Origin allow-list
Bluprynt only loads the widget on origins registered for your partner ID.
To add or remove an origin, contact your Bluprynt representative. If your page sets a Content Security Policy, allow the iframe:
Checklist
1
Keep SECRET_KEY on the server
Store it in your secrets manager or server environment, not in front-end code,
NEXT_PUBLIC_* variables, mobile apps or Git. Anyone with the key can sign tokens for any sub.2
Authenticate the token endpoint
Only signed-in members can mint tokens. Return
401 otherwise.3
Take sub from the session
Never read the user ID from the request body, query string or headers the browser controls. Bluprynt trusts
sub as-is: whoever can choose sub can open that member’s verification.4
Use stable, unique, internal IDs
A database primary key or UUID. Not emails, wallet addresses or usernames, which change or get reused and would end up in a token visible in the browser.
5
Send Cache-Control: no-store
On every token response, including errors, so no browser, CDN or proxy caches a token.
6
Mint per open, keep lifetimes short
A fresh token for each
kyi() call, with the default one-hour lifetime or less. Don’t store tokens.7
Protect against CSRF
Use
POST for the endpoint, plus your usual CSRF protection (same-site cookies or a CSRF token). Otherwise another site could mint tokens through a member’s session.8
Fail closed
If the partner ID or secret is missing, return
503 and hide the button. Never fall back to a shared or test key.9
Don't log tokens
Leave the token and
SECRET_KEY out of logs, analytics and error reports.What the SDK does for you
- It only processes
postMessageevents from abluprynt.comorigin and from its own iframe. - The widget runs in a cross-origin iframe, so your page can’t read what the member types into KYB forms, and the widget can’t read your page.
- The iframe gets only
clipboard-writeandweb-share.
Data handling
Rotating your secret
IfSECRET_KEY may have leaked, ask Bluprynt for a new one, deploy it, and confirm the old one is revoked. Tokens signed with the old key stop working, so members just need to reopen the widget.
Related: Access tokens · Errors and troubleshooting