SDK reference, Incode Web SDK 2 Reference

Third-Party Dependencies

Note

This guide is specific to Web SDK 2.0. If you are still using 1.x, you can find documentation here. Contact your Incode Representative for upgrade information and check if you are a candidate for this upgrade.

Full rollout to all clients still TBD.

The Incode Web SDK loads some resources from domains outside your configured apiURL. This page lists those external network requests — what they're for, and how to remove, replace, or self-host them. Use it to configure Content-Security-Policy allowlists or to run a fully self-hosted deployment.

Summary

Resource Domain Package Default Override
WASM + ML models cdn.incodesmile.com @incodetech/core Loaded for capture or explicit warm-up setup({ wasm: { wasmPath, modelsBasePath, ... } })
Public IP lookup api.ipify.org @incodetech/core Enabled setup({ ipLookup: false })
Translations Application asset host in 2.3.0; api.i18nexus.com in SDK development builds @incodetech/web Bundled locale chunks in published 2.3.0 packages setup({ i18n: { loadPath | skipRemoteLoad, translations } })
Feature management Statsig-managed endpoints internal layer Enabled setup({ featureManagement: false })

Fonts and animations are bundled in @incodetech/web — they don't hit third-party domains and aren't listed here.

@incodetech/web's setup() forwards ipLookup, fingerprint, featureManagement, and environment to @incodetech/core, and applies i18n internally.

WASM / ML models

What: WASM binaries, glue JavaScript, and ML models for face and ID capture.

Default domain: cdn.incodesmile.com

Override individual paths, or point at your own host entirely:

import { setup } from '@incodetech/core';

await setup({
  apiURL: 'https://api.incode.com',
  wasm: {
    wasmPath: '/wasm/webLib.wasm',
    glueCodePath: '/wasm/webLib.js',
    modelsBasePath: '/wasm/models',
  },
});

See WASM Configuration for the full self-hosting walkthrough, including required headers and SIMD variants.

Public IP lookup (ipify)

What: Fetches the client's public IP address, used to enrich the device-fingerprint submission.

Default domain: api.ipify.org

import { setup } from '@incodetech/core';

await setup({
  apiURL: 'https://api.incode.com',
  ipLookup: false,
});

Set ipLookup: false to skip the third-party call entirely — useful for deployments where outbound calls to third-party services are restricted. See the ipLookup and fingerprint options in API Reference for the full behavior, including what each flag does to fingerprint submission.

Translations

Published 2.3.0 packages load the built-in translations as locale chunks from the host serving your application's SDK assets. The default no longer needs an i18nexus CSP allowance. Earlier packages and SDK development builds can fetch translations from api.i18nexus.com.

A custom i18n.loadPath uses your translation endpoint instead;. Allow its host for translation requests. Inline translations override the loaded strings. skipRemoteLoad: true disables remote loading but still permits bundled locales in 2.3.0. See Internationalization.

Feature management (Statsig)

What: Decides feature-gate and experiment values for the session, so Incode can roll changes out progressively and run capture experiments. Served by Statsig via the @statsig/js-client package, loaded as a separate chunk during setup().

Default: enabled. Include its network requirements when configuring your application CSP.

Domains: the client uses Statsig's own default endpoints. The SDK does not override or proxy them, and exposes no option to redirect them, so take the current hostnames from Statsig's CSP guidance when you build an allowlist.

Opt out completely:

import { setup } from '@incodetech/core';

await setup({
  apiURL: 'https://api.incode.com',
  featureManagement: false,
});

With featureManagement: false the chunk is never fetched and no feature-management request leaves the browser. Reads from @incodetech/core/feature-management keep working and resolve to their defaults, so opting out does not break code that checks a gate.

What identity is sent. No customer API key is involved. The integration generates its own anonymous identifier (a "StableID") and enriches it over the session with hashed session, flow, and workflow identifiers. Two privacy defaults are already conservative, and two flags tighten them further:

  • IP address and country are redacted by default before anything is sent. Use redactedUserInfo to redact more fields, or to send those two deliberately.
  • disableStableId: true stops the identifier being generated at all — the strongest control. Evaluations then resolve to control values until session identity arrives.
  • disablePersistence: true keeps identity in memory only, so it is never linkable across page loads.

See FeatureManagementSetupOptions for the full option table, and Feature management for the read API.

API-driven externals (not SDK-configured)

These URLs come from Incode API responses, not hardcoded SDK constants, so they aren't controlled by a setup() option:

  • Theme / logo assets
  • Presigned upload URLs (electronic signature document uploads)
  • Signed PDF document URLs
  • Recording upload URLs (when video recording is enabled). For 2.3.0, allow HTTPS uploads to the destinations supplied for the session. A recording-specific WebSocket allowance is no longer required.

Configure these in Dashboard or with your Incode account team.

The API supplies the desktop-to-mobile redirect URL by default. Set FlowConfig.redirectToMobileUrl to replace this URL for one <incode-flow> instance.

Some modules link to Incode policy pages (for example, terms-of-service or privacy-policy links in consent screens). These are user-initiated navigation, not requests the SDK makes on its own.

See Also