> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gtm-api.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Search issued account shares

> List the account shares your team ISSUED: accounts you lent OUT to another workspace. Sharing is TEMPORARY and revocable; permanent ownership transfer is a web-app-only flow with no MCP tool, so never offer this as a way to give an account away. This is also the polling surface, since there is no get tool and no /{sid} route: read one loan with filter { sid: { eq } } and watch status until active (the holder can work), failed (it never started, read failure_reason), or terminal recalled / returned. filter.owner_account_sid answers 'is this account lent out and to whom'; holder_over_slot finds loans that landed with no free slot. The number recall_account_share has to confirm is pagination.total_count here, NOT total_matched; page_size 0 returns it with no rows. No include[], no counts block, no free-text q. Needs can_view_account_shares.

Contract:
- MCP tool `search_account_shares`, registry package `mcp.id/account_shares`, mount `id.access`.
- Operation `search`, response envelope `search`.
- Flags: read only.



## OpenAPI

````yaml /api-reference/id/openapi.yaml post /api/account-shares/search
openapi: 3.0.3
info:
  title: 'GTM API public contract: gtm.service.id'
  description: >-
    Identity, access and money: users, teams and members, API keys, OAuth
    clients and authorizations, billing products, subscriptions, transactions
    and payment methods, the credit ledger, notifications, TLS certificates,
    observability and support requests.


    GENERATED. This document is projected from the Zod MCP tool registry in
    `product/mcp/gtm.mcp` (one tool per public endpoint, 1:1). Do not edit it by
    hand; edit the tool definition and regenerate with `pnpm openapi:public`.


    Surface: the public `/api` contract of `gtm.service.id`, 77 operations.
    Internal (`/internal`) and health endpoints are deliberately absent; the
    code-faithful spec that documents those lives in
    `product/openapi/gtm.openapi.tech`.


    Conventions:

    - Auth is a bearer JWT, optionally narrowed by the `Team-SID` header.

    - Every success body is an MCP envelope: `success: true` plus one typed
    `operation` shape (`search`, `get`, `create`, `update`, `delete`, `metrics`,
    `group_by`, `action`), and a `meta` block with `trace_id` for support.

    - Every failure is the same `McpError` envelope with a code from a fixed
    16-code taxonomy, so a client maps errors once.

    - Lists page with `page_size` (0 to 500, default 50) plus an opaque forward
    `cursor`; `page_size: 0` returns counts only.

    - On `GET` and `DELETE`, object-valued query parameters (`filter`, `sort`)
    travel as JSON text and array-valued ones repeat as `name[]=value`.

    - The MCP-only `_meta` field (usage analytics) never reaches the backend and
    is not part of this contract.
  version: '1.0'
  contact:
    name: GTM API
    url: https://gtm-api.com
    email: support@gtm-api.com
  license:
    name: Proprietary
    url: https://gtm-api.com/license
servers:
  - url: https://app.gtm-api.com/id/v4
    description: Production, through the app.gtm-api.com gateway
  - url: http://localhost:8021
    description: Local Docker (gtm_id_nginx_dev)
security:
  - BearerJwt: []
    TeamSid: []
tags:
  - name: account_shares
    description: Registry package `mcp.id/account_shares`, served on MCP mount `id.access`.
  - name: api_keys
    description: Registry package `mcp.id/api_keys`, served on MCP mount `id.access`.
  - name: billing_payment_methods
    description: >-
      Registry package `mcp.id/billing_payment_methods`, served on MCP mount
      `id.billing`.
  - name: billing_products
    description: >-
      Registry package `mcp.id/billing_products`, served on MCP mount
      `id.billing`.
  - name: billing_subscriptions
    description: >-
      Registry package `mcp.id/billing_subscriptions`, served on MCP mount
      `id.billing`.
  - name: billing_transactions
    description: >-
      Registry package `mcp.id/billing_transactions`, served on MCP mount
      `id.billing`.
  - name: credit_transactions
    description: >-
      Registry package `mcp.id/credit_transactions`, served on MCP mount
      `id.credits`.
  - name: notifications
    description: >-
      Registry package `mcp.id/notifications`, served on MCP mount
      `id.platform`.
  - name: oauth_authorizations
    description: >-
      Registry package `mcp.id/oauth_authorizations`, served on MCP mount
      `id.access`.
  - name: oauth_clients
    description: Registry package `mcp.id/oauth_clients`, served on MCP mount `id.access`.
  - name: observability_requests
    description: >-
      Registry package `mcp.id/observability_requests`, served on MCP mount
      `id.platform`.
  - name: sessions
    description: Registry package `mcp.id/sessions`, served on MCP mount `id.identity`.
  - name: ssl_certificates
    description: >-
      Registry package `mcp.id/ssl_certificates`, served on MCP mount
      `id.platform`.
  - name: support_requests
    description: >-
      Registry package `mcp.id/support_requests`, served on MCP mount
      `id.platform`.
  - name: team_members
    description: Registry package `mcp.id/team_members`, served on MCP mount `id.identity`.
  - name: teams
    description: Registry package `mcp.id/teams`, served on MCP mount `id.identity`.
  - name: users
    description: Registry package `mcp.id/users`, served on MCP mount `id.identity`.
paths:
  /api/account-shares/search:
    post:
      tags:
        - account_shares
      summary: Search issued account shares
      description: >-
        List the account shares your team ISSUED: accounts you lent OUT to
        another workspace. Sharing is TEMPORARY and revocable; permanent
        ownership transfer is a web-app-only flow with no MCP tool, so never
        offer this as a way to give an account away. This is also the polling
        surface, since there is no get tool and no /{sid} route: read one loan
        with filter { sid: { eq } } and watch status until active (the holder
        can work), failed (it never started, read failure_reason), or terminal
        recalled / returned. filter.owner_account_sid answers 'is this account
        lent out and to whom'; holder_over_slot finds loans that landed with no
        free slot. The number recall_account_share has to confirm is
        pagination.total_count here, NOT total_matched; page_size 0 returns it
        with no rows. No include[], no counts block, no free-text q. Needs
        can_view_account_shares.


        Contract:

        - MCP tool `search_account_shares`, registry package
        `mcp.id/account_shares`, mount `id.access`.

        - Operation `search`, response envelope `search`.

        - Flags: read only.
      operationId: search_account_shares
      requestBody:
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SearchAccountSharesRequest'
      responses:
        '200':
          description: '`search` success envelope.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SearchAccountSharesResponse'
        4XX:
          $ref: '#/components/responses/McpClientError'
        5XX:
          $ref: '#/components/responses/McpServerError'
components:
  schemas:
    SearchAccountSharesRequest:
      type: object
      description: Request body of `search_account_shares`.
      properties:
        filter:
          type: object
          properties:
            sid:
              type: object
              properties:
                eq:
                  type: string
                in:
                  type: array
                  items:
                    type: string
              additionalProperties: false
            channel:
              type: object
              properties:
                eq:
                  type: string
                  enum:
                    - linkedin
                    - email
                in:
                  type: array
                  items:
                    type: string
                    enum:
                      - linkedin
                      - email
              additionalProperties: false
              description: '"My LinkedIn loans" vs "my email loans".'
            status:
              type: object
              properties:
                eq:
                  type: string
                  enum:
                    - pending
                    - owner_parked
                    - active
                    - closing
                    - holder_released
                    - rolling_back
                    - returned
                    - recalled
                    - failed
                ne:
                  type: string
                  enum:
                    - pending
                    - owner_parked
                    - active
                    - closing
                    - holder_released
                    - rolling_back
                    - returned
                    - recalled
                    - failed
                in:
                  type: array
                  items:
                    type: string
                    enum:
                      - pending
                      - owner_parked
                      - active
                      - closing
                      - holder_released
                      - rolling_back
                      - returned
                      - recalled
                      - failed
                nin:
                  type: array
                  items:
                    type: string
                    enum:
                      - pending
                      - owner_parked
                      - active
                      - closing
                      - holder_released
                      - rolling_back
                      - returned
                      - recalled
                      - failed
              additionalProperties: false
              description: >-
                The phase. { eq: "active" } is the live set; { in:
                ["rolling_back","failed"] } is the loans that gave up.
            to_team_sid:
              type: object
              properties:
                eq:
                  type: string
                in:
                  type: array
                  items:
                    type: string
              additionalProperties: false
              description: 'Owner side question: everything lent to team X.'
            to_user_sid:
              type: object
              properties:
                eq:
                  type: string
                in:
                  type: array
                  items:
                    type: string
              additionalProperties: false
            owner_account_sid:
              type: object
              properties:
                eq:
                  type: string
                in:
                  type: array
                  items:
                    type: string
              additionalProperties: false
              description: >-
                Share history of an owned account: "is this account lent out,
                and to whom".
            holder_account_sid:
              type: object
              properties:
                eq:
                  type: string
                in:
                  type: array
                  items:
                    type: string
              additionalProperties: false
              description: 'Holder side question: map a borrowed copy back to its loan.'
            holder_over_slot:
              type: object
              properties:
                eq:
                  type: boolean
              additionalProperties: false
              description: >-
                Which loans reached active but landed with no free slot on the
                holder side.
            end_reason:
              type: object
              properties:
                eq:
                  type: string
                  enum:
                    - returned_by_holder
                    - recalled_by_owner
                    - holder_deleted_copy
                    - holder_team_purged
                    - owner_team_purged
                in:
                  type: array
                  items:
                    type: string
                    enum:
                      - returned_by_holder
                      - recalled_by_owner
                      - holder_deleted_copy
                      - holder_team_purged
                      - owner_team_purged
                is_null:
                  type: boolean
              additionalProperties: false
            failure_reason:
              type: object
              properties:
                eq:
                  type: string
                  enum:
                    - park_failed
                    - export_failed
                    - copy_refused
                    - probe_stale
                    - team_purged
                in:
                  type: array
                  items:
                    type: string
                    enum:
                      - park_failed
                      - export_failed
                      - copy_refused
                      - probe_stale
                      - team_purged
                is_null:
                  type: boolean
              additionalProperties: false
            owner_cluster_id:
              type: object
              properties:
                eq:
                  type: integer
                in:
                  type: array
                  items:
                    type: integer
              additionalProperties: false
            holder_cluster_id:
              type: object
              properties:
                eq:
                  type: integer
                in:
                  type: array
                  items:
                    type: integer
              additionalProperties: false
            phase_claimed_at:
              type: object
              properties:
                gte:
                  type: string
                lte:
                  type: string
                is_null:
                  type: boolean
              additionalProperties: false
            planned_return_at:
              type: object
              properties:
                gte:
                  type: string
                lte:
                  type: string
                gt:
                  type: string
                lt:
                  type: string
                is_null:
                  type: boolean
              additionalProperties: false
              description: '{ is_null: true } is an open ended lend.'
            created_at:
              type: object
              properties:
                gte:
                  type: string
                lte:
                  type: string
                gt:
                  type: string
                lt:
                  type: string
              additionalProperties: false
        sort:
          type: object
          properties:
            field:
              type: string
              enum:
                - created_at
                - planned_return_at
                - updated_at
            direction:
              type: string
              enum:
                - asc
                - desc
              description: Default desc.
          required:
            - field
        page_size:
          type: integer
          minimum: 0
          maximum: 200
          description: >-
            0..200, default 50. page_size=0 = count-only, page_size=1 =
            getFirst.
        cursor:
          type: string
          nullable: true
          description: >-
            Opaque forward cursor from a previous response
            pagination.next_cursor.
    SearchAccountSharesResponse:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - true
        operation:
          type: string
          enum:
            - search
        items:
          type: array
          items:
            type: object
            properties:
              item:
                type: object
                properties:
                  sid:
                    type: string
                  team_sid:
                    type: string
                    description: >-
                      The OWNER team: the row tenant, the side that lent the
                      account out.
                  channel:
                    type: string
                    enum:
                      - linkedin
                      - email
                    description: Which channel service owns the physical account pair.
                  to_team_sid:
                    type: string
                    description: 'The HOLDER team: the side that borrowed the account.'
                  to_user_sid:
                    type: string
                    nullable: true
                    description: >-
                      Resolved user when the share was targeted by email; null
                      when targeted by team sid.
                  to_email:
                    type: string
                    nullable: true
                    description: >-
                      The targeting input kept for audit; null when targeted by
                      team sid.
                  owner_cluster_id:
                    type: integer
                  holder_cluster_id:
                    type: integer
                  owner_account_sid:
                    type: string
                    description: >-
                      The owner's channel account row, parked for the duration
                      of the loan. Prefix agnostic: ln_ac_ on LinkedIn, em_ac_
                      on email.
                  owner_channel_ref:
                    type: string
                    nullable: true
                    description: >-
                      Opaque second row the channel needs to name (LinkedIn puts
                      its ab_br_ browser sid here); null when the channel needs
                      none.
                  holder_account_sid:
                    type: string
                    nullable: true
                    description: >-
                      The holder's copy. NULL until the copy phase lands, so it
                      is null on every pre-active row.
                  holder_channel_ref:
                    type: string
                    nullable: true
                  status:
                    type: string
                    enum:
                      - pending
                      - owner_parked
                      - active
                      - closing
                      - holder_released
                      - rolling_back
                      - returned
                      - recalled
                      - failed
                    description: >-
                      The durable phase, and the answer to "did the loan start".
                      Only active means the holder can work.
                  holder_over_slot:
                    type: boolean
                    description: >-
                      True when the holder had no free account slot at create,
                      so the copy landed in the channel's subscription hold. The
                      loan still reaches active; the holder cannot work until it
                      upgrades.
                  end_reason:
                    type: string
                    nullable: true
                    enum:
                      - returned_by_holder
                      - recalled_by_owner
                      - holder_deleted_copy
                      - holder_team_purged
                      - owner_team_purged
                    description: >-
                      Stamped when an ending is REQUESTED. Only ever set on a
                      row that reached active.
                  failure_reason:
                    type: string
                    nullable: true
                    enum:
                      - park_failed
                      - export_failed
                      - copy_refused
                      - probe_stale
                      - team_purged
                    description: >-
                      Why a pre-active phase gave up. Non null on exactly
                      rolling_back and failed.
                  planned_return_at:
                    type: string
                    nullable: true
                    description: >-
                      Informational only. When it passes the owner is emailed a
                      recall link once; there is NO auto return.
                  expiry_notified_at:
                    type: string
                    nullable: true
                  phase_claimed_at:
                    type: string
                    nullable: true
                  phase_attempts:
                    type: integer
                    description: >-
                      Attempts on the CURRENT phase, reset on every advance. A
                      large and growing value is the stuck signal on a phase
                      that may not give up.
                  ended_at:
                    type: string
                    nullable: true
                  ended_by:
                    type: object
                    nullable: true
                    properties:
                      actor_type:
                        type: string
                        enum:
                          - user
                          - support
                          - api_key
                          - system
                      actor_sid:
                        type: string
                        nullable: true
                      team_sid:
                        type: string
                      permissions:
                        type: object
                        additionalProperties: {}
                      request_sid:
                        type: string
                        nullable: true
                      reason:
                        type: string
                        nullable: true
                    required:
                      - actor_type
                      - actor_sid
                      - team_sid
                      - permissions
                    description: >-
                      Who ended it. The machine readable why is end_reason (an
                      ending) or failure_reason (a failure), never this blob.
                  created_by:
                    type: object
                    nullable: true
                    properties:
                      actor_type:
                        type: string
                        enum:
                          - user
                          - support
                          - api_key
                          - system
                      actor_sid:
                        type: string
                        nullable: true
                      team_sid:
                        type: string
                      permissions:
                        type: object
                        additionalProperties: {}
                      request_sid:
                        type: string
                        nullable: true
                      reason:
                        type: string
                        nullable: true
                    required:
                      - actor_type
                      - actor_sid
                      - team_sid
                      - permissions
                  created_at:
                    type: string
                  updated_at:
                    type: string
                required:
                  - sid
                  - team_sid
                  - channel
                  - to_team_sid
                  - to_user_sid
                  - to_email
                  - owner_cluster_id
                  - holder_cluster_id
                  - owner_account_sid
                  - owner_channel_ref
                  - holder_account_sid
                  - holder_channel_ref
                  - status
                  - holder_over_slot
                  - end_reason
                  - failure_reason
                  - planned_return_at
                  - expiry_notified_at
                  - phase_claimed_at
                  - phase_attempts
                  - ended_at
                  - ended_by
                  - created_by
                  - created_at
                  - updated_at
              included:
                type: object
                additionalProperties: {}
            required:
              - item
              - included
        pagination:
          type: object
          properties:
            next_cursor:
              type: string
              nullable: true
            has_more:
              type: boolean
            total_count:
              type: integer
              nullable: true
          required:
            - next_cursor
            - has_more
            - total_count
        applied_filters:
          type: object
          additionalProperties: {}
        includes:
          type: array
          items:
            type: string
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
        counts:
          type: object
          additionalProperties: {}
      required:
        - success
        - operation
        - items
        - pagination
        - applied_filters
        - includes
        - meta
    McpError:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - validation_failed
                - nothing_to_update
                - not_found
                - relation_not_found
                - invalid_transition
                - limit_exceeded
                - payment_required
                - duplicate_rejected
                - conflict
                - delete_blocked
                - unauthorized
                - forbidden
                - rate_limited
                - internal_error
                - service_unavailable
                - not_implemented
            message:
              type: string
            recoverable:
              type: boolean
            suggestion:
              type: string
            field_errors:
              type: object
              additionalProperties:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: object
                      properties:
                        rule:
                          type: string
                        message:
                          type: string
                      required:
                        - rule
                        - message
            blockers:
              type: array
              items:
                type: object
                properties:
                  type:
                    type: string
                    description: >-
                      Machine-readable blocker type (active_flow, pending_tasks,
                      …).
                  severity:
                    type: string
                    enum:
                      - hard
                      - soft
                    description: >-
                      hard = external action required; soft = acknowledge is
                      enough.
                  description:
                    type: string
                  entity_sid:
                    type: string
                    nullable: true
                  count:
                    type: integer
                  resolution:
                    type: string
                    description: 'Hard: tool name to call. Soft: code for acknowledge[].'
                  resolution_hint:
                    type: string
                required:
                  - type
                  - severity
                  - description
                  - entity_sid
                  - resolution
                  - resolution_hint
            context:
              type: object
              additionalProperties: {}
          required:
            - code
            - message
            - recoverable
        meta:
          type: object
          properties:
            trace_id:
              type: string
              description: UUID v7; same 128-bit value as the X-Trace-Id header.
            span_id:
              type: string
              pattern: ^[0-9a-f]{16}$
              description: 16 hex chars, root span of this request.
            timestamp:
              type: string
              description: ISO 8601 UTC (Y-m-dTH:i:sZ), response time.
            duration_ms:
              type: integer
              minimum: 0
              description: Server-side wall clock.
            debug_url:
              type: string
              description: Deep link to the post-call analysis UI.
          required:
            - trace_id
            - span_id
            - timestamp
            - duration_ms
            - debug_url
      required:
        - success
        - error
  responses:
    McpClientError:
      description: >-
        MCP error envelope. `error.code` is one of validation_failed,
        nothing_to_update, not_found, relation_not_found, invalid_transition,
        limit_exceeded, payment_required, duplicate_rejected, conflict,
        delete_blocked, unauthorized, forbidden, rate_limited, not_implemented.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
    McpServerError:
      description: >-
        MCP error envelope with `error.code` internal_error or
        service_unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/McpError'
  securitySchemes:
    BearerJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Access token issued by gtm.service.id. Its `access_identity` claim
        carries `team_sid`, `actor_sid` and `actor_type`, and that team scope is
        authoritative.
    TeamSid:
      type: apiKey
      in: header
      name: Team-SID
      description: >-
        Team scope for tokens that do not carry one. Ignored when the token
        already names a team.

````