Skip to the documentation
MCP server

Encryption

The public keys that let senders seal mail to you.

Encryption tools

ToolWhat it does
listEncryptionKeysThe OpenPGP public keys published for your addresses, live and retired, newest first, with their fingerprints.
publishEncryptionKeyPublish an armored public key for one of your addresses, or rotate the live one with replaces. It asks for a verification code.
lookupEncryptionKeysThe live public keys of each recipient address, the lookup the composer makes before it seals a message.

Published keys belong to the person who connected the client. Reading and publishing need emails:read, and looking up recipients needs emails:send. A client limited to some addresses lists and publishes only for those.

Only public keys pass through these tools. The private key stays on the device that made it, so nothing here can read sealed mail. In the app’s chat, publishing asks first unless you asked for it.

Some tools on this server make a change the REST API guards with a verification code, and ask for the same code. Until the client has verified a code in the last 60 minutes, or the person has chosen Allow changes for 60 minutes on it in Account → Connected apps, such a tool answers with a result that starts Refused (step_up_required): and changes nothing. emptyAudience never asks for a code. The API Authentication page lists every tool that asks, and shows how to ask for a code and verify it.

Reference

listEncryptionKeys

Scopesemails:readThe app's assistant runs it without askingToolkitworkspace

The OpenPGP public keys published for your addresses in this workspace, the Encryption page of the app: live ones and retired ones, newest first, with their fingerprints. Published keys belong to the person who connected the client.

Inputs

Takes no input.

Also available in

API
GET /encryption/keys
SDK
encryption.listKeys()

publishEncryptionKey

Scopesemails:readThe app's assistant asks first unless you asked for itToolkitworkspace

Publish an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. An address keeps one live key: to rotate, pass the fingerprint of the live key as replaces. Never invent a key; only publish one the person gave you.

Inputs

addressstringRequired
Up to 320 characters
publicKeystringRequired
64 to 65536 charactersPattern^-----BEGIN PGP PUBLIC KEY BLOCK-----[\s\S]+-----END PGP PUBLIC KEY BLOCK-----\s*$
fingerprintstringRequired
Pattern^[0-9A-F]{40}$
algorithmstring
Up to 32 characters
replacesstring
Pattern^[0-9A-F]{40}$

Also available in

API
POST /encryption/keys
SDK
encryption.publishKey()

lookupEncryptionKeys

Scopesemails:sendThe app's assistant runs it without askingToolkitworkspace

The live public keys published for each recipient address, the lookup the composer makes before it seals a message. An address with no key cannot be sent sealed mail.

Inputs

addressesstring[]Required
1 to 51 items

Also available in

API
GET /encryption/keys/lookup
SDK
encryption.lookupKeys()