Currently one can use key_url to specify which key to install. But there is no way to assure that the key obtained is really the one you expected. Ideally, you could also provide something like key_fingerprint so that the key would be checked against it before installing.
Related: #14677