---
title: "Validate token to view shared resources"
method: POST
path: "/cdx/v1/shared-tokens:resources"
tags: ["Shared Tokens (cdx/v1)"]
---

# Validate token to view shared resources

`POST /cdx/v1/shared-tokens:resources`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Validate and decrypt the shared token and view token's shared resources

## Request body

- object — Encrypted Token shared with consumer ## The Shared Tokens Model <SchemaDefinition schemaRef="#/components/schemas/cdx.v1.SharedToken" />
  - `api_version` 'cdx/v1' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'SharedToken' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `token` string, required — The encrypted token

## Response `200`

Consumer validates share token and view consumer resources before redeeming in the workflow

- object
  - `consumer_shared_resources` CdxV1ConsumerSharedResource[]
    - `api_version` 'cdx/v1' — APIVersion defines the schema version of this representation of a resource.
    - `kind` 'ConsumerSharedResource' — Kind defines the object this REST resource represents.
    - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
    - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
      - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
      - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
      - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
      - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
      - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
    - `cloud` string — The cloud service provider of the provider shared cluster.
    - `network_connection_types` CdxV1ConnectionType[] — The network connection types of the provider shared cluster. If the shared cluster is on public internet, then the list will be empty
    - `display_name` string — Consumer resource display name
    - `description` string — Description of consumer resource
    - `tags` string[] — list of tags
    - `schemas` object[] — List of schemas in JSON format. This field is work in progress and subject to changes.
      - `subject` string — Name of the subject
      - `version` integer — Version number
      - `id` integer — Globally unique identifier of the schema
      - `schema_type` string — Schema type
      - `schema` string — Schema definition string
    - `organization_name` string — Shared resource's organization name
    - `organization_description` string — Shared resource's organization description
    - `organization_contact` string, email — Email of the shared resource's organization contact
    - `logo_url` string, uri — Resource logo url

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `403` — The access credentials were considered insufficient to grant access
- `404` — Not Found
- `409` — The request is in conflict with the current server state
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
