---
title: "Publish a public key"
description: "Lets senders seal mail to one of your addresses."
url: "https://openemail.uk/docs/api/encryption/publish-key"
area: "API"
category: "Mailbox"
---

# Publish a public key

Lets senders seal mail to one of your addresses.

`POST /encryption/keys`

## POST /encryption/keys

Lets senders seal mail to one of your addresses.

## Example

Needs `emails:read`. `address` is one of your addresses on a verified domain, `publicKey` the armored OpenPGP public key and `fingerprint` its 40 upper-case hexadecimal characters. Answers 201 with the key.

**curl**

```
curl -X POST "$OE/encryption/keys" -H "$AUTH" -H "Content-Type: application/json" \
  -d '{ "address": "ana@acme.com", "publicKey": "-----BEGIN PGP PUBLIC KEY BLOCK-----\n…", "fingerprint": "3F2A9C1B7E4D5F60A1B2C3D4E5F60718293A4B5C" }'
```

**Response**

```
{
  "object": "encryption_key",
  "id": "pgpk_8c1e4a7f2b9d3e6a0c5f1b28",
  "address": "ana@acme.com",
  "fingerprint": "3F2A9C1B7E4D5F60A1B2C3D4E5F60718293A4B5C",
  "publicKey": "-----BEGIN PGP PUBLIC KEY BLOCK-----\n…\n-----END PGP PUBLIC KEY BLOCK-----",
  "algorithm": "ed25519",
  "createdAt": "2026-09-30T09:12:44.000Z",
  "revokedAt": null,
  "revokedReason": null
}
```

> An address keeps one live key. Publishing another is a 409 `key_already_published`, so to rotate, send the fingerprint of the live key in `replaces` and it is retired as the new one goes live. Mail already sealed to the old key stays readable only with the old private key.

> An app asks for a verification code first: until it has verified one, the call answers 403 `step_up_required`. An API key is never asked.

> Only the public key travels here. The private key stays on the device that made it.

## Reference

- [`POST /encryption/keys`](https://openemail.uk/docs/api/reference/encryption#post-encryption-keys): full reference
