Read one shared session's record
One share this home holds, as a recipient sees it: who published it, which session on which machine it came from, how far the copy reaches and when it stops. It is the same audience rule, the same 404 and the same disclosure record as the entries beside it. Reading the record of a published conversation is a read of that conversation’s existence, and at this home its existence is the thing a share id would otherwise confirm. WHO ELSE A SHARE NAMES IS NOT REPORTED HERE. The list of recipients is a statement about people rather than about the work: whoever published it holds it at their own home, and who has actually opened the copy is the disclosure audit’s answer.
Authorizations
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Path Parameters
The share's id, as SessionShare.shareId reports it: 26 characters of RFC 4648 base32 drawn from a cryptographic source, carrying no encoding of anything. It is NOT a uuid and is deliberately unrelated to the session id it was published from — a share id travels, so an id derived from a session would make every leaked link a statement about the machine it came from.
26^[A-Z2-7]{26}$Response
The share, as this home holds it.
One shared session as the home that RECEIVED it holds it. It is not SessionShare read from the other end, and the difference is which home is speaking. What a publishing home records is what it sent and what it still owes; what this records is what ARRIVED — so the instant on it is when this home took the first delivery, and the position on it is how far the copy here reaches rather than how far a delivery has been acknowledged. THERE IS NO ORGANISATION ON IT, deliberately. One organisation is one home: this home is stamped with the organisation it serves and refuses a token for any other before a handler runs, so the organisation a share belongs to is the organisation asking.
The share's id, which is how this copy is addressed here and everywhere else. It carries no encoding of anything, so it discloses nothing about the session or the machine it came from.
26^[A-Z2-7]{26}$The session this was published FROM, at the home it was published from. It is provenance and nothing more: no session with this id exists here, none is created, and asking this host about it answers nothing.
The subject of whoever published it, read off the verified token that carried the first delivery and never off a payload. It is an identifier and not a display name: names are the identity provider's to answer and would go stale here.
Where the publish stops, so a reader knows whether more of this conversation is still coming.
once, sync How far it has got. On this road it is always active: a revoked share and one whose expiry has passed answer 404, because the conversation they carried has been deleted and confirming that such a share ever existed is itself a disclosure. The field carries the full enum so a client holds one vocabulary for a share at either home.
pending, active, revoked When THIS home took the first delivery, by this home's own clock. It is deliberately not when the person asked for the share: the publishing machine's clock is not a fact this home can vouch for, and what a reader here asks is when the organisation received it.
How far into the conversation this home reaches, in the publishing home's own numbering — the sequence of the last entry held. It is the same number the last row of a read of the entries carries, and the number share-received announces, so a client can tell "there is more" from "I already have this" without a request.
x >= 0When this copy stops and is deleted, carried from the publishing home so this home enforces it by its own clock. A share whose expiry has passed is closed whether or not the sweep has been round yet — which is why state has no expired value.
Absent for a share with no expiry, which nothing this product publishes produces.

