Sign in on a new laptop or phone
Enroll a new laptop or phone for a person who already has an enrolled device. The person approves it from that other device.
Who can do this: the person, on both devices. A person with no enrolled device needs an Owner or Admin to approve instead. See Approve an enrollment.
The samples use the allowed helper from Access decisions.
1. On the new device: ask to enroll
Show the code when it appears. The person compares it on the other device.
const enrollment = await sealdhealthcare.enroll({ hostname: 'records.example-health.com' });enrollment.on('change', () => enrollment.code && showCode(enrollment.code));let enrollment = try await sealdhealthcare.enroll(EnrollRequest(hostname: "records.example-health.com"))for await _ in enrollment.on(.change) where enrollment.code != nil { showCode(enrollment.code!) }val enrollment = sealdhealthcare.enroll(EnrollRequest(hostname = "records.example-health.com"))enrollment.on(EnrollmentEvent.CHANGE).collect { enrollment.code?.let { showCode(it) } }2. On the other device: compare the code and approve
The request arrives as an enrollment-request client event with its requestId. Approve only if both screens show the same code.
const review = await client.people.reviewEnrollment(requestId);showCode(await review.waitForCode());if (codesMatch) await allowed(await review.approve());else await allowed(await review.reject());let review = try await client.people.reviewEnrollment(requestId)showCode(try await review.waitForCode())if codesMatch { _ = try await allowed(review.approve()) }else { _ = try await allowed(review.reject()) }val review = client.people.reviewEnrollment(requestId)showCode(review.waitForCode())if (codesMatch) allowed(review.approve()) else allowed(review.reject())approve() may return a challenge. The approval needs a fresh multi-factor sign-in.
3. On the new device: sign in
wait() returns a Client once the device holds its device certificate (card).
const client = await enrollment.wait(); // rejects with enrollment-rejected or enrollment-lapsedawait client.session.signIn();let client = try await enrollment.wait()try await client.session.signIn()val client = enrollment.wait()client.session.signIn()The new device does not get access to everything at once. Call offline.waiting() to show what is still queued.
Next
- Enroll a device for every
EnrollmentStateand how to resume after a restart. - Restore a lost device when the old device is gone.