wire
In this section
Classes
CborTag
Defined in: src/wire/cbor.ts:8
Constructors
Constructor
new CborTag(tag, value): CborTag;Defined in: src/wire/cbor.ts:9
Parameters
| Parameter | Type |
|---|---|
tag |
number |
value |
unknown |
Returns
Properties
tag
readonly tag: number;Defined in: src/wire/cbor.ts:10
value
readonly value: unknown;Defined in: src/wire/cbor.ts:11
JsonSyntaxError
Defined in: src/wire/json.ts:7
A strict JSON parser for SMART requests and responses: RFC 8259, and a
member name repeated in one object is an error (spec [JSON-1], [JSON-2]).
JSON.parse silently keeps the last duplicate, so it can't enforce this.
Extends
Error
WarningList
Defined in: src/wire/warnings.ts:38
Collects warnings, keeping the first of each code and message.
Constructors
Constructor
new WarningList(): WarningList;Returns
Properties
items
readonly items: CheckinWarning[] = [];Defined in: src/wire/warnings.ts:39
Accessors
duplicateKeys
Get Signature
get duplicateKeys(): {
onDuplicateKey: (key) => void;
};Defined in: src/wire/warnings.ts:44
A CBOR decode option that reports repeated map keys ([ENC-5]).
Returns
{
onDuplicateKey: (key) => void;
}onDuplicateKey
onDuplicateKey: (key) => void;Parameters
| Parameter | Type |
|---|---|
key |
unknown |
Returns
void
Methods
add()
add(
code,
rule,
message): void;Defined in: src/wire/warnings.ts:40
Parameters
| Parameter | Type |
|---|---|
code |
CheckinWarningCode |
rule |
string |
message |
string |
Returns
void
Type Aliases
CborDecodeOptions
type CborDecodeOptions = {
onDuplicateKey?: (key) => void;
};Defined in: src/wire/cbor.ts:82
Properties
onDuplicateKey?
optional onDuplicateKey?: (key) => void;Defined in: src/wire/cbor.ts:88
Called for each map key that repeats an earlier key in the same map. The later value wins. Without a callback, duplicates are kept silently; spec [ENC-5] asks a receiver to warn about them.
Parameters
| Parameter | Type |
|---|---|
key |
unknown |
Returns
void
CheckinWarning
type CheckinWarning = {
code: CheckinWarningCode;
message: string;
rule: string;
};Defined in: src/wire/warnings.ts:30
Properties
code
code: CheckinWarningCode;Defined in: src/wire/warnings.ts:31
message
message: string;Defined in: src/wire/warnings.ts:32
rule
rule: string;Defined in: src/wire/warnings.ts:34
The spec requirement behind the check, such as "VRS-7".
CheckinWarningCode
type CheckinWarningCode =
| "protocol"
| "base64url-padding"
| "cbor-duplicate-key"
| "dcapi-response"
| "device-response-version"
| "device-response-status"
| "documents"
| "issuer-signature"
| "alg"
| "mso-fields"
| "mso-doc-type"
| "mso-validity-info"
| "mso-validity"
| "digest-algorithm"
| "digest"
| "device-signature"
| "device-request-version"
| "doc-requests"
| "items-request"
| "intent-to-retain"
| "encryption-info"
| "reader-auth";Defined in: src/wire/warnings.ts:6
Receiver warnings (spec §2, [RCV-1]). A receiver continues past a warning and reports it; it fails only where spec §8 marks a step as a failure. The codes are the ones the spec's conformance cases use.
CoseSign1
type CoseSign1 = [Uint8Array, Map<unknown, unknown>, Uint8Array | null, Uint8Array];Defined in: src/wire/verify.ts:23
DcapiMdocResponse
type DcapiMdocResponse = {
data: {
response: string;
};
protocol: typeof PROTOCOL_ID;
};Defined in: src/wire/response.ts:41
Properties
data
data: {
response: string;
};Defined in: src/wire/response.ts:43
response
response: string;protocol
protocol: typeof PROTOCOL_ID;Defined in: src/wire/response.ts:42
DcapiResponseInspection
type DcapiResponseInspection = {
cipherText?: {
base64url: string;
hex: string;
};
dcapiResponse: JsonValue;
dcapiResponseDiagnostic: string;
dcapiResponseHex: string;
enc?: {
base64url: string;
hex: string;
};
};Defined in: src/wire/response.ts:48
Properties
cipherText?
optional cipherText?: {
base64url: string;
hex: string;
};Defined in: src/wire/response.ts:53
base64url
base64url: string;hex
hex: string;dcapiResponse
dcapiResponse: JsonValue;Defined in: src/wire/response.ts:51
dcapiResponseDiagnostic
dcapiResponseDiagnostic: string;Defined in: src/wire/response.ts:50
dcapiResponseHex
dcapiResponseHex: string;Defined in: src/wire/response.ts:49
enc?
optional enc?: {
base64url: string;
hex: string;
};Defined in: src/wire/response.ts:52
base64url
base64url: string;hex
hex: string;DeviceRequestInspection
type DeviceRequestInspection = {
deviceRequest: JsonValue;
deviceRequestDiagnostic: string;
deviceRequestHex: string;
docRequests: ItemsRequestInspection[];
};Defined in: src/wire/inspect-request.ts:33
Properties
deviceRequest
deviceRequest: JsonValue;Defined in: src/wire/inspect-request.ts:36
deviceRequestDiagnostic
deviceRequestDiagnostic: string;Defined in: src/wire/inspect-request.ts:35
deviceRequestHex
deviceRequestHex: string;Defined in: src/wire/inspect-request.ts:34
docRequests
docRequests: ItemsRequestInspection[];Defined in: src/wire/inspect-request.ts:37
DeviceResponseCheck
type DeviceResponseCheck =
| {
ok: true;
smartResponseText: string;
warnings: CheckinWarning[];
x5chain: Uint8Array[];
}
| {
error: string;
ok: false;
rule: string;
warnings: CheckinWarning[];
};Defined in: src/wire/verify.ts:328
Union Members
Type Literal
{
ok: true;
smartResponseText: string;
warnings: CheckinWarning[];
x5chain: Uint8Array[];
}ok
ok: true;smartResponseText
smartResponseText: string;The SMART response JSON text from the issuer-signed element.
warnings
warnings: CheckinWarning[];x5chain
x5chain: Uint8Array[];The issuerAuth certificate chain, leaf first, for callers applying trust policy.
Type Literal
{
error: string;
ok: false;
rule: string;
warnings: CheckinWarning[];
}DeviceResponseDocumentInspection
type DeviceResponseDocumentInspection = {
docType?: string;
elements: IssuerSignedElementInspection[];
issuerAuth?: {
digestAlgorithm?: string;
mso?: JsonValue;
msoDiagnostic?: string;
};
};Defined in: src/wire/response.ts:82
Properties
docType?
optional docType?: string;Defined in: src/wire/response.ts:83
elements
elements: IssuerSignedElementInspection[];Defined in: src/wire/response.ts:89
issuerAuth?
optional issuerAuth?: {
digestAlgorithm?: string;
mso?: JsonValue;
msoDiagnostic?: string;
};Defined in: src/wire/response.ts:84
digestAlgorithm?
optional digestAlgorithm?: string;mso?
optional mso?: JsonValue;msoDiagnostic?
optional msoDiagnostic?: string;DeviceResponseInspection
type DeviceResponseInspection = {
deviceResponse: JsonValue;
deviceResponseDiagnostic: string;
deviceResponseHex: string;
documents: DeviceResponseDocumentInspection[];
status?: number;
version?: string;
};Defined in: src/wire/response.ts:92
Properties
deviceResponse
deviceResponse: JsonValue;Defined in: src/wire/response.ts:95
deviceResponseDiagnostic
deviceResponseDiagnostic: string;Defined in: src/wire/response.ts:94
deviceResponseHex
deviceResponseHex: string;Defined in: src/wire/response.ts:93
documents
documents: DeviceResponseDocumentInspection[];Defined in: src/wire/response.ts:98
status?
optional status?: number;Defined in: src/wire/response.ts:97
version?
optional version?: string;Defined in: src/wire/response.ts:96
DeviceSignatureVerification
type DeviceSignatureVerification = {
error?: string;
present: boolean;
signatureValid?: boolean;
};Defined in: src/wire/verify.ts:32
Properties
error?
optional error?: string;Defined in: src/wire/verify.ts:35
present
present: boolean;Defined in: src/wire/verify.ts:33
signatureValid?
optional signatureValid?: boolean;Defined in: src/wire/verify.ts:34
DigestVerification
type DigestVerification = {
allMatch: boolean;
checked: number;
matched: number;
};Defined in: src/wire/verify.ts:38
Properties
allMatch
allMatch: boolean;Defined in: src/wire/verify.ts:41
checked
checked: number;Defined in: src/wire/verify.ts:39
matched
matched: number;Defined in: src/wire/verify.ts:40
DocumentVerification
type DocumentVerification = {
deviceSignature: DeviceSignatureVerification;
digests: DigestVerification;
docType?: string;
issuerAuth: IssuerAuthVerification;
};Defined in: src/wire/verify.ts:44
Properties
deviceSignature
deviceSignature: DeviceSignatureVerification;Defined in: src/wire/verify.ts:47
digests
digests: DigestVerification;Defined in: src/wire/verify.ts:48
docType?
optional docType?: string;Defined in: src/wire/verify.ts:45
issuerAuth
issuerAuth: IssuerAuthVerification;Defined in: src/wire/verify.ts:46
EncryptionInfoInspection
type EncryptionInfoInspection = {
encryptionInfo: JsonValue;
encryptionInfoDiagnostic: string;
encryptionInfoHex: string;
nonce?: {
base64url: string;
hex: string;
};
recipientPublicKey?: JsonValue;
};Defined in: src/wire/inspect-request.ts:40
Properties
encryptionInfo
encryptionInfo: JsonValue;Defined in: src/wire/inspect-request.ts:43
encryptionInfoDiagnostic
encryptionInfoDiagnostic: string;Defined in: src/wire/inspect-request.ts:42
encryptionInfoHex
encryptionInfoHex: string;Defined in: src/wire/inspect-request.ts:41
nonce?
optional nonce?: {
base64url: string;
hex: string;
};Defined in: src/wire/inspect-request.ts:44
base64url
base64url: string;hex
hex: string;recipientPublicKey?
optional recipientPublicKey?: JsonValue;Defined in: src/wire/inspect-request.ts:45
HpkeSealResult
type HpkeSealResult = {
cipherText: Uint8Array;
enc: Uint8Array;
response: DcapiMdocResponse;
};Defined in: src/wire/response.ts:101
Properties
cipherText
cipherText: Uint8Array;Defined in: src/wire/response.ts:103
enc
enc: Uint8Array;Defined in: src/wire/response.ts:102
response
response: DcapiMdocResponse;Defined in: src/wire/response.ts:104
IssuerAuthVerification
type IssuerAuthVerification = {
error?: string;
present: boolean;
signatureValid?: boolean;
x5chain?: Uint8Array[];
};Defined in: src/wire/verify.ts:25
Properties
error?
optional error?: string;Defined in: src/wire/verify.ts:29
present
present: boolean;Defined in: src/wire/verify.ts:26
signatureValid?
optional signatureValid?: boolean;Defined in: src/wire/verify.ts:27
x5chain?
optional x5chain?: Uint8Array[];Defined in: src/wire/verify.ts:28
IssuerSignedElementInspection
type IssuerSignedElementInspection = {
digestID?: number;
elementIdentifier?: string;
elementValue?: JsonValue;
issuerSignedItemDiagnostic: string;
issuerSignedItemTag24Hex: string;
namespace: string;
random?: {
base64url: string;
hex: string;
};
smartHealthCheckinResponse: SmartResponseInspection;
valueDigest?: {
matches?: boolean;
msoSha256?: string;
recomputedSha256: string;
};
};Defined in: src/wire/response.ts:66
Properties
digestID?
optional digestID?: number;Defined in: src/wire/response.ts:68
elementIdentifier?
optional elementIdentifier?: string;Defined in: src/wire/response.ts:70
elementValue?
optional elementValue?: JsonValue;Defined in: src/wire/response.ts:71
issuerSignedItemDiagnostic
issuerSignedItemDiagnostic: string;Defined in: src/wire/response.ts:73
issuerSignedItemTag24Hex
issuerSignedItemTag24Hex: string;Defined in: src/wire/response.ts:72
namespace
namespace: string;Defined in: src/wire/response.ts:67
random?
optional random?: {
base64url: string;
hex: string;
};Defined in: src/wire/response.ts:69
base64url
base64url: string;hex
hex: string;smartHealthCheckinResponse
smartHealthCheckinResponse: SmartResponseInspection;Defined in: src/wire/response.ts:79
valueDigest?
optional valueDigest?: {
matches?: boolean;
msoSha256?: string;
recomputedSha256: string;
};Defined in: src/wire/response.ts:74
matches?
optional matches?: boolean;msoSha256?
optional msoSha256?: string;recomputedSha256
recomputedSha256: string;ItemsRequestInspection
type ItemsRequestInspection = {
docType?: string;
itemsRequest: JsonValue;
itemsRequestDiagnostic: string;
itemsRequestHex: string;
readerAuth?: {
payloadIsDetached: boolean;
protectedHeaders?: JsonValue;
readerAuthHex: string;
signatureHex?: string;
unprotectedHeaders?: JsonValue;
};
requestedElements: {
elementIdentifier: string;
intentToRetain: boolean;
namespace: string;
}[];
requestInfo?: JsonValue;
smartHealthCheckin: SmartRequestInspection;
};Defined in: src/wire/inspect-request.ts:12
Properties
docType?
optional docType?: string;Defined in: src/wire/inspect-request.ts:16
itemsRequest
itemsRequest: JsonValue;Defined in: src/wire/inspect-request.ts:15
itemsRequestDiagnostic
itemsRequestDiagnostic: string;Defined in: src/wire/inspect-request.ts:14
itemsRequestHex
itemsRequestHex: string;Defined in: src/wire/inspect-request.ts:13
readerAuth?
optional readerAuth?: {
payloadIsDetached: boolean;
protectedHeaders?: JsonValue;
readerAuthHex: string;
signatureHex?: string;
unprotectedHeaders?: JsonValue;
};Defined in: src/wire/inspect-request.ts:24
payloadIsDetached
payloadIsDetached: boolean;protectedHeaders?
optional protectedHeaders?: JsonValue;readerAuthHex
readerAuthHex: string;signatureHex?
optional signatureHex?: string;unprotectedHeaders?
optional unprotectedHeaders?: JsonValue;requestedElements
requestedElements: {
elementIdentifier: string;
intentToRetain: boolean;
namespace: string;
}[];Defined in: src/wire/inspect-request.ts:17
elementIdentifier
elementIdentifier: string;intentToRetain
intentToRetain: boolean;namespace
namespace: string;requestInfo?
optional requestInfo?: JsonValue;Defined in: src/wire/inspect-request.ts:22
smartHealthCheckin
smartHealthCheckin: SmartRequestInspection;Defined in: src/wire/inspect-request.ts:23
JsonValue
type JsonValue =
| null
| boolean
| number
| string
| JsonValue[]
| {
[key: string]: JsonValue;
};Defined in: src/wire/cbor.ts:15
OpenedCredential
type OpenedCredential =
| {
deviceResponseBytes: Uint8Array;
ok: true;
warnings: CheckinWarning[];
}
| {
error: string;
ok: false;
rule: string;
warnings: CheckinWarning[];
};Defined in: src/wire/response.ts:273
OpenWalletResponseResult
type OpenWalletResponseResult = {
dcapiResponse: DcapiResponseInspection;
deviceResponse: DeviceResponseInspection;
deviceResponseBytes: Uint8Array;
smartResponseValidation?: {
ok: true;
value: SmartCheckinResponse;
};
};Defined in: src/wire/response.ts:107
Properties
dcapiResponse
dcapiResponse: DcapiResponseInspection;Defined in: src/wire/response.ts:108
deviceResponse
deviceResponse: DeviceResponseInspection;Defined in: src/wire/response.ts:110
deviceResponseBytes
deviceResponseBytes: Uint8Array;Defined in: src/wire/response.ts:109
smartResponseValidation?
optional smartResponseValidation?: {
ok: true;
value: SmartCheckinResponse;
};Defined in: src/wire/response.ts:111
ok
ok: true;value
value: SmartCheckinResponse;OrgIsoMdocInspection
type OrgIsoMdocInspection = {
deviceRequest: DeviceRequestInspection;
encryptionInfo?: EncryptionInfoInspection;
protocol: typeof PROTOCOL_ID;
sessionTranscript?: {
diagnostic: string;
hex: string;
origin: string;
};
};Defined in: src/wire/inspect-request.ts:48
Properties
deviceRequest
deviceRequest: DeviceRequestInspection;Defined in: src/wire/inspect-request.ts:50
encryptionInfo?
optional encryptionInfo?: EncryptionInfoInspection;Defined in: src/wire/inspect-request.ts:51
protocol
protocol: typeof PROTOCOL_ID;Defined in: src/wire/inspect-request.ts:49
sessionTranscript?
optional sessionTranscript?: {
diagnostic: string;
hex: string;
origin: string;
};Defined in: src/wire/inspect-request.ts:52
diagnostic
diagnostic: string;hex
hex: string;origin
origin: string;OrgIsoMdocNavigatorArgument
type OrgIsoMdocNavigatorArgument = {
digital: {
requests: [{
data: {
deviceRequest: string;
encryptionInfo: string;
};
protocol: typeof PROTOCOL_ID;
}];
};
mediation: "required";
};Defined in: src/wire/request.ts:27
Properties
digital
digital: {
requests: [{
data: {
deviceRequest: string;
encryptionInfo: string;
};
protocol: typeof PROTOCOL_ID;
}];
};Defined in: src/wire/request.ts:29
requests
requests: [{
data: {
deviceRequest: string;
encryptionInfo: string;
};
protocol: typeof PROTOCOL_ID;
}];mediation
mediation: "required";Defined in: src/wire/request.ts:28
OrgIsoMdocRequestBundle
type OrgIsoMdocRequestBundle = {
deviceRequestBytes: Uint8Array;
encryptionInfoBytes: Uint8Array;
itemsRequestTag24Bytes: Uint8Array;
navigatorArgument: OrgIsoMdocNavigatorArgument;
nonce: Uint8Array;
readerAuthBytes?: Uint8Array;
readerCertificateDer?: Uint8Array;
readerKeyPair?: CryptoKeyPair;
readerPublicJwk?: JsonWebKey;
requestedElementIdentifier: string;
sessionTranscriptBytes?: Uint8Array;
smartRequestJson: string;
verifierKeyPair: CryptoKeyPair;
verifierPublicJwk: JsonWebKey;
};Defined in: src/wire/request.ts:42
Properties
deviceRequestBytes
deviceRequestBytes: Uint8Array;Defined in: src/wire/request.ts:49
encryptionInfoBytes
encryptionInfoBytes: Uint8Array;Defined in: src/wire/request.ts:50
itemsRequestTag24Bytes
itemsRequestTag24Bytes: Uint8Array;Defined in: src/wire/request.ts:51
navigatorArgument
navigatorArgument: OrgIsoMdocNavigatorArgument;Defined in: src/wire/request.ts:43
nonce
nonce: Uint8Array;Defined in: src/wire/request.ts:46
readerAuthBytes?
optional readerAuthBytes?: Uint8Array;Defined in: src/wire/request.ts:53
readerCertificateDer?
optional readerCertificateDer?: Uint8Array;Defined in: src/wire/request.ts:56
readerKeyPair?
optional readerKeyPair?: CryptoKeyPair;Defined in: src/wire/request.ts:54
readerPublicJwk?
optional readerPublicJwk?: JsonWebKey;Defined in: src/wire/request.ts:55
requestedElementIdentifier
requestedElementIdentifier: string;Defined in: src/wire/request.ts:47
sessionTranscriptBytes?
optional sessionTranscriptBytes?: Uint8Array;Defined in: src/wire/request.ts:52
smartRequestJson
smartRequestJson: string;Defined in: src/wire/request.ts:48
verifierKeyPair
verifierKeyPair: CryptoKeyPair;Defined in: src/wire/request.ts:44
verifierPublicJwk
verifierPublicJwk: JsonWebKey;Defined in: src/wire/request.ts:45
ReaderIdentity
type ReaderIdentity = {
certificateDer: Uint8Array;
keyPair: CryptoKeyPair;
publicJwk: JsonWebKey;
};Defined in: src/wire/reader-auth.ts:10
Properties
certificateDer
certificateDer: Uint8Array;Defined in: src/wire/reader-auth.ts:13
keyPair
keyPair: CryptoKeyPair;Defined in: src/wire/reader-auth.ts:11
publicJwk
publicJwk: JsonWebKey;Defined in: src/wire/reader-auth.ts:12
SmartRequestInspection
type SmartRequestInspection =
| {
json: string;
present: true;
valid: true;
value: SmartCheckinRequest;
}
| {
error: string;
json: string;
present: true;
valid: false;
}
| {
present: false;
};Defined in: src/wire/response.ts:61
SmartResponseInspection
type SmartResponseInspection =
| {
json: string;
present: true;
valid: true;
value: SmartCheckinResponse;
}
| {
error: string;
json: string;
present: true;
valid: false;
}
| {
present: false;
};Defined in: src/wire/response.ts:56
Variables
MDOC_DOC_TYPE
const MDOC_DOC_TYPE: "org.smarthealthit.checkin.1";Defined in: src/wire/request.ts:22
MDOC_NAMESPACE
const MDOC_NAMESPACE: "org.smarthealthit.checkin";Defined in: src/wire/request.ts:23
PROTOCOL_ID
const PROTOCOL_ID: "org-iso-mdoc";Defined in: src/wire/request.ts:21
SMART_REQUEST_INFO_KEY
const SMART_REQUEST_INFO_KEY: "org.smarthealthit.checkin.request";Defined in: src/wire/request.ts:24
SMART_RESPONSE_ELEMENT_ID
const SMART_RESPONSE_ELEMENT_ID: "smart_health_checkin_response";Defined in: src/wire/request.ts:25
Functions
arrayBufferCopy()
function arrayBufferCopy(bytes): ArrayBuffer;Defined in: src/wire/bytes.ts:72
Copy into a fresh ArrayBuffer (WebCrypto inputs must not be SharedArrayBuffer views).
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
ArrayBuffer
base64UrlDecodeBytes()
function base64UrlDecodeBytes(s): Uint8Array;Defined in: src/wire/bytes.ts:13
Parameters
| Parameter | Type |
|---|---|
s |
string |
Returns
Uint8Array
base64UrlDecodeUtf8()
function base64UrlDecodeUtf8(s): string;Defined in: src/wire/bytes.ts:25
Parameters
| Parameter | Type |
|---|---|
s |
string |
Returns
string
base64UrlEncodeBytes()
function base64UrlEncodeBytes(bytes): string;Defined in: src/wire/bytes.ts:5
Byte and encoding primitives shared across the wire layer.
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
string
base64UrlEncodeUtf8()
function base64UrlEncodeUtf8(s): string;Defined in: src/wire/bytes.ts:21
Parameters
| Parameter | Type |
|---|---|
s |
string |
Returns
string
buildDcapiMdocResponse()
function buildDcapiMdocResponse(input): DcapiMdocResponse;Defined in: src/wire/response.ts:114
Parameters
| Parameter | Type |
|---|---|
input |
{ cipherText: Uint8Array; enc: Uint8Array; } |
input.cipherText |
Uint8Array |
input.enc |
Uint8Array |
Returns
buildDcapiSessionTranscript()
function buildDcapiSessionTranscript(input): Promise<Uint8Array<ArrayBufferLike>>;Defined in: src/wire/request.ts:242
SessionTranscript (spec §8.3) — both verifier and wallet compute this identically: dcapiInfo = CBOR([encryptionInfoBase64Url, origin]) handover = ["dcapi", SHA-256(dcapiInfo)] SessionTranscript = CBOR([null, null, handover])
Parameters
| Parameter | Type |
|---|---|
input |
{ encryptionInfo: string | Uint8Array<ArrayBufferLike>; origin: string; } |
input.encryptionInfo |
string | Uint8Array<ArrayBufferLike> |
input.origin |
string |
Returns
Promise<Uint8Array<ArrayBufferLike>>
buildDeviceAuthenticationBytes()
function buildDeviceAuthenticationBytes(input): Uint8Array;Defined in: src/wire/verify.ts:162
DeviceAuthentication (ISO/IEC 18013-5): DeviceAuthentication = ["DeviceAuthentication", SessionTranscript, DocType, DeviceNameSpacesBytes] DeviceAuthenticationBytes = #6.24(bstr .cbor DeviceAuthentication) The deviceSignature COSE_Sign1 carries a detached payload equal to DeviceAuthenticationBytes.
Parameters
| Parameter | Type |
|---|---|
input |
{ deviceNameSpaces: unknown; docType: string; sessionTranscript: Uint8Array; } |
input.deviceNameSpaces |
unknown |
input.docType |
string |
input.sessionTranscript |
Uint8Array |
Returns
Uint8Array
buildDeviceRequestBytes()
function buildDeviceRequestBytes(input): Uint8Array;Defined in: src/wire/request.ts:150
Parameters
| Parameter | Type |
|---|---|
input |
{ responseElementIdentifier?: string; smartRequestJson: string; version?: "1.0" | "1.1"; } |
input.responseElementIdentifier? |
string |
input.smartRequestJson |
string |
input.version? |
"1.0" | "1.1" |
Returns
Uint8Array
buildDeviceRequestBytesFromParts()
function buildDeviceRequestBytesFromParts(input): Uint8Array;Defined in: src/wire/request.ts:182
Parameters
| Parameter | Type |
|---|---|
input |
{ itemsRequestTag24Bytes: Uint8Array; readerAuthBytes?: Uint8Array<ArrayBufferLike>; version: "1.0" | "1.1"; } |
input.itemsRequestTag24Bytes |
Uint8Array |
input.readerAuthBytes? |
Uint8Array<ArrayBufferLike> |
input.version |
"1.0" | "1.1" |
Returns
Uint8Array
buildEncryptionInfoBytes()
function buildEncryptionInfoBytes(input): Uint8Array;Defined in: src/wire/request.ts:222
Parameters
| Parameter | Type |
|---|---|
input |
{ nonce: Uint8Array; recipientPublicJwk: JsonWebKey; } |
input.nonce |
Uint8Array |
input.recipientPublicJwk |
JsonWebKey |
Returns
Uint8Array
buildItemsRequestTag24Bytes()
function buildItemsRequestTag24Bytes(input): Uint8Array;Defined in: src/wire/request.ts:161
Parameters
| Parameter | Type |
|---|---|
input |
{ responseElementIdentifier?: string; smartRequestJson: string; } |
input.responseElementIdentifier? |
string |
input.smartRequestJson |
string |
Returns
Uint8Array
buildOrgIsoMdocRequest()
function buildOrgIsoMdocRequest(smartRequest, options?): Promise<OrgIsoMdocRequestBundle>;Defined in: src/wire/request.ts:59
Parameters
| Parameter | Type |
|---|---|
smartRequest |
SmartCheckinRequest |
options |
{ deviceRequestVersion?: "1.0" | "1.1"; nonce?: Uint8Array<ArrayBufferLike>; origin?: string; readerAuth?: boolean; readerIdentity?: ReaderIdentity; responseElementIdentifier?: string; verifierKeyPair?: CryptoKeyPair; } |
options.deviceRequestVersion? |
"1.0" | "1.1" |
options.nonce? |
Uint8Array<ArrayBufferLike> |
options.origin? |
string |
options.readerAuth? |
boolean |
options.readerIdentity? |
ReaderIdentity |
options.responseElementIdentifier? |
string |
options.verifierKeyPair? |
CryptoKeyPair |
Returns
Promise<OrgIsoMdocRequestBundle>
buildReaderAuthenticationBytes()
function buildReaderAuthenticationBytes(input): Uint8Array;Defined in: src/wire/reader-auth.ts:32
Parameters
| Parameter | Type |
|---|---|
input |
{ itemsRequestTag24Bytes: Uint8Array; sessionTranscriptBytes: Uint8Array; } |
input.itemsRequestTag24Bytes |
Uint8Array |
input.sessionTranscriptBytes |
Uint8Array |
Returns
Uint8Array
bytesEqual()
function bytesEqual(a, b): boolean;Defined in: src/wire/bytes.ts:67
Parameters
| Parameter | Type |
|---|---|
a |
Uint8Array |
b |
Uint8Array |
Returns
boolean
cborDecode()
function cborDecode(bytes, options?): unknown;Defined in: src/wire/cbor.ts:91
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
options |
CborDecodeOptions |
Returns
unknown
cborDiagnostic()
function cborDiagnostic(value): string;Defined in: src/wire/cbor.ts:202
CBOR diagnostic notation (subset), for debug UIs and fixtures.
Parameters
| Parameter | Type |
|---|---|
value |
unknown |
Returns
string
cborEncode()
function cborEncode(value): Uint8Array;Defined in: src/wire/cbor.ts:23
Parameters
| Parameter | Type |
|---|---|
value |
unknown |
Returns
Uint8Array
cborToJsonValue()
function cborToJsonValue(value): JsonValue;Defined in: src/wire/cbor.ts:224
Lossy JSON projection of decoded CBOR (bytes → {$bytes, hex}, tags → {$tag, value}).
Parameters
| Parameter | Type |
|---|---|
value |
unknown |
Returns
certificateSubjectPublicKeyInfo()
function certificateSubjectPublicKeyInfo(certificateDer): Uint8Array;Defined in: src/wire/reader-auth.ts:182
Extract the SubjectPublicKeyInfo (DER) from an X.509 certificate.
Certificate ::= SEQUENCE { tbsCertificate, signatureAlgorithm, signature } TBSCertificate ::= SEQUENCE { [0] version OPTIONAL, serialNumber, signature, issuer, validity, subject, subjectPublicKeyInfo, ... }
Parameters
| Parameter | Type |
|---|---|
certificateDer |
Uint8Array |
Returns
Uint8Array
checkDeviceResponse()
function checkDeviceResponse(input): Promise<DeviceResponseCheck>;Defined in: src/wire/verify.ts:343
Check a decrypted DeviceResponse as a Verifier (spec §8.5 steps 3–7 and [VRS-10]) and return the SMART response text. Never throws.
Parameters
| Parameter | Type | Description |
|---|---|---|
input |
{ deviceResponseBytes: Uint8Array; now?: Date; sessionTranscript: Uint8Array; } |
- |
input.deviceResponseBytes |
Uint8Array |
- |
input.now? |
Date |
The time to check validityInfo against; defaults to now. |
input.sessionTranscript |
Uint8Array |
- |
Returns
Promise<DeviceResponseCheck>
compareBytes()
function compareBytes(a, b): number;Defined in: src/wire/bytes.ts:58
Parameters
| Parameter | Type |
|---|---|
a |
Uint8Array |
b |
Uint8Array |
Returns
number
concatBytes()
function concatBytes(parts): Uint8Array;Defined in: src/wire/bytes.ts:47
Parameters
| Parameter | Type |
|---|---|
parts |
readonly Uint8Array<ArrayBufferLike>[] |
Returns
Uint8Array
createEphemeralReaderIdentity()
function createEphemeralReaderIdentity(subjectCommonName?): Promise<ReaderIdentity>;Defined in: src/wire/reader-auth.ts:16
Parameters
| Parameter | Type | Default value |
|---|---|---|
subjectCommonName |
string |
"SMART Health Check-in Demo Verifier" |
Returns
Promise<ReaderIdentity>
decodeBase64UrlLenient()
function decodeBase64UrlLenient(
value,
warnings,
rule,
what): Uint8Array;Defined in: src/wire/warnings.ts:53
Decode base64url, tolerating padding and the standard alphabet with a warning ([WRQ-2], [VRS-2]). Throws on anything else.
Parameters
| Parameter | Type |
|---|---|
value |
string |
warnings |
WarningList |
rule |
string |
what |
string |
Returns
Uint8Array
extractDcapiResponse()
function extractDcapiResponse(credential): string | DcapiMdocResponse;Defined in: src/browser/index.ts:254
Pull the org-iso-mdoc response payload out of whatever the browser's
credential object looks like: a DigitalCredential with .data (object or
JSON string), a bare {protocol, data} object, or the raw base64url
response string.
Parameters
| Parameter | Type |
|---|---|
credential |
unknown |
Returns
string | DcapiMdocResponse
firstSmartCheckinResponse()
function firstSmartCheckinResponse(deviceResponse): SmartResponseInspection;Defined in: src/wire/response.ts:345
Parameters
| Parameter | Type |
|---|---|
deviceResponse |
DeviceResponseInspection |
Returns
hex()
function hex(bytes): string;Defined in: src/wire/bytes.ts:29
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
string
hexDecode()
function hexDecode(s): Uint8Array;Defined in: src/wire/bytes.ts:33
Parameters
| Parameter | Type |
|---|---|
s |
string |
Returns
Uint8Array
hpkeAesGcm()
function hpkeAesGcm(encrypt, input): Promise<Uint8Array<ArrayBufferLike>>;Defined in: src/wire/hpke.ts:107
Parameters
| Parameter | Type |
|---|---|
encrypt |
boolean |
input |
{ aad: Uint8Array; data: Uint8Array; key: Uint8Array; nonce: Uint8Array; } |
input.aad |
Uint8Array |
input.data |
Uint8Array |
input.key |
Uint8Array |
input.nonce |
Uint8Array |
Returns
Promise<Uint8Array<ArrayBufferLike>>
hpkeContext()
function hpkeContext(input): Promise<{
baseNonce: Uint8Array;
key: Uint8Array;
}>;Defined in: src/wire/hpke.ts:16
Parameters
| Parameter | Type |
|---|---|
input |
{ dh: Uint8Array; enc: Uint8Array; info: Uint8Array; recipientPublicBytes: Uint8Array; } |
input.dh |
Uint8Array |
input.enc |
Uint8Array |
input.info |
Uint8Array |
input.recipientPublicBytes |
Uint8Array |
Returns
Promise<{
baseNonce: Uint8Array;
key: Uint8Array;
}>
hpkeNonce()
function hpkeNonce(baseNonce, sequenceNumber?): Uint8Array;Defined in: src/wire/hpke.ts:130
Parameters
| Parameter | Type | Default value |
|---|---|---|
baseNonce |
Uint8Array |
undefined |
sequenceNumber |
number |
0 |
Returns
Uint8Array
hpkeSealDirectMdoc()
function hpkeSealDirectMdoc(input): Promise<HpkeSealResult>;Defined in: src/wire/response.ts:160
Wallet-side seal — used by tests and the demo's mock wallet.
Parameters
| Parameter | Type |
|---|---|
input |
{ aad?: Uint8Array<ArrayBufferLike>; info: Uint8Array; plaintext: Uint8Array; recipientPublicJwk: JsonWebKey; } |
input.aad? |
Uint8Array<ArrayBufferLike> |
input.info |
Uint8Array |
input.plaintext |
Uint8Array |
input.recipientPublicJwk |
JsonWebKey |
Returns
Promise<HpkeSealResult>
i2osp()
function i2osp(value, length): Uint8Array;Defined in: src/wire/bytes.ts:82
Parameters
| Parameter | Type |
|---|---|
value |
number |
length |
number |
Returns
Uint8Array
importCertificatePublicKey()
function importCertificatePublicKey(certificateDer): Promise<CryptoKey>;Defined in: src/wire/reader-auth.ts:196
Parameters
| Parameter | Type |
|---|---|
certificateDer |
Uint8Array |
Returns
Promise<CryptoKey>
inspectDcapiMdocResponse()
function inspectDcapiMdocResponse(input): DcapiResponseInspection;Defined in: src/wire/response.ts:133
Parameters
| Parameter | Type |
|---|---|
input |
string | DcapiMdocResponse |
Returns
inspectDeviceRequestBytes()
function inspectDeviceRequestBytes(bytes): DeviceRequestInspection;Defined in: src/wire/inspect-request.ts:91
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
inspectDeviceResponseBytes()
function inspectDeviceResponseBytes(bytes): Promise<DeviceResponseInspection>;Defined in: src/wire/response.ts:356
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
Promise<DeviceResponseInspection>
inspectEncryptionInfoBytes()
function inspectEncryptionInfoBytes(bytes): EncryptionInfoInspection;Defined in: src/wire/inspect-request.ts:171
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
inspectItemsRequestBytes()
function inspectItemsRequestBytes(bytes): ItemsRequestInspection;Defined in: src/wire/inspect-request.ts:122
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
inspectOrgIsoMdocNavigatorArgument()
function inspectOrgIsoMdocNavigatorArgument(arg, options?): Promise<OrgIsoMdocInspection>;Defined in: src/wire/inspect-request.ts:59
Parameters
| Parameter | Type |
|---|---|
arg |
unknown |
options |
{ origin?: string; } |
options.origin? |
string |
Returns
Promise<OrgIsoMdocInspection>
inspectSmartRequestInfoValue()
function inspectSmartRequestInfoValue(value): SmartRequestInspection;Defined in: src/wire/response.ts:514
Parameters
| Parameter | Type |
|---|---|
value |
unknown |
Returns
mapGet()
function mapGet(value, key): unknown;Defined in: src/wire/cbor.ts:264
Parameters
| Parameter | Type |
|---|---|
value |
unknown |
key |
string | number |
Returns
unknown
openWalletCredential()
function openWalletCredential(input): Promise<OpenedCredential>;Defined in: src/wire/response.ts:286
The Verifier's first two steps (spec §8.5, [VRS-2] and [VRS-3]): decode the
credential and decrypt it. Fails only if it can't be decoded, lacks enc
or cipherText, or doesn't decrypt; a protocol other than org-iso-mdoc,
padded base64url, and a first entry other than "dcapi" are warnings.
Never throws.
credential is {protocol, data: {response}} or the data.response string.
Parameters
| Parameter | Type |
|---|---|
input |
{ credential: unknown; recipientPrivateKey: CryptoKey; recipientPublicJwk: JsonWebKey; sessionTranscript: Uint8Array; } |
input.credential |
unknown |
input.recipientPrivateKey |
CryptoKey |
input.recipientPublicJwk |
JsonWebKey |
input.sessionTranscript |
Uint8Array |
Returns
Promise<OpenedCredential>
openWalletResponse()
function openWalletResponse(input): Promise<OpenWalletResponseResult>;Defined in: src/wire/response.ts:206
Parameters
| Parameter | Type |
|---|---|
input |
{ aad?: Uint8Array<ArrayBufferLike>; recipientPrivateKey: CryptoKey; recipientPublicJwk: JsonWebKey; response: string | DcapiMdocResponse; sessionTranscript: Uint8Array; smartRequest?: unknown; } |
input.aad? |
Uint8Array<ArrayBufferLike> |
input.recipientPrivateKey |
CryptoKey |
input.recipientPublicJwk |
JsonWebKey |
input.response |
string | DcapiMdocResponse |
input.sessionTranscript |
Uint8Array |
input.smartRequest? |
unknown |
Returns
Promise<OpenWalletResponseResult>
parseJsonStrict()
function parseJsonStrict(text): unknown;Defined in: src/wire/json.ts:9
Parameters
| Parameter | Type |
|---|---|
text |
string |
Returns
unknown
publicJwkToCoseKey()
function publicJwkToCoseKey(jwk): Map<number, number | Uint8Array<ArrayBufferLike>>;Defined in: src/wire/request.ts:199
Parameters
| Parameter | Type |
|---|---|
jwk |
JsonWebKey |
Returns
Map<number, number | Uint8Array<ArrayBufferLike>>
publicJwkToRawP256()
function publicJwkToRawP256(jwk): Uint8Array;Defined in: src/wire/request.ts:211
Parameters
| Parameter | Type |
|---|---|
jwk |
JsonWebKey |
Returns
Uint8Array
sha256()
function sha256(bytes): Promise<Uint8Array<ArrayBufferLike>>;Defined in: src/wire/bytes.ts:78
Parameters
| Parameter | Type |
|---|---|
bytes |
Uint8Array |
Returns
Promise<Uint8Array<ArrayBufferLike>>
signReaderAuth()
function signReaderAuth(input): Promise<Uint8Array<ArrayBufferLike>>;Defined in: src/wire/reader-auth.ts:45
Parameters
| Parameter | Type |
|---|---|
input |
{ itemsRequestTag24Bytes: Uint8Array; readerCertificateDer: Uint8Array; readerPrivateKey: CryptoKey; sessionTranscriptBytes: Uint8Array; } |
input.itemsRequestTag24Bytes |
Uint8Array |
input.readerCertificateDer |
Uint8Array |
input.readerPrivateKey |
CryptoKey |
input.sessionTranscriptBytes |
Uint8Array |
Returns
Promise<Uint8Array<ArrayBufferLike>>
utf8()
function utf8(s): Uint8Array;Defined in: src/wire/bytes.ts:43
Parameters
| Parameter | Type |
|---|---|
s |
string |
Returns
Uint8Array
verifyDeviceResponseSignatures()
function verifyDeviceResponseSignatures(input): Promise<DocumentVerification[]>;Defined in: src/wire/verify.ts:56
Verify every document in a DeviceResponse. All three checks are reported independently so a caller can apply deployment trust policy (e.g. accept a self-attested wallet chain while still requiring a valid signature).
Parameters
| Parameter | Type |
|---|---|
input |
{ deviceResponseBytes: Uint8Array; sessionTranscript: Uint8Array; } |
input.deviceResponseBytes |
Uint8Array |
input.sessionTranscript |
Uint8Array |
Returns
Promise<DocumentVerification[]>
verifyIssuerAuth()
function verifyIssuerAuth(issuerAuthRaw): Promise<IssuerAuthVerification>;Defined in: src/wire/verify.ts:96
Parameters
| Parameter | Type |
|---|---|
issuerAuthRaw |
unknown |
Returns
Promise<IssuerAuthVerification>
verifyReaderAuthSignature()
function verifyReaderAuthSignature(input): Promise<boolean>;Defined in: src/wire/reader-auth.ts:65
Parameters
| Parameter | Type |
|---|---|
input |
{ itemsRequestTag24Bytes: Uint8Array; readerAuthBytes: Uint8Array; readerPublicKey: CryptoKey; sessionTranscriptBytes: Uint8Array; } |
input.itemsRequestTag24Bytes |
Uint8Array |
input.readerAuthBytes |
Uint8Array |
input.readerPublicKey |
CryptoKey |
input.sessionTranscriptBytes |
Uint8Array |
Returns
Promise<boolean>