Skip to main content
A KYI access token lets whoever holds it act as one of your members inside the widget, until it expires. Most integration risks come from minting the wrong token, or giving it to the wrong person.

Origin allow-list

Bluprynt only loads the widget on origins registered for your partner ID. To add or remove an origin, contact your Bluprynt representative. If your page sets a Content Security Policy, allow the iframe:

Checklist

1

Keep SECRET_KEY on the server

Store it in your secrets manager or server environment, not in front-end code, NEXT_PUBLIC_* variables, mobile apps or Git. Anyone with the key can sign tokens for any sub.
2

Authenticate the token endpoint

Only signed-in members can mint tokens. Return 401 otherwise.
3

Take sub from the session

Never read the user ID from the request body, query string or headers the browser controls. Bluprynt trusts sub as-is: whoever can choose sub can open that member’s verification.
4

Use stable, unique, internal IDs

A database primary key or UUID. Not emails, wallet addresses or usernames, which change or get reused and would end up in a token visible in the browser.
5

Send Cache-Control: no-store

On every token response, including errors, so no browser, CDN or proxy caches a token.
6

Mint per open, keep lifetimes short

A fresh token for each kyi() call, with the default one-hour lifetime or less. Don’t store tokens.
7

Protect against CSRF

Use POST for the endpoint, plus your usual CSRF protection (same-site cookies or a CSRF token). Otherwise another site could mint tokens through a member’s session.
8

Fail closed

If the partner ID or secret is missing, return 503 and hide the button. Never fall back to a shared or test key.
9

Don't log tokens

Leave the token and SECRET_KEY out of logs, analytics and error reports.

What the SDK does for you

  • It only processes postMessage events from a bluprynt.com origin and from its own iframe.
  • The widget runs in a cross-origin iframe, so your page can’t read what the member types into KYB forms, and the widget can’t read your page.
  • The iframe gets only clipboard-write and web-share.

Data handling

Rotating your secret

If SECRET_KEY may have leaked, ask Bluprynt for a new one, deploy it, and confirm the old one is revoked. Tokens signed with the old key stop working, so members just need to reopen the widget. Related: Access tokens · Errors and troubleshooting