SDK

Diagnos

The SDK's entry point: one service account's live connection to one workspace.

On this page

class

Signature #

class Diagnos(settings: Settings | None = None, *, token: str | None = None, on_prompt: PromptCallback | None = None, auto_unseal: bool | None = None, transport: VaultTransport | None = None, session: SessionManager | None = None)

The SDK's entry point: one service account's live connection to one workspace.

Members #

workspace_id: str #

property

This service account's workspace, read from its token.

account_id: str #

property

This service account's owning account, read from its token.

name: str #

property

The service account's human-readable name (`slug@<workspace_id>.diagnos.health`).

key_id: str #

property

Id of the token's key pair — what an admin rotates or revokes.

security_groups: list[str] #

property

Ids of every security group this session holds a DEK for; `[]` before `unlock()`.

patients: Patients #

property

`vault.patients` — built once, on first access.

exams: Exams #

property

`vault.exams` — built once, on first access.

drives: Drives #

property

`vault.drives` — built once, on first access.

unlock() -> Keyring #

method

Enrolls (or restores from OpenBao) and returns the live `Keyring`; idempotent.

lock() -> None #

method

Ends the session, best-effort server-side, and always wipes local key material. Unlike `close()`, this is never called automatically — see the `__exit__` docstring for why.

close() -> None #

method

Closes the underlying HTTP clients. Does not `lock()` — see `__exit__`.