Skip to content

What your application does

The SDK does the cryptography and the protocol. Your application does the rest, for the reasons below.

Your applicationBecause
Owns the surface: renders every listing, record, file, editor and what is signed. Lets nothing leave the surface except through a decided actionPlaintext exists only there. The SDK never keeps a copy once your open closes.
Obtains the person’s secret through the unlock adapter, and opens the identity provider in the system browser through the sign-in adapterThe SDK holds the device key. The person’s secret and their sign-in are yours to ask for. Each platform SDK decides how to lock the key with what the unlock adapter returns.
Shows the person what waits, and on whom: access for a new device, a queued group join, a draft, an offline lease’s expiryThe SDK reports these through events and the worklist. It does not show them to the person. Your application must show them. No person should wait without knowing why.
Confirms who is asking, and compares the code, before calling approve()The approver’s own judgment, not a cryptographic check, is the third factor an enrollment needs. The SDK computes the code. Only a person can confirm it matches and that the right person is asking.
Carries out a Copy, Print, Download File or Access Record after an allow decisionThe plaintext is already in your surface. The SDK decides whether the action may happen. Your application copies, prints or downloads it.
States its kind and release in ConfigThe version floor is per ClientKind. The Seald Healthcare Cloud refuses a session below it. Only your application knows what it is and what release it ships.

The browser extension also binds the page’s session

An extension additionally calls session.bindPage(pageSession). A call it makes on behalf of the dashboard page then carries both sessions at once. The Seald Healthcare Cloud answers only when they name the same person:

client.session.bindPage(pageSession); // sends both sessions on every call for the page

Passing undefined unbinds it. See Browser extension for the full flow, including the hostname check. A page on any other origin gets nothing.

Next