Skip to main content
This guide provides a conceptual overview of OneSDK integration with basic code examples. The code snippets shown are illustrative and need to be adapted into your specific framework and application architecture. For complete, working examples:

Core Modules Overview

Individual Module

Complete KYC workflow for individual verification, including document handling, address verification, and profile management.

Biometrics Module

Advanced biometric verification capabilities including facial recognition, liveness detection, and matching.

OCR Module

Intelligent document scanning and data extraction for IDs, passports, and other verification documents.

IDV Module

Comprehensive identity document verification with support for multiple document types across jurisdictions.

eKYC Form Module

Customizable electronic Know Your Customer forms with built-in validation and compliance checks.

Fraud Detection Module

Real-time fraud prevention and detection across multiple risk vectors.

OneSDK Modules Data Capture Flow

OneSDK modules data capture flow diagram

Data capture flow diagram showing module selection options

Quick Integration Guide

1

Install OneSDK

2

Initialize the SDK

Note: The sample code below is just an example. Never generate tokens on the frontend — doing so can expose your credentials. Always generate tokens securely on your backend and pass them to your app as needed.
3

Configure Modules

4

Start Verification

Implementation Best Practices

Initialize modules only when needed and release resources after use. This is especially important for camera-based operations in the Biometrics and OCR modules.

Common Integration Scenarios

Each module can be used independently or as part of a comprehensive verification flow. Check individual module documentation for detailed implementation guidelines.

Content Security Policy (CSP) Settings

You may need to adjust your Content Security Policy (CSP) settings to allow vendors’ scripts and resources to load correctly. Below are the additional CSP rules required based on the vendor you are integrating with:

Permissions-Policy (Camera Access)

If your application sends a Permissions-Policy HTTP header, it controls whether the browser lets OneSDK and the vendor SDK use the camera. This is separate from CSP: a page can pass every CSP rule and still never show the camera permission prompt.
camera=() disables the camera for your page and every iframe inside it. The end user is never asked for camera permission, and document capture and biometrics cannot start. Remove camera=() from any page that hosts OneSDK.
Every vendor needs at least self, because OneSDK and several vendor SDKs run directly in your page. Vendors that render their capture screens inside an iframe also need that iframe’s origin, because OneSDK can only pass camera access to an iframe your policy allows.
Permissions-Policy for Onfido
If you integrate with more than one vendor, combine their origins in a single camera=(...) allowlist.
OneSDK also passes microphone, fullscreen, accelerometer, gyroscope, magnetometer, and geolocation to vendor iframes. If your policy restricts any of these, apply the same allowlist to them.

API Reference

Detailed API documentation for all OneSDK modules and methods.

Migration Guide

Guide for upgrading from previous versions of OneSDK.

Examples Repository

Sample implementations and integration patterns.

Support Portal

Technical support and implementation assistance.