Verschlüsselung
Jede Operation in dieser Gruppe: was sie annimmt, was sie zurückgibt und mit welchen Fehlern sie antworten kann.
Operationen
The OpenPGP public keys that let senders seal mail to an address, the directory the Encryption page of the app publishes to. Only public keys travel here: the private key stays on the device that made it, so nothing in this API can read sealed mail.
Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an app those of the person who connected it.
GET/encryption/keys
List your published keys
Every key published for an address in this workspace, newest first, retired ones included with revokedAt and revokedReason. Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an app those of the person who connected it. A key limited to particular addresses lists only the keys of those addresses.
Requires the emails:read scope.
Rückgabe
The keys, newest first.
Fehler
Die Fehler, die jede Operation zurückgeben kann400401403404422500Fehlerkatalog
Auch verfügbar über
POST/encryption/keys
Publish a public key for an address
Publishes an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. The address has to be an address of this workspace on a verified domain, switched on, and one you may use.
An address keeps one live key. Publishing another while one is live is a 409 key_already_published; to rotate, send the fingerprint of the live key in replaces, and it is retired as the new one is published. Mail already sealed to the old key stays readable only with the old private key.
Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an app those of the person who connected it.
Requires the emails:read scope.
Request-Body
addressstringErforderlichThe address the key is for.
Bis zu 320 ZeichenpublicKeystringErforderlichThe armored OpenPGP PUBLIC KEY BLOCK, up to 64 KB.
64 bis 65536 ZeichenMuster^-----BEGIN PGP PUBLIC KEY BLOCK-----[\s\S]+-----END PGP PUBLIC KEY BLOCK-----\s*$fingerprintstringErforderlichThe fingerprint of the key, 40 upper-case hexadecimal characters.
Muster^[0-9A-F]{40}$algorithmstringThe algorithm of the key, such as
ed25519, for display only.Bis zu 32 ZeichenreplacesstringThe fingerprint of the live key this one replaces, to rotate it.
Muster^[0-9A-F]{40}$
Rückgabe
The key, now published.
Fehler
- 403
The key lacks the scope, or may not send as that address.
step_up_required: the call was made with an OAuth access token that has not been verified in the last 60 minutes. Ask for a code withPOST /security/step-up, send it toPOST /security/step-up/verify, then repeat the call. The person can also choose Allow changes for 60 minutes on the app in Account settings, Connected apps, on the OpenEmail website. An API key is never asked for a code.- 409
key_already_published: the address has a live key andreplaceswas not given, or this key was published for it before.domain_not_verified: the domain of the address is not verified yet.
Die Fehler, die jede Operation zurückgeben kann400401404422500Fehlerkatalog
Auch verfügbar über
GET/encryption/keys/lookup
Find the keys to seal mail to
The live public keys published for each address, the lookup the composer makes before it seals a message. An address with no key comes back with keys empty, so mail to it cannot be sealed. Only keys published by somebody who can read the address count, so a key a former member left behind is never offered.
Requires the emails:send scope.
Query-Parameter
addressesstringErforderlichComma-separated recipient addresses, at most 51. A display name in angle brackets is read as its address.
Rückgabe
One row per address asked about.
Fehler
Die Fehler, die jede Operation zurückgeben kann400401403404422500Fehlerkatalog
Auch verfügbar über
Objekte
AddressKeysobject
objectstringErforderlich- Einer von
"address_keys" addressstringErforderlichThe address as it was read, lower-cased.
keysobject[]ErforderlichfingerprintstringErforderlichpublicKeystringErforderlichcreatedAtstringErforderlich- Format
date-time
AddressKeysListobject
objectstring- Einer von
"list" dataAddressKeys[]
EncryptionKeyobject
objectstringErforderlich- Einer von
"encryption_key" idstringErforderlichpgpk_and 24 hex.addressstringErforderlichfingerprintstringErforderlich40 upper-case hexadecimal characters.
publicKeystringErforderlichThe armored OpenPGP PUBLIC KEY BLOCK.
algorithmstringErforderlichcreatedAtstringErforderlich- Format
date-time revokedAtstringErforderlichWhen it was retired. Null on the live key.
Kann null seinFormatdate-timerevokedReasonstringErforderlich- Kann null sein
EncryptionKeyListobject
objectstring- Einer von
"list" dataEncryptionKey[]