Skip to main content
This endpoint returns encrypted messages waiting for one recipient DID. It does not decrypt them. Because a DID is public, the DID alone is not authorization. Your client must sign a Cache retrieval proof with an Ed25519 verification method authorized by the recipient’s OpenPayloadCacheService.

Build the signed proof

Construct this exact UTF-8 string. Do not add a trailing newline:
Sign those bytes with the authorized Ed25519 private key, then Base64-encode the signature. The timestamp may be ISO-8601, epoch milliseconds, or epoch seconds and must fall within the Cache’s permitted clock skew. Never reuse a nonce with the same operation, DID, and key.

Request

string
required
The recipient DID.
string
required
The authorized OpenPayloadCacheService ID.
string
required
The exact public Cache endpoint bound into the signature.
string
required
The authorized Ed25519 verification-method ID.
string
required
The signed timestamp.
string
required
A new replay-resistant nonce.
string
required
Base64 Ed25519 signature over the exact proof text.

Response

200 Response
This response example shows ordinary DID-service fall-through. A policy-delivered envelope may also contain opaque network-managed policy provenance. Treat it as transport metadata; do not modify it or resubmit it as client authorization.

After retrieval

  1. Verify the envelope and any sender signature your application requires.
  2. Store it safely on the recipient device.
  3. Decrypt it locally.
  4. Record the Cache endpoint from which this copy was retrieved.
  5. Acknowledge it at that Cache only after you no longer need the encrypted copy.
A Relay result can include observed Store endpoints in details.accepted_caches and Archive endpoints in details.accepted_archives. Those lists do not include later accepts after a Forward step and are not embedded in the stored envelope for the recipient. If the recipient retrieves replicas from more than one Cache, it acknowledges each copy at the Cache that returned it.

Straight to the point

Proof operation: pull
Proof device: empty
Proof subject: *