> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# What publishing this session would send, and what it would hold back

> Exactly what would leave this machine if the session were published to the organisation's home, computed before anything leaves it. The entries carry the text as it would be sent — already redacted — and withheld names every place a rule held something back, so a person decides against the document rather than against a promise.
A MATCHED RULE REDACTS IN PLACE AND NEVER DROPS. A withheld span is replaced by a marker naming the rule that took it, and the entry keeps its id, its kind and its place in the transcript — a reader can tell a withheld line from a line nobody wrote, which a gap in the sequence cannot say.
The rules are the host's, configured under [sharing.redaction], and every one of them is on unless somebody turned it off. A client computes none of it and holds no rule of its own.



## OpenAPI

````yaml /es/openapi/v3-current/narya.yaml get /v1/sessions/{sessionId}/share/preview
openapi: 3.1.0
info:
  title: Narya Host API
  version: 1.0.0
  description: >-
    The contract between the Narya host and every client. One long-lived host
    serves this API over a Unix socket in your Narya home. The terminal client
    and the one-shot command that Lerian ships drive this API, and a client you
    write drives the same one.


    Requests authenticate with a bearer token issued by the identity provider
    the host is configured with. An operation that declares another security
    scheme also accepts that credential. A request without a valid credential
    gets 401 with NRY-0011. A caller whose role lacks the permission an
    operation needs gets 403 with NRY-0028.


    Submitting a message returns 202 with a turn id. Everything the turn
    produces streams over GET /v1/events as server-sent events with a typed
    envelope, and a stream resumes from a Last-Event-ID header.


    One error envelope: code, title and message. Codes are NRY- followed by four
    digits. Cursors are opaque.
servers: []
security:
  - bearerAuth: []
tags:
  - name: host
    description: The host process itself — version, uptime, mode, store.
  - name: sessions
    description: Durable conversation containers. Archive, never destroy.
  - name: messages
    description: Submitting work into a session and interrupting it.
  - name: events
    description: The server-sent event stream every client consumes.
  - name: lanes
    description: Parallel tracks inside a session — main, subagent, side.
  - name: agents
    description: Named recipes — instructions, tools, model, policy. Read-only in v1.
  - name: ladder
    description: >-
      What a person can type: the skills and command files in force for one
      repository, and expanding one into text. Five origins merged, nearest
      winning a name, the repository's own rungs gated on trust.
  - name: permissions
    description: Pending permission asks, decisions, and the decision audit.
  - name: intercom
    description: Sessions on one machine finding and messaging each other.
  - name: packages
    description: The one thing a user installs — resources, Go code, or both.
  - name: extensions
    description: >-
      Host-side extensions and the operations each exposes over the wire. This
      is the generic lane a host extension uses to serve its own client half (a
      TUI component, a web panel) or any API-only consumer, without adding
      routes to this contract.
  - name: workflows
    description: Deterministic multi-agent orchestration runs.
  - name: providers
    description: Model suppliers, their auth state, and the model catalogue.
  - name: monitors
    description: >-
      Long-running watchers a session keeps beside its conversation — a test
      runner in watch mode, a build, a log being followed. Started by the model
      or by the person, always listed, always killable.
  - name: records
    description: The queryable local record of everything that happened.
  - name: environments
    description: >-
      Where a session's code lives and its commands run — this machine, or a
      container narya operates. A session that names none runs here.
  - name: schedules
    description: >-
      Work the host's own clock starts with nobody present — a repository, a
      prompt, a rule and what one fire may spend. Cancel, never destroy.
  - name: sharing
    description: >-
      Publishing a session from a developer's own home to the organisation's,
      and what is held back before a byte leaves the machine.
  - name: refinements
    description: >-
      What this owner has taught narya and allowed it to keep — distilled facts,
      and the skills, agents and commands the model wrote for itself. Propose,
      read, consent, roll back. Nothing here fires until a person answers.
  - name: platform
    description: >-
      Calls Lerian's control plane made to a home it hosts, as this home
      recorded them.
paths:
  /v1/sessions/{sessionId}/share/preview:
    parameters:
      - $ref: '#/components/parameters/SessionIdParam'
    get:
      tags:
        - sharing
      summary: What publishing this session would send, and what it would hold back
      description: >-
        Exactly what would leave this machine if the session were published to
        the organisation's home, computed before anything leaves it. The entries
        carry the text as it would be sent — already redacted — and withheld
        names every place a rule held something back, so a person decides
        against the document rather than against a promise.

        A MATCHED RULE REDACTS IN PLACE AND NEVER DROPS. A withheld span is
        replaced by a marker naming the rule that took it, and the entry keeps
        its id, its kind and its place in the transcript — a reader can tell a
        withheld line from a line nobody wrote, which a gap in the sequence
        cannot say.

        The rules are the host's, configured under [sharing.redaction], and
        every one of them is on unless somebody turned it off. A client computes
        none of it and holds no rule of its own.
      operationId: previewSessionShare
      responses:
        '200':
          description: What a publish of this session would send, and what it withheld.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionSharePreview'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    SessionIdParam:
      name: sessionId
      in: path
      required: true
      description: The session's id.
      schema:
        type: string
        format: uuid
  schemas:
    SessionSharePreview:
      type: object
      description: >-
        What publishing one session would send, and what it would hold back. The
        same object the publish then sends, computed by the same function in the
        host.
      required:
        - entries
        - withheld
        - ruleCounts
      properties:
        entries:
          type: array
          description: >-
            The session as it would leave this machine, oldest first. Every
            entry of the transcript is here, redacted where a rule matched: the
            list is the document, not a selection from it.
          items:
            $ref: '#/components/schemas/SessionSharePreviewEntry'
        withheld:
          type: array
          description: >-
            Every place a rule held something back, in transcript order — one
            item per entry per rule. This is what a client draws beside the
            conversation so a reader can see WHERE something was withheld;
            ruleCounts answers how much in total.
          items:
            $ref: '#/components/schemas/SessionShareWithheld'
        ruleCounts:
          type: object
          description: >-
            How many spans each rule withheld across the whole session, keyed by
            the rule's name. Empty when nothing was withheld.
          additionalProperties:
            type: integer
            minimum: 1
      examples:
        - entries:
            - id: 3f1c9a52-8d4e-4b21-9c07-5e2a1d8b6f40
              kind: user-message
              sequence: 1
              text: 'deploy with ANTHROPIC_API_KEY=[redacted: masked-environment]'
            - id: 7a2d4e61-9b3c-4f18-8e05-1c6b3a9d2f57
              kind: tool-result
              sequence: 2
              text: ok  github.com/example/pkg  0.4s
          withheld:
            - entryId: 3f1c9a52-8d4e-4b21-9c07-5e2a1d8b6f40
              rule: masked-environment
              count: 1
          ruleCounts:
            masked-environment: 1
    SessionSharePreviewEntry:
      type: object
      description: >-
        One entry of a session as it would leave this machine: already redacted,
        still in its place.
      required:
        - id
        - kind
        - sequence
      properties:
        id:
          type: string
          format: uuid
          description: >-
            The transcript entry's own id, so the preview a person read and the
            entries that reach the organisation's home name the same rows.
        kind:
          type: string
          enum:
            - user-message
            - assistant-message
            - tool-call
            - tool-result
            - summary
            - system
            - intercom
            - monitor-event
          description: >-
            The transcript row's kind, unchanged by redaction: a reader
            following a conversation needs to know whose voice a withheld line
            was in.
        sequence:
          type: integer
          format: int64
          minimum: 1
          description: The entry's place in this session's transcript.
        text:
          type: string
          description: >-
            What would be sent for this entry, with every rule applied. A
            withheld span reads as a marker naming the rule that took it.

            Absent for an entry that carries nothing this surface publishes — an
            assistant round's reasoning blocks, whose provider signatures never
            leave the host — which is a real state and not an omission. Such an
            entry is still listed, so the sequence a reader follows stays
            honest.
    SessionShareWithheld:
      type: object
      description: One rule holding something back in one entry.
      required:
        - entryId
        - rule
        - count
      properties:
        entryId:
          type: string
          format: uuid
          description: The entry the rule withheld something from.
        rule:
          type: string
          description: >-
            Which rule recognised it, by name. A name rather than a number
            because it travels to a reader: "stored-credential" is something a
            person can act on, and "rule 2" is not. The four the product starts
            with are named-path, stored-credential, masked-environment and
            credential-shape.
        count:
          type: integer
          minimum: 1
          description: >-
            How many spans that rule took out of this entry. One for a whole
            entry withheld by name.
    Error:
      type: object
      description: >-
        The single error envelope every operation returns. Codes are NRY-
        followed by four digits and are catalogued in the top-level
        x-error-catalog extension.
      required:
        - code
        - title
        - message
      properties:
        code:
          type: string
          pattern: ^NRY-[0-9]{4}$
          description: Machine-readable error code from the NRY catalogue.
        title:
          type: string
          maxLength: 256
          description: Short human-readable summary of the error class.
        message:
          type: string
          maxLength: 4096
          description: Specific, actionable description of what went wrong.
        fields:
          type: object
          description: Per-field validation problems.
          additionalProperties:
            type: string
      examples:
        - code: NRY-0002
          title: Session not found
          message: >-
            No session with id 6b9f6d2e-1c3a-4f5b-9d7e-2a8c4e6f0b1d exists on
            this host.
  responses:
    Forbidden:
      description: >-
        The caller is authenticated and is not allowed this operation (NRY-0028
        or NRY-0030).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The addressed resource does not exist on this host.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: The host failed — including a store that refuses writes (NRY-0012).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Enforced on every transport, with no exempt operation. A person's
        request — over the default local unix socket exactly as over a TCP
        listener — must carry a JWT issued by the configured identity provider,
        which the host verifies itself against that issuer's key set: signature,
        issuer, expiry, and the person and organisation it names. Requests
        without a valid one receive 401 NRY-0011. The socket's file permissions
        are transport and are not an authorisation.

````