Encryption
The public keys that let senders seal mail to you.
Encryption tools
| Tool | What it does |
|---|---|
| listEncryptionKeys | The OpenPGP public keys published for your addresses, live and retired, newest first, with their fingerprints. |
| publishEncryptionKey | Publish an armored public key for one of your addresses, or rotate the live one with replaces. It asks for a verification code. |
| lookupEncryptionKeys | The live public keys of each recipient address, the lookup the composer makes before it seals a message. |
Published keys belong to the person who connected the client. Reading and publishing need emails:read, and looking up recipients needs emails:send. A client limited to some addresses lists and publishes only for those.
Only public keys pass through these tools. The private key stays on the device that made it, so nothing here can read sealed mail. In the app’s chat, publishing asks first unless you asked for it.
Some tools on this server make a change the REST API guards with a verification code, and ask for the same code. Until the client has verified a code in the last 60 minutes, or the person has chosen Allow changes for 60 minutes on it in Account → Connected apps, such a tool answers with a result that starts Refused (step_up_required): and changes nothing. emptyAudience never asks for a code. The API Authentication page lists every tool that asks, and shows how to ask for a code and verify it.
Reference
listEncryptionKeys
The OpenPGP public keys published for your addresses in this workspace, the Encryption page of the app: live ones and retired ones, newest first, with their fingerprints. Published keys belong to the person who connected the client.
Inputs
Takes no input.
Also available in
publishEncryptionKey
Publish an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. An address keeps one live key: to rotate, pass the fingerprint of the live key as replaces. Never invent a key; only publish one the person gave you.
- Asks for a verification code
POST /encryption/keys
Inputs
addressstringRequired- Up to 320 characters
publicKeystringRequired- 64 to 65536 charactersPattern
^-----BEGIN PGP PUBLIC KEY BLOCK-----[\s\S]+-----END PGP PUBLIC KEY BLOCK-----\s*$ fingerprintstringRequired- Pattern
^[0-9A-F]{40}$ algorithmstring- Up to 32 characters
replacesstring- Pattern
^[0-9A-F]{40}$
Also available in
lookupEncryptionKeys
The live public keys published for each recipient address, the lookup the composer makes before it seals a message. An address with no key cannot be sent sealed mail.
Inputs
addressesstring[]Required- 1 to 51 items