- HTTP request
- Path parameters
- Query parameters
- Request body
- Response body
- Authorization scopes
- ChainValidation
- Try it!
Creates and uploads a client-side encryption S/MIME public key certificate chain and private key metadata for the authenticated user.
For administrators managing identities and keypairs for users in their organization, requests require authorization with a service account that has domain-wide delegation authority to impersonate users with the https://www.googleapis.com/auth/gmail.settings.basic scope.
For users managing their own identities and keypairs, requests require hardware key encryption turned on and configured.
HTTP request
POST https://gmail.googleapis.com/gmail/v1/users/{userId}/settings/cse/keypairs
The URL uses gRPC Transcoding syntax.
Path parameters
| Parameters | |
|---|---|
userId |
The requester's primary email address. To indicate the authenticated user, you can use the special value |
Query parameters
| Parameters | |
|---|---|
chainValidation |
The type of certificate chain validation to perform at creation. The request will be rejected if the uploaded chain fails to satisfy the requested validation checks. When unspecified, this parameter defaults to |
Request body
The request body contains an instance of CseKeyPair.
Response body
If successful, the response body contains a newly created instance of CseKeyPair.
Authorization scopes
Requires one of the following OAuth scopes:
https://www.googleapis.com/auth/gmail.settings.basichttps://www.googleapis.com/auth/gmail.settings.sharing
For more information, see the Authorization guide.
ChainValidation
The type of certificate chain validation to perform at key pair creation.
| Enums | |
|---|---|
all |
Enable all certificate chain validation and certificate revocation checks. Recommended for normal use. |
none |
Disable all certificate chain validation and certificate revocation checks. This may be useful when deliberately creating key pairs with invalid, out-of-use certificate chains to be used only for decryption of historical S/MIME messages. Key pairs created with invalid or revoked certificates cannot be used in a CseIdentity object. |