# Share private versions with teams

Share an exact released Block or Project Type without publishing its source.

An owner can share an existing **private released version** of a Block or Project
Type with active teammates. This is a host library permission, not a manifest
permission. Do not put team IDs, credentials or sharing grants in a portable
package. The sandbox and typed input/output contract are unchanged.

### Share a version

1. Open the released version from **My builds → Installed versions → Open source**.
2. Choose **Share with teams**, select your teams, and confirm that you have
   permission to share the source. Save team access.
3. Teammates find the version under **Shared with your teams** in the Block library
   or Project Types library. **Preview and install** opens the real import review
   dialog, including the sandbox, tests, permissions and sample execution.
4. After review, choose **Install this version**. The account keeps an installation
   and this device keeps a source checkpoint. Installed Blocks also appear when
   adding a Block to a project's workflow.

Sharing covers one exact entity, version and source digest. Editing a draft,
releasing a later version or changing a Project Type does not extend the grant.
The release stays private: it receives no public listing, public source link,
search entry or sitemap entry. Existing private work stays private after Max ends.
Sharing an existing private release does not require buying Max again. Shared
draft editing and automatic updates of installed copies are separate features.

Both the source owner and recipient must be active members of a granted team
when fetching source or confirming a new installation. StillMade rechecks access
after the package review. Removing a grant or leaving/suspending team membership
removes future cloud library access and downloads. Previously downloaded source,
local checkpoints and embedded project copies remain with their recipients;
revocation cannot retract source already delivered. Team access does not grant
access to the creator's other projects, media, secrets, or payment account.

Imported third-party source keeps its original license and attribution. A private
grant is still source distribution: share only where your license permits it.
Hosted capabilities retain the recipient's normal model, payment, cost and review
confirmations. A team grant never authorizes a provider call or bypasses runtime
tests. Project Type imports remain subject to the current whole-workflow admission
rules; sharing does not enable an unsupported runtime combination.

### Authenticated host API

These are account APIs for StillMade's UI. They are unavailable inside guest code.
All paths below are relative to `/api/blocks` and require the current account's
bearer token. Use the cloud entity UUID, not the manifest's `namespace.name` ID.

| Request | Behavior |
| --- | --- |
| `GET /releases/:entityId/:version/team-access` | Owner reads `{entityId, version, digest, teams:[{id,name,shared,canShare}]}` for a private version. Previously granted inactive teams remain available for removal; `canShare:false` prevents adding them. |
| `PUT /releases/:entityId/:version/team-access` | Owner sends `{teamId, shared, sourceDigest, rightsConfirmed:true}` to grant access; `rightsConfirmed` is unnecessary when `shared:false`. |
| `GET /library?collection=teams` | Returns authorized private releases as `{items,nextCursor}`; pass the returned opaque `cursor` for the next page. |
| `GET /library?collection=installs` | Lists installed releases the account can currently retrieve from the cloud. |
| `GET /releases/:entityId/:version` | Fetches authorized source and its digest through authenticated storage. |
| `POST /install` | Confirms `{entityId,version,sourceDigest,confirmed:true}` after review; include the existing `comfyuiReview` or `capabilityReview` receipt when the runtime requires one. |

A denied or removed release returns `404`; a changed digest returns `409`.
When team sharing is not set up on a StillMade server, team-sharing endpoints return `503`
with `TEAM_ACCESS_SETUP_REQUIRED`. Existing owner/public source access continues;
unavailable team storage never grants access to a private release.
