{"_id":"@bespot/gatekeeper-web-sdk","_rev":"4-8212148d2bd4d4715530f67c689689ab","name":"@bespot/gatekeeper-web-sdk","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.0":{"name":"@bespot/gatekeeper-web-sdk","version":"1.0.0","_id":"@bespot/gatekeeper-web-sdk@1.0.0","maintainers":[{"name":"kathinaios","email":"k.athinaios@bespot.com"},{"name":"bespotapps","email":"appsmanager@bespot.com"}],"homepage":"https://github.com/bespot/gatekeeper-web-sdk-release#readme","bugs":{"url":"https://github.com/bespot/gatekeeper-web-sdk-release/issues"},"dist":{"shasum":"da2403fccd58e6fcee8912b6f6105e744ba2cd59","tarball":"https://registry.npmjs.org/@bespot/gatekeeper-web-sdk/-/gatekeeper-web-sdk-1.0.0.tgz","fileCount":6,"integrity":"sha512-z1NMARlk4ZFyvF9Y96zLhtKR+PVDGM01AZsgNyR9VPoFEvbbbgAISYpu3JxqZ4NI5DVP+L6LCWmKQp7Rwghclw==","signatures":[{"sig":"MEYCIQCpz95mgMwv7ztgcCW8CWx2ykaVIwiaOebGBCCscuk7TAIhANFsGZMmWyyDU3Srhwg2i/zCjvpi15hKpTro9iyM1P0U","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":91640},"main":"./dist/safe-sdk.umd.min.js","type":"module","module":"./dist/safe-sdk.esm.min.js","exports":{".":{"import":"./dist/safe-sdk.esm.min.js","require":"./dist/safe-sdk.umd.min.js"}},"gitHead":"199d9648717f2c4e089eff0825ef4faef0d89562","private":false,"_npmUser":{"name":"bespotapps","email":"appsmanager@bespot.com"},"repository":{"url":"git+https://github.com/bespot/gatekeeper-web-sdk-release.git","type":"git"},"_npmVersion":"10.9.8","description":"Bespot Gatekeeper Web SDK","directories":{},"_nodeVersion":"22.22.3","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/gatekeeper-web-sdk_1.0.0_1782124339106_0.8015116898561783","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@bespot/gatekeeper-web-sdk","version":"1.0.1","keywords":["fraud-prevention","fraud-detection","bot-detection","ai-agent-detection","geolocation","geolocation-verification","location-spoofing","vpn-detection","proxy-detection","device-fingerprinting","account-takeover","multi-accounting","bonus-abuse","risk-scoring","security","javascript-sdk","web-sdk","gaming","ecommerce","fintech"],"_id":"@bespot/gatekeeper-web-sdk@1.0.1","maintainers":[{"name":"kathinaios","email":"k.athinaios@bespot.com"},{"name":"bespotapps","email":"appsmanager@bespot.com"}],"homepage":"https://github.com/bespot/gatekeeper-web-sdk-release#readme","bugs":{"url":"https://github.com/bespot/gatekeeper-web-sdk-release/issues"},"dist":{"shasum":"0e659ec2cb187cb63854313023d5935299865666","tarball":"https://registry.npmjs.org/@bespot/gatekeeper-web-sdk/-/gatekeeper-web-sdk-1.0.1.tgz","fileCount":6,"integrity":"sha512-WE3UTj+mvXxmW3lEaeS2DLJ+ok2sdoqbL0kDYKJxz3G1gnuItOgMNqd5PG49gOk3KYm473hi9PKyKcgsMcrpoA==","signatures":[{"sig":"MEQCIH8Roy91t1mj41xD4WOSdfu/sfztOqqj9kdPNFpYIfWlAiBMcxJiAt29UqwgjuVRi4lm4fGokSoqz0AIAEoz25Ef+Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bespot%2fgatekeeper-web-sdk@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":95937},"main":"./dist/safe-sdk.umd.min.js","type":"module","module":"./dist/safe-sdk.esm.min.js","exports":{".":{"import":"./dist/safe-sdk.esm.min.js","require":"./dist/safe-sdk.umd.min.js"}},"gitHead":"abebafe1157d2711dffb5a9807ec1a7af16035f2","private":false,"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:94ac6856-5e7b-4aba-af96-ade42c868f03"}},"repository":{"url":"git+https://github.com/bespot/gatekeeper-web-sdk-release.git","type":"git"},"_npmVersion":"11.13.0","description":"Bespot Gatekeeper Web SDK","directories":{},"_nodeVersion":"24.17.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/gatekeeper-web-sdk_1.0.1_1782818551351_0.06773205879582722","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@bespot/gatekeeper-web-sdk","version":"1.0.2","keywords":["fraud-prevention","fraud-detection","bot-detection","ai-agent-detection","geolocation","geolocation-verification","location-spoofing","vpn-detection","proxy-detection","device-fingerprinting","account-takeover","multi-accounting","bonus-abuse","risk-scoring","security","javascript-sdk","web-sdk","gaming","ecommerce","fintech"],"license":"SEE LICENSE IN LICENSE","_id":"@bespot/gatekeeper-web-sdk@1.0.2","maintainers":[{"name":"kathinaios","email":"k.athinaios@bespot.com"},{"name":"bespotapps","email":"appsmanager@bespot.com"}],"homepage":"https://github.com/bespot/gatekeeper-web-sdk-release#readme","bugs":{"url":"https://github.com/bespot/gatekeeper-web-sdk-release/issues"},"dist":{"shasum":"937293c0652806b5a965db57abe409f1604ef4c6","tarball":"https://registry.npmjs.org/@bespot/gatekeeper-web-sdk/-/gatekeeper-web-sdk-1.0.2.tgz","fileCount":6,"integrity":"sha512-s7ng9frB2/OKY3hvAglYwmZ8pTAVgnomoKsDA40jGSb2DKck7ghL+15UtROnUzSBxvRX+ZD8dEpaygZxFit44Q==","signatures":[{"sig":"MEUCIDUR0mA0p9GSHMd66g7w/ZhsMbodrdglpoC4juWWgiVmAiEA9v6+Rx8sZZKyh2KWQNpu0gUj5JO/h5cY68nUdv3y5pY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bespot%2fgatekeeper-web-sdk@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":100207},"main":"./dist/safe-sdk.umd.min.js","type":"module","module":"./dist/safe-sdk.esm.min.js","engines":{"node":">=22"},"exports":{".":{"import":"./dist/safe-sdk.esm.min.js","require":"./dist/safe-sdk.umd.min.js"}},"gitHead":"54fd454442d5978f65f7e3210b43f35f184d2231","private":false,"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:94ac6856-5e7b-4aba-af96-ade42c868f03"}},"repository":{"url":"git+https://github.com/bespot/gatekeeper-web-sdk-release.git","type":"git"},"_npmVersion":"11.16.0","description":"Bespot Gatekeeper Web SDK","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/gatekeeper-web-sdk_1.0.2_1785159538159_0.6479344235222875","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@bespot/gatekeeper-web-sdk","version":"1.0.3","description":"Bespot Gatekeeper Web SDK","license":"SEE LICENSE IN LICENSE","private":false,"type":"module","engines":{"node":">=22"},"exports":{".":{"import":"./dist/safe-sdk.esm.min.js","require":"./dist/safe-sdk.umd.min.js"}},"main":"./dist/safe-sdk.umd.min.js","module":"./dist/safe-sdk.esm.min.js","keywords":["fraud-prevention","fraud-detection","bot-detection","ai-agent-detection","geolocation","geolocation-verification","location-spoofing","vpn-detection","proxy-detection","device-fingerprinting","account-takeover","multi-accounting","bonus-abuse","risk-scoring","security","javascript-sdk","web-sdk","gaming","ecommerce","fintech"],"repository":{"type":"git","url":"git+https://github.com/bespot/gatekeeper-web-sdk-release.git"},"bugs":{"url":"https://github.com/bespot/gatekeeper-web-sdk-release/issues"},"homepage":"https://github.com/bespot/gatekeeper-web-sdk-release#readme","scripts":{"sandbox":"npx --yes http-server . -o /examples/sandbox/index.html"},"gitHead":"72374bacdc6fa9013bc9631ee932b7b1769060d1","_id":"@bespot/gatekeeper-web-sdk@1.0.3","_nodeVersion":"24.20.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-Xkb6LOWKltgauuUhnUyH8ODZ4R7nEYu23uVQAobKsW7wjlV1Tcii2fztPy3Zmzm0ariqQJfUx/YUP6P7Kw9YDQ==","shasum":"abbf3c949aa342901390cd3c85e7e7033759517a","tarball":"https://registry.npmjs.org/@bespot/gatekeeper-web-sdk/-/gatekeeper-web-sdk-1.0.3.tgz","fileCount":6,"unpackedSize":101877,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bespot%2fgatekeeper-web-sdk@1.0.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHTuN7JzsIjOYuVbcE9XC433DV0pqzGVkQR4YCz8XufvAiAVMqYNSeSrreXH30fpL86bjkxiOgdVj82TgSHtf/iYZQ=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:94ac6856-5e7b-4aba-af96-ade42c868f03"}},"directories":{},"maintainers":[{"name":"kathinaios","email":"k.athinaios@bespot.com"},{"name":"bespotapps","email":"appsmanager@bespot.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gatekeeper-web-sdk_1.0.3_1789051217845_0.06227438338073199"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-22T10:32:18.969Z","modified":"2026-09-10T14:40:18.440Z","1.0.0":"2026-06-22T10:32:19.224Z","1.0.1":"2026-06-30T11:22:31.492Z","1.0.2":"2026-07-27T13:38:58.319Z","1.0.3":"2026-09-10T14:40:17.985Z"},"bugs":{"url":"https://github.com/bespot/gatekeeper-web-sdk-release/issues"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/bespot/gatekeeper-web-sdk-release#readme","keywords":["fraud-prevention","fraud-detection","bot-detection","ai-agent-detection","geolocation","geolocation-verification","location-spoofing","vpn-detection","proxy-detection","device-fingerprinting","account-takeover","multi-accounting","bonus-abuse","risk-scoring","security","javascript-sdk","web-sdk","gaming","ecommerce","fintech"],"repository":{"type":"git","url":"git+https://github.com/bespot/gatekeeper-web-sdk-release.git"},"description":"Bespot Gatekeeper Web SDK","maintainers":[{"name":"kathinaios","email":"k.athinaios@bespot.com"},{"name":"bespotapps","email":"appsmanager@bespot.com"}],"readme":"# Bespot Gatekeeper Web SDK\n\n[![npm](https://img.shields.io/npm/v/@bespot/gatekeeper-web-sdk?style=flat-square&logo=npm&logoColor=white)](https://www.npmjs.com/package/@bespot/gatekeeper-web-sdk)\n[![release](https://img.shields.io/github/v/release/bespot/gatekeeper-web-sdk-release?style=flat-square&logo=github&label=release)](https://github.com/bespot/gatekeeper-web-sdk-release/releases)\n[![Socket](https://badge.socket.dev/npm/package/@bespot/gatekeeper-web-sdk/latest)](https://socket.dev/npm/package/@bespot/gatekeeper-web-sdk/overview/latest)\n[![License](https://img.shields.io/badge/License-Integrator%20License-red?style=flat-square&logo=data%3Aimage%2Fpng%3Bbase64%2CiVBORw0KGgoAAAANSUhEUgAAAEAAAABACAIAAAAlC%2BaJAAADvklEQVR4nOyaXUg0VRjH%2F6u7uq66ra%2FvW%2BZGJrnaWhltq%2BlSBiH2QZkXdRFRYERGRDdFIEQE0kVliSRd1J0opWYhdNGF4mpiliBrapblVx9%2BhK7f67q7unFycHbWmXXmnNV5F%2BbHIs8z83ee579zZs6cYfVh%2B4tIZJLUboAVzYDaaAbURjOgNpoBtdEMqE3CG9Ar0F4148ESLg6G8O3oBfWkCCUG8m%2FGe3VcvOO7Tgwk%2FBDSDKiNZkBtNANqQ2sgHI5zI7QomcgiOTqO3pKkwzULMtPIro0dMtNdCrQGAkEuSE7C42WoccFRgLRUXrDqxfAUOt2YXopHn5LQGjg4JH8LrfjwZdhuERHkXMHTleTTO4LGDvj8bH1KQnsN7B7g7ny0N4h3H8lTLrS9BbOJstB50J4BUyo%2BeQ0ZaSTe2kPfOCYXsL6N4zC5Epw2VDthTOHExXlofgUvNV%2FEpU9roMDKBV8M4KNu%2BA4Fe78awsc9ZHSVFnFbKu7EM5XoGmRqVgy2eaDTjcb26O5P%2BHcL9c2Y%2BZPf8moNDMlM5cRgMLDjQ1N3LIE%2FiHfb%2BPRGCx6%2Bl76cBAwGvvsJ%2B%2BfdWyYX4Jnj0yoHfTkJGAz8MCNLNuDhY2chfTkJGAz89pcs2eQCH9%2BUBUs6fUUxGAyseGXJltYEqfUqfUUxaA34AzgMylJ6dwVpVgZlRQloDQRCcpVRPk9ntzhx6euBeM%2FFtAaMBrlKU6og9QcoK0pAayDFEN2ZFNlmQbq5R1lRAoYhJPN%2Bkp8jSP9Zp68oBoMB%2B62yZPfczserXmzv01cUg8HAA3fJkkU%2BPozN0peTgMFAlSN6fJ%2FFVQyblU%2F7xiWVBj0sNFMEgwFjCt5%2BDjppQYaRCE5Z9Qqei07RAQ3PYqwVIy3o%2BwD336GoC7Z54BEnmurFH29yr%2BDzN3BbxBXc2ovQkYjy0VI8X0Vua%2BS%2FsskBDQqWWbQrsvHfUZALczoeK8NDJej3wPMHWcSEjnDtBjiLUH2fYNIdnMDXw%2BKHKrcL0mwzGXW%2FyH2XQWugo5%2Fc0T99nXRpMuLJcvKRYmIOb34muffs963kDFANoTDw468YncEL72N%2BJZbyOIwuN%2BqaYi19IpedJ2%2Bc5pfl96LkDGztYehnEqxtcs%2BYU4uofYeMoifK4bAh3ciLlzeI%2BEs3Zv8%2B57A936PWBXsel7Z8g90D%2BU3p4vaLLZ2OjP5M0%2F%2BvFrcVNQF9MirsyMrE9CLmYp7Ss2W1n5ypjGZAbTQDaqMZUBvNgNpoBtQm4Q38FwAA%2F%2F8fNufzjhQUMgAAAABJRU5ErkJggg%3D%3D)](LICENSE)\n\nWeb SDK for Bespot Gatekeeper, a fraud prevention and location integrity platform for web\napplications.\n\nUse this SDK to run real-time fraud checks in browser sessions and receive policy results for\nhigh-risk actions such as signup, login, checkout, reward redemption, wallet actions, account\nchanges, or location-restricted access.\n\nGatekeeper helps detect and evaluate bot traffic, AI agents, location spoofing, VPN/proxy use,\nsuspicious browser or device signals, multi-accounting, and abuse patterns such as bonus, promo,\nor reward fraud.\n\n## Prerequisites\n\nBefore integrating, sign up at **[gatekeeper.bespot.com](https://gatekeeper.bespot.com?utm_source=readme&utm_medium=signup&utm_campaign=gatekeeper-web-sdk&utm_content=readme-signup)** to create your account and obtain your API key and other credentials for SDK runtime configuration.\n\n## Documentation\n\nSDK integration guides live in this repository. Official Bespot product documentation is at **[docs.bespot.com](https://docs.bespot.com?utm_source=readme&utm_medium=docs-home&utm_campaign=gatekeeper-web-sdk&utm_content=readme-docs-home)**.\n\n| Document | Description |\n|----------|-------------|\n| [Integration guide](docs/integration-guide.md) | Full end-to-end integration reference |\n| [Authentication](docs/authentication.md) | JWT access tokens and OAuth (server-side) |\n| [Error reference](docs/error-reference.md) | Error handling rules and `error.name` catalog |\n| [SDK versioning](docs/versioning.md) | SDK package version vs application version |\n| [Templates](templates/) | Copy-paste HTML and config starters |\n| [Sandbox](examples/sandbox/) | Manual UMD/ESM credential check against `dist/` |\n\nOfficial authentication API reference: [Bespot Authentication Guide](https://docs.bespot.com/api/auth?utm_source=readme&utm_medium=docs-auth&utm_campaign=gatekeeper-web-sdk&utm_content=readme-docs-auth).\n\n## Installation\n\nSDK bundles are distributed via **npm** and **GitHub Releases** (`safe-sdk.esm.min.js`, `safe-sdk.umd.min.js`). Each release includes both ESM and UMD builds — download and host directly; no extraction step required.\n\n### npm (recommended)\n\nRequires **Node.js** on your development machine to run `npm install`. The SDK itself runs in the browser — Node is not needed at runtime.\n\n```bash\nnpm install @bespot/gatekeeper-web-sdk\n```\n\n```ts\nimport SafeSDK from '@bespot/gatekeeper-web-sdk'\n```\n\n### CDN / script tag (no build step)\n\nNo Node.js required. Download `safe-sdk.esm.min.js` or `safe-sdk.umd.min.js` from the [Releases](https://github.com/bespot/gatekeeper-web-sdk-release/releases) page and host the files on your CDN or static origin.\n\n## Quick start\n\n1. **Account** — sign in at gatekeeper.bespot.com and collect your credentials\n2. **Install** — `npm install @bespot/gatekeeper-web-sdk` or download from [Releases](https://github.com/bespot/gatekeeper-web-sdk-release/releases)\n3. **Configure** — four runtime fields: `baseUrl`, `apiKey`, `applicationId`, `applicationVersion` ([runtime configuration](docs/integration-guide.md#5-runtime-configuration))\n4. **Authenticate** — obtain a JWT from your backend ([authentication](docs/authentication.md))\n5. **Integrate** — `await sdk.initialize(jwt)` then `await sdk.check()` ([integration sequence](docs/integration-guide.md#6-integration-sequence))\n6. **Optional — verify credentials** — from this repo run `npm run sandbox` ([sandbox README](examples/sandbox/))\n\n```ts\nconst sdk = new SafeSDK({\n  baseUrl: 'bespot-gatekeeper-base-url', // e.g. 'https://gatekeeper.bespotcompany.com'\n  apiKey: 'your-api-key', // e.g. '13CTrcYiya9NNnRyd3jXA21CULPPDSqM90sdFnGs'\n  applicationId: 'your-app-id', // e.g. 'mywebapp.mycompany.com'\n  applicationVersion: 'your-app-version', // e.g. '2.4.1'\n})\n\nawait sdk.initialize(jwt)\n\nconst result = await sdk.check()\nif (result instanceof Error) {\n  console.error('Check failed:', result.name)\n} else {\n  console.log('Check passed:', result)\n}\n```\n\nStarter pages: [templates/integration-esm.html](templates/integration-esm.html), [templates/integration-umd.html](templates/integration-umd.html). Credentials sandbox: [examples/sandbox/](examples/sandbox/).\n\n## Network behavior\n\nThis SDK makes **runtime-only** HTTPS requests to the Gatekeeper API URL you configure in\n`baseUrl`:\n\n- `POST /device/{applicationId}/{applicationVersion}/register` — on `initialize()`\n- `POST /device/{applicationId}/{applicationVersion}/check` — on `check()` and periodic checks\n\n- No install scripts (`preinstall`, `postinstall`, etc.)\n- No network activity during `npm install`\n- Network requests occur during `initialize()`, `check()`, and optionally during periodic\n  checks if you call `subscribe()` (see [periodic checks](docs/integration-guide.md#periodic-checks))\n- Requests use the browser `fetch` API with a 30-second timeout, your API key, and JWT\n\nThis behavior is required for Gatekeeper fraud and location checks.\n\n## Data collection\n\nDuring `initialize()` and `check()` (and periodic checks when `subscribe()` is active), the SDK\ncollects browser and device signals needed for fraud prevention and location integrity:\n\n- **Device fingerprint** — canvas, WebGL, and audio signals are hashed into a deterministic\n  `device_seed` (raw fingerprint values are not transmitted)\n- **Geolocation** — browser Geolocation API when the user grants permission (see\n  [geolocation](docs/integration-guide.md#10-geolocation))\n- **Browser and device metadata** — user agent, screen, locale, connection type, and related\n  fields included in check payloads\n- **Persistent identifiers** — session data stored across localStorage, sessionStorage, cookies,\n  and IndexedDB for device continuity across visits\n\nCollection happens only at runtime in the browser. There is no install-time or background data\ncollection outside your integration (`initialize()`, `check()`, and optional `subscribe()`).\n\nIntegrators are responsible for disclosing this behavior to end users and obtaining consent where\nrequired by applicable privacy law and your policies.\n\n## Distribution format\n\nPublished npm and GitHub Release artifacts are intentionally **minified** production bundles\n(`safe-sdk.esm.min.js`, `safe-sdk.umd.min.js`). Source maps are not included in the npm package.\n\nEach GitHub Release includes `SHA256SUMS` for verifying bundle integrity.\n\n## License\n\nUse of the SDK is governed by [LICENSE](LICENSE).\n\n## Support\n\nSee [Support](docs/integration-guide.md#16-support) in the integration guide.\n","readmeFilename":"README.md"}