Aller à la documentation
Go

client.Encryption

Chaque méthode de cet espace de noms : sa signature, ses paramètres, ce qu'elle retourne et un exemple.

Méthodes

The OpenPGP public keys that let senders seal mail to your addresses: list the ones you published, publish or rotate one, and look up the keys of recipients before sealing a message.

Encryption.ListKeys

List your published encryption keys

Portéesemails:read
Signature
ListKeys(ctx context.Context, opts ...openemail.RequestOption) ([]openemail.Object, error)

Returns every OpenPGP public key published for an address in this workspace, newest first, the Encryption page of the app. Retired keys are included, with revokedAt and revokedReason set, and the live key of each address has revokedAt null.

Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an access token those of the person who connected the app. A key limited to particular addresses lists only the keys of those addresses.

Paramètres

openemail.WithAPIKeystring

Overrides the client's API key for this call only.

Retourne

A []openemail.Object, each with id, address, fingerprint, publicKey, algorithm, createdAt, revokedAt and revokedReason.

Exemple

keys, err := client.Encryption.ListKeys(ctx)if err != nil {	return err} for _, key := range keys {	fmt.Println(key.String("address"), key.String("fingerprint"), key.String("revokedAt"))}

Remarques

  • Only public keys travel through the API. The private key stays on the device that made it.

Aussi disponible dans

API
GET /encryption/keys
TypeScript
encryption.listKeys()
Python
encryption.list_keys()
Ruby
encryption.list_keys
PHP
encryption->listKeys
Java
encryption().listKeys
C#
Encryption.ListKeysAsync
CLI
openemail encryption list-keys

Encryption.PublishKey

Publish a public key for one of your addresses

Portéesemails:read
Signature
PublishKey(ctx context.Context, body openemail.Body, opts ...openemail.RequestOption) (openemail.Object, error)

Publishes an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. The address has to be an address of this workspace on a verified domain, switched on, and one you may use.

An address keeps one live key. To rotate, pass the fingerprint of the live key as replaces: it is retired as the new key is published. Mail already sealed to the old key stays readable only with the old private key.

Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an access token those of the person who connected the app.

Paramètres

addressstringObligatoire

The address the key is for.

publicKeystringObligatoire

The armored OpenPGP PUBLIC KEY BLOCK, up to 64 KB.

fingerprintstringObligatoire

The fingerprint of the key, 40 upper-case hexadecimal characters.

algorithmstring

The algorithm of the key, such as ed25519, for display only.

replacesstring

The fingerprint of the live key this one replaces, to rotate it.

openemail.WithAPIKeystring

Overrides the client's API key for this call only.

Retourne

An openemail.Object for the key, now live.

Exemple

armored, err := os.ReadFile("ana.asc")if err != nil {	return err} key, err := client.Encryption.PublishKey(ctx, openemail.Body{	"address":     "[email protected]",	"publicKey":   string(armored),	"fingerprint": "3F2A9C1B7E4D5F60A1B2C3D4E5F60718293A4B5C",})if err != nil {	return err} fmt.Println(key.ID())

Remarques

  • With an OAuth access token it asks for a verification code: until the app has verified one, it is refused with 403 step_up_required. An API key is never asked.

  • A second key while one is live, without replaces, is 409 key_already_published, and so is a key that was published for the address before. An address on a domain that is not verified yet is 409 domain_not_verified, and an address you may not use is 403 address_not_allowed.

  • The SDK does not retry it.

Aussi disponible dans

API
POST /encryption/keys
TypeScript
encryption.publishKey()
Python
encryption.publish_key()
Ruby
encryption.publish_key
PHP
encryption->publishKey
Java
encryption().publishKey
C#
Encryption.PublishKeyAsync
CLI
openemail encryption publish-key

Encryption.LookupKeys

Find the keys to seal mail to

Portéesemails:send
Signature
LookupKeys(ctx context.Context, addresses []string, opts ...openemail.RequestOption) ([]openemail.Object, error)

Returns the live public keys published for each recipient address, the lookup the composer makes before it seals a message. An address with no key comes back with keys empty, so mail to it cannot be sealed. Only keys published by somebody who can read the address count.

Paramètres

addresses[]stringObligatoire

Recipient addresses, at most 51, sent comma-separated.

openemail.WithAPIKeystring

Overrides the client's API key for this call only.

Retourne

A []openemail.Object, one per address, each with address and keys, every key with fingerprint, publicKey and createdAt.

Exemple

found, err := client.Encryption.LookupKeys(ctx, []string{"[email protected]", "[email protected]"})if err != nil {	return err} for _, lookup := range found {	fmt.Println(lookup.String("address"), lookup.String("object"))}

Remarques

  • A display name in angle brackets is read as its address.

Aussi disponible dans

API
GET /encryption/keys/lookup
TypeScript
encryption.lookupKeys()
Python
encryption.lookup_keys()
Ruby
encryption.lookup_keys
PHP
encryption->lookupKeys
Java
encryption().lookupKeys
C#
Encryption.LookupKeysAsync
CLI
openemail encryption lookup-keys