Skip to main content
GET
Who has opened this shared copy, and when

Authorizations

Authorization
string
header
required

Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.

Path Parameters

shareId
string
required

The share's id, as SessionShare.shareId reports it: 26 characters of RFC 4648 base32 drawn from a cryptographic source, carrying no encoding of anything. It is NOT a uuid and is deliberately unrelated to the session id it was published from — a share id travels, so an id derived from a session would make every leaked link a statement about the machine it came from.

Required string length: 26
Pattern: ^[A-Z2-7]{26}$

Query Parameters

cursor
string

Opaque pagination cursor from a previous page's nextCursor or prevCursor.

Maximum string length: 1024
limit
integer
default:25

Maximum items per page.

Required range: 1 <= x <= 100

Response

One page of the audit, newest first.

One page of a shared session's audit, newest first. An EMPTY page never means the audit is unavailable: a home that cannot read its own audit answers 500 rather than an empty list.

items
object[]
required
limit
integer
required
Required range: x >= 1
nextCursor
string

The position the next page starts from, present only when this home holds an older entry. There is no prevCursor: the audit is append-only and read backwards from the newest, so the page a client came from is the one it already has.