Skip to content

Adapters

Adapters supplies what the SDK does not do itself. The SDK holds the device key and runs the protocol. It never asks a person for their secret and never opens a browser. Every Config carries Adapters, the only platform-specific surface.

FieldRequiredWhat it does
unlockYesObtains the person’s secret for the device key.
signInYesOpens the identity provider’s authorization URL in the system browser.
attestationOnly on mobileThe platform’s attestation of a session key held in hardware.
offlineMediumWhere the tenant issues oneReads and writes a custodian’s backup key share.

Your application always supplies unlock. On mobile, the platform SDK ships attestation and a system-browser signIn for you. Everything else in the SDK API is the same call on every platform.

unlock

UnlockAdapter.unlock(purpose) obtains the person’s secret for the device key, however your application does that: a passphrase, a platform biometric prompt, a hardware key. What it returns is typed by each platform SDK.

interface UnlockAdapter {
unlock(purpose: UnlockPurpose): Promise<unknown>;
}

UnlockPurpose says why the SDK asks. Use it to shape the prompt.

PurposeAsked when
connectsealdhealthcare.connect(tenantId) unlocks the device key for the first time in this process.
resumeThe session went inactive and session.resume() needs the key again, with no identity-provider round trip.
signAn operation needs this device’s signature after a fresh multi-factor sign-in: an approval, a revoke, a role change.
open-offlineAn open falls back to the offline lease and needs the device key to open the copy the offline lease covers.
enrollA new device generates its device key while enrolling.

signIn

SignInAdapter.authorize(url, redirectUri) opens the identity provider’s authorization URL in the system browser. It returns the redirect URL the browser came back with. The SDK uses PKCE and holds no client secret. The SDK reuses this adapter for stepUp(), a fresh multi-factor sign-in mid-flow, for example after a challenge decision.

interface SignInAdapter {
authorize(url: string, redirectUri: string): Promise<string>;
}

If the person closes the browser or backs out of the identity provider, the call your application made throws SealdHealthcareError with code canceled. Return to what you were doing. This is not a fault.

attestation

On mobile, AttestationAdapter.attest(sessionKeyPublic) returns the platform’s attestation of a session key held in hardware.

interface AttestationAdapter {
attest(sessionKeyPublic: Bytes): Promise<Bytes>;
}

offlineMedium

The SDK writes a custodian’s backup key share to a hardware token, where the tenant issues one. Otherwise the share is a printed code. OfflineMediumAdapter writes and reads the share.

interface OfflineMediumAdapter {
write(share: Bytes, fingerprint: string): Promise<void>;
read(): Promise<Bytes>;
}

Mobile adapters the platform ships

The mobile SDKs ship the attestation adapter and a system-browser sign-in adapter for you. Your mobile application usually supplies only unlock.

AdapterSwiftKotlin
AttestationAppAttestAdapter()KeyAttestationAdapter(context)
Sign-inWebAuthenticationSignIn(presentationAnchor:)CustomTabsSignIn(activity)

Next