# Hosted zrok2 environment cannot create any public share – \[POST /share\]\[500\] shareInternalServerError

**URL:** <https://openziti.discourse.group/t/hosted-zrok2-environment-cannot-create-any-public-share-post-share-500-shareinternalservererror/6044>\
**Category:** zrok\
**Created:** [September 6, 2026, 2:10am UTC](https://openziti.discourse.group/t/hosted-zrok2-environment-cannot-create-any-public-share-post-share-500-shareinternalservererror/6044 "2026-09-06T02:10:42Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![tlaloc2k-ws](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/tlaloc2k-ws/32/4333_2.png) [@tlaloc2k-ws](https://openziti.discourse.group/u/tlaloc2k-ws)\
**Post date:** [September 6, 2026, 2:10am UTC](https://openziti.discourse.group/t/hosted-zrok2-environment-cannot-create-any-public-share-post-share-500-shareinternalservererror/6044/1 "2026-09-06T02:10:42Z")

</div>

Hi, I’m using hosted zrok with **zrok2 v2.0.4 [6ff92039]** on Windows 11.

My environment appears healthy for account/config operations, but it cannot create any public share.

**Environment**

- API endpoint: `https://api-v2.zrok.io`
- EnvZId: `pMKYCPv7I2`
- Only one environment exists on the account.
- `zrok2 status` shows Account Token and EnvZId set.

**What works**

- `zrok2 status`
- `zrok2 list environments --json`
- `zrok2 list names --json`
- `zrok2 create name`
- `zrok2 delete name`

**What fails**

Any attempt to create a public share fails with:

`unable to create share (unable to create share: [POST /share][500] shareInternalServerError "")`

This happens:

- with an existing reserved name;
- after deleting and recreating the reserved name;
- with a brand-new reserved name;
- and even with **no reserved name at all**.

Example:

`zrok2 share public 127.0.0.1:4175 --headless --force-local`

returns:

`[ERROR]: unable to create share (unable to create share: [POST /share][500] shareInternalServerError "")`

**Reserved-name behavior**

Names such as `tlaloc-tl-seguimientos` and `tlaloc-tl-acceso` can be created successfully and appear in `list names`, but they do not get an active share/shareToken because `POST /share` fails.

The public endpoints therefore return:

`share <name>.shares.zrok.io not found`

**Environment listing**

There is only one environment:

`EnvZId: pMKYCPv7I2`

I also tested a completely new name and an unnamed public share, and both fail with the same 500, so this does not appear to be limited to a stale reserved-name mapping.

Could you please inspect the hosted controller/OpenZiti state for this environment and reconcile any stale/missing identity, service, policy, or mapping state preventing `POST /share` from succeeding?

I can provide the hosted account email privately if needed.

Thanks.
