Dev Center

Integrate with the SDK, CLI, or API

A Python SDK, a CLI, and an mTLS-authenticated REST API — keys are born and live only in your process's memory, and the server never sees anything but ciphertext.

Open source packages

A simplified development experience

We offer a Python SDK, a CLI that runs on Windows, Mac, and Linux, and a RESTful API ready for a container or Kubernetes environment — all while keeping end-to-end encryption (E2E), and all of it open source under the Apache 2.0 license.

  • diagnos

    The Python library behind the vault: import it, touch `vault.patients`, and unlock happens on its own — encrypted in your own process, start to finish.

  • diagnos-cli

    The whole SDK, straight in your terminal: `diagnos login` handles enrollment, and the patients, exams, and files commands take it from there.

  • diagnos-api

    A thin REST facade over the same SDK, for teams that speak HTTP instead of Python — authenticated only by mTLS certificate.

We love open source

The license grants commercial use, modification, and redistribution, with an express patent grant — the only ask is preserving the copyright notice and flagging the changes you make. We're not promising support, a public roadmap, or a contribution process: this is open source, not a product with a support contract.

git clone https://github.com/diagnos-tech/integration && cd integration
Cloning into 'integration'...
ls -d apps/*/
apps/api/ → diagnos-api
apps/cli/ → diagnos-cli
apps/sdk/ → diagnos
head -n1 LICENSE
Public repository diagnos-tech/integration

Get building

Quickstart

Pick a package and an install method — the commands below are exactly what the repository's READMEs verify.

Every command below needs a DIAGNOS_API_TOKEN, issued by a workspace admin. How to get one

bash
pip install diagnos
python
from diagnos import Diagnos

with Diagnos() as vault:
    for row in vault.patients.list():
        patient = vault.patients.get(row.document_id)
        print(patient.record.legal_name)

Access control

The packages are public. The token isn't.

DIAGNOS_API_TOKEN identifies a service account and its workspace, and is issued by a workspace admin. On its own, it unlocks nothing — the human approval from the three steps below is what does.

What the full API reference covers

  • OpenAPI 3.1 specification
  • Bearer token authentication
  • Sandbox and production environments

The full reference is public — reach it through the GitHub repository or the documentation below, no approval required. To authenticate calls, create a DIAGNOS_API_TOKEN under Settings → Service accounts, inside your workspace.

Zero trust

End-to-end secure integration

No process reads anything on its own: enrollment trades keys and waits for a person to approve — live, or ahead of time.

How approval happens
  1. Generates a keypair on the spot

    The process creates a hybrid keypair (X25519 + ML-KEM-768) straight in memory and registers where it's running — operating system, container, hostname, and user.

  2. Prints the invite

    A link and a six-digit code go out on stderr — that's the only output of this step.

    The code confirms, together with the link, that whoever is approving is the same person looking at this terminal.

  3. An admin approves

    A workspace admin opens the link in the web app, checks the description, types the code, and picks which security groups that process may read. Those groups' keys get sealed to the process's public keys — never to the process itself.

All of this lives in memory: stopping the process erases the keys, and restarting requires approval again. That's the design, not a limitation — whoever needs to restart without a human nearby, like Kubernetes or a scheduled job, sets up auto-unseal through OpenBao — the Automatically mode, alongside.

  1. Generates a keypair on the spot

    The process creates a hybrid keypair (X25519 + ML-KEM-768) straight in memory and registers where it's running — operating system, container, hostname, and user.

  2. Asks for the sealed key

    Instead of printing an invite and waiting, the process asks OpenBao for the key already sealed to it — no link, no six-digit code.

  3. OpenBao releases it on the spot

    OpenBao checks that the keypair matches what was authorized and releases the secret right away, without waiting on anyone.

The human approval didn't disappear — it just happened earlier, when OpenBao was configured, not on every restart. Switching environments or revoking access still needs an admin.