Skip to content

Enrollment

SealdHealthcare.enroll(request) returns an Enrollment. A new device shows it to the person while it waits for an approver. It resolves to a Client once the SDK holds the device certificate (card) and has verified it offline.

wait

wait resolves with the Client once the SDK holds the card and has verified it offline. It rejects with enrollment-rejected or enrollment-lapsed. An enrolled device may still wait for access to some objects. The Client shows what the device still waits for (waiting()).

wait(): Promise<Client>

Returns: The Client for the newly enrolled device.

Records: Nothing. Not a decision.

Errors: enrollment-rejected if the approver rejected the request, enrollment-lapsed if it lapsed before an approver acted.

cancel

cancel withdraws the request and discards the key.

cancel(): Promise<void>

Returns: Nothing.

Records: Nothing. Not a decision.

on

on subscribes to changes in the enrollment’s state, such as the code becoming available once the approver opens the request.

on(event: 'change', handler: (state: EnrollmentState) => void): Unsubscribe

Parameters

NameTypeDescription
event'change' (TypeScript), EnrollmentEvent (Swift and Kotlin)The only event this object raises.
handler(state: EnrollmentState) => voidCalled with the new state on every change.

In Swift: for await state in enrollment.on(.change) { ... }. In Kotlin: enrollment.on(EnrollmentEvent.CHANGE).collect { state -> ... }.

Returns: Unsubscribe.

Records: Nothing. Not a decision.

Types

EnrollRequest

What SealdHealthcare.enroll takes.

interface EnrollRequest {
hostname: string;
tenantId: TenantId;
replaces?: RecipientId;
foundingToken?: string;
}
FieldTypeDescription
hostnamestringThe Seald Healthcare Cloud hostname as the person entered it, such as records.example-health.com. The SDK keeps it beside the device key. The browser extension answers only this hostname’s page.
tenantIdTenantIdThe tenant this device is enrolling into.
replacesRecipientId, optionalA replacement: the card it replaces, which the approver signs too. Revoke a lost device. Never replace it.
foundingTokenstring, optionalThe tenant’s first device, or a re-founding: the one-use token that stands in for an approver.

EnrollmentState

type EnrollmentState = 'pending' | 'opened' | 'revealed' | 'approved' | 'enrolled' | 'rejected' | 'lapsed';
ValueMeaning
pendingThe request was submitted and waits for an approver to open it.
openedAn approver opened the request.
revealedThis device revealed its secret. The code is now available.
approvedThe approver compared the code and approved.
enrolledThe SDK holds the card and verified it offline. wait() resolves.
rejectedThe approver rejected the request.
lapsedThe request lapsed before an approver acted.

EnrollmentEvent

The event Enrollment.on raises, named in Swift and Kotlin where TypeScript uses the string literal 'change'.

type EnrollmentEvent = 'change';
ValueMeaning
changeThe enrollment’s state changed.

Enrollment

interface Enrollment {
readonly requestId: string;
readonly tenantId: TenantId;
readonly state: EnrollmentState;
readonly code?: string;
readonly lapsesAt: Date;
wait(): Promise<Client>;
cancel(): Promise<void>;
on(event: 'change', handler: (state: EnrollmentState) => void): Unsubscribe;
}
FieldTypeDescription
requestIdstringThe enrollment request’s id, passed to resumeEnrollment after a restart.
tenantIdTenantIdThe tenant this device is enrolling into.
stateEnrollmentStateThe request’s current state.
codestring, optionalThe six-digit code, available once the approver has opened the request and this device has revealed its secret. The person reads it out.
lapsesAtDateWhen the request lapses if no approver acts.
wait() => Promise<Client>See above.
cancel() => Promise<void>See above.
on(event, handler) => UnsubscribeSee above.