Skip to content

Adapters

Pass Adapters to create in Config.adapters. A platform SDK ships its own adapters where the platform has one, such as a hardware key store and its attestation on mobile. Your application supplies the rest. Each SDK locks the device key with what the unlock adapter returns, in its own way. That locking is internal to each SDK.

Types

Adapters

interface Adapters {
unlock: UnlockAdapter;
signIn: SignInAdapter;
attestation?: AttestationAdapter;
offlineMedium?: OfflineMediumAdapter;
}
FieldTypeDescription
unlockUnlockAdapterObtains the person’s secret for the device key. Your application always supplies this.
signInSignInAdapterOpens the identity provider in the system browser. Your application always supplies this, unless a mobile platform’s system-browser adapter covers it.
attestationAttestationAdapter, optionalOn mobile, the platform’s attestation of a session key held in hardware. The mobile SDKs ship this.
offlineMediumOfflineMediumAdapter, optionalA hardware token a tenant issues to custodians for backup key shares, where the tenant issues one.

UnlockPurpose

The reason the SDK asks for the person’s secret. Use it to word the prompt.

type UnlockPurpose = 'connect' | 'resume' | 'sign' | 'open-offline' | 'enroll';
ValueWhen
connectSealdHealthcare.connect is unlocking the device key for the first time this run.
resumesession.resume is unlocking after inactivity.
signThe device key is about to sign something, such as an enrollment approval.
open-offlineThe device is opening what an offline lease covers, with no session.
enrollSealdHealthcare.enroll is generating and protecting a new device key.

UnlockAdapter

interface UnlockAdapter {
unlock(purpose: UnlockPurpose): Promise<unknown>;
}
MemberTypeDescription
unlock(purpose: UnlockPurpose) => Promise<unknown>Obtains the person’s secret for the device key: a passphrase prompt, a platform biometric, or a hardware key store’s unlock. Each SDK types what it returns, because each SDK locks the device key under it differently.

SignInAdapter

Opens the identity provider’s authorization URL in the system browser and returns the redirect URL the browser came back with. The SDK uses PKCE and holds no client secret. A fresh multi-factor sign-in for an approval goes through here too.

interface SignInAdapter {
authorize(url: string, redirectUri: string): Promise<string>;
}
MemberTypeDescription
authorize(url: string, redirectUri: string) => Promise<string>Opens url in the system browser and returns the URL the browser was redirected back to.

AttestationAdapter

On mobile, the platform’s attestation of a session key held in hardware.

interface AttestationAdapter {
attest(sessionKeyPublic: Bytes): Promise<Bytes>;
}
MemberTypeDescription
attest(sessionKeyPublic: Bytes) => Promise<Bytes>Attests the given session public key in hardware and returns the attestation.

OfflineMediumAdapter

Reads and writes a hardware token that a tenant issues to custodians. Without a token, a backup key share is a printed code.

interface OfflineMediumAdapter {
write(share: Bytes, fingerprint: string): Promise<void>;
read(): Promise<Bytes>;
}
MemberTypeDescription
write(share: Bytes, fingerprint: string) => Promise<void>Writes a custodian’s share and its fingerprint to the hardware token.
read() => Promise<Bytes>Reads a share back from the hardware token, for backupKey.proveShare or recovery.takePart.

The shipped mobile adapters

The mobile SDKs ship an attestation adapter and a system-browser sign-in adapter. Your application supplies only unlock.

Adapters(unlock: unlock, signIn: WebAuthenticationSignIn(presentationAnchor: anchor), attestation: AppAttestAdapter())
AdapterPlatformSupplies
AppAttestAdapter()SwiftAttestationAdapter, backed by the platform’s hardware attestation.
KeyAttestationAdapter(context)KotlinAttestationAdapter, backed by the platform’s hardware attestation.
WebAuthenticationSignIn(presentationAnchor:)SwiftSignInAdapter, opening the identity provider in the system browser.
CustomTabsSignIn(activity)KotlinSignInAdapter, opening the identity provider in the system browser.