Fraud ID Generation - React Native

SDK Requirement

Requires @deuna/react-native-sdk version 2.1.10 or higher.
Android requires Android Gradle Plugin (AGP) 8.5.1+. iOS requires iOS 13.0+.


Use the initializeFraudProviders static function to warm up providers, and the generateFraudId instance method or the fraudCredentials widget parameter to generate a unified DEUNA fraud payload using supported anti-fraud providers.

The DEUNA React Native SDK uses a modular, reflection-based architecture (zero-bloat): it does not bundle any third-party fraud SDKs by default. Only add the specific provider(s) you plan to use. If you don't use a provider, you don't pay any app size penalty.


Supported Providers

ProviderDescriptionRequired Parameters
MERCADOPAGOMercado Pago device behavior profiling(None required)
RISKIFIEDRiskified Beacon beaconingstoreDomain
CYBERSOURCECyberSource ThreatMetrix profilingorgId, merchantId (Optional: fpServer)
SIGNIFYDSignifyd ThreatMetrix profilingorgId (Optional: fpServer)
ACCERTIFYAccertify InMobile profilingConfig files in assets/bundle (Optional: locationConsent, phoneConsent)
KOUNTKount Data CollectormerchantId, clientId, dataCollectorUrl, environment
SIFTSift Science device profilingaccountId, beaconKey

Dependency Linking (Select Only What You Need)

Follow the instructions for your project environment (Expo or React Native CLI).

A. Expo (Config Plugin)

In Expo projects using Continuous Native Generation (CNG) or EAS Build, enable only the providers you have contracted by listing them in the fraudProviders array in app.json:

{
  "expo": {
    "plugins": [
      [
        "@deuna/react-native-sdk",
        {
          "fraudProviders": [
            // Add ONLY the providers you need, e.g.:
            "mercadopago",
            "riskified"
          ]
        }
      ]
    ]
  }
}

Supported keys in fraudProviders: "mercadopago", "riskified", "cybersource", "signifyd", "accertify", "kount", "sift".

📘

AAR Files & Asset placement in Expo

  • Cybersource / Signifyd / Accertify: If using any of these providers in Android, place their required .aar files in android/app/libs/<provider>/ (download links provided below under React Native CLI).
  • Accertify Configuration Assets: Place server_keys_message_hosted.json and inmobile.properties in android/app/src/main/assets/ and server_keys_message_hosted.json with InMobile.plist in your iOS project / bundle.

After updating app.json, regenerate the native projects:

npx expo prebuild --clean

B. React Native CLI

In standard React Native CLI projects, add the native dependencies only for the providers you need in your host application files (android/app/build.gradle and ios/Podfile):

Android (android/app/build.gradle and root build.gradle / settings.gradle)

  1. If using Mercado Pago, ensure the Mercado Libre Maven repository is included in your android/build.gradle (or settings.gradle):
allprojects {
    repositories {
        google()
        mavenCentral()
        maven { url "https://artifacts.mercadolibre.com/repository/android-releases/" }
    }
}
  1. Download and place vendor AAR files if using Cybersource, Signifyd, or Accertify:

    • Cybersource: Download the Cybersource AAR files and place them in android/app/libs/cybersource/.
    • Signifyd: Download the Signifyd AAR files and place them in android/app/libs/signifyd/.
    • Accertify: Download the Accertify AAR files (inmobile and inmobile-common) and place them in android/app/libs/accertify/.
  2. Add only the dependencies for the providers you require inside android/app/build.gradle under dependencies { ... }:

dependencies {
    // --- Add ONLY the providers you use ---

    // Mercado Pago
    implementation("com.mercadolibre.android.device:sdk:4.0.1")

    // Riskified
    implementation("com.riskified:android-sdk:1.11.0:nogoogle@aar")

    // CyberSource (AARs placed in app/libs/cybersource)
    implementation(fileTree(dir: "libs/cybersource", include: ["*.aar"]))

    // Signifyd (AARs placed in app/libs/signifyd)
    implementation(fileTree(dir: "libs/signifyd", include: ["*.aar"]))

    // Accertify (AARs placed in app/libs/accertify + required transitive dependencies)
    implementation(fileTree(dir: "libs/accertify", include: ["*.aar"]))
    implementation("io.insert-koin:koin-core:3.5.6")
    implementation("androidx.biometric:biometric:1.1.0")
    implementation("org.jetbrains.kotlinx:kotlinx-serialization-json:1.6.3")

    // Kount
    implementation("com.kount:kount-data-collector:4.1.0")

    // Sift
    implementation("sift-android:sift-android:0.14.0")
}
  1. Accertify Configuration Assets (Android & iOS):
    • Android: Place server_keys_message_hosted.json and inmobile.properties in your android/app/src/main/assets/ directory.
    • iOS: Add server_keys_message_hosted.json and InMobile.plist to your Xcode project under your app's Copy Bundle Resources target.

iOS (ios/Podfile)

Inside your target 'YourApp' do block, add only the subspecs for the providers you need:

target 'YourApp' do
  # Add ONLY the subspecs you need:
  pod 'DeunaSDK/MercadoPago'
  pod 'DeunaSDK/Riskified'
  pod 'DeunaSDK/Cybersource'
  pod 'DeunaSDK/Signifyd'
  pod 'DeunaSDK/Kount'
  pod 'DeunaSDK/Sift'
  pod 'DeunaSDK/Accertify'
end

Then run:

pod install

Provider Details & Constraints

RISKIFIED

  • Required: storeDomain
  • Example config:
    {
      "RISKIFIED": {
        "storeDomain": "yourdomain.com"
      }
    }
⚠️

iOS Simulator Note

The third-party RiskifiedBeacon iOS library excludes native ARM64 simulators. When testing on Apple Silicon simulators, run with an x86_64 (Rosetta) simulator destination or test on a physical iOS device.


CYBERSOURCE

  • Required: orgId, merchantId
  • Optional: fpServer (default: h.online-metrix.net)
  • Example config:
    {
      "CYBERSOURCE": {
        "orgId": "your_org_id",
        "merchantId": "your_merchant_id"
      }
    }

SIGNIFYD

  • Required: orgId
  • Optional: fpServer (default: imgs.signifyd.com)
  • Example config:
    {
      "SIGNIFYD": {
        "orgId": "your_org_id"
      }
    }
⚠️

Android Incompatibility: Cybersource and Signifyd

CYBERSOURCE and SIGNIFYD use conflicting variants of the LexisNexis ThreatMetrix SDK (TMXProfiling-rl vs TMXProfiling). You cannot link both in the same Android app simultaneously. Use only one.


ACCERTIFY

  • Optional: locationConsent (default: true), phoneConsent (default: true)
  • Required Files: The public encryption key file server_keys_message_hosted.json and endpoint properties (inmobile.properties in Android src/main/assets/ and InMobile.plist in the iOS bundle resources) must be obtained from Accertify during merchant onboarding.
  • Transitive Dependencies (Android): The Accertify AAR requires Koin DI (io.insert-koin:koin-core:3.5.6), AndroidX Biometric (androidx.biometric:biometric:1.1.0), and Kotlinx Serialization (org.jetbrains.kotlinx:kotlinx-serialization-json:1.6.3) to run without runtime exceptions.
  • Example config:
    {
      "ACCERTIFY": {
        "locationConsent": true,
        "phoneConsent": false
      }
    }

KOUNT

  • Required: merchantId, clientId, dataCollectorUrl, environment
  • Example config:
    {
      "KOUNT": {
        "merchantId": "your_merchant_id",
        "clientId": "your_client_id",
        "dataCollectorUrl": "https://...",
        "environment": "TEST"
      }
    }

SIFT

  • Required: accountId, beaconKey
  • Example config:
    {
      "SIFT": {
        "accountId": "your_account_id",
        "beaconKey": "your_beacon_key"
      }
    }

MERCADOPAGO

  • Required: None ({})
  • Android: Requires the MercadoLibre Maven repository (https://artifacts.mercadolibre.com/repository/android-releases/) and dependency com.mercadolibre.android.device:sdk:4.0.1.
  • iOS: Linked via pod 'DeunaSDK/MercadoPago'.
  • Example config:
    {
      "MERCADOPAGO": {}
    }

Early Background Initialization

📘

Crucial for Performance

Certain anti-fraud providers, especially Mercado Pago, require up to 3.5 seconds to perform hardware profiling and generate device fingerprint tokens.

To avoid delays during checkout, call DeunaSDK.initializeFraudProviders(...) as early as possible—such as when the user enters the shopping cart screen, when mounting the main store view, or on initial app load.

Because initializeFraudProviders is a static method, it can be executed in the background before instantiating or launching any checkout widget:

import { useEffect } from 'react';
import { DeunaSDK } from '@deuna/react-native-sdk';

const CartScreen = () => {
  useEffect(() => {
    // Pre-warm fraud SDKs as soon as the cart or store view mounts
    DeunaSDK.initializeFraudProviders({
      MERCADOPAGO: {},
    });
  }, []);

  return (
    // Your cart UI components
  );
};

Implementation in TypeScript

Option 1: Direct Call via Instance Method (deunaSDK.generateFraudId)

generateFraudId is an instance method on your initialized DeunaSDK instance. It automatically uses your configured publicApiKey and environment:

import { DeunaSDK } from '@deuna/react-native-sdk';

const deunaSDK = new DeunaSDK({
  publicApiKey: 'YOUR_PUBLIC_API_KEY',
  environment: 'production',
});

// Example: Calling generateFraudId on the SDK instance
async function getFraudToken() {
  const fraudId = await deunaSDK.generateFraudId({
    RISKIFIED: {
      storeDomain: 'yourdomain.com',
    },
    MERCADOPAGO: {},
  });

  // Returns a Base64-encoded JSON string or null
  console.log('Base64 Fraud ID:', fraudId);

  if (fraudId) {
    const decoded = atob(fraudId);
    console.log('Decoded Tokens:', JSON.parse(decoded));
  }
}

Option 2: Pass fraudCredentials Directly to Widgets

When using DEUNA payment widgets (initPaymentWidget, initElements, initNextAction, initVoucherWidget), pass your provider configuration directly via fraudCredentials. The SDK will call generateFraudId internally at purchase time:

await deunaSDK.initPaymentWidget({
  orderToken: 'YOUR_ORDER_TOKEN',
  mode: Mode.MODAL,
  callbacks: {
    onSuccess: (data) => console.log('Payment success:', data),
    onError: (error) => console.error('Payment error:', error),
    onClosed: () => console.log('Widget closed'),
  },
  fraudCredentials: {
    RISKIFIED: {
      storeDomain: 'yourdomain.com',
    },
    MERCADOPAGO: {},
  },
});

Behavior Notes

  • Zero-bloat & Crash-safe: If a provider is included in the JSON request but its native dependency was not added to the app, the native reflection safely ignores it without crashing.
  • Parallel Execution: All requested providers profile concurrently on background threads.
  • Fallback Behavior: If no valid providers are configured or available on the device, generateFraudId resolves to null.