{"_id":"@bobospay/bobospay-checkout","_rev":"5-abbb95e3619c7287ac6f6b374f5d636c","name":"@bobospay/bobospay-checkout","dist-tags":{"latest":"1.2.1"},"versions":{"1.0.0":{"name":"@bobospay/bobospay-checkout","version":"1.0.0","keywords":["bobospay","checkout","payment","payment-sdk","sdk","cdn","typescript"],"author":{"name":"Bobospay"},"license":"MIT","_id":"@bobospay/bobospay-checkout@1.0.0","maintainers":[{"name":"corel9","email":"bankolecorneille@gmail.com"}],"dist":{"shasum":"e61ea388ffc8bd8db957d864bd658683b5bfd3a2","tarball":"https://registry.npmjs.org/@bobospay/bobospay-checkout/-/bobospay-checkout-1.0.0.tgz","fileCount":15,"integrity":"sha512-2BnW9MzMFOrxAuMufqYanZ1pRGEZpnVUtziUreAM4/ZMDXeYOgos99O5PTHUoACfkeAtJH/z8+jPjS4C6cRBQg==","signatures":[{"sig":"MEUCIQCOY+mbH8x/xq4DTZbZvm8kk7LGviTHsvhq2kdSMvTjZgIgN49flSIKszsDTHnNshqK1VjQmnelZO7S78ZkJOptMmA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28250},"main":"dist/bobospay.cjs.js","type":"module","types":"dist/index.d.ts","unpkg":"dist/bobospay.iife.js","module":"dist/bobospay.es.js","exports":{".":{"import":"./dist/bobospay.es.js","require":"./dist/bobospay.cjs.js"}},"gitHead":"979b10c602d751918d368565ae91c1d9b852afe3","scripts":{"dev":"vite","lint":"eslint \"src/**/*.{ts,tsx,js}\" || true","test":"vitest","build":"npm run build:lib && npm run build:types","prepare":"npm run build","build:lib":"vite build","test:unit":"vitest run","test:watch":"vitest --watch","build:types":"tsc --emitDeclarationOnly","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"corel9","email":"bankolecorneille@gmail.com"},"_npmVersion":"11.6.2","description":"Secure, embeddable TypeScript payment checkout SDK for Bobospay (iframe-based, CDN-ready)","directories":{},"_nodeVersion":"24.12.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vue":"^3.3.4","vite":"^7.3.1","jsdom":"^28.1.0","react":"^18.2.0","eslint":"^9.39.3","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^20.0.0","@types/jsdom":"^28.0.0","@types/react":"^18.2.21"},"_npmOperationalInternal":{"tmp":"tmp/bobospay-checkout_1.0.0_1772389455624_0.22351186659975042","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@bobospay/bobospay-checkout","version":"1.0.1","keywords":["bobospay","checkout","payment","payment-sdk","sdk","cdn","typescript"],"author":{"name":"Bobospay"},"license":"MIT","_id":"@bobospay/bobospay-checkout@1.0.1","maintainers":[{"name":"corel9","email":"bankolecorneille@gmail.com"}],"dist":{"shasum":"887b867b7e598404bf63f11f06f5e49e36ff4b78","tarball":"https://registry.npmjs.org/@bobospay/bobospay-checkout/-/bobospay-checkout-1.0.1.tgz","fileCount":15,"integrity":"sha512-kM2oh9CZuwNu7zLnoDoUH/8SX4XDJravQQlBJq2JOAYxoOkgr7HnEpNlMfhGQYt4S+fDMrPIALkqIMAPq4sjZQ==","signatures":[{"sig":"MEUCICJS/25ZabSIm2sQsWlLRGcF7/gSGZ1wSs5yMd69Tve3AiEAihk/kEi9IBWbeVgYkvwQqr9QyawCZLGxpV6uvqk/kAo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28894},"main":"dist/bobospay.cjs.js","type":"module","types":"dist/index.d.ts","unpkg":"dist/bobospay.iife.js","module":"dist/bobospay.es.js","exports":{".":{"import":"./dist/bobospay.es.js","require":"./dist/bobospay.cjs.js"}},"gitHead":"e5dbb3b03a035b7764c532e22025e33f645cca29","scripts":{"dev":"vite","lint":"eslint \"src/**/*.{ts,tsx,js}\" || true","test":"vitest","build":"npm run build:lib && npm run build:types","prepare":"npm run build","build:lib":"vite build","test:unit":"vitest run","test:watch":"vitest --watch","build:types":"tsc --emitDeclarationOnly","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"corel9","email":"bankolecorneille@gmail.com"},"_npmVersion":"11.6.2","description":"Secure, embeddable TypeScript payment checkout SDK for Bobospay (iframe-based, CDN-ready)","directories":{},"_nodeVersion":"24.12.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vue":"^3.3.4","vite":"^7.3.1","jsdom":"^28.1.0","react":"^18.2.0","eslint":"^9.39.3","vitest":"^4.0.18","gh-pages":"^6.3.0","happy-dom":"20.7.0","typescript":"^5.9.3","@types/node":"^20.0.0","@types/jsdom":"^28.0.0","@types/react":"^18.2.21"},"_npmOperationalInternal":{"tmp":"tmp/bobospay-checkout_1.0.1_1772392366545_0.561239303696333","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@bobospay/bobospay-checkout","version":"1.1.0","keywords":["bobospay","checkout","payment","payment-sdk","sdk","cdn","typescript"],"author":{"name":"Bobospay"},"license":"MIT","_id":"@bobospay/bobospay-checkout@1.1.0","maintainers":[{"name":"corel9","email":"bankolecorneille@gmail.com"}],"dist":{"shasum":"b1d022684cb11a6523cdba9d62e6ba1a1e101fc5","tarball":"https://registry.npmjs.org/@bobospay/bobospay-checkout/-/bobospay-checkout-1.1.0.tgz","fileCount":15,"integrity":"sha512-KWE6+H+32hfF5T8Ekg62pTZ17UthFJbPYJ53QweY+lOY2rIU0extvCa6kvxtg3adhjDoaiYloQ3lce/WTkymUg==","signatures":[{"sig":"MEUCIGOdnwl2v24GQ/BzyBMTsJCh0lyUugeNjpvqUNmPqSPSAiEA87vqpYlrYWnREjn5of0J2UKz5+o0k3fHaASuw+J9NkI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":39706},"main":"dist/bobospay.cjs.js","type":"module","types":"dist/index.d.ts","unpkg":"dist/bobospay.iife.js","module":"dist/bobospay.es.js","exports":{".":{"import":"./dist/bobospay.es.js","require":"./dist/bobospay.cjs.js"}},"gitHead":"e787fb94f24815889665203b69d8e554b9b84815","scripts":{"dev":"vite","lint":"eslint \"src/**/*.{ts,tsx,js}\" || true","test":"vitest","build":"npm run build:lib && npm run build:types","prepare":"npm run build","build:lib":"vite build","test:unit":"vitest run","test:watch":"vitest --watch","build:types":"tsc --emitDeclarationOnly","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"corel9","email":"bankolecorneille@gmail.com"},"_npmVersion":"11.9.0","description":"Secure, embeddable TypeScript payment checkout SDK for Bobospay (iframe-based, CDN-ready)","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vue":"^3.3.4","vite":"^7.3.1","jsdom":"^28.1.0","react":"^18.2.0","eslint":"^9.39.3","vitest":"^4.0.18","gh-pages":"^6.3.0","happy-dom":"20.7.0","typescript":"^5.9.3","@types/node":"^20.0.0","@types/jsdom":"^28.0.0","@types/react":"^18.2.21"},"_npmOperationalInternal":{"tmp":"tmp/bobospay-checkout_1.1.0_1773314525599_0.24190198328486257","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@bobospay/bobospay-checkout","version":"1.2.0","keywords":["bobospay","checkout","payment","payment-sdk","sdk","cdn","typescript"],"author":{"name":"Bobospay"},"license":"MIT","_id":"@bobospay/bobospay-checkout@1.2.0","maintainers":[{"name":"corel9","email":"bankolecorneille@gmail.com"}],"dist":{"shasum":"834e01f33326a0fd846518c4c85c57fe2e04f9a6","tarball":"https://registry.npmjs.org/@bobospay/bobospay-checkout/-/bobospay-checkout-1.2.0.tgz","fileCount":25,"integrity":"sha512-bPuz7b2HJJ/WcCYPtRpMZBMGpTKj48KkAyz/CeaOZJG/3OGogxXDiZ1ChnW22wzdEvI/KlFOXFMvWI7ddDaDOA==","signatures":[{"sig":"MEQCIACA/gq9OilP464RtP6dGCaRhUg/dt2K83etY3Pw29S9AiAmy4+EzfdhiILsSqpobNjNRqpnTuoKHX4Bfmykb83pjw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32278},"main":"dist/bobospay.cjs.js","type":"module","types":"dist/index.d.ts","module":"dist/bobospay.es.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/bobospay.js","require":"./dist/bobospay.cjs"},"./vue":{"types":"./dist/vue/index.d.ts","import":"./dist/vue.js","require":"./dist/vue.cjs"},"./react":{"types":"./dist/react/index.d.ts","import":"./dist/react.js","require":"./dist/react.cjs"}},"gitHead":"ec34ece52344267c0b588f2610e5d0a148103028","scripts":{"dev":"vite","lint":"eslint \"src/**/*.{ts,tsx,js}\" || true","test":"vitest","build":"npm run build:lib && npm run build:types","prepare":"npm run build","build:lib":"vite build","test:unit":"vitest run","test:watch":"vitest --watch","build:types":"tsc --emitDeclarationOnly","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"corel9","email":"bankolecorneille@gmail.com"},"_npmVersion":"11.9.0","description":"Secure, embeddable TypeScript payment checkout SDK for Bobospay (iframe-based, CDN-ready)","directories":{},"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vue":"^3.3.4","vite":"^7.3.1","jsdom":"^28.1.0","react":"^18.2.0","eslint":"^9.39.3","vitest":"^4.0.18","gh-pages":"^6.3.0","happy-dom":"20.7.0","typescript":"^5.9.3","@types/node":"^20.0.0","@types/jsdom":"^28.0.0","@types/react":"^18.2.21"},"_npmOperationalInternal":{"tmp":"tmp/bobospay-checkout_1.2.0_1774564612536_0.22974309938190896","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@bobospay/bobospay-checkout","version":"1.2.1","description":"Secure, embeddable TypeScript payment checkout SDK for Bobospay (iframe-based, CDN-ready)","keywords":["bobospay","checkout","payment","payment-sdk","sdk","cdn","typescript"],"publishConfig":{"access":"public"},"license":"MIT","author":{"name":"Bobospay"},"type":"module","main":"dist/bobospay.cjs.js","module":"dist/bobospay.es.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/bobospay.js","require":"./dist/bobospay.cjs"},"./react":{"types":"./dist/react/index.d.ts","import":"./dist/react.js","require":"./dist/react.cjs"},"./vue":{"types":"./dist/vue/index.d.ts","import":"./dist/vue.js","require":"./dist/vue.cjs"}},"scripts":{"build:types":"tsc --emitDeclarationOnly","build:lib":"vite build","build":"npm run build:lib && npm run build:types","dev":"vite","lint":"eslint \"src/**/*.{ts,tsx,js}\" || true","prepare":"npm run build","test":"vitest","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","test:unit":"vitest run"},"devDependencies":{"@types/jsdom":"^28.0.0","@types/node":"^20.0.0","@types/react":"^18.2.21","eslint":"^9.39.3","gh-pages":"^6.3.0","jsdom":"^28.1.0","react":"^18.2.0","typescript":"^5.9.3","vite":"^7.3.1","vitest":"^4.0.18","vue":"^3.3.4","happy-dom":"20.7.0"},"gitHead":"923ea0f9cd55e84787db1feb9cc3cb7d437617a0","_id":"@bobospay/bobospay-checkout@1.2.1","_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-XZZ+CqSbwqmjIHkaH5l1/sEyx3j4vuE+Sl5+rBcoT954ToGMSjglhZ17sgtZAy0Q4068QnUEcQeu+7Qwhrbu0w==","shasum":"d99e9b6f646704851762c5a40c60c39ac9518d6a","tarball":"https://registry.npmjs.org/@bobospay/bobospay-checkout/-/bobospay-checkout-1.2.1.tgz","fileCount":19,"unpackedSize":31265,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD7uKRyb+jIBhx/LY2l61u5fvyZzhi7uUY/Y14O42gWeQIgBaLGB5ECFWJfq54BBNiMuAngv2+ugykTuSD71l5xqnE="}]},"_npmUser":{"name":"corel9","email":"bankolecorneille@gmail.com"},"directories":{},"maintainers":[{"name":"corel9","email":"bankolecorneille@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/bobospay-checkout_1.2.1_1774565771135_0.3355977190208004"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-01T18:24:15.527Z","modified":"2026-03-26T22:56:11.417Z","1.0.0":"2026-03-01T18:24:15.774Z","1.0.1":"2026-03-01T19:12:46.679Z","1.1.0":"2026-03-12T11:22:05.760Z","1.2.0":"2026-03-26T22:36:52.728Z","1.2.1":"2026-03-26T22:56:11.280Z"},"author":{"name":"Bobospay"},"license":"MIT","keywords":["bobospay","checkout","payment","payment-sdk","sdk","cdn","typescript"],"description":"Secure, embeddable TypeScript payment checkout SDK for Bobospay (iframe-based, CDN-ready)","maintainers":[{"name":"corel9","email":"bankolecorneille@gmail.com"}],"readme":"# @bobospay/bobospay-checkout\n\n[![npm](https://img.shields.io/npm/v/@bobospay/bobospay-checkout)](https://www.npmjs.com/package/@bobospay/bobospay-checkout)\n[![license](https://img.shields.io/npm/l/@bobospay/bobospay-checkout)](./LICENSE)\n\nSecure, embeddable TypeScript payment checkout SDK for Bobospay. The SDK renders a hosted Bobospay payment form inside a sandboxed `<iframe>` and communicates with the parent page via validated `postMessage` events.\n\n> **Only the public `clientId` is used in the browser. Never expose your private API key / client secret on the client side.**\n\n---\n\n## Table of contents\n\n- [Installation](#installation)\n- [Quick start (CDN)](#quick-start-cdn)\n- [Quick start (npm / ESM)](#quick-start-npm--esm)\n- [Two init modes](#two-init-modes)\n  - [Mode 1 — API mode (`init`)](#mode-1--api-mode-init)\n  - [Mode 2 — URL mode (`initWithUrl`)](#mode-2--url-mode-initwithurl)\n- [React](#react)\n- [Vue 3](#vue-3)\n- [UI options](#ui-options)\n- [Customer object](#customer-object)\n- [Security](#security)\n- [CDN URLs reference](#cdn-urls-reference)\n\n---\n\n## Installation\n\n```bash\nnpm install @bobospay/bobospay-checkout\n# or\nyarn add @bobospay/bobospay-checkout\n```\n\n---\n\n## Quick start (CDN)\n\n```html\n<script src=\"https://cdn.jsdelivr.net/npm/@bobospay/bobospay-checkout@1.1.0/dist/bobospay.iife.js\"></script>\n<script>\n  const sdk = BobospayCheckout.createBobospayCheckout();\n\n  sdk.init({ clientId: 'ci_test_xxx' }, {\n    transaction: { amount: 5000, currency: 'XOF' },\n    customer: { firstname: 'Jane', lastname: 'Doe', email: 'jane@example.com' },\n    callback: (result) => console.log('Payment result:', result),\n    ui: { closeButton: true, overlayClose: true }\n  });\n\n  document.getElementById('pay-btn').addEventListener('click', () => sdk.open());\n</script>\n```\n\n---\n\n## Quick start (npm / ESM)\n\n```ts\nimport { createBobospayCheckout } from '@bobospay/bobospay-checkout'\n\nconst sdk = createBobospayCheckout()\n\nsdk.init({ clientId: 'ci_test_xxx' }, {\n  transaction: { amount: 5000, currency: 'XOF' },\n  customer: { id: 'cust_abc123' },          // or provide firstname/lastname/email\n  callback: (result) => console.log(result),\n  ui: { closeButton: true }\n})\n\nawait sdk.open()\n```\n\n---\n\n## Two init modes\n\n### Mode 1 — API mode (`init`)\n\nThe SDK calls `POST /v2/checkout-js` on the Bobospay API to create the checkout session, then opens the returned URL in the iframe.\n\n```ts\nsdk.init(\n  { clientId: 'ci_test_xxx' },    // public client ID (identifies live vs sandbox)\n  {\n    transaction: {\n      amount: 5000,                // amount in minor units (e.g. cents / kobo / centimes)\n      currency: 'XOF',\n      note: 'Order #1042',         // optional\n      channels: ['card', 'mobile_money'],  // optional: restrict payment channels\n    },\n    customer: {\n      // Option A — customer already exists on your backend\n      id: 'cust_abc123',\n\n      // Option B — provide minimal customer info\n      // firstname: 'Jane',\n      // lastname: 'Doe',\n      // email: 'jane@example.com',\n      // phone: '+22601234567',    // optional\n    },\n    callback: (result) => {\n      // result is the decoded payment object from the hosted page\n      console.log(result)\n    },\n    ui: { closeButton: true, overlayClose: true }\n  }\n)\n\nawait sdk.open()\n```\n\n**Base URLs by environment** (derived from the `clientId` prefix):\n\n| `clientId` prefix | Environment | API base URL |\n|---|---|---|\n| `ci_live_` | Production | `https://bobospay.com/api/v2` |\n| `ci_test_` | Sandbox | `https://sandbox.bobospay.com/api/v2` |\n| other | Local dev | `http://127.0.0.1:8000/api/v2` |\n\n---\n\n### Mode 2 — URL mode (`initWithUrl`)\n\nUse this when **your backend already created the checkout session** (via the Bobospay server SDK or a direct API call) and returned the hosted payment URL. No `clientId`, `transaction` or `customer` data is needed in the browser.\n\n```ts\n// 1. Your backend calls POST /v2/checkout-js and returns the URL to the frontend.\nconst paymentUrl = await fetchPaymentUrlFromYourBackend()\n\n// 2. Pass it directly to initWithUrl().\nsdk.initWithUrl(paymentUrl, {\n  callback: (result) => console.log('Payment result:', result),\n  ui: { closeButton: true }\n})\n\nawait sdk.open()\n```\n\nThe SDK validates that `paymentUrl` belongs to a trusted Bobospay domain before opening the iframe. Accepted hostnames:\n\n| Hostname | Environment |\n|---|---|\n| `checkout.bobospay.com` | Production (HTTPS required) |\n| `checkout-sandbox.bobospay.com` | Sandbox (HTTPS required) |\n| `localhost` / `127.x.x.x` | Local development |\n\nAny other domain will throw immediately — an arbitrary URL can never be injected into the iframe.\n\n---\n\n## React\n\nThe package ships a `useReactCheckout` hook. Both init modes are available:\n\n```tsx\nimport React from 'react'\nimport { useReactCheckout } from '@bobospay/bobospay-checkout'\n\nexport function PayButton() {\n  const { init, initWithUrl, open } = useReactCheckout()\n\n  // --- Mode 1: API mode ---\n  const handleApiPay = React.useCallback(async () => {\n    init({ clientId: 'ci_test_xxx' }, {\n      transaction: { amount: 5000, currency: 'XOF' },\n      customer: { firstname: 'Jane', lastname: 'Doe', email: 'jane@example.com' },\n      callback: (result) => console.log('paid', result),\n      ui: { closeButton: true }\n    })\n    await open()\n  }, [init, open])\n\n  // --- Mode 2: URL mode (server-side created session) ---\n  const handleUrlPay = React.useCallback(async () => {\n    const paymentUrl = await fetch('/api/create-payment').then(r => r.json()).then(d => d.url)\n    initWithUrl(paymentUrl, {\n      callback: (result) => console.log('paid', result),\n      ui: { closeButton: true }\n    })\n    await open()\n  }, [initWithUrl, open])\n\n  return (\n    <>\n      <button onClick={handleApiPay}>Pay (API mode)</button>\n      <button onClick={handleUrlPay}>Pay (URL mode)</button>\n    </>\n  )\n}\n```\n\n---\n\n## Vue 3\n\nThe package ships a `useVueCheckout` composable. Both init modes are available:\n\n```vue\n<template>\n  <button @click=\"handleApiPay\">Pay (API mode)</button>\n  <button @click=\"handleUrlPay\">Pay (URL mode)</button>\n</template>\n\n<script setup lang=\"ts\">\nimport { useVueCheckout } from '@bobospay/bobospay-checkout'\n\nconst { init, initWithUrl, open } = useVueCheckout()\n\n// --- Mode 1: API mode ---\nasync function handleApiPay() {\n  init({ clientId: 'ci_test_xxx' }, {\n    transaction: { amount: 5000, currency: 'XOF' },\n    customer: { id: 'cust_abc123' },\n    callback: (result) => console.log('paid', result),\n    ui: { closeButton: true }\n  })\n  await open()\n}\n\n// --- Mode 2: URL mode (server-side created session) ---\nasync function handleUrlPay() {\n  const { url } = await fetch('/api/create-payment').then(r => r.json())\n  initWithUrl(url, {\n    callback: (result) => console.log('paid', result),\n    ui: { closeButton: true }\n  })\n  await open()\n}\n</script>\n```\n\n---\n\n## UI options\n\nAll `ui` fields are optional:\n\n| Option | Type | Default | Description |\n|---|---|---|---|\n| `width` | `number \\| string` | `420` | Iframe width (px or CSS string) |\n| `height` | `number \\| string` | `680` | Iframe height (px or CSS string) |\n| `closeButton` | `boolean` | `false` | Show a close button above the iframe |\n| `overlayClose` | `boolean` | `false` | Click on the backdrop to close |\n| `containerSelector` | `string \\| null` | `null` | CSS selector for the mount container (defaults to `document.body`) |\n\n---\n\n## Customer object\n\nRequired when using **API mode** (`init`). You must provide either an `id` **or** minimal contact details:\n\n```ts\n// Option A — existing customer id\ncustomer: { id: 'cust_abc123' }\n\n// Option B — new / guest customer\ncustomer: {\n  firstname: 'Jane',   // required if no id\n  lastname: 'Doe',     // required if no id\n  email: 'jane@example.com',  // required if no id, must be valid\n  phone: '+22601234567',      // optional\n  country: 'CI',              // optional, ISO 3166-1 alpha-2\n}\n```\n\nNot needed in **URL mode** (`initWithUrl`) — the customer is already attached to the session server-side.\n\n---\n\n## Security\n\n- **Never expose your private API key** in client-side code. Only the public `clientId` (prefix `ci_live_` or `ci_test_`) belongs in the browser.\n- The SDK validates `postMessage` origins against a strict whitelist of Bobospay-owned hosts.\n- In URL mode the payment URL is validated against trusted Bobospay domains before being set as the iframe `src`.\n- The iframe is rendered with `referrerpolicy=\"no-referrer\"` and the `allow=\"payment\"` permission policy.\n- Apply a strict Content-Security-Policy (`frame-src`) on merchant pages that restricts iframe sources to Bobospay checkout domains.\n\n---\n\n## CDN URLs reference\n\nReplace `1.1.0` with the version you want to pin, or omit for the latest release.\n\n| Format | jsDelivr | unpkg |\n|---|---|---|\n| IIFE (CDN / global) | `https://cdn.jsdelivr.net/npm/@bobospay/bobospay-checkout@1.1.0/dist/bobospay.iife.js` | `https://unpkg.com/@bobospay/bobospay-checkout@1.1.0/dist/bobospay.iife.js` |\n| ES Module | `https://cdn.jsdelivr.net/npm/@bobospay/bobospay-checkout@1.1.0/dist/bobospay.es.js` | `https://unpkg.com/@bobospay/bobospay-checkout@1.1.0/dist/bobospay.es.js` |\n| CommonJS | `https://cdn.jsdelivr.net/npm/@bobospay/bobospay-checkout@1.1.0/dist/bobospay.cjs.js` | `https://unpkg.com/@bobospay/bobospay-checkout@1.1.0/dist/bobospay.cjs.js` |\n| TypeScript types | `dist/index.d.ts` (included in npm package) | — |\n\nThe IIFE build exposes a global `BobospayCheckout` object with the `createBobospayCheckout` factory.\n\n---\n\n## License\n\nMIT © Bobospay\n","readmeFilename":"README.md"}