Skip to content

What the SDK does for you

The SDK does these jobs on its own, without a call from your application. You never call them. The SDK runs each job at the moment named below. Where an event exists, client.on reports the job.

WhenWhat the SDK doesHow your application learns it
The first session in a tenantFetches the backup key registration, checks it against the trust root built into the SDK, and pins its fingerprint.The session event, once state reaches open.
Every sessionRefreshes the identity provider’s token, proves the session key on every request, and sends a record of what the session opened at its end.This runs behind every call you make. There is nothing to listen for beyond the session event’s ordinary state changes.
Every session, as a memberGives access to new devices and new group members that wait on this device. Starts the next epoch for a key domain a member left.The backfill event, and the roles event when a mapped group changes what this person can reach.
Every session, as the person’s other deviceGives the person’s new device access to every key domain and record at once.The backfill event, listing what now waits for it.
A saveFinishes a save that was left half-done. Retries it if another save in the key domain lands first. Saves under the next epoch if the epoch changed during the write.No separate event. It happens inside the objects.save call. The Saved or BaseMoved your application already handles reports it.
Every device certificate (card) the SDK relies onVerifies the card offline against the trust root built into the SDK. Checks that the card names this tenant. Leaves out a card that fails the check.The operation that depended on the card proceeds without it. It fails with trust-failed if none of the cards it needed passed.
While reachable, where the tenant enables itAsks for and renews the offline lease over the worklist, fetching every stored object it covers.The lease event, carrying the current LeaseState, or undefined when the offline lease ends.
On reconnectSends the record of what this device opened offline before any other request. Then reports the drafts waiting behind it.The drafts event, with the count of drafts now waiting to be saved.
Any refusal that names this deviceDiscards the offline lease, locks the client, and reports it.The revoked event.
A ceremony where this device’s custodian takes part lastHolds the share in memory and rebuilds the key at the token. For recovery, gives the new domain owner access. Discards everything it held.The ceremony event names the ceremony. recovery.takePart resolves with Participation once this device’s part completes.

Next