Skip to navigation

Encrypted messages

View as Markdown

Use an encrypted message when your application encrypts message content and the receiving application is responsible for decrypting it. Set is_encrypted to true when calling POST /api/connect/messages:

POST /api/connect/messages
Authorization: Bearer YOUR_ACCESS_TOKEN
Content-Type: application/json
Accept: application/json
{
"to": "3f8f5f7c-5183-42f4-9d19-910a758838aa",
"type": "text",
"message": "ENCRYPTED_PAYLOAD",
"is_encrypted": true
}

Replace ENCRYPTED_PAYLOAD with the ciphertext produced by your application. The request uses the same authentication and recipient rules as a standard Connect API message.

What Zorvia does

When is_encrypted is true, Zorvia:

  • queues and sends the supplied payload;
  • marks the stored message as encrypted;
  • hides the message content from Zorvia inbox and API message views; and
  • excludes the content from message search.

Zorvia displays an Encrypted message hidden placeholder to workspace users instead of the payload.

Zorvia does not encrypt or decrypt the message value. Encrypt it before making the request, keep encryption keys outside Zorvia, and ensure the receiving application can decrypt the payload. Media URLs are public and must be protected separately.

Unencrypted messages

Omit is_encrypted or set it to false for a normal message. Zorvia then displays and indexes the message using its standard behavior.