ドキュメント本文へスキップ
Python

openemail.encryption

この名前空間のすべてのメソッドの、シグネチャ、パラメーター、戻り値、例。

メソッド

The OpenPGP public keys that let senders seal mail to your addresses: list the ones you published, publish or rotate one, and look up the keys of recipients before sealing a message.

encryption.list_keys()

List your published encryption keys

スコープemails:read
シグネチャ
def list_keys(    *,    api_key: str | None = None,    timeout: float | None = None,) -> builtins.list[EncryptionKeyResource]

Returns every OpenPGP public key published for an address in this workspace as one list, newest first, as the Encryption page of the app shows them. Retired keys are included, with revokedAt and revokedReason set, and the live key of each address has revokedAt set to None.

Published keys belong to a person. An API key reads and publishes the keys of the workspace owner, and an access token those of the person who connected the app. An API key limited to particular addresses lists only the keys of those addresses.

パラメーター

api_keystr

Overrides the client's API key for this call only.

timeoutfloat

Seconds this call may take, the response included, before it raises OpenEmailNetworkError with is_timeout. It overrides the client's timeout for this call, and 0 turns the limit off.

戻り値

list[EncryptionKeyResource], each with id, address, fingerprint, publicKey, algorithm, createdAt, revokedAt and revokedReason.

例

from openemail import openemail keys = openemail.encryption.list_keys() for key in keys:    state = 'live' if key['revokedAt'] is None else 'retired'    print(key['address'], key['fingerprint'], state)

注意事項

  • Only public keys travel through the API. The private key stays on the device that made it.

ほかの提供先

API
GET /encryption/keys
TypeScript
encryption.listKeys()
Ruby
encryption.list_keys
CLI
openemail encryption list-keys

encryption.publish_key()

Publish a public key for one of your addresses

スコープemails:read
シグネチャ
def publish_key(    body: EncryptionKeyPublish,    *,    api_key: str | None = None,    timeout: float | None = None,) -> EncryptionKeyResource

Publishes an armored OpenPGP public key for one of your addresses, so that senders can seal mail to it, as Publish on the Encryption page does. The address has to be an address of this workspace on a verified domain, switched on, and one you may use.

An address keeps one live key. To rotate, pass the fingerprint of the live key as replaces: it is retired as the new key is published. Mail already sealed to the old key stays readable only with the old private key.

Published keys belong to a person. An API key reads and publishes the keys of the workspace owner, and an access token those of the person who connected the app.

パラメーター

body['address']str必須

The address the key is for.

body['publicKey']str必須

The armored OpenPGP PUBLIC KEY BLOCK, up to 64 KB.

body['fingerprint']str必須

The fingerprint of the key, 40 upper-case hexadecimal characters.

body['algorithm']str

The algorithm of the key, such as ed25519, for display only.

body['replaces']str

The fingerprint of the live key this one replaces, to rotate it.

api_keystr

Overrides the client's API key for this call only.

timeoutfloat

Seconds this call may take, the response included, before it raises OpenEmailNetworkError with is_timeout. It overrides the client's timeout for this call, and 0 turns the limit off.

戻り値

EncryptionKeyResource for the key, now live.

例

from openemail import openemail armored = (    '-----BEGIN PGP PUBLIC KEY BLOCK-----\n\n'    'mDMEZxN4mBYJKwYBBAHaRw8BAQdAv2y8nV5k1o8Wq3dJ0rJmZzJ9T0p6l4x2c1bC\n'    '-----END PGP PUBLIC KEY BLOCK-----\n') key = openemail.encryption.publish_key(    {        'address': '[email protected]',        'publicKey': armored,        'fingerprint': '3F2A9C1B7E4D5F60A1B2C3D4E5F60718293A4B5C',    }) print(key['id'], key['address'], key['createdAt'])

注意事項

  • With an OAuth access token it asks for a verification code: until the app has verified one, it is refused with 403 step_up_required, and is_step_up_required on the error says so. An API key is never asked.

  • A second key while one is live, without replaces, is 409 key_already_published, and so is a key that was published for the address before. An address on a domain that is not verified yet is 409 domain_not_verified, and an address you may not use is 403 address_not_allowed.

  • The SDK does not retry it.

ほかの提供先

API
POST /encryption/keys
TypeScript
encryption.publishKey()
Ruby
encryption.publish_key
CLI
openemail encryption publish-key

encryption.lookup_keys()

Find the keys to seal mail to

スコープemails:send
シグネチャ
def lookup_keys(    *,    addresses: Sequence[str],    api_key: str | None = None,    timeout: float | None = None,) -> builtins.list[EncryptionKeyLookupResource]

Returns the live public keys published for each recipient address, the lookup the composer makes before it seals a message. An address with no key comes back with keys empty, so mail to it cannot be sealed. Only keys published by somebody who can read the address count.

パラメーター

addressesSequence[str]必須

Recipient addresses, at most 51, sent comma-separated.

api_keystr

Overrides the client's API key for this call only.

timeoutfloat

Seconds this call may take, the response included, before it raises OpenEmailNetworkError with is_timeout. It overrides the client's timeout for this call, and 0 turns the limit off.

戻り値

list[EncryptionKeyLookupResource], one per address, each with address and keys, every key with fingerprint, publicKey and createdAt.

例

from openemail import openemail found = openemail.encryption.lookup_keys(addresses=['[email protected]', '[email protected]']) for entry in found:    print(entry['address'], [key['fingerprint'] for key in entry['keys']]) if not all(entry['keys'] for entry in found):    print('Some recipients have no key, so the message cannot be sealed')

注意事項

  • A display name in angle brackets is read as its address.

ほかの提供先

API
GET /encryption/keys/lookup
TypeScript
encryption.lookupKeys()
Ruby
encryption.lookup_keys
CLI
openemail encryption lookup-keys