Skip to content

Seald Healthcare

create is the SDK’s entry point. It resolves to a SealdHealthcare object, which your application holds before connecting to a tenant. With a SealdHealthcare object, your application can:

  • enroll a device
  • connect an existing enrollment
  • forget an enrollment
  • verify an evidence pack offline

create

create creates the SDK bound to a platform. It fetches nothing, because the trust root and the timestamp authorities’ roots are built into the SDK.

function create(config: Config): Promise<SealdHealthcare>

Parameters

NameTypeDescription
configConfigThe client kind, the application’s release, and its adapters.

Returns: SealdHealthcare, the entry point bound to this platform.

Records: Nothing. Not a decision.

Errors: None. create contacts nothing and cannot fail with a SealdHealthcareError.

contract

The SDK API major this SDK implements, and the Cloud API major it calls.

readonly contract: { sdkApi: number; cloudApi: number }

Returns: The two majors. Show them in a support ticket to say which contract your application runs against.

Records: Nothing. Not a decision.

enrollments

The enrollments this device holds, one per tenant.

enrollments(): Promise<EnrollmentSummary[]>

Returns: One EnrollmentSummary per tenant this device is enrolled in.

Records: Nothing. Not a decision.

enroll

A new device asks for a device certificate (card). enroll signs in, generates the device key, and submits the request. The Enrollment it returns starts in state pending.

enroll(request: EnrollRequest): Promise<Enrollment>

Parameters

NameTypeDescription
requestEnrollRequestThe hostname, the tenant, and either the card being replaced or a founding token.

Returns: The Enrollment your application shows the person the code on, and waits on.

Records: Nothing. Not a decision.

Errors

  • trust-failed: the tenant’s registration or a card fails its check against the trust root built into the SDK.
  • unreachable: the Seald Healthcare Cloud cannot be reached.
  • canceled: the person does not complete the unlock or the sign-in.

resumeEnrollment

resumeEnrollment returns the request the device still waits on after a restart. A resumed wait starts no second request.

resumeEnrollment(requestId: string): Promise<Enrollment>

Parameters

NameTypeDescription
requestIdstringThe request id from the Enrollment this device was waiting on before the restart.

Returns: The same Enrollment, at its current state.

Records: Nothing. Not a decision.

Errors: not-found if the SDK holds no such request.

connect

Unlocks the device key of one tenant’s enrollment and returns its Client, with no session open yet.

connect(tenantId: TenantId): Promise<Client>

Parameters

NameTypeDescription
tenantIdTenantIdThe tenant to connect this device’s enrollment to.

Returns: The Client for that tenant. Calls the unlock adapter.

Records: Nothing. Not a decision.

Errors

  • locked: the unlock adapter cannot obtain the person’s secret.
  • not-found: this device holds no enrollment for the tenant.
  • revoked: this device’s card is no longer active.
  • release-below-floor: the application’s release is below the tenant’s version floor.

forget

forget removes an enrollment from this device. The card stays active until someone revokes it in the tenant.

forget(tenantId: TenantId): Promise<void>

Parameters

NameTypeDescription
tenantIdTenantIdThe tenant whose enrollment this device forgets.

Returns: Nothing.

Records: Nothing. Not a decision.

verifyPack

verifyPack verifies an evidence pack offline against the trust root built into the SDK and the timestamp authorities’ roots. It needs no enrollment and no key. It resolves no ref.

verifyPack(pack: Bytes): Promise<PackVerification>

Parameters

NameTypeDescription
packBytesThe evidence pack’s raw bytes, as evidence.export produced them.

Returns: A PackVerification: whether the pack verifies and, if not, the first failure.

Records: Nothing. Not a decision.

Who may call it: Anyone, from a Seald Healthcare object created with no enrollment. Verification needs no key.

Types

Config

The configuration create takes.

interface Config {
kind: ClientKind;
release: string;
adapters: Adapters;
}
FieldTypeDescription
kindClientKindThe kind of Seald Healthcare Client, stated on every session. The version floor is per kind.
releasestringThe application’s release, major.minor.patch, checked against the customer’s version floor.
adaptersAdaptersWhat this platform and this application supply. See Adapters.

Contract

The shape contract returns in Kotlin, where a return type needs a name.

data class Contract(val sdkApi: Int, val cloudApi: Int)
FieldTypeDescription
sdkApiIntThe SDK API major this SDK implements.
cloudApiIntThe Cloud API major this SDK calls.

EnrollmentSummary

One row of SealdHealthcare.enrollments(): one enrollment this device holds.

interface EnrollmentSummary {
tenantId: TenantId;
hostname: string;
recipientId: RecipientId;
person: Person;
cardState: Card['state'];
}
FieldTypeDescription
tenantIdTenantIdThe tenant this enrollment is in.
hostnamestringThe Seald Healthcare Cloud hostname this device enrolled with.
recipientIdRecipientIdThis device’s own recipient id in that tenant.
personPersonThe person this device is enrolled as.
cardStateCard’s stateThe card’s state as last learned from the Seald Healthcare Cloud. The SDK learns the withdrawal feed’s latest state on the next request.