Publish a public key
Lets senders seal mail to one of your addresses.
Runs the real call on your workspace.
POST /encryption/keys
Lets senders seal mail to one of your addresses.
Example
Needs emails:read. address is one of your addresses on a verified domain, publicKey the armored OpenPGP public key and fingerprint its 40 upper-case hexadecimal characters. Answers 201 with the key.
curl -X POST "$OE/encryption/keys" -H "$AUTH" -H "Content-Type: application/json" \ -d '{ "address": "[email protected]", "publicKey": "-----BEGIN PGP PUBLIC KEY BLOCK-----\n…", "fingerprint": "3F2A9C1B7E4D5F60A1B2C3D4E5F60718293A4B5C" }'{ "object": "encryption_key", "id": "pgpk_8c1e4a7f2b9d3e6a0c5f1b28", "address": "[email protected]", "fingerprint": "3F2A9C1B7E4D5F60A1B2C3D4E5F60718293A4B5C", "publicKey": "-----BEGIN PGP PUBLIC KEY BLOCK-----\n…\n-----END PGP PUBLIC KEY BLOCK-----", "algorithm": "ed25519", "createdAt": "2026-09-30T09:12:44.000Z", "revokedAt": null, "revokedReason": null}An address keeps one live key. Publishing another is a 409 key_already_published, so to rotate, send the fingerprint of the live key in replaces and it is retired as the new one goes live. Mail already sealed to the old key stays readable only with the old private key.
An app asks for a verification code first: until it has verified one, the call answers 403 step_up_required. An API key is never asked.
Only the public key travels here. The private key stays on the device that made it.