchDepth":869,"depth":870,"links":871},"",1,2,[872,873,874,875,876,877,878,879,880,881],{"id":271,"depth":870,"text":272},{"id":326,"depth":870,"text":327},{"id":372,"depth":870,"text":373},{"id":388,"depth":870,"text":389},{"id":416,"depth":870,"text":417},{"id":485,"depth":870,"text":486},{"id":507,"depth":870,"text":508},{"id":550,"depth":870,"text":551},{"id":740,"depth":870,"text":741},{"id":837,"depth":870,"text":838},"The public paste tool at paste.credenshare.io — no account, no plan allowance, a fixed 24-hour expiry and a link that opens once by default. Plus the signed-in version and what it adds.","md",{},true,{"title":56,"description":882},"MihebCZmqkD-vMyMTmSFGGVPAzGCMoBRsvEilwHTPuA",[889,891],{"title":52,"path":53,"stem":54,"description":890,"children":-1},"Someone sent you a CredenShare link asking for a password or key. What the link is, what happens to what you type, and who can read it.",{"title":60,"path":61,"stem":62,"description":892,"children":-1},"Every email and in-app alert CredenShare produces, who receives each one, what you can turn off, and the events that notify nobody.",1788908846768]