Skip to main content
The verification flow mounts into an element you provide, runs the capture screens your dashboard defines, and calls you back once the server has decided.

1. Mint a session token on your backend

Your API key stays on your server. Exchange it for a short-lived session token and return that to your frontend.
Never ship an API key to the browser, and never embed one in your frontend bundle or in a public repository. The SDK is designed so it never needs one — it only ever sees the short-lived session token.

2. Mount the flow

When you are done, tear it down. This stops the camera, clears frame buffers, removes the UI, and drops listeners:

3. Handle the decision

onComplete fires once, with the server’s authoritative result:
See Results and errors for every decision value and what to do with it.

Handling token expiry

Session tokens are short-lived by design. When one expires the SDK fires onExpire rather than failing the flow — mint a fresh token and hand it back:
The user keeps their place. Nothing already captured is lost.

What the dashboard controls

The flow renders strictly from your dashboard configuration: which screens appear, which documents are offered, whether each is captured front-only or front-and-back, and the theme. Change it in the dashboard, not in your code. No redeploy is required.
The intro screen shows the end user a language picker and a light/dark toggle. Both switch live and drive every subsequent screen. Your language and colorScheme options set the starting values.

Before you go live

Embedding requirements

The camera and CSP headers your page must allow. The most common launch blocker.

Configuration reference

Every option and every controller method.