Skip to content

Share

You share a key domain, not a single object. Sharing gives the person or group access to every object in the key domain, now and in the future. Access covers every device of the person, and every future member of the group. Only a domain owner can share. client.domains can also share a single record without giving access to the key domain.

Share and unshare a key domain

share takes the key domain’s root locator and a ShareTarget, either { person } or { group }. Sharing to a person gives every device they hold access, across every epoch the key domain has had. Sharing to a group is a standing decision. When a person joins the group later, an existing member device gives them access in its next session. You do nothing more.

The samples use the allowed helper from Access decisions.

await allowed(await client.domains.share(root, { person: alice }));
await allowed(await client.domains.share(root, { group: 'cardiology-nurses' }));

share resolves with the key domain’s new escrowVersion once the share is recorded. unshare removes access at once and starts a new epoch. The person keeps access to versions saved before the unshare, under the epoch they held. They cannot open versions saved after it.

await allowed(await client.domains.unshare(root, { person: alice }));

Share a single record

shareRecord and unshareRecord give or remove access to one record’s versions for a person outside the key domain. That person is a record recipient, not a domain member. Access works version by version, not for the whole key domain at once. Each version adds its own cost. For ordinary sharing, share the key domain.

const shared = await allowed(await client.domains.shareRecord(locator, bob));
await allowed(await client.domains.unshareRecord(locator, bob));

shareRecord resolves with the number of versions it added access to. The recipient shows up beside the record’s other recipients the next time you list it.

What the SDK does for you

  • Verifies every device certificate (card) of a target against the trust root built into the SDK, before giving it access.
  • Gives access to every device a shared person holds, not only their current one.
  • Keeps a group share a standing decision. A member device gives a later joiner access. You do nothing.
  • Starts a new epoch on every unshare. A removed person keeps only what they already had.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
denyThe caller is not a domain owner, or the policies otherwise refuse the share.Show text. Only a domain owner can share a key domain. Only a domain owner or a person holding the Owner role can unshare it.
challengeThe policies require a fresh multi-factor sign-in first.Call stepUp(), or use the allowed helper.

Next