Skip to main content
Encryption keys reach your app in the callback fragment, not through an API call. The only app-facing encryption endpoint is the public-key lookup for e2ee:asymmetric apps. The SDK wraps it as lookupAppPublicKeyByHandle and lookupAppUserByPublicKey.

GET /api/encryption/app-lookup

Public. No credentials required.
string
required
Your app’s client ID. Results are limited to identities that authorized this app.
string
Look up an identity by handle. Case-insensitive.
string
Look up the identity that owns an app public key (base64 SPKI).
Provide exactly one of handle or public_key.
Errors:
  • 400 both or neither of handle and public_key, or a malformed public key
  • 404 app not found
  • 404 identity not found, it has not signed in to this app, or it has no app public key yet
  • 429 rate limited
A 404 for an existing user usually means they have not used your app with e2ee:asymmetric. Ask them to sign in to your app rather than creating keys on their behalf.
Last modified on September 28, 2026