Browser boundary
Client SDK
The client SDK opens a dedicated login window and accepts only a response from the configured login origin and the exact popup it created.
Public surface
VeilPass.login accepts a gateId and optional timeout. It resolves to VerifiedLogin or throws a typed VeilPassError. It never exposes the proof payload to host application code.
import { VeilPass } from "@veilpass/sdk";
const veilpass = new VeilPass({
loginOrigin: "https://login.veilpass.dev",
});
const result = await veilpass.login({ gateId: "premium-holder" });
// result never contains the wallet addressChannel rules
The SDK uses the configured exact login origin as postMessage targetOrigin and accepts messages only from that origin, the popup window it opened, and the per-login state. It validates the payload with the strict proof schema, allows only one verification request at a time, and removes listeners on success/error, popup close, and timeout. Keep loginOrigin trusted and fixed by application configuration; never derive it from user input or the incoming message.
Host routes are required
The SDK sends same-origin fetches to POST /api/challenges and POST /api/verify. You must implement both on your host's origin. The SDK does not proxy these through login.veilpass.dev, and the current 0.2.x release does not provide configurable path options. See the package README for the exact responsibility boundary.