# E23000 — RealtimeEncryptedChannelFanout

A publish to a `private-encrypted-` channel must name only that channel.

- **HTTP status**: `422`
- **Type**: `validation_error`
- **Name**: `RealtimeEncryptedChannelFanout`

## What to do

Each encrypted channel derives its own key, so an event sealed for one channel is unreadable ciphertext to every other channel's subscribers. Publish to the encrypted channel in its own call, or use the batch publish, which carries one channel per event.

Operations that resolve this:

- [Publish a Realtime event](/docs/api/reference/publish-realtime-app-event)
- [Publish a batch of Realtime events](/docs/api/reference/publish-realtime-app-batch)

## Related

- [E23xxx — Realtime](/docs/api/errors/E23xxx): every code in this range
- [Errors](/docs/api/errors): the full wire contract, status mapping, and error catalog
- [Error handling](/docs/guides/errors): branching on `type` and `code`, validation details, and `vendor_code`