[{"data":1,"prerenderedAt":986},["ShallowReactive",2],{"navigation":3,"/sdks":258,"/sdks-surround":981},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":220,"api":260,"body":261,"description":976,"extension":977,"links":260,"meta":978,"navigation":379,"path":221,"seo":979,"stem":222,"__hash__":980},"docs/7.sdks/0.index.md",null,{"type":262,"value":263,"toc":969},"minimark",[264,284,291,391,397,402,483,490,509,513,594,598,601,667,671,674,909,915,918,923,933,937,940,943,946,965],[265,266,267,268,272,273,272,276,279,280,283],"p",{},"There are four official clients: ",[269,270,271],"a",{"href":227},"Node",", ",[269,274,275],{"href":231},"Python",[269,277,278],{"href":235},"Go"," and ",[269,281,282],{"href":239},"Rust",".",[265,285,286,287,290],{},"They are not thin wrappers around the REST API. The ",[269,288,289],{"href":133},"API"," accepts ciphertext and returns a short code, which means calling it directly obliges you to implement AES-256-GCM, HKDF, the envelope layout and the fragment encoding correctly before your first share works. Each SDK does that part, so the call you write takes plaintext fields and hands back a finished link:",[292,293,298],"pre",{"className":294,"code":295,"language":296,"meta":297,"style":297},"language-ts shiki shiki-themes github-light github-dark github-dark","const share = await crs.shares.create({\n  title: 'Staging deploy credentials',\n  fields: [{ key: 'Password', value: 'correct horse', type: 'password' }],\n})\n\nshare.link // https://crs.sh/aB3dEf12#1xK9...\n","ts","",[299,300,301,331,344,368,374,381],"code",{"__ignoreMap":297},[302,303,306,310,314,317,320,324,328],"span",{"class":304,"line":305},"line",1,[302,307,309],{"class":308},"so5gQ","const",[302,311,313],{"class":312},"suiK_"," share",[302,315,316],{"class":308}," =",[302,318,319],{"class":308}," await",[302,321,323],{"class":322},"slsVL"," crs.shares.",[302,325,327],{"class":326},"shcOC","create",[302,329,330],{"class":322},"({\n",[302,332,334,337,341],{"class":304,"line":333},2,[302,335,336],{"class":322},"  title: ",[302,338,340],{"class":339},"sfrk1","'Staging deploy credentials'",[302,342,343],{"class":322},",\n",[302,345,347,350,353,356,359,362,365],{"class":304,"line":346},3,[302,348,349],{"class":322},"  fields: [{ key: ",[302,351,352],{"class":339},"'Password'",[302,354,355],{"class":322},", value: ",[302,357,358],{"class":339},"'correct horse'",[302,360,361],{"class":322},", type: ",[302,363,364],{"class":339},"'password'",[302,366,367],{"class":322}," }],\n",[302,369,371],{"class":304,"line":370},4,[302,372,373],{"class":322},"})\n",[302,375,377],{"class":304,"line":376},5,[302,378,380],{"emptyLinePlaceholder":379},true,"\n",[302,382,384,387],{"class":304,"line":383},6,[302,385,386],{"class":322},"share.link ",[302,388,390],{"class":389},"sCsY4","// https://crs.sh/aB3dEf12#1xK9...\n",[265,392,393,394,396],{},"If you are working in one of these four languages, this is the path we would rather you took. ",[269,395,164],{"href":165}," remains the reference for anyone implementing the wire format from scratch.",[398,399,401],"h2",{"id":400},"installing","Installing",[403,404,405,421],"table",{},[406,407,408],"thead",{},[409,410,411,415,418],"tr",{},[412,413,414],"th",{},"Language",[412,416,417],{},"Package",[412,419,420],{},"Install",[422,423,424,440,455,469],"tbody",{},[409,425,426,429,435],{},[427,428,271],"td",{},[427,430,431,434],{},[299,432,433],{},"@credenshare/sdk"," on npm",[427,436,437],{},[299,438,439],{},"npm install @credenshare/sdk",[409,441,442,444,450],{},[427,443,275],{},[427,445,446,449],{},[299,447,448],{},"credenshare"," on PyPI",[427,451,452],{},[299,453,454],{},"pip install credenshare",[409,456,457,459,464],{},[427,458,278],{},[427,460,461],{},[299,462,463],{},"github.com/CredenShare/credenshare-sdk-go",[427,465,466],{},[299,467,468],{},"go get github.com/CredenShare/credenshare-sdk-go",[409,470,471,473,478],{},[427,472,282],{},[427,474,475,477],{},[299,476,448],{}," on crates.io",[427,479,480],{},[299,481,482],{},"cargo add credenshare",[265,484,485,486,489],{},"All four are published, and each repository is tagged and carries a GitHub Release at the same version. The commands above are unpinned on purpose — the registry resolves the current release, and a ",[299,487,488],{},"0.x"," line moves often enough that a version written into documentation is stale before you read it. Pin in your own manifest, not from here.",[491,492,495],"callout",{"color":493,"icon":494},"info","i-lucide-info",[265,496,497,504,505,508],{},[498,499,500,501,503],"strong",{},"These are ",[299,502,488],{}," releases."," The surface is free to change at any minor bump, and it has: recent releases altered the ",[299,506,507],{},"Field"," type in two languages and split one error class into three. Read the changelog in the repository before upgrading, and pin a version you have tested.",[398,510,512],{"id":511},"what-every-client-does","What every client does",[514,515,516,523,529,535,544,550,564,570,580,586],"ul",{},[517,518,519,522],"li",{},[498,520,521],{},"Encrypts before sending."," A fresh 32-byte content key per share, AES-256-GCM under a key derived with HKDF. The content key never goes to CredenShare.",[517,524,525,528],{},[498,526,527],{},"Assembles the link",", including the fragment that carries the key. That link is the secret.",[517,530,531,534],{},[498,532,533],{},"Derives the access token"," from the content key, so the server can gate a read without being able to decrypt.",[517,536,537,543],{},[498,538,539,540],{},"Sends an ",[299,541,542],{},"Idempotency-Key"," on every create.",[517,545,546,549],{},[498,547,548],{},"Verifies webhook signatures",", including during the 24-hour rotation window when deliveries carry two.",[517,551,552,555,556,559,560,563],{},[498,553,554],{},"Parses the credential, and derives the custody public key from it."," Each client exposes a ",[299,557,558],{},"Credential"," type over the three-part ",[299,561,562],{},"crs_sk_live_\u003CkeyId>.\u003CauthSecret>[.\u003CcustodySecret>]"," form, and can derive the custody public key locally — the value you register so an API-created share can be re-read later.",[517,565,566,569],{},[498,567,568],{},"Refuses to transmit the custody secret."," The third part never reaches the wire. The bearer value is assembled from the parsed parts rather than by trimming the string, and asserted again at the request boundary.",[517,571,572,575,576,579],{},[498,573,574],{},"Raises a dedicated error on a 429",", exposing ",[299,577,578],{},"Retry-After"," as seconds. Node reads both forms the header can take — delta-seconds and an HTTP-date converted to whole seconds from now. Python, Go and Rust parse digits only, so an HTTP-date leaves the value unset there. None of them sleep or retry on a 429 for you.",[517,581,582,585],{},[498,583,584],{},"Wraps the content key for account custody, on request."," Node, Python and Go take a custody flag on create: the client wraps the content key to the custody public key derived from your credential's third part, so the share stays readable from your dashboard and not only from its link. Rust does not offer it yet — a Rust-created share is link-only.",[517,587,588,591,592,283],{},[498,589,590],{},"Ships the conformance vectors inside the installed artifact",", so you can check the exact build you installed. See ",[269,593,242],{"href":243},[398,595,597],{"id":596},"what-none-of-them-do","What none of them do",[265,599,600],{},"This list is exhaustive as of today, and worth reading before you plan around a capability.",[514,602,603,619,633,647,657],{},[517,604,605,608,609,272,612,279,615,618],{},[498,606,607],{},"No reads."," ",[299,610,611],{},"readLink",[299,613,614],{},"read_link",[299,616,617],{},"ReadLink"," exist and always fail. The recipient path is guarded by proof-of-work and captcha checks that bearer auth would skip, so exposing it to a credential would turn the API into an enumeration bypass. Open the link in a browser.",[517,620,621,624,625,629,630,283],{},[498,622,623],{},"No credential or webhook management."," Nothing mints, rotates, lists or revokes an API key or a signing secret, and nothing manages a webhook endpoint. Rotation is only ever ",[626,627,628],"em",{},"consumed",", by passing several secrets to ",[299,631,632],{},"verify",[517,634,635,638,639,642,643,646],{},[498,636,637],{},"No typed webhook events."," There is no ",[299,640,641],{},"constructEvent","-style parse-and-verify helper, no event-type constants, no delivery listing and no replay. You verify the raw body, then parse it yourself. The ",[269,644,645],{"href":201},"event list"," is the reference.",[517,648,649,652,653,656],{},[498,650,651],{},"No MCP."," See ",[269,654,655],{"href":213},"MCP"," — it is the only programmatic route to secure requests and browser-assisted shares.",[517,658,659,662,663,666],{},[498,660,661],{},"Shares only."," All four speak ",[299,664,665],{},"/shares",". Pastes, secure requests, files, teams, organizations, seats, subscriptions and audit logs are not covered.",[398,668,670],{"id":669},"choosing-between-them","Choosing between them",[265,672,673],{},"They implement the same specification and interoperate — content one writes, another reads. The differences that would actually change your choice:",[403,675,676,690],{},[406,677,678],{},[409,679,680,682,684,686,688],{},[412,681],{},[412,683,271],{},[412,685,275],{},[412,687,278],{},[412,689,282],{},[422,691,692,709,740,755,775,800,813,836,849,862,876,894],{},[409,693,694,697,700,703,706],{},[427,695,696],{},"Runtime floor",[427,698,699],{},"Node 20",[427,701,702],{},"Python 3.9",[427,704,705],{},"Go 1.21",[427,707,708],{},"Rust 1.88",[409,710,711,714,717,725,728],{},[427,712,713],{},"Runtime dependencies",[427,715,716],{},"none",[427,718,719,272,722],{},[299,720,721],{},"cryptography",[299,723,724],{},"httpx",[427,726,727],{},"none (stdlib)",[427,729,730,731,272,734,272,737],{},"RustCrypto, ",[299,732,733],{},"serde",[299,735,736],{},"base64",[299,738,739],{},"ureq",[409,741,742,745,748,751,753],{},[427,743,744],{},"Also runs on",[427,746,747],{},"Deno, Bun, Workers, browsers",[427,749,750],{},"—",[427,752,750],{},[427,754,750],{},[409,756,757,760,763,766,773],{},[427,758,759],{},"Asynchronous",[427,761,762],{},"yes",[427,764,765],{},"no",[427,767,768,769,772],{},"no (",[299,770,771],{},"context","-aware)",[427,774,765],{},[409,776,777,780,785,790,795],{},[427,778,779],{},"Walks every page for you",[427,781,782],{},[299,783,784],{},"iterateAll",[427,786,787],{},[299,788,789],{},"iter_all",[427,791,792],{},[299,793,794],{},"IterateShares",[427,796,797],{},[299,798,799],{},"for_each_share",[409,801,802,805,807,809,811],{},[427,803,804],{},"Bounded — the walk cannot loop forever",[427,806,762],{},[427,808,762],{},[427,810,762],{},[427,812,762],{},[409,814,815,818,824,829,834],{},[427,816,817],{},"Testing seam",[427,819,820,821],{},"injectable ",[299,822,823],{},"fetch",[427,825,826,828],{},[299,827,724],{}," transport",[427,830,831],{},[299,832,833],{},"*http.Client",[427,835,716],{},[409,837,838,841,843,845,847],{},[427,839,840],{},"Extra field members preserved",[427,842,762],{},[427,844,762],{},[427,846,762],{},[427,848,762],{},[409,850,851,854,856,858,860],{},[427,852,853],{},"Short code cannot escape the path",[427,855,762],{},[427,857,762],{},[427,859,762],{},[427,861,762],{},[409,863,864,867,870,872,874],{},[427,865,866],{},"Rejects a malformed fragment",[427,868,869],{},"mostly",[427,871,762],{},[427,873,762],{},[427,875,762],{},[409,877,878,881,884,886,889],{},[427,879,880],{},"Crypto compiles without the HTTP stack",[427,882,883],{},"n/a — no HTTP dependency",[427,885,765],{},[427,887,888],{},"n/a — stdlib",[427,890,891],{},[299,892,893],{},"default-features = false",[409,895,896,899,901,903,905],{},[427,897,898],{},"Custody wrap on create",[427,900,762],{},[427,902,762],{},[427,904,762],{},[427,906,907],{},[498,908,765],{},[265,910,911,912,914],{},"The one remaining ",[498,913,765],{}," is a capability Rust has not implemented, not a bug.",[265,916,917],{},"Every client's page-walking helper now refuses a response that echoes a page number other than the one requested, because a server that does that makes progress unobservable. Node, Python and Rust additionally stop at a hard ceiling of 100,000 pages; Go stops on the first short page or the reported total instead, and carries no absolute cap.",[265,919,920,921,914],{},"The five defects that used to sit in that table are fixed: Go and Rust preserve extra field members, Python percent-encodes the short code and Rust refuses one that is not opaque, and Python's fragment decode validates the alphabet. None of them ever affected the cryptography — every client still reproduces the conformance vectors exactly. The one remaining ",[498,922,765],{},[265,924,925,926,279,929,932],{},"The fragment row is still a spectrum rather than a pass/fail: Node accepts ",[299,927,928],{},"+",[299,930,931],{},"/"," — not base64url characters — which the other three reject. Only Go, Python and Rust reject strictly.",[398,934,936],{"id":935},"the-specification-is-what-binds-them","The specification is what binds them",[265,938,939],{},"The four SDKs and the CredenShare application share no code. That is deliberate: a package the production application depended on would be a supply-chain surface, and for a product whose claim is that we cannot read your data, it is the wrong surface to open.",[265,941,942],{},"The cost of that decision is drift, and drift here does not produce a test failure — it produces content that can never be decrypted. What holds the implementations together is the specification plus a fixture every one of them must reproduce, byte for byte. If a client and the specification disagree, the client is wrong.",[944,945],"hr",{},[491,947,949],{"color":493,"icon":948},"i-lucide-arrow-right",[265,950,951,952,958,959,964],{},"All four clients work on every plan, free included. ",[269,953,957],{"href":954,"rel":955},"https://credenshare.io/pricing",[956],"nofollow","Create an account"," to mint an API key, or ",[269,960,963],{"href":961,"rel":962},"https://credenshare.io/enterprise",[956],"talk to us"," about volume and team seats.",[966,967,968],"style",{},"html pre.shiki code .so5gQ, html code.shiki .so5gQ{--shiki-light:#D73A49;--shiki-default:#F97583;--shiki-dark:#F97583}html pre.shiki code .suiK_, html code.shiki .suiK_{--shiki-light:#005CC5;--shiki-default:#79B8FF;--shiki-dark:#79B8FF}html pre.shiki code .slsVL, html code.shiki .slsVL{--shiki-light:#24292E;--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8}html pre.shiki code .shcOC, html code.shiki .shcOC{--shiki-light:#6F42C1;--shiki-default:#B392F0;--shiki-dark:#B392F0}html pre.shiki code .sfrk1, html code.shiki .sfrk1{--shiki-light:#032F62;--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF}html pre.shiki code .sCsY4, html code.shiki .sCsY4{--shiki-light:#6A737D;--shiki-default:#6A737D;--shiki-dark:#6A737D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":297,"searchDepth":305,"depth":333,"links":970},[971,972,973,974,975],{"id":400,"depth":333,"text":401},{"id":511,"depth":333,"text":512},{"id":596,"depth":333,"text":597},{"id":669,"depth":333,"text":670},{"id":935,"depth":333,"text":936},"Official CredenShare clients for Node, Python, Go and Rust — they perform the encryption, so you pass plaintext and get back a link.","md",{},{"title":220,"description":976},"ueAwWNTzM0Ftqduoun5b09jZYhUlDvOBdbZOXVDEQT0",[982,984],{"title":216,"path":217,"stem":218,"description":983,"children":-1},"The error envelope, every error code you can hit, request-rate limits, and what an authentication failure actually looks like.",{"title":226,"path":227,"stem":228,"description":985,"children":-1},"The official TypeScript client — encrypts locally, assembles the link, verifies webhooks. ESM only, no runtime dependencies.",1788908850674]