What's new
This page lists what each Cardinal SDK release has added, newest first. Changes that can break existing code are marked Breaking and come with migration instructions in Migration.
Releases that only contain internal, build or CI changes are not listed.
2.14.0 β 2026-10-01β
- Breaking (TypeScript and Kotlin/JS): the SDK requires Node.js 24 or later. The JavaScript build no longer uses
eval, so bundlers that reject it, such as Rolldown, can now bundle the SDK. See Migration.
2.13.6 β 2026-10-01β
- Breaking (TypeScript): the
onMalformedEntityoption introduced in 2.13.4 is replaced byentityListDecodingStrategy, which takesEntityListDecodingStrategy.Strict(the default) ornew EntityListDecodingStrategy.DiscardMalformed(handler), like in Kotlin. See Discard malformed entities in list reads. - TypeScript: the filter discovery API is now available as
sdk.filter, as it already was in Kotlin. See Everything about filters.
2.13.5 β 2026-09-28β
- New read-only
Group.status(GroupStatus.PayingorGroupStatus.Free). A group without an explicit status inherits the status of its first ancestor that isPayingorFree, and isFreeif there is none. - New
InvoicingCode.agreementNumber: the reimbursement agreement number obtained during a pre-authorization. - Subscriptions: when the server drops the websocket without a closing frame, the subscription now emits
EntitySubscriptionEvent.ConnectionError.ClosedByServerinstead of failing.
2.13.4 β 2026-09-23β
- New option to discard the entities that can't be decoded in list and page reads, instead of failing the whole
request (Kotlin:
entityListDecodingStrategy, TypeScript:onMalformedEntity). Not available in Python or Dart. See Discard malformed entities in list reads.
2.13.3 β 2026-09-02β
- Breaking:
HealthElementAsserter.externalAsserterIdentifieris now anExternalAsserterIdentifier, which wraps theIdentifier.
2.13.2 β 2026-08-12β
- Breaking:
HealthElementAsserter(asserterId, asserterType)is replaced byHealthElementAsserter(localAsserterIdentifier, externalAsserterIdentifier). Exactly one of the two must be set.
2.13.1 β 2026-08-11β
- Fix: the
assertersof health elements are now correctly encrypted by default. 2.13.0 used an invalid encrypted-field path.
2.13.0 β 2026-08-11β
- New
HealthElement.qualifiedLinks: typed links from a health element to other health elements, for example a complication of another condition. - New
HealthElement.asserters: who asserts that the condition is true (FHIR asserter): a patient, a healthcare party or a related person. Asserters are encrypted by default. - See HealthElement. These fields are not yet available in the Dart SDK.
2.12.1 β 2026-08-03β
- Fix:
calendarItem.linkToPatientno longer fails on calendar items that are not linked to a patient yet. Before this fix it also did not block calendar items that were already linked.
2.12.0 β 2026-07-30β
- New
RelatedPersonentity andsdk.relatedPersonAPI, withRelatedPersonFilters, to store a patient's relatives and other contact persons. See RelatedPerson. - New
Partnership.partnerType(PartnerType) to link a patient to a related person. - Python: the
lenient_jsonoption is renamed toignoreUnknownFields(see 2.10.0).
2.11.0 β 2026-07-26β
- New
withEncryptionMetadataAndDelegatesmethods on all the APIs of encryptable entities, for fine-grained control over what each delegate can access. See Basic operations. - New
user.removeUserMobilePhone(userId, previousMobilePhone). See User. accessLog.withEncryptionMetadata: the patient is now optional. Breaking (TypeScript):patientmoved into the options object.- New
receipt.listReceiptsBetweenDates(and in-group variant), and in-groupgetRawReceiptAttachment.
2.10.0 β 2026-07-06β
- New
ignoreUnknownFieldsoption, which replaceslenientJson(Kotlin and TypeScript) and now also applies to decrypted content. A custom KotlinhttpClientnow requireshttpClientJson, and the other way round. See Ignore unknown fields. - Breaking:
Annotationis split intoDecryptedAnnotationandEncryptedAnnotation. This affects thenotesof contacts, health elements, patients, services and addresses.
2.9.0 β 2026-07-02β
- New
InsuranceFilters(all,byIdentifiers,byCode,byTag), withinsurance.matchInsurancesByandfilterInsurancesBy[Sorted]. See Everything about filters. - The calendar item occupancy methods are now also available on
CardinalSdk(they were added toCardinalBaseSdkin 2.8.0).
2.8.0 β 2026-07-01β
- New calendar item occupancy histograms:
getCalendarItemsOccupancyByPeriodForSelf,β¦ForHealthcarePartyandβ¦AndAgendaId(onCardinalBaseSdk). See Calendar items occupancy.
2.7.0 β 2026-06-18β
- New
sdk.filterAPI (getFilterOptionsDefinitions) andFilterOptionsCatalog, to discover the available filter options at runtime, for example to build dynamic query builders. Kotlin only at first: TypeScript support came in 2.13.6, and Python has aFilterApiclass since 2.11.0 but nosdk.filterproperty yet. See Everything about filters.
2.6.0 β 2026-05-29β
- 2FA:
Enable2faRequestnow requires the currentotpand accepts an optionalalgorithm(Sha1by default,Sha256orSha512). NewUser.systemMetadata.uses2fa. Initializing the SDK no longer fails when the user still has to provide a 2FA code. See Set up 2FA. - Breaking: the sortability of filter options has been reviewed. Many filters (
byIdentifiers,byPatientsβ¦, code and tag filters, β¦) can no longer be used as the first argument offilterβ¦BySorted. See Everything about filters.
2.5.0 β 2026-05-20β
- New
Role.description, and adescriptionparameter onrole.createRole. See Define user roles. - Breaking:
Partnershipis split intoDecryptedPartnershipandEncryptedPartnership. - More fields are encrypted by default: the asserters, care team and episodes of health elements, and the participants and locations of contacts.
2.4.x β 2026-04-23 to 2026-05-04β
- Breaking (2.4.0):
healthcareParty.registerPatientis renamed toregisterHealthcareParty. - 2.4.0: the
macosX64Kotlin target is removed. 2.4.1: alinuxArm64target is added. - 2.4.2: the multi-code service filters take a
Map<String, Set<String>>.
2.3.x β 2026-04-02 to 2026-04-10β
- 2.3.0: new
recovery.createRecoveryInfoForAvailableParentKeyPairs, which lets a child data owner create recovery data for its parent's keypairs. See Share data with many users. - 2.3.1: new
contact.decryptPatientIdOfService, to find the patient of a service. - 2.3.2: new service filters on codes and tags combined with a value date (
byCodesAndValueDate,byCodePrefixAndValueDate,byTagCodesAndValueDate,byTagPrefixAndValueDateand their patient variants). - 2.3.2: the
Serialization.CardinalSerializerModuleused by the SDK is now public, for custom KotlinJsoninstances. - Breaking (2.3.1):
Patient.preferredUserIdis removed. - Breaking (2.3.0):
group.createGroupno longer takes aroleparameter.
2.2.0 β 2026-03-26β
- New
user.modifyUserPassword,modifyUserEmailandmodifyUserMobilePhone, which don't need the user revision and work with a smart authentication provider. See User.