Skip to content

Sessions

An enrolled device needs an open session before any call that gets a decision. Use client.session to:

  • sign in through the identity provider
  • resume after inactivity
  • sign out
  • read the session’s state and, while a session is open, who is signed in and for how long

Sign in, resume, sign out

signIn opens the identity provider in the system browser and proves the device key in the same step. Call resume after inactivity. It unlocks the device key and signs a fresh nonce, with no round trip to the identity provider. If the tenant requires the identity provider on resume, resume throws sign-in-required instead.

const session = await client.session.signIn();
// later, after inactivity:
await client.session.resume();
await client.session.signOut();

Watch the session state

client.session.state is one of five values. client.on('session', ...) reports each change. React to it, typically by calling resume while the person is still there.

SessionStateMeaning
noneNo session has been opened yet.
openSigned in and active.
inactiveThe person stepped away past the inactivity lifetime. resume gets them back in.
offlineThe Seald Healthcare Cloud is unreachable. What the offline lease covers still opens.
endedYour application called signOut, or the session’s overall lifetime ran out.
client.on('session', async ({ state }) => {
if (state === 'inactive') await client.session.resume();
});

Read the current session

While a session is open, client.session.current is a Session. It carries:

  • person: the signed-in person
  • multiFactor: whether they signed in with multi-factor
  • openedAt: when the session opened
  • lifetimes: the tenant’s three lifetimes, in seconds
    • inactivity: how long the session may stay idle before inactive
    • tokenRefresh: how often the SDK refreshes the identity provider’s token
    • overall: the hard ceiling before ended
const current = client.session.current;
if (current) showBadge(current.person, current.multiFactor, current.lifetimes.overall);

Lock the device key

client.lock() locks the device key in memory without ending the session on the Seald Healthcare Cloud. The next call that needs the key unlocks it again through the unlock adapter. Check client.locked before a call that would otherwise surprise the person with an unlock prompt.

client.lock();
if (client.locked) showUnlockPrompt();

What the SDK does for you

  • Runs the identity provider’s authorization code flow with PKCE, holding no client secret.
  • Proves the device key on every request for the life of the session.
  • Refreshes the identity provider’s token on its own, at the tenant’s tokenRefresh lifetime.
  • Sends the session’s manifest, a record of what it opened, when the session ends.
  • Pins the backup key registration’s fingerprint on the first session in a tenant.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
lockedA call needed the device key and it is locked.Prompt for the person’s unlock secret. The SDK also asks through the unlock adapter automatically.
no-sessionA call needed an open session and none exists.Call signIn.
sign-in-requiredThe tenant requires the identity provider on resume, or the token refresh was refused.Call signIn again.
revokedThe device certificate (card) of this device is no longer active.The SDK has already discarded the offline lease and locked the device key. Tell the person to re-enroll from another device.
release-below-floorThis application’s release is below the tenant’s version floor.Tell the person to update through your release channel.
unreachableThe Seald Healthcare Cloud cannot be reached.Retry when back online. What the offline lease covers still opens.

Next