ドキュメント本文へスキップ
API

暗号化

このグループのすべてのオペレーションの、受け付ける内容、返す内容、返しうるエラー。

オペレーション

The OpenPGP public keys that let senders seal mail to an address, the directory the Encryption page of the app publishes to. Only public keys travel here: the private key stays on the device that made it, so nothing in this API can read sealed mail.

Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an app those of the person who connected it.

GET/encryption/keys

List your published keys

スコープemails:read読み取り

Every key published for an address in this workspace, newest first, retired ones included with revokedAt and revokedReason. Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an app those of the person who connected it. A key limited to particular addresses lists only the keys of those addresses.

Requires the emails:read scope.

戻り値

The keys, newest first.

エラー

どのオペレーションも返しうるエラー400401403404422500エラー一覧

ほかの提供先

SDK
encryption.listKeys()
CLI
openemail encryption list-keys
MCP
listEncryptionKeys

POST/encryption/keys

Publish a public key for an address

スコープemails:readデータを変更
確認コードが必要

Publishes an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. The address has to be an address of this workspace on a verified domain, switched on, and one you may use.

An address keeps one live key. Publishing another while one is live is a 409 key_already_published; to rotate, send the fingerprint of the live key in replaces, and it is retired as the new one is published. Mail already sealed to the old key stays readable only with the old private key.

Published keys belong to a person. A key reads and publishes the keys of the workspace owner, and an app those of the person who connected it.

Requires the emails:read scope.

リクエストボディ

addressstring必須

The address the key is for.

320文字まで
publicKeystring必須

The armored OpenPGP PUBLIC KEY BLOCK, up to 64 KB.

64〜65536文字パターン^-----BEGIN PGP PUBLIC KEY BLOCK-----[\s\S]+-----END PGP PUBLIC KEY BLOCK-----\s*$
fingerprintstring必須

The fingerprint of the key, 40 upper-case hexadecimal characters.

パターン^[0-9A-F]{40}$
algorithmstring

The algorithm of the key, such as ed25519, for display only.

32文字まで
replacesstring

The fingerprint of the live key this one replaces, to rotate it.

パターン^[0-9A-F]{40}$

戻り値

The key, now published.

エラー

403

The key lacks the scope, or may not send as that address.

step_up_required: the call was made with an OAuth access token that has not been verified in the last 60 minutes. Ask for a code with POST /security/step-up, send it to POST /security/step-up/verify, then repeat the call. The person can also choose Allow changes for 60 minutes on the app in Account settings, Connected apps, on the OpenEmail website. An API key is never asked for a code.

409

key_already_published: the address has a live key and replaces was not given, or this key was published for it before. domain_not_verified: the domain of the address is not verified yet.

どのオペレーションも返しうるエラー400401404422500エラー一覧

ほかの提供先

SDK
encryption.publishKey()
CLI
openemail encryption publish-key
MCP
publishEncryptionKey

GET/encryption/keys/lookup

Find the keys to seal mail to

スコープemails:send読み取り

The live public keys published for each address, the lookup the composer makes before it seals a message. An address with no key comes back with keys empty, so mail to it cannot be sealed. Only keys published by somebody who can read the address count, so a key a former member left behind is never offered.

Requires the emails:send scope.

クエリパラメーター

addressesstring必須

Comma-separated recipient addresses, at most 51. A display name in angle brackets is read as its address.

戻り値

One row per address asked about.

エラー

どのオペレーションも返しうるエラー400401403404422500エラー一覧

ほかの提供先

SDK
encryption.lookupKeys()
CLI
openemail encryption lookup-keys
MCP
lookupEncryptionKeys

オブジェクト

AddressKeysobject

objectstring必須
次のいずれか"address_keys"
addressstring必須

The address as it was read, lower-cased.

keysobject[]必須
fingerprintstring必須
publicKeystring必須
createdAtstring必須
形式date-time

AddressKeysListobject

objectstring
次のいずれか"list"

EncryptionKeyobject

objectstring必須
次のいずれか"encryption_key"
idstring必須

pgpk_ and 24 hex.

addressstring必須
fingerprintstring必須

40 upper-case hexadecimal characters.

publicKeystring必須

The armored OpenPGP PUBLIC KEY BLOCK.

algorithmstring必須
createdAtstring必須
形式date-time
revokedAtstring必須

When it was retired. Null on the live key.

null も可形式date-time
revokedReasonstring必須
null も可

EncryptionKeyListobject

objectstring
次のいずれか"list"