Skip to content

backupKey

client.backupKey creates the tenant’s backup key for a set of custodians and delivers each their share. It proves a share yearly. It replaces a custodian without changing the key’s fingerprint.

registration

registration returns the tenant’s backup key registration.

registration(): Promise<BackupKeyRegistration | undefined>;

Returns: The tenant’s BackupKeyRegistration, or nothing if none exists.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

mint

mint creates the tenant’s backup key for three to seven custodians, with a quorum from two up to one fewer. The SDK splits the key into shares and delivers one to each custodian. It signs the registration after a fresh multi-factor sign-in.

mint(options: { custodians: Person[]; quorum?: number }): Promise<Decided<BackupKeyRegistration>>;
ParameterTypeDescription
custodiansPerson[]Three to seven custodians.
quorumnumber, optionalFrom two up to one fewer than the custodian count.

Returns: A Decided<BackupKeyRegistration>.

Records: One decision and one access event.

Who may call it: The Owner role.

Errors: no-session, unreachable, canceled.

abandon

abandon abandons a registration before it completes. No key domain ever relied on that key.

abandon(registrationId: string): Promise<void>;
ParameterTypeDescription
registrationIdstringThe incomplete registration to abandon.

Returns: Nothing.

Records: Nothing. Not a decision.

Errors: no-session, unreachable, not-found.

receiveShare

receiveShare lets a custodian collect their share from the worklist.

receiveShare(registrationId: string): Promise<ShareDelivery>;
ParameterTypeDescription
registrationIdstringThe registration this share belongs to.

Returns: A ShareDelivery: the share to save onto the offline medium, then the receipt.

Records: Nothing. Not a decision.

Errors: no-session, unreachable, not-found.

proveShare

proveShare proves that a custodian still holds a valid share. The floor requires this once a year. It reports whether the share matches, then discards the share from memory.

proveShare(share: ShareInput): Promise<{ held: boolean }>;
ParameterTypeDescription
shareShareInputThe custodian’s share, from a printed code or the hardware token.

Returns: held: whether the share the custodian holds is still valid. In Swift and Kotlin, the Bool or Boolean itself.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

replaceCustodian

replaceCustodian runs a ceremony that rebuilds the same key and splits it again for a new set of custodians. The fingerprint and every pin stay the same.

replaceCustodian(change: { leaving: Person; joining: Person }): Promise<Decided<Ceremony>>;
ParameterTypeDescription
leavingPersonThe custodian being replaced.
joiningPersonThe new custodian.

Returns: A Decided<Ceremony>. recovery describes Ceremony and Participation.

Records: One decision and one access event.

Errors: no-session, unreachable, not-found.

Types

ShareInput

A custodian’s share, presented from their offline medium: a printed code, or the hardware token through the adapter.

type ShareInput = { code: string } | { medium: 'token' };
CasePayloadDescription
codecodeThe share as a printed code.
tokennoneThe share read from the hardware token through the offline medium adapter.

BackupKeyRegistration

interface BackupKeyRegistration {
registrationId: string;
state: 'pending' | 'complete';
fingerprint: string;
custodians: { person: Person; received: boolean; lastProvedAt?: Date }[];
quorum: number;
mintedBy: RecipientId;
mintedAt: Date;
}
FieldTypeDescription
registrationIdstringIdentifies the registration.
state"pending" or "complete"Whether every custodian has received their share.
fingerprintstringThe key’s fingerprint, pinned on every device that signs in.
custodianslist of person, received and last provedEach custodian, whether they have received their share, and when they last proved it.
quorumnumberHow many custodians must agree to rebuild the key.
mintedByRecipientIdWho created the key.
mintedAtdateWhen it was created.

ShareDelivery

On a custodian’s device: the share to save onto the offline medium, then the receipt.

interface ShareDelivery {
registrationId: string;
fingerprint: string;
code?: string;
receipt(): Promise<void>;
}
FieldTypeDescription
registrationIdstringThe registration this share belongs to.
fingerprintstringThe key’s fingerprint, shown beside the code.
codestring, optionalThe share as a printable code. The SDK discards it from memory once you call receipt(). Absent when the offline medium adapter wrote it instead.
receipt()functionThis device key signs it. The Seald Healthcare Cloud then deletes its encrypted copy of the share. The SDK keeps only what it needs to verify a share later, not the share itself.