---
title: "Encryption"
description: "The public keys that let senders seal mail to you."
url: "https://openemail.uk/docs/mcp/tools/encryption"
area: "MCP server"
category: "Tools"
---

# Encryption

The public keys that let senders seal mail to you.

## Encryption tools

| Tool | What it does |
| --- | --- |
| listEncryptionKeys | The OpenPGP public keys published for your addresses, live and retired, newest first, with their fingerprints. |
| publishEncryptionKey | Publish an armored public key for one of your addresses, or rotate the live one with `replaces`. It asks for a verification code. |
| lookupEncryptionKeys | The live public keys of each recipient address, the lookup the composer makes before it seals a message. |

> Published keys belong to the person who connected the client. Reading and publishing need `emails:read`, and looking up recipients needs `emails:send`. A client limited to some addresses lists and publishes only for those.

> Only public keys pass through these tools. The private key stays on the device that made it, so nothing here can read sealed mail. In the app’s chat, publishing asks first unless you asked for it.

> Some tools on this server make a change the REST API guards with a verification code, and ask for the same code. Until the client has verified a code in the last 60 minutes, or the person has chosen Allow changes for 60 minutes on it in Account → Connected apps, such a tool answers with a result that starts `Refused (step_up_required):` and changes nothing. `emptyAudience` never asks for a code. The API Authentication page lists every tool that asks, and shows how to ask for a code and verify it.

## Reference

### `listEncryptionKeys`

The OpenPGP public keys published for your addresses in this workspace, the Encryption page of the app: live ones and retired ones, newest first, with their fingerprints. Published keys belong to the person who connected the client.

- Scopes: `emails:read`.
- The app's assistant runs it without asking.
- Toolkit: `workspace`.

**Inputs**

Takes no input.

Also available in: API [`GET /encryption/keys`](https://openemail.uk/docs/api/reference/encryption#get-encryption-keys); SDK [`encryption.listKeys()`](https://openemail.uk/docs/sdk/reference/encryption#listKeys).

### `publishEncryptionKey`

Publish an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. An address keeps one live key: to rotate, pass the fingerprint of the live key as replaces. Never invent a key; only publish one the person gave you.

- Scopes: `emails:read`.
- The app's assistant asks first unless you asked for it.
- Asks for a verification code, the same as [`POST /encryption/keys`](https://openemail.uk/docs/api/reference/encryption#post-encryption-keys).
- Toolkit: `workspace`.

**Inputs**

- `address` (`string`, required, up to 320 characters)
- `publicKey` (`string`, required, 64 to 65536 characters, pattern `^-----BEGIN PGP PUBLIC KEY BLOCK-----[\s\S]+-----END PGP PUBLIC KEY BLOCK-----\s*$`)
- `fingerprint` (`string`, required, pattern `^[0-9A-F]{40}$`)
- `algorithm` (`string`, up to 32 characters)
- `replaces` (`string`, pattern `^[0-9A-F]{40}$`)

Also available in: API [`POST /encryption/keys`](https://openemail.uk/docs/api/reference/encryption#post-encryption-keys); SDK [`encryption.publishKey()`](https://openemail.uk/docs/sdk/reference/encryption#publishKey).

### `lookupEncryptionKeys`

The live public keys published for each recipient address, the lookup the composer makes before it seals a message. An address with no key cannot be sent sealed mail.

- Scopes: `emails:send`.
- The app's assistant runs it without asking.
- Toolkit: `workspace`.

**Inputs**

- `addresses` (`string[]`, required, 1 to 51 items)

Also available in: API [`GET /encryption/keys/lookup`](https://openemail.uk/docs/api/reference/encryption#get-encryption-keys-lookup); SDK [`encryption.lookupKeys()`](https://openemail.uk/docs/sdk/reference/encryption#lookupKeys).
