wire

In this section

Classes

CborTag

Defined in: src/wire/cbor.ts:8

Constructors

Constructor
new CborTag(tag, value): CborTag;

Defined in: src/wire/cbor.ts:9

Parameters
Parameter Type
tag number
value unknown
Returns

CborTag

Properties

tag
readonly tag: number;

Defined in: src/wire/cbor.ts:10

value
readonly value: unknown;

Defined in: src/wire/cbor.ts:11


JsonSyntaxError

Defined in: src/wire/json.ts:7

A strict JSON parser for SMART requests and responses: RFC 8259, and a member name repeated in one object is an error (spec [JSON-1], [JSON-2]). JSON.parse silently keeps the last duplicate, so it can't enforce this.

Extends


WarningList

Defined in: src/wire/warnings.ts:38

Collects warnings, keeping the first of each code and message.

Constructors

Constructor
new WarningList(): WarningList;
Returns

WarningList

Properties

items
readonly items: CheckinWarning[] = [];

Defined in: src/wire/warnings.ts:39

Accessors

duplicateKeys
Get Signature
get duplicateKeys(): {
  onDuplicateKey: (key) => void;
};

Defined in: src/wire/warnings.ts:44

A CBOR decode option that reports repeated map keys ([ENC-5]).

Returns
{
  onDuplicateKey: (key) => void;
}
onDuplicateKey
onDuplicateKey: (key) => void;
Parameters
Parameter Type
key unknown
Returns

void

Methods

add()
add(
   code, 
   rule, 
   message): void;

Defined in: src/wire/warnings.ts:40

Parameters
Parameter Type
code CheckinWarningCode
rule string
message string
Returns

void

Type Aliases

CborDecodeOptions

type CborDecodeOptions = {
  onDuplicateKey?: (key) => void;
};

Defined in: src/wire/cbor.ts:82

Properties

onDuplicateKey?
optional onDuplicateKey?: (key) => void;

Defined in: src/wire/cbor.ts:88

Called for each map key that repeats an earlier key in the same map. The later value wins. Without a callback, duplicates are kept silently; spec [ENC-5] asks a receiver to warn about them.

Parameters
Parameter Type
key unknown
Returns

void


CheckinWarning

type CheckinWarning = {
  code: CheckinWarningCode;
  message: string;
  rule: string;
};

Defined in: src/wire/warnings.ts:30

Properties

code
code: CheckinWarningCode;

Defined in: src/wire/warnings.ts:31

message
message: string;

Defined in: src/wire/warnings.ts:32

rule
rule: string;

Defined in: src/wire/warnings.ts:34

The spec requirement behind the check, such as "VRS-7".


CheckinWarningCode

type CheckinWarningCode = 
  | "protocol"
  | "base64url-padding"
  | "cbor-duplicate-key"
  | "dcapi-response"
  | "device-response-version"
  | "device-response-status"
  | "documents"
  | "issuer-signature"
  | "alg"
  | "mso-fields"
  | "mso-doc-type"
  | "mso-validity-info"
  | "mso-validity"
  | "digest-algorithm"
  | "digest"
  | "device-signature"
  | "device-request-version"
  | "doc-requests"
  | "items-request"
  | "intent-to-retain"
  | "encryption-info"
  | "reader-auth";

Defined in: src/wire/warnings.ts:6

Receiver warnings (spec §2, [RCV-1]). A receiver continues past a warning and reports it; it fails only where spec §8 marks a step as a failure. The codes are the ones the spec's conformance cases use.


CoseSign1

type CoseSign1 = [Uint8Array, Map<unknown, unknown>, Uint8Array | null, Uint8Array];

Defined in: src/wire/verify.ts:23


DcapiMdocResponse

type DcapiMdocResponse = {
  data: {
     response: string;
  };
  protocol: typeof PROTOCOL_ID;
};

Defined in: src/wire/response.ts:41

Properties

data
data: {
  response: string;
};

Defined in: src/wire/response.ts:43

response
response: string;
protocol
protocol: typeof PROTOCOL_ID;

Defined in: src/wire/response.ts:42


DcapiResponseInspection

type DcapiResponseInspection = {
  cipherText?: {
     base64url: string;
     hex: string;
  };
  dcapiResponse: JsonValue;
  dcapiResponseDiagnostic: string;
  dcapiResponseHex: string;
  enc?: {
     base64url: string;
     hex: string;
  };
};

Defined in: src/wire/response.ts:48

Properties

cipherText?
optional cipherText?: {
  base64url: string;
  hex: string;
};

Defined in: src/wire/response.ts:53

base64url
base64url: string;
hex
hex: string;
dcapiResponse
dcapiResponse: JsonValue;

Defined in: src/wire/response.ts:51

dcapiResponseDiagnostic
dcapiResponseDiagnostic: string;

Defined in: src/wire/response.ts:50

dcapiResponseHex
dcapiResponseHex: string;

Defined in: src/wire/response.ts:49

enc?
optional enc?: {
  base64url: string;
  hex: string;
};

Defined in: src/wire/response.ts:52

base64url
base64url: string;
hex
hex: string;

DeviceRequestInspection

type DeviceRequestInspection = {
  deviceRequest: JsonValue;
  deviceRequestDiagnostic: string;
  deviceRequestHex: string;
  docRequests: ItemsRequestInspection[];
};

Defined in: src/wire/inspect-request.ts:33

Properties

deviceRequest
deviceRequest: JsonValue;

Defined in: src/wire/inspect-request.ts:36

deviceRequestDiagnostic
deviceRequestDiagnostic: string;

Defined in: src/wire/inspect-request.ts:35

deviceRequestHex
deviceRequestHex: string;

Defined in: src/wire/inspect-request.ts:34

docRequests
docRequests: ItemsRequestInspection[];

Defined in: src/wire/inspect-request.ts:37


DeviceResponseCheck

type DeviceResponseCheck = 
  | {
  ok: true;
  smartResponseText: string;
  warnings: CheckinWarning[];
  x5chain: Uint8Array[];
}
  | {
  error: string;
  ok: false;
  rule: string;
  warnings: CheckinWarning[];
};

Defined in: src/wire/verify.ts:328

Union Members

Type Literal
{
  ok: true;
  smartResponseText: string;
  warnings: CheckinWarning[];
  x5chain: Uint8Array[];
}
ok
ok: true;
smartResponseText
smartResponseText: string;

The SMART response JSON text from the issuer-signed element.

warnings
warnings: CheckinWarning[];
x5chain
x5chain: Uint8Array[];

The issuerAuth certificate chain, leaf first, for callers applying trust policy.


Type Literal
{
  error: string;
  ok: false;
  rule: string;
  warnings: CheckinWarning[];
}

DeviceResponseDocumentInspection

type DeviceResponseDocumentInspection = {
  docType?: string;
  elements: IssuerSignedElementInspection[];
  issuerAuth?: {
     digestAlgorithm?: string;
     mso?: JsonValue;
     msoDiagnostic?: string;
  };
};

Defined in: src/wire/response.ts:82

Properties

docType?
optional docType?: string;

Defined in: src/wire/response.ts:83

elements
elements: IssuerSignedElementInspection[];

Defined in: src/wire/response.ts:89

issuerAuth?
optional issuerAuth?: {
  digestAlgorithm?: string;
  mso?: JsonValue;
  msoDiagnostic?: string;
};

Defined in: src/wire/response.ts:84

digestAlgorithm?
optional digestAlgorithm?: string;
mso?
optional mso?: JsonValue;
msoDiagnostic?
optional msoDiagnostic?: string;

DeviceResponseInspection

type DeviceResponseInspection = {
  deviceResponse: JsonValue;
  deviceResponseDiagnostic: string;
  deviceResponseHex: string;
  documents: DeviceResponseDocumentInspection[];
  status?: number;
  version?: string;
};

Defined in: src/wire/response.ts:92

Properties

deviceResponse
deviceResponse: JsonValue;

Defined in: src/wire/response.ts:95

deviceResponseDiagnostic
deviceResponseDiagnostic: string;

Defined in: src/wire/response.ts:94

deviceResponseHex
deviceResponseHex: string;

Defined in: src/wire/response.ts:93

documents
documents: DeviceResponseDocumentInspection[];

Defined in: src/wire/response.ts:98

status?
optional status?: number;

Defined in: src/wire/response.ts:97

version?
optional version?: string;

Defined in: src/wire/response.ts:96


DeviceSignatureVerification

type DeviceSignatureVerification = {
  error?: string;
  present: boolean;
  signatureValid?: boolean;
};

Defined in: src/wire/verify.ts:32

Properties

error?
optional error?: string;

Defined in: src/wire/verify.ts:35

present
present: boolean;

Defined in: src/wire/verify.ts:33

signatureValid?
optional signatureValid?: boolean;

Defined in: src/wire/verify.ts:34


DigestVerification

type DigestVerification = {
  allMatch: boolean;
  checked: number;
  matched: number;
};

Defined in: src/wire/verify.ts:38

Properties

allMatch
allMatch: boolean;

Defined in: src/wire/verify.ts:41

checked
checked: number;

Defined in: src/wire/verify.ts:39

matched
matched: number;

Defined in: src/wire/verify.ts:40


DocumentVerification

type DocumentVerification = {
  deviceSignature: DeviceSignatureVerification;
  digests: DigestVerification;
  docType?: string;
  issuerAuth: IssuerAuthVerification;
};

Defined in: src/wire/verify.ts:44

Properties

deviceSignature
deviceSignature: DeviceSignatureVerification;

Defined in: src/wire/verify.ts:47

digests
digests: DigestVerification;

Defined in: src/wire/verify.ts:48

docType?
optional docType?: string;

Defined in: src/wire/verify.ts:45

issuerAuth
issuerAuth: IssuerAuthVerification;

Defined in: src/wire/verify.ts:46


EncryptionInfoInspection

type EncryptionInfoInspection = {
  encryptionInfo: JsonValue;
  encryptionInfoDiagnostic: string;
  encryptionInfoHex: string;
  nonce?: {
     base64url: string;
     hex: string;
  };
  recipientPublicKey?: JsonValue;
};

Defined in: src/wire/inspect-request.ts:40

Properties

encryptionInfo
encryptionInfo: JsonValue;

Defined in: src/wire/inspect-request.ts:43

encryptionInfoDiagnostic
encryptionInfoDiagnostic: string;

Defined in: src/wire/inspect-request.ts:42

encryptionInfoHex
encryptionInfoHex: string;

Defined in: src/wire/inspect-request.ts:41

nonce?
optional nonce?: {
  base64url: string;
  hex: string;
};

Defined in: src/wire/inspect-request.ts:44

base64url
base64url: string;
hex
hex: string;
recipientPublicKey?
optional recipientPublicKey?: JsonValue;

Defined in: src/wire/inspect-request.ts:45


HpkeSealResult

type HpkeSealResult = {
  cipherText: Uint8Array;
  enc: Uint8Array;
  response: DcapiMdocResponse;
};

Defined in: src/wire/response.ts:101

Properties

cipherText
cipherText: Uint8Array;

Defined in: src/wire/response.ts:103

enc
enc: Uint8Array;

Defined in: src/wire/response.ts:102

response
response: DcapiMdocResponse;

Defined in: src/wire/response.ts:104


IssuerAuthVerification

type IssuerAuthVerification = {
  error?: string;
  present: boolean;
  signatureValid?: boolean;
  x5chain?: Uint8Array[];
};

Defined in: src/wire/verify.ts:25

Properties

error?
optional error?: string;

Defined in: src/wire/verify.ts:29

present
present: boolean;

Defined in: src/wire/verify.ts:26

signatureValid?
optional signatureValid?: boolean;

Defined in: src/wire/verify.ts:27

x5chain?
optional x5chain?: Uint8Array[];

Defined in: src/wire/verify.ts:28


IssuerSignedElementInspection

type IssuerSignedElementInspection = {
  digestID?: number;
  elementIdentifier?: string;
  elementValue?: JsonValue;
  issuerSignedItemDiagnostic: string;
  issuerSignedItemTag24Hex: string;
  namespace: string;
  random?: {
     base64url: string;
     hex: string;
  };
  smartHealthCheckinResponse: SmartResponseInspection;
  valueDigest?: {
     matches?: boolean;
     msoSha256?: string;
     recomputedSha256: string;
  };
};

Defined in: src/wire/response.ts:66

Properties

digestID?
optional digestID?: number;

Defined in: src/wire/response.ts:68

elementIdentifier?
optional elementIdentifier?: string;

Defined in: src/wire/response.ts:70

elementValue?
optional elementValue?: JsonValue;

Defined in: src/wire/response.ts:71

issuerSignedItemDiagnostic
issuerSignedItemDiagnostic: string;

Defined in: src/wire/response.ts:73

issuerSignedItemTag24Hex
issuerSignedItemTag24Hex: string;

Defined in: src/wire/response.ts:72

namespace
namespace: string;

Defined in: src/wire/response.ts:67

random?
optional random?: {
  base64url: string;
  hex: string;
};

Defined in: src/wire/response.ts:69

base64url
base64url: string;
hex
hex: string;
smartHealthCheckinResponse
smartHealthCheckinResponse: SmartResponseInspection;

Defined in: src/wire/response.ts:79

valueDigest?
optional valueDigest?: {
  matches?: boolean;
  msoSha256?: string;
  recomputedSha256: string;
};

Defined in: src/wire/response.ts:74

matches?
optional matches?: boolean;
msoSha256?
optional msoSha256?: string;
recomputedSha256
recomputedSha256: string;

ItemsRequestInspection

type ItemsRequestInspection = {
  docType?: string;
  itemsRequest: JsonValue;
  itemsRequestDiagnostic: string;
  itemsRequestHex: string;
  readerAuth?: {
     payloadIsDetached: boolean;
     protectedHeaders?: JsonValue;
     readerAuthHex: string;
     signatureHex?: string;
     unprotectedHeaders?: JsonValue;
  };
  requestedElements: {
     elementIdentifier: string;
     intentToRetain: boolean;
     namespace: string;
  }[];
  requestInfo?: JsonValue;
  smartHealthCheckin: SmartRequestInspection;
};

Defined in: src/wire/inspect-request.ts:12

Properties

docType?
optional docType?: string;

Defined in: src/wire/inspect-request.ts:16

itemsRequest
itemsRequest: JsonValue;

Defined in: src/wire/inspect-request.ts:15

itemsRequestDiagnostic
itemsRequestDiagnostic: string;

Defined in: src/wire/inspect-request.ts:14

itemsRequestHex
itemsRequestHex: string;

Defined in: src/wire/inspect-request.ts:13

readerAuth?
optional readerAuth?: {
  payloadIsDetached: boolean;
  protectedHeaders?: JsonValue;
  readerAuthHex: string;
  signatureHex?: string;
  unprotectedHeaders?: JsonValue;
};

Defined in: src/wire/inspect-request.ts:24

payloadIsDetached
payloadIsDetached: boolean;
protectedHeaders?
optional protectedHeaders?: JsonValue;
readerAuthHex
readerAuthHex: string;
signatureHex?
optional signatureHex?: string;
unprotectedHeaders?
optional unprotectedHeaders?: JsonValue;
requestedElements
requestedElements: {
  elementIdentifier: string;
  intentToRetain: boolean;
  namespace: string;
}[];

Defined in: src/wire/inspect-request.ts:17

elementIdentifier
elementIdentifier: string;
intentToRetain
intentToRetain: boolean;
namespace
namespace: string;
requestInfo?
optional requestInfo?: JsonValue;

Defined in: src/wire/inspect-request.ts:22

smartHealthCheckin
smartHealthCheckin: SmartRequestInspection;

Defined in: src/wire/inspect-request.ts:23


JsonValue

type JsonValue = 
  | null
  | boolean
  | number
  | string
  | JsonValue[]
  | {
[key: string]: JsonValue;
};

Defined in: src/wire/cbor.ts:15


OpenedCredential

type OpenedCredential = 
  | {
  deviceResponseBytes: Uint8Array;
  ok: true;
  warnings: CheckinWarning[];
}
  | {
  error: string;
  ok: false;
  rule: string;
  warnings: CheckinWarning[];
};

Defined in: src/wire/response.ts:273


OpenWalletResponseResult

type OpenWalletResponseResult = {
  dcapiResponse: DcapiResponseInspection;
  deviceResponse: DeviceResponseInspection;
  deviceResponseBytes: Uint8Array;
  smartResponseValidation?: {
     ok: true;
     value: SmartCheckinResponse;
  };
};

Defined in: src/wire/response.ts:107

Properties

dcapiResponse
dcapiResponse: DcapiResponseInspection;

Defined in: src/wire/response.ts:108

deviceResponse
deviceResponse: DeviceResponseInspection;

Defined in: src/wire/response.ts:110

deviceResponseBytes
deviceResponseBytes: Uint8Array;

Defined in: src/wire/response.ts:109

smartResponseValidation?
optional smartResponseValidation?: {
  ok: true;
  value: SmartCheckinResponse;
};

Defined in: src/wire/response.ts:111

ok
ok: true;
value
value: SmartCheckinResponse;

OrgIsoMdocInspection

type OrgIsoMdocInspection = {
  deviceRequest: DeviceRequestInspection;
  encryptionInfo?: EncryptionInfoInspection;
  protocol: typeof PROTOCOL_ID;
  sessionTranscript?: {
     diagnostic: string;
     hex: string;
     origin: string;
  };
};

Defined in: src/wire/inspect-request.ts:48

Properties

deviceRequest
deviceRequest: DeviceRequestInspection;

Defined in: src/wire/inspect-request.ts:50

encryptionInfo?
optional encryptionInfo?: EncryptionInfoInspection;

Defined in: src/wire/inspect-request.ts:51

protocol
protocol: typeof PROTOCOL_ID;

Defined in: src/wire/inspect-request.ts:49

sessionTranscript?
optional sessionTranscript?: {
  diagnostic: string;
  hex: string;
  origin: string;
};

Defined in: src/wire/inspect-request.ts:52

diagnostic
diagnostic: string;
hex
hex: string;
origin
origin: string;

OrgIsoMdocNavigatorArgument

type OrgIsoMdocNavigatorArgument = {
  digital: {
     requests: [{
        data: {
           deviceRequest: string;
           encryptionInfo: string;
        };
        protocol: typeof PROTOCOL_ID;
     }];
  };
  mediation: "required";
};

Defined in: src/wire/request.ts:27

Properties

digital
digital: {
  requests: [{
     data: {
        deviceRequest: string;
        encryptionInfo: string;
     };
     protocol: typeof PROTOCOL_ID;
  }];
};

Defined in: src/wire/request.ts:29

requests
requests: [{
  data: {
     deviceRequest: string;
     encryptionInfo: string;
  };
  protocol: typeof PROTOCOL_ID;
}];
mediation
mediation: "required";

Defined in: src/wire/request.ts:28


OrgIsoMdocRequestBundle

type OrgIsoMdocRequestBundle = {
  deviceRequestBytes: Uint8Array;
  encryptionInfoBytes: Uint8Array;
  itemsRequestTag24Bytes: Uint8Array;
  navigatorArgument: OrgIsoMdocNavigatorArgument;
  nonce: Uint8Array;
  readerAuthBytes?: Uint8Array;
  readerCertificateDer?: Uint8Array;
  readerKeyPair?: CryptoKeyPair;
  readerPublicJwk?: JsonWebKey;
  requestedElementIdentifier: string;
  sessionTranscriptBytes?: Uint8Array;
  smartRequestJson: string;
  verifierKeyPair: CryptoKeyPair;
  verifierPublicJwk: JsonWebKey;
};

Defined in: src/wire/request.ts:42

Properties

deviceRequestBytes
deviceRequestBytes: Uint8Array;

Defined in: src/wire/request.ts:49

encryptionInfoBytes
encryptionInfoBytes: Uint8Array;

Defined in: src/wire/request.ts:50

itemsRequestTag24Bytes
itemsRequestTag24Bytes: Uint8Array;

Defined in: src/wire/request.ts:51

navigatorArgument: OrgIsoMdocNavigatorArgument;

Defined in: src/wire/request.ts:43

nonce
nonce: Uint8Array;

Defined in: src/wire/request.ts:46

readerAuthBytes?
optional readerAuthBytes?: Uint8Array;

Defined in: src/wire/request.ts:53

readerCertificateDer?
optional readerCertificateDer?: Uint8Array;

Defined in: src/wire/request.ts:56

readerKeyPair?
optional readerKeyPair?: CryptoKeyPair;

Defined in: src/wire/request.ts:54

readerPublicJwk?
optional readerPublicJwk?: JsonWebKey;

Defined in: src/wire/request.ts:55

requestedElementIdentifier
requestedElementIdentifier: string;

Defined in: src/wire/request.ts:47

sessionTranscriptBytes?
optional sessionTranscriptBytes?: Uint8Array;

Defined in: src/wire/request.ts:52

smartRequestJson
smartRequestJson: string;

Defined in: src/wire/request.ts:48

verifierKeyPair
verifierKeyPair: CryptoKeyPair;

Defined in: src/wire/request.ts:44

verifierPublicJwk
verifierPublicJwk: JsonWebKey;

Defined in: src/wire/request.ts:45


ReaderIdentity

type ReaderIdentity = {
  certificateDer: Uint8Array;
  keyPair: CryptoKeyPair;
  publicJwk: JsonWebKey;
};

Defined in: src/wire/reader-auth.ts:10

Properties

certificateDer
certificateDer: Uint8Array;

Defined in: src/wire/reader-auth.ts:13

keyPair
keyPair: CryptoKeyPair;

Defined in: src/wire/reader-auth.ts:11

publicJwk
publicJwk: JsonWebKey;

Defined in: src/wire/reader-auth.ts:12


SmartRequestInspection

type SmartRequestInspection = 
  | {
  json: string;
  present: true;
  valid: true;
  value: SmartCheckinRequest;
}
  | {
  error: string;
  json: string;
  present: true;
  valid: false;
}
  | {
  present: false;
};

Defined in: src/wire/response.ts:61


SmartResponseInspection

type SmartResponseInspection = 
  | {
  json: string;
  present: true;
  valid: true;
  value: SmartCheckinResponse;
}
  | {
  error: string;
  json: string;
  present: true;
  valid: false;
}
  | {
  present: false;
};

Defined in: src/wire/response.ts:56

Variables

MDOC_DOC_TYPE

const MDOC_DOC_TYPE: "org.smarthealthit.checkin.1";

Defined in: src/wire/request.ts:22


MDOC_NAMESPACE

const MDOC_NAMESPACE: "org.smarthealthit.checkin";

Defined in: src/wire/request.ts:23


PROTOCOL_ID

const PROTOCOL_ID: "org-iso-mdoc";

Defined in: src/wire/request.ts:21


SMART_REQUEST_INFO_KEY

const SMART_REQUEST_INFO_KEY: "org.smarthealthit.checkin.request";

Defined in: src/wire/request.ts:24


SMART_RESPONSE_ELEMENT_ID

const SMART_RESPONSE_ELEMENT_ID: "smart_health_checkin_response";

Defined in: src/wire/request.ts:25

Functions

arrayBufferCopy()

function arrayBufferCopy(bytes): ArrayBuffer;

Defined in: src/wire/bytes.ts:72

Copy into a fresh ArrayBuffer (WebCrypto inputs must not be SharedArrayBuffer views).

Parameters

Parameter Type
bytes Uint8Array

Returns

ArrayBuffer


base64UrlDecodeBytes()

function base64UrlDecodeBytes(s): Uint8Array;

Defined in: src/wire/bytes.ts:13

Parameters

Parameter Type
s string

Returns

Uint8Array


base64UrlDecodeUtf8()

function base64UrlDecodeUtf8(s): string;

Defined in: src/wire/bytes.ts:25

Parameters

Parameter Type
s string

Returns

string


base64UrlEncodeBytes()

function base64UrlEncodeBytes(bytes): string;

Defined in: src/wire/bytes.ts:5

Byte and encoding primitives shared across the wire layer.

Parameters

Parameter Type
bytes Uint8Array

Returns

string


base64UrlEncodeUtf8()

function base64UrlEncodeUtf8(s): string;

Defined in: src/wire/bytes.ts:21

Parameters

Parameter Type
s string

Returns

string


buildDcapiMdocResponse()

function buildDcapiMdocResponse(input): DcapiMdocResponse;

Defined in: src/wire/response.ts:114

Parameters

Parameter Type
input { cipherText: Uint8Array; enc: Uint8Array; }
input.cipherText Uint8Array
input.enc Uint8Array

Returns

DcapiMdocResponse


buildDcapiSessionTranscript()

function buildDcapiSessionTranscript(input): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: src/wire/request.ts:242

SessionTranscript (spec §8.3) — both verifier and wallet compute this identically: dcapiInfo = CBOR([encryptionInfoBase64Url, origin]) handover = ["dcapi", SHA-256(dcapiInfo)] SessionTranscript = CBOR([null, null, handover])

Parameters

Parameter Type
input { encryptionInfo: string | Uint8Array<ArrayBufferLike>; origin: string; }
input.encryptionInfo string | Uint8Array<ArrayBufferLike>
input.origin string

Returns

Promise<Uint8Array<ArrayBufferLike>>


buildDeviceAuthenticationBytes()

function buildDeviceAuthenticationBytes(input): Uint8Array;

Defined in: src/wire/verify.ts:162

DeviceAuthentication (ISO/IEC 18013-5): DeviceAuthentication = ["DeviceAuthentication", SessionTranscript, DocType, DeviceNameSpacesBytes] DeviceAuthenticationBytes = #6.24(bstr .cbor DeviceAuthentication) The deviceSignature COSE_Sign1 carries a detached payload equal to DeviceAuthenticationBytes.

Parameters

Parameter Type
input { deviceNameSpaces: unknown; docType: string; sessionTranscript: Uint8Array; }
input.deviceNameSpaces unknown
input.docType string
input.sessionTranscript Uint8Array

Returns

Uint8Array


buildDeviceRequestBytes()

function buildDeviceRequestBytes(input): Uint8Array;

Defined in: src/wire/request.ts:150

Parameters

Parameter Type
input { responseElementIdentifier?: string; smartRequestJson: string; version?: "1.0" | "1.1"; }
input.responseElementIdentifier? string
input.smartRequestJson string
input.version? "1.0" | "1.1"

Returns

Uint8Array


buildDeviceRequestBytesFromParts()

function buildDeviceRequestBytesFromParts(input): Uint8Array;

Defined in: src/wire/request.ts:182

Parameters

Parameter Type
input { itemsRequestTag24Bytes: Uint8Array; readerAuthBytes?: Uint8Array<ArrayBufferLike>; version: "1.0" | "1.1"; }
input.itemsRequestTag24Bytes Uint8Array
input.readerAuthBytes? Uint8Array<ArrayBufferLike>
input.version "1.0" | "1.1"

Returns

Uint8Array


buildEncryptionInfoBytes()

function buildEncryptionInfoBytes(input): Uint8Array;

Defined in: src/wire/request.ts:222

Parameters

Parameter Type
input { nonce: Uint8Array; recipientPublicJwk: JsonWebKey; }
input.nonce Uint8Array
input.recipientPublicJwk JsonWebKey

Returns

Uint8Array


buildItemsRequestTag24Bytes()

function buildItemsRequestTag24Bytes(input): Uint8Array;

Defined in: src/wire/request.ts:161

Parameters

Parameter Type
input { responseElementIdentifier?: string; smartRequestJson: string; }
input.responseElementIdentifier? string
input.smartRequestJson string

Returns

Uint8Array


buildOrgIsoMdocRequest()

function buildOrgIsoMdocRequest(smartRequest, options?): Promise<OrgIsoMdocRequestBundle>;

Defined in: src/wire/request.ts:59

Parameters

Parameter Type
smartRequest SmartCheckinRequest
options { deviceRequestVersion?: "1.0" | "1.1"; nonce?: Uint8Array<ArrayBufferLike>; origin?: string; readerAuth?: boolean; readerIdentity?: ReaderIdentity; responseElementIdentifier?: string; verifierKeyPair?: CryptoKeyPair; }
options.deviceRequestVersion? "1.0" | "1.1"
options.nonce? Uint8Array<ArrayBufferLike>
options.origin? string
options.readerAuth? boolean
options.readerIdentity? ReaderIdentity
options.responseElementIdentifier? string
options.verifierKeyPair? CryptoKeyPair

Returns

Promise<OrgIsoMdocRequestBundle>


buildReaderAuthenticationBytes()

function buildReaderAuthenticationBytes(input): Uint8Array;

Defined in: src/wire/reader-auth.ts:32

Parameters

Parameter Type
input { itemsRequestTag24Bytes: Uint8Array; sessionTranscriptBytes: Uint8Array; }
input.itemsRequestTag24Bytes Uint8Array
input.sessionTranscriptBytes Uint8Array

Returns

Uint8Array


bytesEqual()

function bytesEqual(a, b): boolean;

Defined in: src/wire/bytes.ts:67

Parameters

Parameter Type
a Uint8Array
b Uint8Array

Returns

boolean


cborDecode()

function cborDecode(bytes, options?): unknown;

Defined in: src/wire/cbor.ts:91

Parameters

Parameter Type
bytes Uint8Array
options CborDecodeOptions

Returns

unknown


cborDiagnostic()

function cborDiagnostic(value): string;

Defined in: src/wire/cbor.ts:202

CBOR diagnostic notation (subset), for debug UIs and fixtures.

Parameters

Parameter Type
value unknown

Returns

string


cborEncode()

function cborEncode(value): Uint8Array;

Defined in: src/wire/cbor.ts:23

Parameters

Parameter Type
value unknown

Returns

Uint8Array


cborToJsonValue()

function cborToJsonValue(value): JsonValue;

Defined in: src/wire/cbor.ts:224

Lossy JSON projection of decoded CBOR (bytes → {$bytes, hex}, tags → {$tag, value}).

Parameters

Parameter Type
value unknown

Returns

JsonValue


certificateSubjectPublicKeyInfo()

function certificateSubjectPublicKeyInfo(certificateDer): Uint8Array;

Defined in: src/wire/reader-auth.ts:182

Extract the SubjectPublicKeyInfo (DER) from an X.509 certificate.

Certificate ::= SEQUENCE { tbsCertificate, signatureAlgorithm, signature } TBSCertificate ::= SEQUENCE { [0] version OPTIONAL, serialNumber, signature, issuer, validity, subject, subjectPublicKeyInfo, ... }

Parameters

Parameter Type
certificateDer Uint8Array

Returns

Uint8Array


checkDeviceResponse()

function checkDeviceResponse(input): Promise<DeviceResponseCheck>;

Defined in: src/wire/verify.ts:343

Check a decrypted DeviceResponse as a Verifier (spec §8.5 steps 3–7 and [VRS-10]) and return the SMART response text. Never throws.

Parameters

Parameter Type Description
input { deviceResponseBytes: Uint8Array; now?: Date; sessionTranscript: Uint8Array; } -
input.deviceResponseBytes Uint8Array -
input.now? Date The time to check validityInfo against; defaults to now.
input.sessionTranscript Uint8Array -

Returns

Promise<DeviceResponseCheck>


compareBytes()

function compareBytes(a, b): number;

Defined in: src/wire/bytes.ts:58

Parameters

Parameter Type
a Uint8Array
b Uint8Array

Returns

number


concatBytes()

function concatBytes(parts): Uint8Array;

Defined in: src/wire/bytes.ts:47

Parameters

Parameter Type
parts readonly Uint8Array<ArrayBufferLike>[]

Returns

Uint8Array


createEphemeralReaderIdentity()

function createEphemeralReaderIdentity(subjectCommonName?): Promise<ReaderIdentity>;

Defined in: src/wire/reader-auth.ts:16

Parameters

Parameter Type Default value
subjectCommonName string "SMART Health Check-in Demo Verifier"

Returns

Promise<ReaderIdentity>


decodeBase64UrlLenient()

function decodeBase64UrlLenient(
   value, 
   warnings, 
   rule, 
   what): Uint8Array;

Defined in: src/wire/warnings.ts:53

Decode base64url, tolerating padding and the standard alphabet with a warning ([WRQ-2], [VRS-2]). Throws on anything else.

Parameters

Parameter Type
value string
warnings WarningList
rule string
what string

Returns

Uint8Array


extractDcapiResponse()

function extractDcapiResponse(credential): string | DcapiMdocResponse;

Defined in: src/browser/index.ts:254

Pull the org-iso-mdoc response payload out of whatever the browser's credential object looks like: a DigitalCredential with .data (object or JSON string), a bare {protocol, data} object, or the raw base64url response string.

Parameters

Parameter Type
credential unknown

Returns

string | DcapiMdocResponse


firstSmartCheckinResponse()

function firstSmartCheckinResponse(deviceResponse): SmartResponseInspection;

Defined in: src/wire/response.ts:345

Parameters

Parameter Type
deviceResponse DeviceResponseInspection

Returns

SmartResponseInspection


hex()

function hex(bytes): string;

Defined in: src/wire/bytes.ts:29

Parameters

Parameter Type
bytes Uint8Array

Returns

string


hexDecode()

function hexDecode(s): Uint8Array;

Defined in: src/wire/bytes.ts:33

Parameters

Parameter Type
s string

Returns

Uint8Array


hpkeAesGcm()

function hpkeAesGcm(encrypt, input): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: src/wire/hpke.ts:107

Parameters

Parameter Type
encrypt boolean
input { aad: Uint8Array; data: Uint8Array; key: Uint8Array; nonce: Uint8Array; }
input.aad Uint8Array
input.data Uint8Array
input.key Uint8Array
input.nonce Uint8Array

Returns

Promise<Uint8Array<ArrayBufferLike>>


hpkeContext()

function hpkeContext(input): Promise<{
  baseNonce: Uint8Array;
  key: Uint8Array;
}>;

Defined in: src/wire/hpke.ts:16

Parameters

Parameter Type
input { dh: Uint8Array; enc: Uint8Array; info: Uint8Array; recipientPublicBytes: Uint8Array; }
input.dh Uint8Array
input.enc Uint8Array
input.info Uint8Array
input.recipientPublicBytes Uint8Array

Returns

Promise<{ baseNonce: Uint8Array; key: Uint8Array; }>


hpkeNonce()

function hpkeNonce(baseNonce, sequenceNumber?): Uint8Array;

Defined in: src/wire/hpke.ts:130

Parameters

Parameter Type Default value
baseNonce Uint8Array undefined
sequenceNumber number 0

Returns

Uint8Array


hpkeSealDirectMdoc()

function hpkeSealDirectMdoc(input): Promise<HpkeSealResult>;

Defined in: src/wire/response.ts:160

Wallet-side seal — used by tests and the demo's mock wallet.

Parameters

Parameter Type
input { aad?: Uint8Array<ArrayBufferLike>; info: Uint8Array; plaintext: Uint8Array; recipientPublicJwk: JsonWebKey; }
input.aad? Uint8Array<ArrayBufferLike>
input.info Uint8Array
input.plaintext Uint8Array
input.recipientPublicJwk JsonWebKey

Returns

Promise<HpkeSealResult>


i2osp()

function i2osp(value, length): Uint8Array;

Defined in: src/wire/bytes.ts:82

Parameters

Parameter Type
value number
length number

Returns

Uint8Array


importCertificatePublicKey()

function importCertificatePublicKey(certificateDer): Promise<CryptoKey>;

Defined in: src/wire/reader-auth.ts:196

Parameters

Parameter Type
certificateDer Uint8Array

Returns

Promise<CryptoKey>


inspectDcapiMdocResponse()

function inspectDcapiMdocResponse(input): DcapiResponseInspection;

Defined in: src/wire/response.ts:133

Parameters

Parameter Type
input string | DcapiMdocResponse

Returns

DcapiResponseInspection


inspectDeviceRequestBytes()

function inspectDeviceRequestBytes(bytes): DeviceRequestInspection;

Defined in: src/wire/inspect-request.ts:91

Parameters

Parameter Type
bytes Uint8Array

Returns

DeviceRequestInspection


inspectDeviceResponseBytes()

function inspectDeviceResponseBytes(bytes): Promise<DeviceResponseInspection>;

Defined in: src/wire/response.ts:356

Parameters

Parameter Type
bytes Uint8Array

Returns

Promise<DeviceResponseInspection>


inspectEncryptionInfoBytes()

function inspectEncryptionInfoBytes(bytes): EncryptionInfoInspection;

Defined in: src/wire/inspect-request.ts:171

Parameters

Parameter Type
bytes Uint8Array

Returns

EncryptionInfoInspection


inspectItemsRequestBytes()

function inspectItemsRequestBytes(bytes): ItemsRequestInspection;

Defined in: src/wire/inspect-request.ts:122

Parameters

Parameter Type
bytes Uint8Array

Returns

ItemsRequestInspection


inspectOrgIsoMdocNavigatorArgument()

function inspectOrgIsoMdocNavigatorArgument(arg, options?): Promise<OrgIsoMdocInspection>;

Defined in: src/wire/inspect-request.ts:59

Parameters

Parameter Type
arg unknown
options { origin?: string; }
options.origin? string

Returns

Promise<OrgIsoMdocInspection>


inspectSmartRequestInfoValue()

function inspectSmartRequestInfoValue(value): SmartRequestInspection;

Defined in: src/wire/response.ts:514

Parameters

Parameter Type
value unknown

Returns

SmartRequestInspection


mapGet()

function mapGet(value, key): unknown;

Defined in: src/wire/cbor.ts:264

Parameters

Parameter Type
value unknown
key string | number

Returns

unknown


openWalletCredential()

function openWalletCredential(input): Promise<OpenedCredential>;

Defined in: src/wire/response.ts:286

The Verifier's first two steps (spec §8.5, [VRS-2] and [VRS-3]): decode the credential and decrypt it. Fails only if it can't be decoded, lacks enc or cipherText, or doesn't decrypt; a protocol other than org-iso-mdoc, padded base64url, and a first entry other than "dcapi" are warnings. Never throws.

credential is {protocol, data: {response}} or the data.response string.

Parameters

Parameter Type
input { credential: unknown; recipientPrivateKey: CryptoKey; recipientPublicJwk: JsonWebKey; sessionTranscript: Uint8Array; }
input.credential unknown
input.recipientPrivateKey CryptoKey
input.recipientPublicJwk JsonWebKey
input.sessionTranscript Uint8Array

Returns

Promise<OpenedCredential>


openWalletResponse()

function openWalletResponse(input): Promise<OpenWalletResponseResult>;

Defined in: src/wire/response.ts:206

Parameters

Parameter Type
input { aad?: Uint8Array<ArrayBufferLike>; recipientPrivateKey: CryptoKey; recipientPublicJwk: JsonWebKey; response: string | DcapiMdocResponse; sessionTranscript: Uint8Array; smartRequest?: unknown; }
input.aad? Uint8Array<ArrayBufferLike>
input.recipientPrivateKey CryptoKey
input.recipientPublicJwk JsonWebKey
input.response string | DcapiMdocResponse
input.sessionTranscript Uint8Array
input.smartRequest? unknown

Returns

Promise<OpenWalletResponseResult>


parseJsonStrict()

function parseJsonStrict(text): unknown;

Defined in: src/wire/json.ts:9

Parameters

Parameter Type
text string

Returns

unknown


publicJwkToCoseKey()

function publicJwkToCoseKey(jwk): Map<number, number | Uint8Array<ArrayBufferLike>>;

Defined in: src/wire/request.ts:199

Parameters

Parameter Type
jwk JsonWebKey

Returns

Map<number, number | Uint8Array<ArrayBufferLike>>


publicJwkToRawP256()

function publicJwkToRawP256(jwk): Uint8Array;

Defined in: src/wire/request.ts:211

Parameters

Parameter Type
jwk JsonWebKey

Returns

Uint8Array


sha256()

function sha256(bytes): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: src/wire/bytes.ts:78

Parameters

Parameter Type
bytes Uint8Array

Returns

Promise<Uint8Array<ArrayBufferLike>>


signReaderAuth()

function signReaderAuth(input): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: src/wire/reader-auth.ts:45

Parameters

Parameter Type
input { itemsRequestTag24Bytes: Uint8Array; readerCertificateDer: Uint8Array; readerPrivateKey: CryptoKey; sessionTranscriptBytes: Uint8Array; }
input.itemsRequestTag24Bytes Uint8Array
input.readerCertificateDer Uint8Array
input.readerPrivateKey CryptoKey
input.sessionTranscriptBytes Uint8Array

Returns

Promise<Uint8Array<ArrayBufferLike>>


utf8()

function utf8(s): Uint8Array;

Defined in: src/wire/bytes.ts:43

Parameters

Parameter Type
s string

Returns

Uint8Array


verifyDeviceResponseSignatures()

function verifyDeviceResponseSignatures(input): Promise<DocumentVerification[]>;

Defined in: src/wire/verify.ts:56

Verify every document in a DeviceResponse. All three checks are reported independently so a caller can apply deployment trust policy (e.g. accept a self-attested wallet chain while still requiring a valid signature).

Parameters

Parameter Type
input { deviceResponseBytes: Uint8Array; sessionTranscript: Uint8Array; }
input.deviceResponseBytes Uint8Array
input.sessionTranscript Uint8Array

Returns

Promise<DocumentVerification[]>


verifyIssuerAuth()

function verifyIssuerAuth(issuerAuthRaw): Promise<IssuerAuthVerification>;

Defined in: src/wire/verify.ts:96

Parameters

Parameter Type
issuerAuthRaw unknown

Returns

Promise<IssuerAuthVerification>


verifyReaderAuthSignature()

function verifyReaderAuthSignature(input): Promise<boolean>;

Defined in: src/wire/reader-auth.ts:65

Parameters

Parameter Type
input { itemsRequestTag24Bytes: Uint8Array; readerAuthBytes: Uint8Array; readerPublicKey: CryptoKey; sessionTranscriptBytes: Uint8Array; }
input.itemsRequestTag24Bytes Uint8Array
input.readerAuthBytes Uint8Array
input.readerPublicKey CryptoKey
input.sessionTranscriptBytes Uint8Array

Returns

Promise<boolean>