---
title: PGP (Pretty Good Privacy)
slug: pgp-pretty-good-privacy
docTags: 
createdAt: 2026-02-24T10:06:59.703Z
---

[PGP (Pretty Good Privacy)](https://apps.make.com/crypto#encryptor-modules) is a cryptographic tool that encrypts a message using both symmetric and asymetric keys. A signature can be sent with the message to further ensure integrity and authentication.

The sender generates a temporary session key, a random number used only once. The session key is used as a symmetric key to encrypt the message. The sender uses a public key from the receiver to encrypt and send the session key. The sender transfers both the encrypted session key and the encrypted message to the receiver. Finally, the receiver uses their private key to decrypt the session key and then uses the session key to decrypt the message.

PGP keys in Make must have at least 2048 bits.

:::::ExpandableHeading
## Example: Encrypt and decrypt a PGP message with the Encryptor app

In this example we will:

1. Select content to encrypt and send to a recipient.
2. Generate a pair of private and public keys for the sender and recipient.
3. Encrypt the message.
4. Decrypt the message.

****
**Step 1: Select content to encrypt**

In this example, we set a variable `InitialText` with our content to send encrypted.&#x20;

In your scenario, you may have the content set another way or pulled from a different source.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/9wX8upJMbxY8yqAmPXHk--20260209-123012.png" size="60" width="724" height="555" position="flex-start" showCaption="false"}

**Step 2: Generate a pair of private and public keys for the sender and recipient:**

::::WorkflowBlock
:::WorkflowBlockItem
Go to a PGP key generator website of your choice. In this example, we use [this tool](https://pgpkeygenerator.com/).
:::

:::WorkflowBlockItem
Select or set the following values:
**Key Algorithm:** RSA (ECC can be used in Make as well)
**Key Size**: 2048 bits
**Name:** Enter a name to identify the use of the keys.
**Email:** Enter an email address.
**Passphrase:** Content used to protect the private key.&#x20;
**Expiration time:** Select when you want the keys to expire.
:::

:::WorkflowBlockItem
Click **Generate Keys** to get a pair of private and public RSA keys. If you are using a different tool to generate your keys, your steps may be different.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/gx3znp3EhD_KUkir1uEyE-20260210-133205.png" size="80" width="804" height="947" position="flex-start" showCaption="false"}
:::

:::WorkflowBlockItem
Copy the private and public keys and save them in a safe place. Additionally, remember the passphrase you used. You will need all three in Make.
:::
::::

:::hint{type="info"}
Both the sender and recipient need a set of private and public keys. The sender and recipient create these key pairs separately and share the public keys with each other.

To encrypt a message, the sender uses the recipient's public key. The recipient uses their private key to decrypt the message.

If the sender also uses their private key to sign the message (not required), the recipient needs the sender's public key to validate the signature.
:::



**Step 3:  Encrypt the message:**

::::WorkflowBlock
:::WorkflowBlockItem
Add the **Encryptor > Encrypt a PGP message** module to your scenario.
:::

:::WorkflowBlockItem
For the required **Public key**, click **Create a keychain**.
:::

:::WorkflowBlockItem
Enter a **Name** for your recipient's public key.
:::

:::WorkflowBlockItem
In the **Public Key** field, enter the recipient's public key.
:::

:::WorkflowBlockItem
Click **Create**.
:::

:::WorkflowBlockItem
Optional: If you want to attach a verifiable signature, click **Create a keychain** for the **Private key** field. Repeat steps 3, 4, and 5 to create the sender's private key.
:::

:::WorkflowBlockItem
In the **Message** field, map the value of the content you want to encrypt.
:::

:::WorkflowBlockItem
Click **Save**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/ztyb4KPV4X2JP-Ys6pkSG-20260210-151406.png" size="40" width="484" height="422" position="flex-start" showCaption="false"}
:::
::::

The ouput of this module is the encrypted message and a verifiable signature is included.&#x20;



**Step 4: Decrypt the message:**

::::WorkflowBlock
:::WorkflowBlockItem
Add the **Encryptor > Decrypt a PGP message** module to your scenario.
:::

:::WorkflowBlockItem
For the required **Private key**, click **Create a keychain**.
:::

:::WorkflowBlockItem
Enter a **Name** for your recipient's private key.
:::

:::WorkflowBlockItem
In the **Private Key** field, enter the recipient's private key.
:::

:::WorkflowBlockItem
Click **Create**.
:::

:::WorkflowBlockItem
Optional: If a verifiable signature was attached, click **Create a keychain** for the **Public key** field. Repeat steps 3, 4, and 5 to create the sendér's public key.
:::

:::WorkflowBlockItem
In the **Message** field, map the value of the content you want to decrypt.
:::

:::WorkflowBlockItem
For the **Verify signature with a public key&#x20;**&#x66;ield, click Yes or No. Click **Yes** if a signature is attached.
:::

:::WorkflowBlockItem
Click **Save**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/6ScVNNJ1b0h3WYdumM8Og-20260210-152412.png" size="40" width="485" height="527" position="flex-start" showCaption="false"}
:::
::::

The message is decrypted. The output of this module is the decrypted message and should match the original content set in the `InitialText` variable.

:::hint{type="warning"}
If the wrong private key is used, the message has been modified, or there is a problem with the sender's signature, the module outputs an error.
:::
:::::

