Skip to content

This page describes the category, not a specific product. Desktop tools that are keyset-aware read a production keyset and use it to inspect or process content. Their behaviour differs, but the way they treat a keyset follows a recognisable pattern.

Expected keyset format

These tools expect a plain-text keyset with named, categorised entries, conventionally named prod.keys. They generally do not require a particular revision, but they do require the categories relevant to the operation to be present. See the file-structure guide for what “well-formed” means here.

Configuration

Most tools are told where the keyset lives either through a configuration value, a command-line argument, or a fixed directory next to the application. When a tool reports a missing keyset, the configuration path is the first thing to check — not the file’s contents.

Keyset recognition

Recognition is usually structural: the tool looks for a file with the expected name and checks that it parses into named entries. A file that parses but is missing a needed category is recognised and then fails later — a different error at a different stage.

Compatibility

Compatibility for a desktop tool means that the categories the tool needs are present at the revision the content requires. It is not a property of the tool alone. The compatibility hub explains the full chain.

Common errors

  • “Keys not found” / “No keyset”: a placement or configuration problem — see missing keyset.
  • “Invalid key” naming one entry: a formatting or naming problem — see invalid key.
  • A parse failure on a file that looks correct: an encoding or line-ending problem — see file-format problems.
  • A failure at the decryption stage: the wrong revision or category for the content — see decryption errors.