Retrieves an existing client-side encryption key pair.
For administrators managing identities and keypairs for users in their organization, requests require authorization with a service account
that has domain-wide delegation authority
to impersonate users with the https://www.googleapis.com/auth/gmail.settings.basic
scope.
For users managing their own identities and keypairs, requests require hardware key encryption turned on and configured.
HTTP request
GET https://gmail.googleapis.com/gmail/v1/users/{userId}/settings/cse/keypairs/{keyPairId}
The URL uses gRPC Transcoding syntax.
Path parameters
| Parameters | |
|---|---|
userId
|
The requester's primary email address. To indicate the authenticated user, you can use the special value |
keyPairId
|
The identifier of the key pair to retrieve. |
Request body
The request body must be empty.
Response body
If successful, the response body contains an instance of CseKeyPair
.
Authorization scopes
Requires one of the following OAuth scopes:
-
https://www.googleapis.com/auth/gmail.settings.basic -
https://mail.google.com/ -
https://www.googleapis.com/auth/gmail.modify -
https://www.googleapis.com/auth/gmail.readonly -
https://www.googleapis.com/auth/gmail.settings.sharing
For more information, see the Authorization guide .

