Capture inspector

Loads a checked-in capture from Chrome on Android and shows its actual bytes for every structure in the Wire protocol explainer, so you can compare your own implementation with it byte for byte.

Load a different capture

This page auto-loads the checked-in Chrome/Android capture (android-chrome-capture). To compare another capture, pick a folder laid out like fixtures/dcapi-requests/android-chrome-capture and fixtures/responses/android-chrome-capture. The Testing EHR can also open a run here directly.

Comparing your implementation with this capture

Walk the same steps as spec Appendix A, which lists the expected value at each one. The capture's HPKE private key is published with it (recipient-private.jwk.json), so you can decrypt it yourself.

  1. Request. Decode device-request.cbor. Check the docType, namespace, element, and that the SMART request text is in requestInfo["org.smarthealthit.checkin.request"].
  2. Transcript. Build dcapiInfo = CBOR([encryptionInfoBase64url, origin]), hash it with SHA-256, build CBOR([null, null, ["dcapi", hash]]), and compare with session-transcript.cbor. Comparing dcapiInfo itself with the transcript file never matches.
  3. Decrypt. Open dcapi-response.cbor with the private key and info = session-transcript.cbor; the result is device-response.cbor.
  4. Response. Check SHA-256(issuer-signed-item-tag24.cbor) against the MSO digest for the item's digestID, then verify issuerAuth and the detached device signature over device-authentication.cbor.

From a checkout of the spec repository, after bun install:

bun tools/wire/inspect-mdoc-request.ts fixtures/dcapi-requests/android-chrome-capture --out /tmp/out/request
bun tools/wire/inspect-mdoc-response.ts fixtures/responses/android-chrome-capture/device-response.cbor --out /tmp/out/response

This capture's SMART response has 4 artifacts and 4 status entries. That describes this capture, not what every response looks like.

No run directory selected yet.