Skip to main content
The Youverify Web SDK lets you embed liveness detection and document capture directly in your web application — no redirect to a hosted page required. The SDK is compatible with all major browsers and devices. Before launching any SDK flow you must generate a session token from your backend to keep your secret API key off the client.

Installation

Choose either the npm package or the CDN script tag, depending on whether your project uses a Node.js-based build pipeline.
Install the package for your chosen flow:

Integration steps

1

Generate a session ID server-side

Your backend calls the Youverify API to generate a short-lived session ID. This call uses your secret API key — it must happen on your server, not in the browser.
Response:
2

Pass the session ID to your front-end

Return the sessionId from your backend API to the browser. You might expose a thin endpoint on your own server for the browser to call, for example GET /api/verification-session.
3

Initialize the SDK

Construct the SDK instance with your public merchant key and the session ID. Register your callbacks before calling launch().
4

Launch the verification flow

Call launch() when your user is ready to start — for example, on a button click.

Callbacks

Configuration options

string
required
Your Youverify public merchant key. Safe to embed in browser code. Retrieve it from Settings → API KEY / Webhook in the Cowork dashboard.
string
required
The short-lived session ID generated by your backend. See Session Tokens.
boolean
default:"false"
Set to true to run in sandbox mode using test data. Set to false for production.
function
Callback invoked when the user successfully completes the verification flow. Receives a result data object.
function
Callback invoked when verification fails or an error occurs. Receives an error object.
function
Callback invoked when the user closes the SDK modal without completing the flow.
The session ID you generate is tied to the verification result on Youverify’s side. After the SDK flow completes, call your backend to retrieve the result using the Liveness History endpoint or by reading the entity record via the API. The session ID is the join key between the SDK-collected biometric data and your entity record.
Session IDs are short-lived (default TTL: 120 seconds, configurable between 30 and 600 seconds). Generate a fresh session ID for each verification attempt — do not cache or reuse them.
Never pass your API secret key to the Web SDK. Use only your public merchant key on the client side. Your secret key must remain on your server.