{"_id":"@antifraud/sdk-client-js","_rev":"4-c1fed2b04ee75873887d5d3c31e991d0","name":"@antifraud/sdk-client-js","dist-tags":{"latest":"1.1.7"},"versions":{"1.0.2":{"name":"@antifraud/sdk-client-js","version":"1.0.2","_id":"@antifraud/sdk-client-js@1.0.2","maintainers":[{"name":"mseptiaan-antifraud","email":"muhammad.septian@antifraud.id"}],"dist":{"shasum":"6fa780de9ddc5033e950f4f3ebda291bce45da08","tarball":"https://registry.npmjs.org/@antifraud/sdk-client-js/-/sdk-client-js-1.0.2.tgz","fileCount":10,"integrity":"sha512-f4mbtldqBdxdncehjfycBJLF848pb7InCI8GCzX7agkfW/NNvsbCyXtAzshsHae+Lmr2Z26onc5mkSwNiNppfg==","signatures":[{"sig":"MEQCIG0UBscGPaMSHaCbl7wzBsLM2SnjEMV7eFgmoAYgyT8xAiAqSJ87pjU8lcErF3SaFDx7yaa1ClgDkMjU98uE6QC0Tw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":102816},"main":"./dist/antifraud.cjs.js","type":"module","types":"./dist/index.d.ts","module":"./dist/antifraud.esm.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/antifraud.esm.js","require":"./dist/antifraud.cjs.js"}},"gitHead":"ec3d7e122bdcd55751a9198f71b513fcb451cc0f","scripts":{"test":"vitest run","build":"vite build","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"mseptiaan-antifraud","email":"muhammad.septian@antifraud.id"},"_npmVersion":"10.8.2","description":"Antifraud Web Browser SDK — device fingerprint collection and session management","directories":{},"_nodeVersion":"20.20.2","_hasShrinkwrap":false,"devDependencies":{"vite":"^5.4.0","jsdom":"^25.0.0","vitest":"^2.1.0","typescript":"^5.5.0","@types/node":"^26.1.1","vite-plugin-dts":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk-client-js_1.0.2_1784458097214_0.5478193459831555","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@antifraud/sdk-client-js","version":"1.0.4","_id":"@antifraud/sdk-client-js@1.0.4","maintainers":[{"name":"mseptiaan-antifraud","email":"muhammad.septian@antifraud.id"}],"dist":{"shasum":"a5c6ad188dfd50fcdda33dc087d0e583f8a94cbd","tarball":"https://registry.npmjs.org/@antifraud/sdk-client-js/-/sdk-client-js-1.0.4.tgz","fileCount":10,"integrity":"sha512-cMAY9GW+oITX3SC+H5zg6hunmUk5otwqWhIfoObDz6gnXg3CEKlFlFdJMx2Ps3BsFUkDrMzUhPrhfyEAlBLo7A==","signatures":[{"sig":"MEYCIQDGQUqEldfW3/HokrBsNDDzShjxLyxOTPFrrwUy+It00QIhAI73Q+eYHOAbc7BGs+reEttb1fxYCVEFFWx1zeqoTd7T","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":110900},"main":"./dist/antifraud.cjs.js","type":"module","types":"./dist/index.d.ts","module":"./dist/antifraud.esm.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/antifraud.esm.js","require":"./dist/antifraud.cjs.js"}},"gitHead":"d987e3513214ff580d50c6a3b65651e673b1d4ea","scripts":{"test":"vitest run","build":"vite build","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"mseptiaan-antifraud","email":"muhammad.septian@antifraud.id"},"_npmVersion":"10.8.2","description":"Antifraud Web Browser SDK — device fingerprint collection and session management","directories":{},"_nodeVersion":"20.20.2","_hasShrinkwrap":false,"devDependencies":{"vite":"^5.4.0","jsdom":"^25.0.0","vitest":"^2.1.0","typescript":"^5.5.0","@types/node":"^26.1.1","vite-plugin-dts":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk-client-js_1.0.4_1784459337439_0.8583216153976754","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@antifraud/sdk-client-js","version":"1.1.2","_id":"@antifraud/sdk-client-js@1.1.2","maintainers":[{"name":"mseptiaan-antifraud","email":"muhammad.septian@antifraud.id"}],"homepage":"https://github.com/antifraud-id/sdk-client-js#readme","bugs":{"url":"https://github.com/antifraud-id/sdk-client-js/issues"},"dist":{"shasum":"214cafe974407f72e2e4a454238d5dc3be6110cd","tarball":"https://registry.npmjs.org/@antifraud/sdk-client-js/-/sdk-client-js-1.1.2.tgz","fileCount":10,"integrity":"sha512-rjBqlKLgLFcTFHRqtdTIBUT2UHoZn6ZzXAPIW0r5iefxP4KHyHFDTPTUnzpb5rRW9rj2IdHCgBRWaa6xuXs2lA==","signatures":[{"sig":"MEQCIFmsZoBNDij8cGa9tj2KJm7YTuCuRcGzEfj6QsN/lb11AiBqieaWEGfObvdj5c5jr/HjaQ//+2KasjsLl9iXI6JPjg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@antifraud%2fsdk-client-js@1.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":122366},"main":"./dist/antifraud.cjs.js","type":"module","types":"./dist/index.d.ts","module":"./dist/antifraud.esm.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/antifraud.esm.js","require":"./dist/antifraud.cjs.js"}},"gitHead":"58ecb2e0f028200b4f27f45ca5ca6907a96546d2","scripts":{"test":"vitest run","build":"vite build","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c422630c-fcb7-46f2-a699-a020548b9771"}},"repository":{"url":"git+https://github.com/antifraud-id/sdk-client-js.git","type":"git"},"_npmVersion":"12.0.2","description":"Antifraud Web Browser SDK — device fingerprint collection and session management","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"vite":"^5.4.0","jsdom":"^25.0.0","vitest":"^2.1.0","typescript":"^5.5.0","@types/node":"^26.1.1","vite-plugin-dts":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk-client-js_1.1.2_1785402055258_0.051321152149017335","host":"s3://npm-registry-packages-npm-production"}},"1.1.7":{"name":"@antifraud/sdk-client-js","version":"1.1.7","description":"Antifraud Web Browser SDK — device fingerprint collection and session management","repository":{"type":"git","url":"git+https://github.com/antifraud-id/sdk-client-js.git"},"type":"module","main":"./dist/antifraud.cjs.js","module":"./dist/antifraud.esm.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/antifraud.esm.js","require":"./dist/antifraud.cjs.js","types":"./dist/index.d.ts"}},"scripts":{"build":"vite build","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest"},"devDependencies":{"@types/node":"^26.1.1","jsdom":"^25.0.0","typescript":"^5.5.0","vite":"^5.4.0","vite-plugin-dts":"^4.0.0","vitest":"^2.1.0"},"gitHead":"42bd8ed3cbf7fd33cdfa20bb304c5006a5e6ed00","_id":"@antifraud/sdk-client-js@1.1.7","bugs":{"url":"https://github.com/antifraud-id/sdk-client-js/issues"},"homepage":"https://github.com/antifraud-id/sdk-client-js#readme","_nodeVersion":"22.23.1","_npmVersion":"12.0.2","dist":{"integrity":"sha512-FCuwEPcO5JB/D6mDW2YZVTP91EahpvUZxqMkZd4rOptyhucpBlOr08rvXK9veCUQ6Mr7He4XkvYL03KSJ2I35w==","shasum":"8932b4b472bc3544dca412eba8bddb3526044992","tarball":"https://registry.npmjs.org/@antifraud/sdk-client-js/-/sdk-client-js-1.1.7.tgz","fileCount":10,"unpackedSize":122363,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@antifraud%2fsdk-client-js@1.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDRBoL7ZN8odljpkcqnzwNIrpeT4Zod5Sr6eS7iG39afQIhAManp1sXP/eqWWUksDVMrkmTi57prIx3/5G/1VvEMkce"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c422630c-fcb7-46f2-a699-a020548b9771"}},"directories":{},"maintainers":[{"name":"mseptiaan-antifraud","email":"muhammad.septian@antifraud.id"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk-client-js_1.1.7_1785407191213_0.4545593537202681"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-19T10:48:17.045Z","modified":"2026-07-30T10:26:31.770Z","1.0.2":"2026-07-19T10:48:17.385Z","1.0.4":"2026-07-19T11:08:57.585Z","1.1.2":"2026-07-30T09:00:55.388Z","1.1.7":"2026-07-30T10:26:31.384Z"},"bugs":{"url":"https://github.com/antifraud-id/sdk-client-js/issues"},"homepage":"https://github.com/antifraud-id/sdk-client-js#readme","repository":{"type":"git","url":"git+https://github.com/antifraud-id/sdk-client-js.git"},"description":"Antifraud Web Browser SDK — device fingerprint collection and session management","maintainers":[{"name":"mseptiaan-antifraud","email":"muhammad.septian@antifraud.id"}],"readme":"# @antifraud/sdk-client-js\n\nAntifraud Web Browser SDK — collects browser fingerprint signals, encrypts them with hybrid RSA-OAEP + AES-256-GCM, and exchanges them for a `session_id` via `POST /v1/session`.\n\n## Installation\n\n### CDN URL Scheme\n\n| URL | Purpose | Caching |\n|---|---|---|\n| `https://sdk.antifraud.id/v{version}/antifraud.min.js` | **Production (recommended)** | `Cache-Control: public, max-age=31536000, immutable` |\n| `https://sdk.antifraud.id/antifraud.min.js` | Prototyping — redirects to latest version | Short TTL, not for SRI |\n\nUse the versioned URL in production. It is immutable — the content never changes for a given version — so browsers and CDNs can cache it aggressively and SRI hashes remain stable.\n\n### Script Tag (IIFE)\n\n```html\n<!-- Production: pin a version, add SRI -->\n<script\n  src=\"https://sdk.antifraud.id/v0.1.0/antifraud.min.js\"\n  integrity=\"sha384-...\"\n  crossorigin=\"anonymous\"\n></script>\n<script>\n  const antifraud = Antifraud.init({ projectId: '...', publicKey: '...' });\n</script>\n```\n\nQuick prototyping (not for production):\n\n```html\n<script src=\"https://sdk.antifraud.id/antifraud.min.js\"></script>\n```\n\n### npm\n\n```bash\nnpm install @antifraud/sdk-client-js\n```\n\n```ts\nimport { Antifraud } from '@antifraud/sdk-client-js';\n\nconst antifraud = Antifraud.init({\n  projectId: '45608b8c-ed39-4ce8-8607-81a4cd26deed',\n  publicKey: `-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...\n-----END PUBLIC KEY-----`,\n});\n```\n\n## Quick Start\n\n```ts\nimport { Antifraud } from '@antifraud/sdk-client-js';\n\nconst antifraud = Antifraud.init({\n  projectId: '45608b8c-ed39-4ce8-8607-81a4cd26deed',\n  publicKey: '-----BEGIN PUBLIC KEY-----\\nMIIBIjAN...\\n-----END PUBLIC KEY-----',\n});\n\ndocument.getElementById('register-form').addEventListener('submit', async (e) => {\n  e.preventDefault();\n\n  try {\n    const { sessionId } = await antifraud.createSession();\n\n    // Send sessionId to your backend\n    await fetch('/api/register', {\n      method: 'POST',\n      headers: { 'Content-Type': 'application/json' },\n      body: JSON.stringify({\n        email: 'user@example.com',\n        antifraud_session_id: sessionId,\n      }),\n    });\n  } catch (err) {\n    console.error('Antifraud session error:', err);\n    // Proceed without scoring (fail-open)\n  }\n});\n```\n\n## API Reference\n\n### `Antifraud.init(config)`\n\nInitializes the SDK and returns an `AntifraudClient` instance.\n\n| Parameter | Type | Required | Default | Description |\n|---|---|---|---|---|\n| `projectId` | `string` | yes | — | Your project ID |\n| `publicKey` | `string` | yes | — | RSA public key (PEM format) |\n| `apiUrl` | `string` | no | `https://api.antifraud.id` | API base URL |\n| `timeout` | `number` | no | `5000` | HTTP timeout in ms |\n| `autoCollect` | `boolean` | no | `true` | Collect on init |\n\n### `AntifraudClient`\n\n#### `collect(): DeviceInfo`\n\nReturns the raw (unencrypted) fingerprint object for inspection.\n\n#### `createSession(): Promise<SessionResult>`\n\nCollects, encrypts, and exchanges the fingerprint for a `session_id`. Concurrent calls are deduped — if a request is in-flight, the same promise is returned.\n\nReturns `{ sessionId: string }`.\n\n## Merchant Integration Checklist\n\n### Content Security Policy (CSP)\n\nAdd these directives to your CSP headers:\n\n```\nconnect-src https://api.antifraud.id\nscript-src https://sdk.antifraud.id\n```\n\n### CORS\n\nThe server must return `Access-Control-Allow-Origin` and allow the `X-Antifraud-Project-ID` header for browser requests to succeed.\n\n### Subresource Integrity (SRI)\n\nPin the SDK version with an integrity hash. Use the versioned URL — the content is immutable per version, so the hash will never change:\n\n```html\n<script\n  src=\"https://sdk.antifraud.id/v0.1.0/antifraud.min.js\"\n  integrity=\"sha384-<hash>\"\n  crossorigin=\"anonymous\"\n></script>\n```\n\nTo generate the hash for a release:\n\n```bash\ncat dist/antifraud.min.js | openssl dgst -sha384 -binary | openssl base64 -A\n```\n\n## Ad Blocker Mitigation\n\nPrivacy lists (EasyPrivacy, Fanboy) may block fingerprinting scripts by filename or CDN domain. Mitigations:\n\n- Serve the SDK from your own domain (reverse proxy `sdk.antifraud.id`)\n- Versioned URLs (`/v0.1.0/antifraud.min.js`) are less likely to match static blocklist patterns than unversioned paths\n- The absence of an SDK call is itself a signal for the scoring model\n\n## Privacy & Compliance\n\nDevice fingerprinting for fraud prevention is generally treated as legitimate interest under GDPR / ePrivacy. This varies by jurisdiction. Consult with your legal counsel.\n\n## browserId Behavior\n\nThe `browserId` is stored in `localStorage` and persists across page loads. It is:\n\n- **Volatile** — cleared in private/incognito mode and by manual browser clear\n- **Resettable** — user can clear it at any time\n- **Weak identity signal** — not a durable user ID; the scoring model should treat it accordingly\n\n## Error Handling\n\nThe SDK throws typed errors. Use a try/catch with fail-open pattern:\n\n```ts\ntry {\n  const { sessionId } = await antifraud.createSession();\n} catch (err) {\n  if (err.name === 'RateLimitError') { /* 429 */ }\n  if (err.name === 'TimeoutError') { /* request timed out */ }\n  if (err.name === 'ServerError') { /* 5xx */ }\n  if (err.name === 'EncryptionError') { /* not HTTPS */ }\n  // Proceed without scoring (fail-open)\n}\n```\n\n## Browser Support\n\n| Browser | Minimum Version |\n|---|---|\n| Chrome | 63+ |\n| Firefox | 57+ |\n| Safari | 11+ |\n| Edge | 79+ |\n\nAll support `crypto.subtle` (requires HTTPS or localhost).\n\n## Build from Source\n\n```bash\nnpm install\nnpm run build      # → dist/antifraud.min.js, dist/antifraud.esm.js, dist/antifraud.cjs.js\nnpm run typecheck  # TypeScript type checking\nnpm run test       # Unit tests\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}