[{"data":1,"prerenderedAt":864},["ShallowReactive",2],{"navigation":3,"/teams/zero-knowledge-for-teams":258,"/teams/zero-knowledge-for-teams-surround":859},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":112,"api":260,"body":261,"description":853,"extension":854,"links":260,"meta":855,"navigation":856,"path":113,"seo":857,"stem":114,"__hash__":858},"docs/4.teams/6.zero-knowledge-for-teams.md",null,{"type":262,"value":263,"toc":839},"minimark",[264,273,278,281,284,301,305,323,331,335,343,416,422,429,432,436,439,442,465,468,472,479,486,573,591,595,605,614,617,621,630,639,642,646,652,655,733,738,741,763,766,770,823,826],[265,266,267,268,272],"p",{},"Rolling zero-knowledge custody out to a team is a ceremony between two people, and the steps only work in one order. This page is the team side; ",[269,270,271],"a",{"href":45},"Zero-knowledge custody"," covers setting it up for yourself.",[274,275,277],"h2",{"id":276},"what-a-team-key-is-for","What a team key is for",[265,279,280],{},"Without a team key, content can be reopened from the app only by whoever created it — a colleague's encrypted share is opaque to everyone else in the app, including the team's owner. (Anyone holding the link can still open it; the link carries the key.) A team key changes that: team content is wrapped to a single keypair for the whole team, so access is granted once per member instead of once per item, and adding or removing a member never re-encrypts anything.",[265,282,283],{},"The team key is generated in an admin's browser. CredenShare never holds it, which is why every step below has to be performed by a person rather than by us.",[265,285,286,287,291,292,296,297,300],{},"Zero-knowledge custody requires the ",[288,289,290],"code",{},"zero_knowledge"," entitlement, which is on ",[293,294,295],"strong",{},"Business and Enterprise"," only. The panel resolves that from the ",[293,298,299],{},"team's"," subscription, not from the admin's personal one — so a team on Business gives its admins the feature even if they hold no plan of their own. A seat member with no subscription can set up a passphrase for the same reason: the seat carries the entitlement.",[274,302,304],{"id":303},"where-it-lives","Where it lives",[265,306,307,310,311,314,315,318,319,322],{},[293,308,309],{},"My Teams"," → the team → the ",[293,312,313],{},"Zero-knowledge for this team"," panel at the foot of the team page. The heading carries an ",[293,316,317],{},"On"," or ",[293,320,321],{},"Off"," badge.",[265,324,325,326,330],{},"Every member sees the panel. Only an owner or admin sees the controls. While the team key is off, a member who is not an admin reads ",[327,328,329],"em",{},"\"Only a team admin or owner can enable this.\""," where the button would be — unless they have no passphrase of their own, in which case the passphrase notice takes that spot instead. Once the team key is on, a plain member sees no controls at all.",[274,332,334],{"id":333},"the-order","The order",[336,337,340],"callout",{"color":338,"icon":339},"warning","i-lucide-alert-triangle",[265,341,342],{},"Steps 1 and 2 are the admin's, step 3 is each member's, step 4 is the admin's again. Out of order, the admin walks into a member who cannot proceed: there is nothing to wrap the team key to until that member holds a key of their own.",[344,345,346,363,381,395],"ol",{},[347,348,349,352,353,355,356,358,359,362],"li",{},[293,350,351],{},"The admin sets up their own passphrase."," In ",[293,354,64],{}," → ",[293,357,246],{},". A team key can only be created and handed out by someone who holds their own key. Skip this and the panel replies ",[327,360,361],{},"\"You need your own encryption passphrase first — set it up in Account → Security.\""," and offers no button.",[347,364,365,368,369,372,373,376,377,380],{},[293,366,367],{},"The admin turns it on for the team."," ",[293,370,371],{},"Enable for this team",", on a device that is activated — the admin's own grant is created in the same request, and a team key nobody holds could never be granted from. If the device is locked, the ",[293,374,375],{},"Activate this device"," dialog opens first; activating reloads the panel rather than resuming the action, so press the button again afterwards. On success: ",[327,378,379],{},"\"Zero-knowledge enabled for this team\"",".",[347,382,383,386,387,390,391,394],{},[293,384,385],{},"Each member sets up their own passphrase."," Until a member does, they sit in the panel under ",[293,388,389],{},"Waiting for the member",", annotated ",[327,392,393],{},"\"needs to set up their passphrase\"",", with no button beside them. That is not a fault to report; it is the queue saying whose move it is.",[347,396,397,400,401,404,405,408,409,412,413,415],{},[293,398,399],{},"The admin grants each member access."," Members who have enrolled move to ",[293,402,403],{},"Waiting for you to grant access",", each with a ",[293,406,407],{},"Grant access"," button. Granting means unwrapping the team key, so it also requires an activated device — otherwise the panel shows ",[327,410,411],{},"\"Activate this device to grant access — granting requires the team key, which only your own passphrase can unlock.\""," Activating from there reloads the panel, so press ",[293,414,407],{}," again.",[265,417,418,419],{},"Once everyone is through, the panel reads ",[327,420,421],{},"\"Every member has access.\"",[265,423,424,425,428],{},"Between steps 2 and 4, members can see that team items exist but cannot open them. They get the notice ",[327,426,427],{},"\"A team admin has not granted you access to this team's encrypted content yet. You can see that items exist but cannot open them until they do.\""," That is expected, and only an admin can clear it.",[265,430,431],{},"An invitation that has not been accepted cannot be granted. Membership has to be confirmed first.",[274,433,435],{"id":434},"what-counts-as-team-content","What counts as team content",[265,437,438],{},"A share, paste or secure request is team content when it was created while that team was selected in the team switcher. Personal-context items are never wrapped to a team key, whoever created them.",[265,440,441],{},"Three conditions all have to hold at creation time for a team wrap to exist:",[443,444,445,452,458],"ul",{},[347,446,447,448,451],{},"the team key was ",[293,449,450],{},"enabled",";",[347,453,454,455,451],{},"the item was created ",[293,456,457],{},"in the team's context",[347,459,460,461,464],{},"the creator had their ",[293,462,463],{},"own passphrase set up",", on a plan that included custody.",[265,466,467],{},"If any one of them was false, no team wrap was written, and nothing done afterwards goes back and fills it in.",[274,469,471],{"id":470},"enabling-is-forward-only","Enabling is forward-only",[265,473,474,475,478],{},"Turning the team key on wraps ",[293,476,477],{},"new"," team content only. Everything created before is untouched and keeps working exactly as it did.",[265,480,481,482,485],{},"Turning it off is the mirror image and destroys nothing: ",[327,483,484],{},"\"Existing team content still opens. New content will not be added to the team key.\""," The keypair stays in place, every existing wrap keeps being served, and members keep their grants. Turning it back on resumes wrapping new content, and nobody needs re-granting.",[487,488,489,508],"table",{},[490,491,492],"thead",{},[493,494,495,499,502,505],"tr",{},[496,497,498],"th",{},"Action",[496,500,501],{},"Existing team content",[496,503,504],{},"New team content",[496,506,507],{},"Member grants",[509,510,511,527,543,557],"tbody",{},[493,512,513,518,521,524],{},[514,515,516],"td",{},[293,517,371],{},[514,519,520],{},"Untouched, no team wrap added",[514,522,523],{},"Wrapped to the team key",[514,525,526],{},"Admin's own grant created",[493,528,529,534,537,540],{},[514,530,531],{},[293,532,533],{},"Turn off for this team",[514,535,536],{},"Keeps opening",[514,538,539],{},"Not wrapped",[514,541,542],{},"Kept",[493,544,545,550,552,555],{},[514,546,547],{},[293,548,549],{},"Turn back on for this team",[514,551,536],{},[514,553,554],{},"Wrapped again",[514,556,542],{},[493,558,559,564,567,570],{},[514,560,561],{},[293,562,563],{},"Reset this team's key",[514,565,566],{},"Stops opening for the team",[514,568,569],{},"Wrapped to the new key",[514,571,572],{},"All destroyed; the admin's own is re-created",[265,574,575,576,579,580,583,584,587,588,380],{},"Enabling is refused on a plan without the entitlement — ",[327,577,578],{},"\"Zero-knowledge custody requires a Business or Enterprise plan\"",". Turning it ",[293,581,582],{},"off"," is deliberately not gated, so a team whose plan has lapsed is never trapped with a switch it cannot flip. Enabling a team that already has a key gives ",[327,585,586],{},"\"Zero-knowledge is already enabled for this team\"","; acting on a team that has none gives ",[327,589,590],{},"\"Zero-knowledge is not enabled for this team\"",[274,592,594],{"id":593},"granting-and-revoking","Granting and revoking",[265,596,597,598,404,601,604],{},"Grants are per member, listed under ",[293,599,600],{},"Has access",[293,602,603],{},"Revoke"," button. Revoking needs no activated device — it deletes a stored wrap rather than producing one.",[336,606,607],{"color":338,"icon":339},[265,608,609,610,613],{},"Revoking is not the same as taking the key back. In the product's own words: ",[327,611,612],{},"\"They will not be handed the team key again. A device that already holds it keeps it until the team key is rotated.\""," A browser that has already unwrapped the team key still holds it locally. Genuine forward secrecy needs a reset, which is destructive — see below.",[265,615,616],{},"Removing someone from the team has the same practical effect without touching their grant: every team-key endpoint checks confirmed membership first, so once they are out we will not serve them the team key at all. Their grant row survives, which means re-adding them later restores access with no second ceremony. If you want the grant itself gone, revoke it before removing them.",[274,618,620],{"id":619},"resetting-a-team-key","Resetting a team key",[265,622,623,625,626,629],{},[293,624,563],{}," exists for one situation: an admin created a new encryption key without their old passphrase, so the wrap that gave them the team key was addressed to an account key they no longer hold. The panel names that state — ",[327,627,628],{},"\"This team's key can no longer be opened with your account key\""," — and offers the reset only to an owner or admin, because a member's answer is to ask for a re-grant instead.",[336,631,632],{"color":338,"icon":339},[265,633,634,635,638],{},"A reset is genuinely destructive. It deletes the team keypair and every grant with it, then mints a fresh key wrapped to the admin's current account key. ",[293,636,637],{},"Team content wrapped to the old key stops opening for the team",", permanently, and every member has to be granted again from step 4. It is a recovery path, not maintenance: use it when the old key is already unreachable.",[265,640,641],{},"Personal copies survive a reset. Each member's own items still carry a wrap to their own account key, and links already sent to recipients keep working, because their key travels in the link rather than through the team.",[274,643,645],{"id":644},"what-the-organisation-can-and-cannot-recover","What the organisation can and cannot recover",[265,647,648,649],{},"The question this usually comes down to: ",[293,650,651],{},"someone has left — can we retrieve a credential they shared?",[265,653,654],{},"Sometimes. An owner or admin holding a team-key grant can rebuild the link for a departed member's team share, from the Shares list in that team's context. Admins and owners see every member's shares and secure requests for the team; a plain member is scoped to their own regardless of what they ask for. What decides it is whether a team wrap was written when the item was created.",[487,656,657,667],{},[490,658,659],{},[493,660,661,664],{},[496,662,663],{},"The item was",[496,665,666],{},"Recoverable by an admin",[509,668,669,680,692,703,712,723],{},[493,670,671,674],{},[514,672,673],{},"Created in the team context, with the team key on, by an enrolled member",[514,675,676,679],{},[293,677,678],{},"Yes"," — open it from the team's Shares list",[493,681,682,689],{},[514,683,684,685,688],{},"Created in that person's ",[293,686,687],{},"personal"," context",[514,690,691],{},"No",[493,693,694,701],{},[514,695,696,697,700],{},"Created ",[293,698,699],{},"before"," the team key was enabled",[514,702,691],{},[493,704,705,710],{},[514,706,707,708],{},"Created while the team key was switched ",[293,709,582],{},[514,711,691],{},[493,713,714,721],{},[514,715,716,717,720],{},"Created before that person set up ",[293,718,719],{},"their own"," passphrase",[514,722,691],{},[493,724,725,731],{},[514,726,727,728],{},"Wrapped to a team key that has since been ",[293,729,730],{},"reset",[514,732,691],{},[336,734,735],{"color":338,"icon":339},[265,736,737],{},"CredenShare cannot recover any of it, in any of those rows. We hold ciphertext and no key — there is no support override and no escalation that produces one. If a credential is unreachable and still needed, rotate it at its source.",[265,739,740],{},"Two practical notes for an offboarding run:",[443,742,743,757],{},[347,744,745,746,748,749,752,753,756],{},"Rebuild a colleague's link from the ",[293,747,142],{}," list. That page's copy and QR actions pass the team context, which is what makes the team wrap usable; the dashboard's ",[293,750,751],{},"Recent Shares"," card and the share ",[293,754,755],{},"Info"," dialog resolve only your own account's copy of the key.",[347,758,759,760,762],{},"Do the recovery ",[293,761,699],{}," you reset anything. A reset performed to rescue a stranded admin also destroys the team's route into everything the departing employee left behind.",[265,764,765],{},"Submissions to a secure request follow the same rule. A request created in the team context carries a team wrap, so an admin can open its submissions; one created personally can be opened only by its owner, or by whoever holds the owner's access link.",[274,767,769],{"id":768},"when-it-does-not-behave","When it does not behave",[487,771,772,782],{},[490,773,774],{},[493,775,776,779],{},[496,777,778],{},"What you see",[496,780,781],{},"What it means",[509,783,784,795,805,813],{},[493,785,786,792],{},[514,787,788,789,791],{},"A member sits in ",[293,790,389],{}," and never moves",[514,793,794],{},"They have not set up their passphrase. Nothing an admin does will advance this. A member who enrolled after the page was loaded also stays here until you reload the team page.",[493,796,797,802],{},[514,798,799,801],{},[293,800,407],{}," fails for one member",[514,803,804],{},"Their invitation has not been accepted. An unconfirmed invitee still appears in the list, but the team key cannot be wrapped to anyone who is not a confirmed member.",[493,806,807,810],{},[514,808,809],{},"The admin's own content opens but the team's does not",[514,811,812],{},"The admin's account key was replaced. Look for the stranded-key card — the panel only tests for that state once this device is activated, so activate it first.",[493,814,815,820],{},[514,816,817],{},[327,818,819],{},"\"This link can no longer be rebuilt\"",[514,821,822],{},"A wrap exists but was made under a key that no longer opens — the signature of a destructive rotation, or of a team key reset.",[824,825],"hr",{},[265,827,828,829,831,832,834,835,380],{},"Related: ",[269,830,271],{"href":45}," for passphrases, device activation and what each way of replacing a key costs, and ",[269,833,251],{"href":252}," for what is encrypted where. If something here does not match what you see, write to ",[269,836,838],{"href":837},"mailto:support@credenshare.io","support@credenshare.io",{"title":840,"searchDepth":841,"depth":842,"links":843},"",1,2,[844,845,846,847,848,849,850,851,852],{"id":276,"depth":842,"text":277},{"id":303,"depth":842,"text":304},{"id":333,"depth":842,"text":334},{"id":434,"depth":842,"text":435},{"id":470,"depth":842,"text":471},{"id":593,"depth":842,"text":594},{"id":619,"depth":842,"text":620},{"id":644,"depth":842,"text":645},{"id":768,"depth":842,"text":769},"The ordered ceremony for rolling zero-knowledge custody out to a team, how per-member grants and revocation work, and what an organisation can and cannot recover when someone leaves.","md",{},true,{"title":112,"description":853},"_nuTY70zGi_VB6fqdNhwEXyb4ehA1V4gxQepc-r4yWM",[860,862],{"title":108,"path":109,"stem":110,"description":861,"children":-1},"The owner-set inactivity timeout, IP access restrictions, access-log retention per plan, what the access trail records, and why no role can read another member's history.",{"title":121,"path":117,"stem":118,"description":863,"children":-1},"Troubleshooting and support — how to reach CredenShare, what to put in your message, what support can and cannot do, and where the rest of the help pages are.",1788908849986]