{"_id":"@canton-vc/adapter-sumsub","_rev":"3-82f9ef2facb5d755714984336cc7619b","name":"@canton-vc/adapter-sumsub","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"@canton-vc/adapter-sumsub","version":"0.1.0","keywords":["canton","kyc","sumsub","adapter","canton-vc"],"author":{"url":"https://github.com/Farukest","name":"Abdullah Faruk Özden","email":"abdullahfarukozden@gmail.com"},"license":"Apache-2.0","_id":"@canton-vc/adapter-sumsub@0.1.0","maintainers":[{"name":"0xflydev","email":"0xflydev@gmail.com"}],"homepage":"https://github.com/Farukest/canton-vc/tree/main/packages/adapter-sumsub#readme","bugs":{"url":"https://github.com/Farukest/canton-vc/issues"},"dist":{"shasum":"440c55b64d2a8397da6cc57a51c8ba9ec05a30f6","tarball":"https://registry.npmjs.org/@canton-vc/adapter-sumsub/-/adapter-sumsub-0.1.0.tgz","fileCount":8,"integrity":"sha512-qLyS5sWuEKsoMKSXiOX3buEjpA7DedOfcQF6YfMApZYS8kBeJZ+HpvTxR/8WGtS31m7peJwNlYGsrMt+1Btr9A==","signatures":[{"sig":"MEUCIQCTye+kVZKdgbmoCj2iEfT7h8R3hMCzbWYXG4L9VvUc1QIgJqH998LBln5WBkLR15avtgTpmJ1BfIsoj40ovEgncbs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49402},"main":"./src/index.ts","type":"module","_from":"file:canton-vc-adapter-sumsub-0.1.0.tgz","types":"./src/index.ts","engines":{"node":">=18"},"exports":{".":{"types":"./src/index.ts","default":"./src/index.ts"}},"scripts":{"lint":"biome check src tests","test":"vitest run","clean":"rm -rf .turbo dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"0xflydev","email":"0xflydev@gmail.com"},"_resolved":"C:\\Users\\FARUKE~1\\AppData\\Local\\Temp\\a9a4359457ebbc8b40857649599e18ed\\canton-vc-adapter-sumsub-0.1.0.tgz","_integrity":"sha512-qLyS5sWuEKsoMKSXiOX3buEjpA7DedOfcQF6YfMApZYS8kBeJZ+HpvTxR/8WGtS31m7peJwNlYGsrMt+1Btr9A==","repository":{"url":"git+https://github.com/Farukest/canton-vc.git","type":"git","directory":"packages/adapter-sumsub"},"_npmVersion":"11.6.2","description":"Sumsub KYC provider adapter for canton-vc. Wraps Sumsub's applicants API with per-request HMAC authentication (X-App-Access-Sig over ts+method+path+body) and the multi-algorithm webhook digest scheme (X-Payload-Digest), behind the vendor-agnostic KycProvi","directories":{},"sideEffects":false,"_nodeVersion":"24.12.0","dependencies":{"zod":"4.3.6","@canton-vc/core":"0.1.0","@canton-vc/kyc-provider":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"2.1.8","typescript":"5.6.3","@types/node":"22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/adapter-sumsub_0.1.0_1779586288234_0.698405803382764","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@canton-vc/adapter-sumsub","version":"0.2.0","keywords":["canton","kyc","sumsub","adapter","canton-vc"],"author":{"url":"https://github.com/Farukest","name":"Abdullah Faruk Özden","email":"abdullahfarukozden@gmail.com"},"license":"Apache-2.0","_id":"@canton-vc/adapter-sumsub@0.2.0","maintainers":[{"name":"0xflydev","email":"0xflydev@gmail.com"}],"homepage":"https://github.com/Farukest/canton-vc/tree/main/packages/adapter-sumsub#readme","bugs":{"url":"https://github.com/Farukest/canton-vc/issues"},"dist":{"shasum":"ec0733d9550b86b27b13ac487761a3eb2efbc8a7","tarball":"https://registry.npmjs.org/@canton-vc/adapter-sumsub/-/adapter-sumsub-0.2.0.tgz","fileCount":8,"integrity":"sha512-E4znycCC5PAVhWB34XczlinIjY6u6Agxza1bu4F1BaOX6jDcItlArCpgp5/2sT9o34dwV/s685umZG5+OB7PHg==","signatures":[{"sig":"MEYCIQD3BSnt7XD1cnzT3qe1U0/tv56H2fircDOGRFv6VeGrEgIhAKQv6l7cVwDPgFTIFpzse8SmUWrNmR65Z/dVBo30klR4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49797},"main":"./src/index.ts","type":"module","_from":"file:canton-vc-adapter-sumsub-0.2.0.tgz","types":"./src/index.ts","engines":{"node":">=18"},"exports":{".":{"types":"./src/index.ts","default":"./src/index.ts"}},"scripts":{"lint":"biome check src tests","test":"vitest run","clean":"rm -rf .turbo dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"0xflydev","email":"0xflydev@gmail.com"},"_resolved":"C:\\Users\\FARUKE~1\\AppData\\Local\\Temp\\f50ef8ba10c9ba32636c4faf62667f4e\\canton-vc-adapter-sumsub-0.2.0.tgz","_integrity":"sha512-E4znycCC5PAVhWB34XczlinIjY6u6Agxza1bu4F1BaOX6jDcItlArCpgp5/2sT9o34dwV/s685umZG5+OB7PHg==","repository":{"url":"git+https://github.com/Farukest/canton-vc.git","type":"git","directory":"packages/adapter-sumsub"},"_npmVersion":"11.6.2","description":"Sumsub KYC provider adapter for canton-vc. Wraps Sumsub's applicants API with per-request HMAC authentication (X-App-Access-Sig over ts+method+path+body) and the multi-algorithm webhook digest scheme (X-Payload-Digest), behind the vendor-agnostic KycProvi","directories":{},"sideEffects":false,"_nodeVersion":"24.12.0","dependencies":{"zod":"4.3.6","@canton-vc/core":"0.2.0","@canton-vc/kyc-provider":"0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"2.1.8","typescript":"5.6.3","@types/node":"22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/adapter-sumsub_0.2.0_1779984357206_0.7621397555437521","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@canton-vc/adapter-sumsub","version":"0.3.0","description":"Sumsub KYC provider adapter for canton-vc. Wraps Sumsub's applicants API with per-request HMAC authentication (X-App-Access-Sig over ts+method+path+body) and the multi-algorithm webhook digest scheme (X-Payload-Digest), behind the vendor-agnostic KycProvi","license":"Apache-2.0","type":"module","main":"./src/index.ts","types":"./src/index.ts","exports":{".":{"types":"./src/index.ts","default":"./src/index.ts"}},"sideEffects":false,"engines":{"node":">=18"},"dependencies":{"zod":"4.3.6","@canton-vc/core":"0.3.0","@canton-vc/kyc-provider":"0.3.0"},"devDependencies":{"@types/node":"22.10.2","typescript":"5.6.3","vitest":"2.1.8"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/Farukest/canton-vc.git","directory":"packages/adapter-sumsub"},"keywords":["canton","kyc","sumsub","adapter","canton-vc"],"author":{"name":"Abdullah Faruk Özden","email":"abdullahfarukozden@gmail.com","url":"https://github.com/Farukest"},"homepage":"https://github.com/Farukest/canton-vc/tree/main/packages/adapter-sumsub#readme","bugs":{"url":"https://github.com/Farukest/canton-vc/issues"},"scripts":{"lint":"biome check src tests","typecheck":"tsc --noEmit","test":"vitest run","clean":"rm -rf .turbo dist"},"_id":"@canton-vc/adapter-sumsub@0.3.0","_integrity":"sha512-pr7QH2f/sfj9mpdJQOcfTNWSSk0OPXkzsiEZ/FDPU2xx5c6gI8ofClygxw4Hm6JWbnXuiaDEQzSyFkxmQMaKPw==","_resolved":"C:\\Users\\FARUKE~1\\AppData\\Local\\Temp\\36264886fb4b29f3453967da09e525df\\canton-vc-adapter-sumsub-0.3.0.tgz","_from":"file:canton-vc-adapter-sumsub-0.3.0.tgz","_nodeVersion":"24.12.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-pr7QH2f/sfj9mpdJQOcfTNWSSk0OPXkzsiEZ/FDPU2xx5c6gI8ofClygxw4Hm6JWbnXuiaDEQzSyFkxmQMaKPw==","shasum":"f362942445ba241d67de88eec2377871b15b824d","tarball":"https://registry.npmjs.org/@canton-vc/adapter-sumsub/-/adapter-sumsub-0.3.0.tgz","fileCount":8,"unpackedSize":49993,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDzS4cGY4sn5wOAw9PHhBFWAifK4Hagfoa5nS5dNOhvLgIhAMKo9S8SYttuzLlhMepiWeXZP+WtlWSDK+CeERRqg/Mn"}]},"_npmUser":{"name":"0xflydev","email":"0xflydev@gmail.com"},"directories":{},"maintainers":[{"name":"0xflydev","email":"0xflydev@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/adapter-sumsub_0.3.0_1780019781096_0.8611172709734436"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-24T01:31:28.004Z","modified":"2026-05-29T01:56:21.376Z","0.1.0":"2026-05-24T01:31:28.394Z","0.2.0":"2026-05-28T16:05:57.339Z","0.3.0":"2026-05-29T01:56:21.261Z"},"bugs":{"url":"https://github.com/Farukest/canton-vc/issues"},"author":{"name":"Abdullah Faruk Özden","email":"abdullahfarukozden@gmail.com","url":"https://github.com/Farukest"},"license":"Apache-2.0","homepage":"https://github.com/Farukest/canton-vc/tree/main/packages/adapter-sumsub#readme","keywords":["canton","kyc","sumsub","adapter","canton-vc"],"repository":{"type":"git","url":"git+https://github.com/Farukest/canton-vc.git","directory":"packages/adapter-sumsub"},"description":"Sumsub KYC provider adapter for canton-vc. Wraps Sumsub's applicants API with per-request HMAC authentication (X-App-Access-Sig over ts+method+path+body) and the multi-algorithm webhook digest scheme (X-Payload-Digest), behind the vendor-agnostic KycProvi","maintainers":[{"name":"0xflydev","email":"0xflydev@gmail.com"}],"readme":"# @canton-vc/adapter-sumsub\n\nProduction [`KycProvider`](../kyc-provider) implementation for the\n[Sumsub](https://sumsub.com) KYC vendor.\n\n## Install\n\n```bash\npnpm add @canton-vc/adapter-sumsub @canton-vc/kyc-provider\n```\n\n## Usage\n\n```ts\nimport { SumsubAdapter } from '@canton-vc/adapter-sumsub';\n\nconst kyc = new SumsubAdapter({\n  appToken: process.env.SUMSUB_APP_TOKEN!,     // 'sbx:…' (sandbox) or 'prd:…' (prod)\n  secretKey: process.env.SUMSUB_SECRET_KEY!,   // signs every REST request\n  webhookSecret: process.env.SUMSUB_WEBHOOK_SECRET!, // signs inbound webhooks\n  identityLevelName: 'id-and-liveness',\n  // optional:\n  addressLevelName: 'enhanced-poa-level',\n});\n\n// 1. Start a session — redirect the user to session.redirectUrl\nconst session = await kyc.startSession({ userRef: 'user-123' });\n\n// 2. Pull the decision after callback (or webhook fallback)\nconst decision = await kyc.fetchDecision(session.sessionId);\n// decision.status === 'approved' | 'declined' | 'in_review' | 'pending' | 'expired'\n\n// 3. Verify webhook (in your /webhook/sumsub handler)\nconst event = await kyc.verifyWebhook(rawBody, request.headers);\nif (event === null) return new Response('invalid', { status: 400 });\n// event.type === 'decision' | 'session.expired'\n```\n\n## Authentication — per-request HMAC\n\nUnlike adapters that use a static API key, Sumsub signs **every**\nREST request. The adapter computes\n`HMAC-SHA256(secretKey, ts + method + path + body)` and sends it in\n`X-App-Access-Sig`, alongside `X-App-Access-Ts` (Unix seconds) and\n`X-App-Token` (your app token). The signing helper is exported as\n`signSumsubRequest` for testing.\n\n## Webhook signature\n\nSumsub signs webhooks with a separate, per-endpoint secret configured\nin the Sumsub console. The digest is sent in `X-Payload-Digest`, with\n`X-Payload-Digest-Alg` selecting the algorithm: `HMAC_SHA1_HEX`,\n`HMAC_SHA256_HEX`, or `HMAC_SHA512_HEX`. The adapter verifies all\nthree in constant time.\n\n## End-to-end testing\n\nSumsub publishes an officially supported development path: the\n`testCompleted` endpoint short-circuits the applicant lifecycle to\napproval so the issuer can exercise the full adapter surface\n(`startSession` → `fetchDecision` → `verifyWebhook`) against the real\nSumsub API without requiring a human to upload documents on every\nrun. The repository's `scripts/live-sumsub-canton-e2e-v2.ts` chains\nthis through to a real Canton 3.4 participant — a 16-phase smoke\nrunning every DAML choice on the deployed DAR (`createCredential`,\n`Credential_PublicFetch`, `Credential_ArchiveAsHolder`,\n`RevokeCredential` cascade, `UpdateCredentials`, `createKycNft`,\nstandalone `BurnNft`, wrong-admin reject) against live\ninfrastructure end-to-end.\n\n## Configuration reference\n\n| Field | Required | Default | Purpose |\n|---|---|---|---|\n| `appToken` | ✅ | — | Sumsub app token (`sbx:` sandbox / `prd:` prod). |\n| `secretKey` | ✅ | — | Per-request HMAC signing key. |\n| `webhookSecret` | ✅ | — | Webhook digest verification key. |\n| `identityLevelName` | ✅ | — | Sumsub level name for identity workflow. |\n| `addressLevelName` |   | — | Sumsub level name for proof-of-address workflow. |\n| `baseUrl` |   | `https://api.sumsub.com` | API root. |\n| `requestTimeoutMs` |   | `10000` | Per-request HTTP timeout. |\n| `websdkTtlSeconds` |   | `1800` | WebSDK link TTL passed to Sumsub. |\n| `fetch` |   | `globalThis.fetch` | Override the fetch implementation. |\n| `clock` |   | `Date.now` | Override the wall-clock source. |\n\n## Implementing another vendor\n\nThe companion reference adapter\n[`@canton-vc/adapter-didit`](../adapter-didit) uses a structurally\ndifferent wire shape (static API key + canonical-JSON webhook HMAC\n+ session-id identity model + workflow-id vocabulary). Pick whichever\nof the two is closer to your target vendor's authentication pattern\nand adapt from there. Open an issue with the vendor name to claim\nthe next adapter.\n\n## License\n\nApache 2.0 — see [LICENSE](../../LICENSE).\n","readmeFilename":"README.md"}