---
title: "Register a Flows encryption key"
method: POST
path: "/v1/whatsapp/flows/encryption-key"
tags: ["WhatsApp Flows"]
---

# Register a Flows encryption key

`POST /v1/whatsapp/flows/encryption-key`

Register (or replace) the RSA business public key for WhatsApp Flows endpoint
encryption on the phone number. Uploading a new key replaces the previous one:
only one key is active per phone number. The corresponding private key must be
served by the flow's endpoint, or endpoint-backed flows (flow_action:
data_exchange) will fail at runtime even though the key is registered.

## Request body

- object
  - `accountId` string, required — WhatsApp social account ID
  - `businessPublicKey` string, required — RSA public key in PEM format. Rejected if it is a private key or not a valid RSA public key PEM.

## Response `200`

Encryption key registered

- object
  - `success` boolean

## Other responses

- `400` — Invalid request
- `401` — Unauthorized
- `403` — The API key is a restricted key (zrk_ prefix) and may not perform this operation. Three cases. (1) The operation's resource group (see the operation's x-resource-group) is disabled on the key: fix it by creating a key with the group enabled in the dashboard API keys tab and revoking the old one. (2) The operation is admin-plane (x-resource-group admin-plane: API keys, invites, connected apps, member identity), which is never grantable to restricted keys; the error reads "Restricted API keys cannot manage API keys, invites, or member identity." and the fix is a full-access key or the dashboard, never a new restricted key. (3) On webhook subscription writes, delivery-log reads and replays, a named event maps to a resource group the key does not hold, so a restricted key can never create or edit a subscription broader than itself (a no-messages key cannot subscribe to, test-fire, redeliver or read logs for message.* events).
- `404` — WhatsApp account not found
- `502` — Meta rejected the request

## Changes

- **2026-09-04** `2d81890d21d5` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/zernio/apis/zernio-api/changes/v1/whatsapp/flows/encryption-key/post.md)

---

[API](https://skmtc.dev/zernio/apis/zernio-api.md) · [All operations](https://skmtc.dev/zernio/apis/zernio-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/zernio/zernio-api/revisions/2d81890d21d5/schema)
