Sharing & signing

How does electronic signature work in diagnos?

Signing a report happens on a separate device: you open a link or scan a QR code on your phone, confirm it's you with your passkey, and complete a short ceremony there — not on the screen where the report is open. Starting a signature request from the report screen isn't available yet; this covers what the signing ceremony itself does.

  • Updated on
  • 2 min read

diagnos doesn't sign a report on the screen where you're reading it. Signing happens on a second device — your security device, usually your phone — after you open a link or scan a QR code there. Requesting a signature from the report screen itself isn't available in the interface yet; what's described below is the signing step, which does work end to end once that link exists.

What happens on your security device#

  1. Unlock with your passkey. The first time, this registers your phone as your security device; after that, it's the same fingerprint or face unlock you already use.
  2. Allow location. The ceremony requires it and won't continue without it.
  3. Match the code shown on the other screen. A short code (digits or a pattern) appears where the document is open. You enter the matching one on your phone — this proves both screens belong to the same signing attempt.
  4. Confirm with your passkey again. This second confirmation is the signature itself.

Once it completes, the original screen updates on its own — there's nothing to refresh or check manually.

What the signature actually proves#

The result is a certificate: your device's public key, the WebAuthn proof it produced, and the exact hash of the document version you signed — enough for anyone to verify that this key signed this specific document at this specific time, without needing to see the report itself. That certificate is stored permanently and is publicly readable by design (so outside verification doesn't require a login), but it never contains clinical content — no patient name, no report text, only hashes and signing metadata.

See also#