Skip to content
CredenShare
Teams

Joining a Team

What the invitation looks like, how to accept it before it expires, and what changes for your account once you are a member.

Someone has invited you to their CredenShare team. This page is written for the person being invited.

The invitation

An owner or admin adds your email address, and CredenShare emails you. The message names the team, gives the team owner's email address — the owner, not necessarily the admin who added you — states when the invitation expires, and carries the acceptance link:

https://app.credenshare.io/team-invite-confirm/?teamId=<team>&token=<token>

The token is valid for 24 hours from the moment the invitation was sent. There is no in-app inbox of pending invitations — the emailed link is the only way to accept.

Accepting

  1. Sign in at app.credenshare.io using the address the invitation was sent to.
  2. Open the link from the email.
  3. The page confirms on its own. You will see Confirming invitation..., then Welcome to the team! and the team's name.
  4. Select Go to My Teams.

Two things go wrong often enough to be worth naming.

You must be signed in as the invited address. The link does not carry your email; the app supplies whichever account you are signed in as. Accepting while signed in as a different account fails with Unable to confirm user invitation. Sign out, sign in as the invited address, then open the link again.

Copy the whole link. If it is truncated, the page stops with Invalid invitation link. Missing required parameters. before contacting the server.

Until you accept, you cannot open the team. Attempting to reach it returns You do not have permission to perform this action on this team. That is the invitation still being pending, not a fault.

If the invitation has expired

Past 24 hours, accepting fails with Confirmation token is invalid or expired. Ask a team owner or admin to resend it — they have a resend action next to your pending entry in the team's Members list.

A resend sent while the original is still valid re-sends the same link, so both emails work. A resend after it has lapsed issues a new link with a fresh 24 hours, and the old one stops working.

If you did not already have a CredenShare account

The invitation creates the account for you, with the email address already verified. The email carries a second link alongside the acceptance link: a CredenShare share titled Your login information, holding your email address and a generated password.

That share expires five minutes after you first open it. Open it once, copy the password straight away, and sign in. Then change the password under Account → Security → Change Password.

Accept the invitation as well — creating the account and joining the team are two separate steps, and only the acceptance link does the second one.

What changes once you join

You now have two workspaces: Personal, and the team. The switcher sits at the top of the sidebar, under the logo, and shows the active one; the team's own page has a Use Context button that does the same thing. Personal is the default, and nothing about your personal workspace changes when you join.

Which workspace is active decides where a new share, secure request or paste is filed, and whose allowance it draws on.

Created in PersonalCreated in the team workspace
Filed underYour own accountThe team
Counts againstYour own plan's allowanceThe team owner's allowance, shared with everyone in the team
Visible to team adminsNoYes

Your entitlements in the team come from the organisation, not from a plan of your own. A seat member has no subscription — you occupy one of the owner's seats — so the server resolves the team's plan through the team owner's subscription every time you act in the team workspace. On a Business team, a share you create in the team workspace is judged against Business limits even if your personal account is on Free.

The pooled allowance is genuinely pooled: everyone's team shares come out of one figure, and expired and deleted shares stay in the tally. See Plans and share allowance for how the window is worked out.

While the team workspace is active, the interface gates on the team's plan rather than your own: a confirmed member of any role can read the team's entitlements and its share usage. Billing itself stays with the owner — the renewal date, auto-renew, pending plan changes and add-ons are withheld from members. If a feature the team's plan includes does not appear for you, ask the team owner rather than upgrading your own account.

Automatic logout

A team owner can set a maximum inactivity timeout for everyone in the team. Your effective timeout is the shorter of that limit and your own setting under Account → Security → Automatic Logout; when it elapses you are signed out. Setting a longer personal value does not override the team's limit.

What your team can and cannot see

  • Team owners and admins see every share and secure request created in the team workspace, with an Owner column showing who created each one. Other members see only their own items, and that scoping is enforced on the server rather than hidden in the interface.
  • Your Personal workspace is never included. Team lists only ever cover items attributed to that team.
  • A share's access history stays with its creator. Views, timestamps and IP addresses are readable only by the account that created the share — a team admin browsing the team's list cannot open your access trail.
  • Seeing an item is not reading it. Shares are encrypted in your browser and the key travels in the link, so what an admin sees is metadata: title, short code, views, created and expiry dates. The exception is a team using zero-knowledge custody, below.

Leaving

There is no self-serve way to leave a team. Ask a team owner or admin to remove you; only they can. Removing you does not delete the shares you created in the team workspace, and it does not touch your personal account or your Personal workspace.

If the team uses zero-knowledge custody

Zero-knowledge custody is included with Business and Enterprise plans, and it is what lets team owners and admins open the team's encrypted content. Holding a seat on such a team is enough — you do not need a Business plan of your own — but only once you have accepted: a pending invitation confers nothing.

Joining is a two-step ceremony, and the second step is not yours.

  1. Enrol. Go to Account → Security → Zero-knowledge custody and select Set up now. A passphrase is generated for you and shown once. Save it — nobody can recover it for you.
  2. Wait for a grant. A team admin who holds the team key wraps it to your new account key. Until they do, the team's page tells you: A team admin has not granted you access to this team's encrypted content yet. You can see that items exist but cannot open them until they do.

The order matters. Nothing can be wrapped to you before you have enrolled, so an admin cannot grant you access first and have you enrol afterwards.

Full detail is in Zero-knowledge for teams.

Still stuck

Email support@credenshare.io with the team name and the address the invitation was sent to.