Skip to main content
The chmod SDK renders the whole verification experience inside your app: document capture, the liveness check, and an optional result screen. You launch it with a token and it hands back a typed outcome.

iOS

Swift Package Manager. SwiftUI and UIKit. iOS 16+.

Android

Gradle via GitHub Packages. Compose and Views. minSdk 24.

React Native

In progress.

Flutter

In progress.

What the SDK needs

Exactly two things:
string
Your chmod API host, the same one your backend calls.
string
A token scoped to one transaction, minted by your backend with Create transaction.
Optionally, a configuration object controlling how the flow looks and behaves. See SDK configuration.
Your app must never hold your API client id and secret. It receives an sdk_token that only permits the calls for one transaction, and it should get that token from your own backend over your own authenticated endpoint.

The shape of an integration

On both platforms the sequence is the same, and it is short:
1

Ask your backend for a token

Your app calls an endpoint you own. That endpoint authenticates the user, creates the transaction, and returns the sdk_token. Do this off the main thread.
2

Launch the flow

Hand the token to the SDK. It takes over the screen and drives the user through capture.
3

Receive the outcome

The SDK returns completed, cancelled or failed, always on the main thread.
4

Let your backend deliver the verdict

The decision is produced after capture ends and reaches your backend through the webhook. Your app finds out from your backend, not from the SDK.

Three outcomes, and what they mean

completed does not mean approved. It means the capture finished and everything was uploaded. The verdict is produced afterwards, usually within seconds, and delivered to your backend through the webhook.An app that shows a success screen at completed is lying to the user roughly as often as your rejection rate.
Every outcome carries the transaction id, so you can correlate what the app saw with what your backend later receives.

Permissions

The SDK asks for what it needs, when it needs it, and converts a refusal into a typed result rather than a crash.
Do not request the camera permission yourself before launching the flow. Asking early, out of context, gets you a denial with nothing on screen to explain why you needed it. The SDK asks at the moment the camera appears, which is when the user understands the request.
Location is off unless you turn it on, and it only matters if you use the GPS rules in device policy.

What the SDK reports

Alongside the images, the SDK collects signals about the device: model and OS, whether it is an emulator, whether root or jailbreak was detected, network type and carrier, and (with permission) GPS coordinates. Those signals are what device_policy acts on, and they all come back in result_data.metadata so you can audit any decision.

Versions

The copy, the colours and the capture behaviour are configured identically on both platforms, and the localization keys are shared. See SDK configuration.