暗号化
送信者があなた宛てのメールに封をするための公開鍵。
暗号化のツール
| ツール | 機能 |
|---|---|
| listEncryptionKeys | あなたのアドレスに公開された OpenPGP 公開鍵。有効なものも廃止されたものも新しい順に、フィンガープリント付きで示す。 |
| publishEncryptionKey | あなたのアドレスのアーマー形式の公開鍵を公開するか、replaces で有効な鍵をローテーションする。確認コードを求める。 |
| lookupEncryptionKeys | 各受信者アドレスの有効な公開鍵。メッセージに封をする前にコンポーザーが行う検索である。 |
公開された鍵はクライアントを接続した人に属する。読み取りと公開には emails:read、受信者の検索には emails:send が必要。一部のアドレスに限定されたクライアントは、それらのアドレスについてだけ一覧と公開を行う。
これらのツールを通るのは公開鍵だけである。秘密鍵はそれを作った端末に残るので、ここでは封をされたメールを読めない。アプリのチャットでは、頼まれていない限り公開の前に確認する。
このサーバーの一部のツールは、REST API が確認コードで保護している変更を行うため、同じコードを求めます。クライアントが直近 60 分以内にコードを確認しておらず、本人がアカウント → 接続済みアプリでそのクライアントに「60分間、変更を許可」を選んでもいない間、これらのツールは Refused (step_up_required): で始まる結果を返し、何も変更しません。emptyAudience がコードを求めることはありません。コードを求めるツールの一覧と、コードの要求と確認の方法は API の認証ページにあります。
リファレンス
listEncryptionKeys
The OpenPGP public keys published for your addresses in this workspace, the Encryption page of the app: live ones and retired ones, newest first, with their fingerprints. Published keys belong to the person who connected the client.
入力
入力はありません。
ほかの提供先
publishEncryptionKey
Publish an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. An address keeps one live key: to rotate, pass the fingerprint of the live key as replaces. Never invent a key; only publish one the person gave you.
- 確認コードが必要
POST /encryption/keys
入力
addressstring必須- 320文字まで
publicKeystring必須- 64〜65536文字パターン
^-----BEGIN PGP PUBLIC KEY BLOCK-----[\s\S]+-----END PGP PUBLIC KEY BLOCK-----\s*$ fingerprintstring必須- パターン
^[0-9A-F]{40}$ algorithmstring- 32文字まで
replacesstring- パターン
^[0-9A-F]{40}$
ほかの提供先
lookupEncryptionKeys
The live public keys published for each recipient address, the lookup the composer makes before it seals a message. An address with no key cannot be sent sealed mail.
入力
addressesstring[]必須- 1〜51件