Skip to content

Types

These identifiers and small shared types appear across every namespace. They name a tenant, a device, a person, a role and the kind of client an application is.

Identifiers

type TenantId = string;
type RecipientId = string;
type Locator = string;
type EventId = string;
type Bytes = Uint8Array;
type Seconds = number;
NameDescription
TenantIdImmutable. Device certificates (cards), stored objects and evidence carry it.
RecipientIdSixteen bytes of SHA-256 over a device’s public key, base64url. Every part of the SDK names a device by it.
LocatorThe opaque id of a record, file, folder or key domain root, the same across versions.
EventIdAn access event, assigned by the Seald Healthcare Cloud.
BytesRaw bytes.
SecondsA duration in seconds.

Person

Person names a person as the identity provider names them. It never holds a name or an email address.

interface Person {
iss: string;
sub: string;
}
FieldTypeDescription
issstringThe identity provider’s issuer.
substringThe person’s subject at that issuer.

Group

Group names a group as the identity provider names it.

type Group = string;

Role

Owner, Admin, Employee and Contractor are fixed. Any other name is a role the tenant created.

type Role = 'owner' | 'admin' | 'employee' | 'contractor' | string;

A tenant can create its own role names. Role is a plain string on every platform rather than a closed enum. The four fixed roles are the string literals shown. Any other value is a role the tenant created.

Classification

type Classification = 'phi' | 'pii' | 'public' | 'de-identified';
ValueDescription
phiProtected health information.
piiPersonally identifiable information.
publicNo restriction.
de-identifiedIdentifiers removed.

ClientKind

type ClientKind = 'extension' | 'desktop' | 'mobile' | 'sdk';
ValueDescription
extensionThe browser extension.
desktopA desktop application.
mobileA mobile application.
sdkAn AI agent or another integration built directly on the SDK.

A tenant sets the version floor per kind. It applies at create and on every session.

Decided

Every call the tenant’s policies decide returns a Decided. It is one of three decisions:

  • allow, with what was asked for
  • deny, with its reason
  • challenge, to sign in again

Every decision carries the EventId of its access event. Access decisions covers each decision and the allowed helper.

type Outcome = 'allow' | 'deny' | 'challenge';
type Decided<T = {}> = Allowed<T> | Denied | Challenged<T>;

Denied

interface Denied {
outcome: 'deny';
eventId: EventId;
reason: DenyReason;
text: string;
}
FieldTypeDescription
eventIdEventIdThe access event this decision recorded.
reasonDenyReasonOne of the fixed deny reasons.
textstringThe fixed words the person sees.

Challenged

interface Challenged<T> {
outcome: 'challenge';
eventId: EventId;
stepUp(): Promise<Decided<T>>;
}
FieldTypeDescription
eventIdEventIdThe access event this decision recorded.
stepUp() => Promise<Decided<T>>Runs a fresh multi-factor sign-in through the sign-in adapter, then repeats the request. It returns a second decision with its own access event.

Unsubscribe

type Unsubscribe = () => void;

client.on returns an Unsubscribe in TypeScript. Call it to stop receiving that event. Swift represents the same subscription as an AsyncStream you stop by ending iteration. Kotlin represents it as a Flow you stop by canceling collection. Neither needs an Unsubscribe value of its own.

Card

A Card is a device certificate, signed by its tenant’s identity authority.

interface Card {
recipientId: RecipientId;
tenantId: TenantId;
person: Person;
issuedAt: Date;
state: 'active' | 'superseded' | 'revoked';
replaces?: RecipientId;
}
FieldTypeDescription
recipientIdRecipientIdThe device this card certifies.
tenantIdTenantIdThe tenant it was issued in.
personPersonWhose device it is.
issuedAtdateWhen it was issued.
state"active", "superseded" or "revoked"The card’s status, as the withdrawal feed reports it. A card that is no longer active locks the client that holds it.
replacesRecipientId, optionalThe card this one replaces, for a replacement enrollment.