# Publish a public report link

Publishes a PUBLIC link to a report: anybody holding the URL can open its numbers with no sign-in, which is why it is an admin's. The token is answered exactly ONCE — only its sha256 is stored, so a lost URL is re-published, never looked up. Body is optional: `label` and `expires_at` (RFC3339, and it must be in the future; 30 days by default, since a public link with no clock is a standing credential). A report grouped by an identifying field cannot be published at all, checked here and again at every render. Take one down with `delete_reports_shares_id`.

Access class: `workspace:admin`.

## Endpoint

`POST /v1/reports/views/{id}/shares`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| id | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "expires_at": "string",
    "label": "string"
  },
  "params": {
    ":id": "string"
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
