Skip to main content

Overview

The MLE Public Keys API allows you to manage your public keys used for Message Level Encryption (MLE) with Method’s API. You can register, retrieve, and delete your public keys through these endpoints. Two key uses are supported:
  • Encryption keys (use: "enc", alg: "RSA-OAEP-256") are used by Method to encrypt responses to you. Every MLE integration needs one.
  • Signing keys (use: "sig", alg: "RS256") are used by Method to verify the signature on your requests. These are required only on the signed MLE path.

Key Management Operations

Key Registration Types

You can register your public key using two methods:

Direct Registration

Post your public key directly to Method with the JWK fields.

Well-Known Endpoint

Provide a URL where Method can dynamically fetch your JWKS (JSON Web Key Set).
Important: Each key ID (kid) can only be registered once using either method. If you have a public key available through your well-known endpoint, you should not register the same public key through direct registration, even if you change the kid.
A team may use both mechanisms together, provided each kid is registered through only one of them. A single well-known endpoint can serve both your encryption key and your signing key.

Key Status

Your registered keys can have the following statuses:
  • active: The key is in service for its declared use — encrypting responses to you for use: "enc", or verifying your request signatures for use: "sig"
  • disabled: The key has been deleted and cannot be used
Keys also accept optional iat, nbf, and exp claims. Method preserves them and uses them for key selection and validity checks on the signed MLE path.

Authentication

All MLE Public Keys API endpoints require authentication using your Method API key: