Skip to content

End-to-End Encryption

Every read is encrypted in transit (TLS) and at rest. End-to-end encryption adds two things: the drawing is stored encrypted to a key made for that one request, and the files a read returns are encrypted to your key, so only you can open them.

What is encrypted

Without end-to-end encryption With end-to-end encryption
The drawing, while it waits to be read Encrypted at rest Also encrypted to a key pair made for this request alone
Result files behind a payload_url (sheet and view images, a redacted drawing) Encrypted at rest Encrypted to your public key, when you send one: only your private key opens them
Structured results (payload_dict) Sent over TLS Sent over TLS, not encrypted to your key
Replaying the result of an identical earlier request Possible Never: a request with end-to-end encryption is not kept for replay

To read the drawing, Werk24 decrypts it for the duration of the read.

Switching it on

End-to-end encryption has to be switched on for your account; until it is, the server does not make a key pair for your requests. It is an add-on on the plans that take add-ons, or part of a contract; werk24.io/pricing lists them.

With the Python client

Make a key pair once and keep the private key and its passphrase to yourself. Then pass both halves to every read:

from werk24 import AskSheetImages, Werk24Client
from werk24.models.v2.internal import EncryptionKeys
from werk24.utils.crypt import generate_new_key_pair

passphrase = b"<a passphrase you keep>"
private_key_pem, public_key_pem = generate_new_key_pair(passphrase)

keys = EncryptionKeys(
    client_public_key_pem=public_key_pem,
    client_private_key_pem=private_key_pem,
    client_private_key_passphrase=passphrase,
)


async def read(path: str) -> None:
    async with Werk24Client() as client:
        with open(path, "rb") as drawing:
            async for message in client.read_drawing(
                drawing, [AskSheetImages()], encryption_keys=keys
            ):
                # payload_bytes is already decrypted with your private key.
                print(message.message_subtype, len(message.payload_bytes or b""))

With end-to-end encryption on the account, the client also encrypts the drawing to the key the server made for the request before uploading it. The client sends your public key whenever you pass encryption_keys, so result files are encrypted to it either way.

Always pass encryption_keys once it is switched on

With end-to-end encryption on the account, a read without encryption_keys fails: the client still encrypts the drawing to the server's key, but the server can only use that key when your public key comes with the read.

With the HTTP API

Send your PEM public key in the public_key form field of the HTTP API submit. On this route it is used only when end-to-end encryption is switched on for your account; otherwise it is ignored and result files are not encrypted to it. With it switched on but no public_key sent, result files are not encrypted to a key of yours either. Werk24 encrypts the drawing it received on arrival, before storing it.

Decrypt a downloaded file with your private key, for example with werk24.utils.crypt.decrypt_with_private_key(private_key_pem, passphrase, data).