Import a public key that arrived in an email
When an external correspondent attaches their PGP public key, one tap stores it under their address so your replies are encrypted and signatures checked.
To encrypt a message to someone outside Private.Ki, you need their PGP public key. The usual way to get it is that they send it to you: as a .asc attachment or pasted into the text of a message. Private.Ki notices, marks the message, and offers to import the key with one tap. Once imported, the key is used automatically every time you write to that address.
Recognise a message with a key
- In the phone list, the row shows a green key glyph (Public key attached) before the sender's name.
- In the open message, a panel above the body reads Public key is attached, with an Import button.
The panel appears only on received messages, and only when the message contains a key: either an attachment of type application/pgp-keys or a block beginning -----BEGIN PGP PUBLIC KEY BLOCK----- in the text.
Import the key
- Open the message from the person whose key you want.
- Wait a moment. The panel briefly shows Checking… while the app compares the attached key with what you already hold for this address. If they match, it shows Imported with a check mark and you are done.Web & desktop screenshotAbove the body: Public key is attached — Import.This capture is produced by the screenshot pipeline and will appear here.
Above the body: Public key is attached — Import.Web & desktop iPhone screenshotAbove the body: Public key is attached — Import.Same screen as on the web, single column. This capture is produced by the screenshot pipeline and will appear here.Above the body: Public key is attached — Import.iPhone Android screenshotAbove the body: Public key is attached — Import.Same screen as on the web, single column. This capture is produced by the screenshot pipeline and will appear here.Above the body: Public key is attached — Import.Android - Tap Import. The button reads Saving and then Imported. The key is now stored under the sender's address.
- Check the result by starting a reply: the recipient chip gets a green padlock and Encrypt can be turned on. If the message was signed, reopening it now shows Signature verified instead of the amber triangle.
Imported keys are listed under Key management in Settings, each with its Email, Expires and Imported at date, a Preview and a delete button. You can also paste a key there by hand — see Import public keys.
Before you trust a key
A key in an email proves only that whoever sent the email had that key. For anything that matters, confirm the fingerprint with the person by another channel — a call, a chat, a card they gave you — before you rely on it. Private.Ki does not do this for you; it also does not check that the address inside the key matches the sender's address, so look at the Email field in Key management after importing if you are unsure.
If you later receive a different key from the same address, importing it replaces the old one. Treat an unexpected key change the way you would treat a stranger asking for the spare key to your house: ask why first.
Limits
You can hold up to 1,000 external keys. Above that, Import shows Limit reached. 1000 external keys maximum; delete keys you no longer need in Key management.
What our server sees
Cannot see
- The key itself or the address it belongs to — both are encrypted with your master key before upload, and the address is stored only as a keyed hash
Can see
- That an incoming message carried a public key
- How many external keys you hold, and when each was saved
Common questions
The panel says "Error importing key!"
The attachment could not be parsed as an OpenPGP public key, or the network request failed. Ask the sender for their key again, or paste the key block by hand in Key management, which reports what is wrong with it.
The sender pasted a key but no panel appears
The text must contain the complete block from -----BEGIN PGP PUBLIC KEY BLOCK----- to -----END PGP PUBLIC KEY BLOCK-----. A key inside a quoted reply, a screenshot or a .txt attachment is not detected — copy it and paste it into Key management instead.
Do I need this for other Private.Ki users?
No. Every Private.Ki account has a key that is found automatically. Importing is only for addresses outside Private.Ki.
Where is the imported key used?
For encrypting mail to that address, and for checking signatures on mail from it. Chat is between Private.Ki accounts only, so external keys play no part there.