Source
Encryption & access control — found from sitemap — Rocket.Chat
Checked for Rocket.Chat on 5 Oct 2026
- Page
- https://docs.rocket.chat/docs/end-to-end-encryption-specifications
- Checked
- 5 Oct 2026, 04:41 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:951f48911ac1266b4c4f0ed5585439f122abe1cfe831b05a1795919bf8ed7af6
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
E2ee scope Report an error
“Rocket.Chat enhances security by supporting E2EE for private and direct conversations.”
-
E2ee search limitation Report an error
“Encrypted messages will not appear in search results”
-
E2ee audit limitation Report an error
“Encrypted content cannot be audited”
-
E2ee bot limitation Report an error
“Bots may not be able to access encrypted messages unless explicitly supported”
-
E2ee master key Report an error
“This phrase is used to derive a 256-bit AES-GCM Master Key through a secure key-derivation process.”
-
E2ee key storage Report an error
“The public key (Ku) is stored on the server, while the private key (Kr) is first encrypted using the AES-GCM Master Key derived from the user’s mnemonic recovery phrase and then sent to the server for secure storage in the user record.”
-
E2ee algorithms Report an error
“Client key pair: RSA-OAEP, 2048-bit (SHA-256) Master key: AES-GCM, 256-bit, PBKDF2 with 100,000 iterations and random salt Session key: AES-GCM, 256-bit”
-
E2ee push encrypted payload Report an error
“Push notifications for messages in E2EE rooms contain only the encrypted payload of the message. Decryption of this payload occurs locally on mobile clients (iOS and Android) before the message is displayed.”
-
E2ee push community edition Report an error
“This feature is available in the Community Edition.”
-
E2ee push fetch full mode Report an error
“For enhanced security, premium plans (opens in new tab) introduce an additional push notification mode: Fetch full message content from the server on receipt”
-
E2ee push fetch full gateway content Report an error
“The push gateways (e.g., Google, Apple, or others) do not transmit any message content, encrypted or otherwise.”
-
E2ee room key reset Report an error
“Rocket.Chat supports resetting encryption keys for a conversation. When a user resets the Session Keys for a room, all participants’ previous keys are removed from their subscriptions, allowing them to receive a new key and continue the conversation seamlessly.”
-
E2ee room key reset permission Report an error
“Only users with the appropriate authorization level (for example, room owners or administrators) can initiate a room key reset. Regular users cannot trigger this operation.”
-
E2ee old room keys limit Report an error
“The oldRoomKeys array is limited to 10 elements. When this limit is exceeded, the oldest key is deleted, which may render some older messages indecipherable.”
-
E2ee key export Report an error
“Rocket.Chat does not export encryption keys directly for security reasons. Users should securely store their mnemonic recovery phrase, which allows re-deriving the master key when needed.”
-
E2ee permanent loss Report an error
“If all participants in a conversation lose access to their Session Keys, that conversation is permanently inaccessible.”
-
E2ee offline participation Report an error
“Because keys are stored in the database and are persistent, the other users in the room do not need to be online to participate in an E2EE conversation.”
-
E2ee API methods Report an error
“Rocket.Chat provides several server methods that support E2EE operations, including key generation, distribution, and session management.”