Skip to content

Sign in on a new laptop or phone

Enroll a new laptop or phone for a person who already has an enrolled device. The person approves it from that other device.

Who can do this: the person, on both devices. A person with no enrolled device needs an Owner or Admin to approve instead. See Approve an enrollment.

The samples use the allowed helper from Access decisions.

1. On the new device: ask to enroll

Show the code when it appears. The person compares it on the other device.

const enrollment = await sealdhealthcare.enroll({ hostname: 'records.example-health.com' });
enrollment.on('change', () => enrollment.code && showCode(enrollment.code));

2. On the other device: compare the code and approve

The request arrives as an enrollment-request client event with its requestId. Approve only if both screens show the same code.

const review = await client.people.reviewEnrollment(requestId);
showCode(await review.waitForCode());
if (codesMatch) await allowed(await review.approve());
else await allowed(await review.reject());

approve() may return a challenge. The approval needs a fresh multi-factor sign-in.

3. On the new device: sign in

wait() returns a Client once the device holds its device certificate (card).

const client = await enrollment.wait(); // rejects with enrollment-rejected or enrollment-lapsed
await client.session.signIn();

The new device does not get access to everything at once. Call offline.waiting() to show what is still queued.

Next