{"_id":"@burjx/web-sdk","name":"@burjx/web-sdk","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@burjx/web-sdk","version":"1.0.0","description":"BurjX browser SDK for hosted regulated onboarding","type":"module","sideEffects":false,"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc --project tsconfig.build.json","typecheck":"tsc --project tsconfig.json"},"_id":"@burjx/web-sdk@1.0.0","_integrity":"sha512-lU4Ke/Zv6dhK5s1xC8WW6ZiEpy0UakLbKpIzo5CzpG8GOLph8ZRdDJG9W25DSU+ahooVnwbbjYyp68jAooTYZA==","_resolved":"/tmp/burjx-ticket14-release.3AEXVd/burjx-web-sdk-1.0.0.tgz","_from":"file:/tmp/burjx-ticket14-release.3AEXVd/burjx-web-sdk-1.0.0.tgz","_nodeVersion":"22.22.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-lU4Ke/Zv6dhK5s1xC8WW6ZiEpy0UakLbKpIzo5CzpG8GOLph8ZRdDJG9W25DSU+ahooVnwbbjYyp68jAooTYZA==","shasum":"f9315ff5b6c7407cb46a6b42d189914fd50d344b","tarball":"https://registry.npmjs.org/@burjx/web-sdk/-/web-sdk-1.0.0.tgz","fileCount":20,"unpackedSize":54597,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCe21ksbWok5BCliO7rEH6O4S+0ATowBBgBhbSPsFuxswIhAMzQyg8mDpX7KcOQnU2khxBk6D5qk6jV8bShJHtFNJMB"}]},"_npmUser":{"name":"burjx","email":"tech@burjx.com"},"directories":{},"maintainers":[{"name":"burjx","email":"tech@burjx.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/web-sdk_1.0.0_1785365103629_0.08231569570573738"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-29T22:45:03.457Z","1.0.0":"2026-07-29T22:45:03.769Z","modified":"2026-07-29T22:45:03.989Z"},"maintainers":[{"name":"burjx","email":"tech@burjx.com"}],"description":"BurjX browser SDK for hosted regulated onboarding","readme":"# `@burjx/web-sdk` 1.0\n\nThe browser SDK opens or embeds the BurjX-hosted onboarding URL returned by the\nPartner API. It does not accept Business Client, End Client, workflow, or\ncredential configuration.\n\nObtain `onboardingUrl` from your authenticated backend. Never place a\n`@burjx/partner-sdk` OAuth access token in browser code.\n\n```ts\nimport { mount } from \"@burjx/web-sdk\";\n\nconst onboarding = mount({\n  onboardingUrl,\n  element: document.querySelector(\"#burjx-onboarding\")!,\n  initializationTimeoutMs: 15_000,\n  callbacks: {\n    onInitializing: () => console.log(\"Initializing\"),\n    onReady: () => console.log(\"Ready\"),\n    onActionRequired: ({ kind }) => console.log(\"Action required\", kind),\n    onSubmitted: () => console.log(\"Submitted; read back on the server\"),\n    onClosed: ({ reason }) => console.log(\"Closed\", reason),\n    onFailed: ({ error }) => console.error(error.code),\n  },\n});\n\nconst result = await onboarding.result;\nif (result.type === \"submitted\") {\n  // Read the authoritative Journey through @burjx/partner-sdk on your server.\n}\n\n// Programmatic close is idempotent and removes owned browser resources.\nonboarding.close();\n```\n\nUse `open({ onboardingUrl, callbacks })` for the hosted-link mode. Both modes\nshare `initializing`, `ready`, `action-required`, `submitted`, `closed`, and\n`failed` outcomes. `submitted` means the interactive step ended and\nauthoritative readback is still required; it does not claim verification\napproval. Pass an `AbortSignal` to cancel and use\n`initializationTimeoutMs` to override the 15-second initialization timeout.\n`ready` means the origin-bound BurjX experience is initialized, so that timer\ndoes not include time the End Client spends entering identity information.\n\nFailures use `WebSdkError` and distinguish an invalid, expired, or redeemed\nlaunch; origin or Return URL mismatch; blocked popup; network or timeout; and\nhosted-service unavailability without exposing provider details.\n\n`mount` sends the exact parent page origin to the BurjX-hosted page. That page\nrevalidates it against the Launcher Credential and the Application's current\npublished Allowed Origins before initialization. The SDK accepts lifecycle\nmessages only from the exact onboarding origin and the exact frame or window\nit created. BurjX also revalidates the current published Return URL immediately\nbefore returning from the hosted experience.\n\nLocale is selected when your trusted server creates the Journey. Pass\n`locale: \"ar\"` to that server-side request only when the published Application\nallows Arabic; do not add a client-side locale override. Arabic Journeys render\ncomplete BurjX-controlled Arabic copy with `lang=\"ar\"` and right-to-left\ndirection while keeping the same provider-independent lifecycle callbacks,\nauthoritative Journey readback, and Normalized Event structures as English.\nThe administrator dashboard and developer documentation remain English.\n\nThe responsive hosted experience supports current iOS Safari and Android\nChrome for KYC and KYB. Embedded frames fill the available inline size and use\nthe dynamic viewport so focused controls remain scrollable when a mobile\nkeyboard reduces the visible area. Camera and file selection remain\nprovider-owned handoffs; user close, Return URL revalidation, and lifecycle\ncallbacks use the same browser contract on mobile. BurjX does not publish a\nnative iOS or Android SDK.\n\nThe package is framework-independent. It can be imported safely during SSR,\nbut calling `open` or `mount` without a supported browser throws\n`WebSdkError` with `unsupported_environment`. In React, call `mount` from an\neffect and return `controller.close` from the effect cleanup; no React wrapper\npackage is required.\n\nVersion 1.0 targets desktop Chrome 149–150, Edge 149–150, Firefox 150–151,\nSafari 18 and 26, plus current iOS Safari 26 and Android Chrome 150. Newer\nmajors in those families remain eligible. The exported\n`WEB_SDK_SUPPORT_POLICY` is the machine-readable release policy, and older or\nundeclared browsers throw `unsupported_environment` before creating a frame or\npopup. The automated\ncompatibility gate proves the built package against Chromium, Firefox, and\nWebKit snapshots from the current and previous pinned Playwright releases,\nplus the current stable Chrome and Edge channels when installed. Its mobile\nprojects use current iPhone/WebKit and Pixel/Chrome emulation for responsive\nbrowser-contract evidence. Engine and device emulation are not presented as\nphysical-device, branded iOS Safari, or deployed-provider proof.\n\n## Migrating to 1.0\n\nVersion 1.0 stabilizes the embedded and hosted lifecycle, typed failures,\nawaitable completion, close, cancellation, timeout, and idempotent cleanup\ncontracts. See [MIGRATION.md](./MIGRATION.md) for the upgrade checklist and\n[CHANGELOG.md](./CHANGELOG.md) for release history.\n\n## Versioning, deprecation, and advisories\n\nThe public package interface follows Semantic Versioning. Backward-compatible\ncapabilities ship in a minor release, backward-compatible fixes in a patch, and\nan intentional breaking interface change requires a new major release.\n\nAn ordinary supported interface will receive a published deprecation notice and\nreplacement path at least six months before removal. BurjX may shorten that\nwindow only for a security or regulatory requirement. An accelerated change\nmust ship with an advisory that identifies the impact, replacement, and\neffective date; it is never applied as an undocumented breaking change.\n","readmeFilename":"README.md","_rev":"1-f76b4ac1a080b4b05a8467beb0528b98"}