Installation
Choose either the npm package or the CDN script tag, depending on whether your project uses a Node.js-based build pipeline.- npm
- CDN (jsDelivr)
- CDN (UNPKG)
Install the package for your chosen flow:
Integration steps
1
Generate a session ID server-side
Your backend calls the Youverify API to generate a short-lived session ID. This call uses your secret API key — it must happen on your server, not in the browser.Response:
2
Pass the session ID to your front-end
Return the
sessionId from your backend API to the browser. You might expose a thin endpoint on your own server for the browser to call, for example GET /api/verification-session.3
Initialize the SDK
Construct the SDK instance with your public merchant key and the session ID. Register your callbacks before calling
launch().4
Launch the verification flow
Call
launch() when your user is ready to start — for example, on a button click.Callbacks
Configuration options
string
required
Your Youverify public merchant key. Safe to embed in browser code. Retrieve it from Settings → API KEY / Webhook in the Cowork dashboard.
string
required
The short-lived session ID generated by your backend. See Session Tokens.
boolean
default:"false"
Set to
true to run in sandbox mode using test data. Set to false for production.function
Callback invoked when the user successfully completes the verification flow. Receives a result data object.
function
Callback invoked when verification fails or an error occurs. Receives an error object.
function
Callback invoked when the user closes the SDK modal without completing the flow.
How results link back to your entity
The session ID you generate is tied to the verification result on Youverify’s side. After the SDK flow completes, call your backend to retrieve the result using the Liveness History endpoint or by reading the entity record via the API. The session ID is the join key between the SDK-collected biometric data and your entity record.Session IDs are short-lived (default TTL: 120 seconds, configurable between 30 and 600 seconds). Generate a fresh session ID for each verification attempt — do not cache or reuse them.