SDK Requirement
Requires @deuna/react-native-sdk version 2.1.10 or higher.
Android requires Android Gradle Plugin (AGP) 8.5.1+. iOS requires iOS 13.0+.
Use the initializeFraudProviders static function to warm up providers, and the generateFraudId instance method or the fraudCredentials widget parameter to generate a unified DEUNA fraud payload using supported anti-fraud providers.
The DEUNA React Native SDK uses a modular, reflection-based architecture (zero-bloat): it does not bundle any third-party fraud SDKs by default. Only add the specific provider(s) you plan to use. If you don't use a provider, you don't pay any app size penalty.
Supported Providers
| Provider | Description | Required Parameters |
|---|---|---|
| MERCADOPAGO | Mercado Pago device behavior profiling | (None required) |
| RISKIFIED | Riskified Beacon beaconing | storeDomain |
| CYBERSOURCE | CyberSource ThreatMetrix profiling | orgId, merchantId (Optional: fpServer) |
| SIGNIFYD | Signifyd ThreatMetrix profiling | orgId (Optional: fpServer) |
| ACCERTIFY | Accertify InMobile profiling | Config files in assets/bundle (Optional: locationConsent, phoneConsent) |
| KOUNT | Kount Data Collector | merchantId, clientId, dataCollectorUrl, environment |
| SIFT | Sift Science device profiling | accountId, beaconKey |
Dependency Linking (Select Only What You Need)
Follow the instructions for your project environment (Expo or React Native CLI).
A. Expo (Config Plugin)
In Expo projects using Continuous Native Generation (CNG) or EAS Build, enable only the providers you have contracted by listing them in the fraudProviders array in app.json:
{
"expo": {
"plugins": [
[
"@deuna/react-native-sdk",
{
"fraudProviders": [
// Add ONLY the providers you need, e.g.:
"mercadopago",
"riskified"
]
}
]
]
}
}Supported keys in fraudProviders: "mercadopago", "riskified", "cybersource", "signifyd", "accertify", "kount", "sift".
AAR Files & Asset placement in Expo
- Cybersource / Signifyd / Accertify: If using any of these providers in Android, place their required
.aarfiles inandroid/app/libs/<provider>/(download links provided below under React Native CLI).- Accertify Configuration Assets: Place
server_keys_message_hosted.jsonandinmobile.propertiesinandroid/app/src/main/assets/andserver_keys_message_hosted.jsonwithInMobile.plistin your iOS project / bundle.
After updating app.json, regenerate the native projects:
npx expo prebuild --cleanB. React Native CLI
In standard React Native CLI projects, add the native dependencies only for the providers you need in your host application files (android/app/build.gradle and ios/Podfile):
Android (android/app/build.gradle and root build.gradle / settings.gradle)
android/app/build.gradle and root build.gradle / settings.gradle)- If using Mercado Pago, ensure the Mercado Libre Maven repository is included in your
android/build.gradle(orsettings.gradle):
allprojects {
repositories {
google()
mavenCentral()
maven { url "https://artifacts.mercadolibre.com/repository/android-releases/" }
}
}-
Download and place vendor AAR files if using Cybersource, Signifyd, or Accertify:
- Cybersource: Download the Cybersource AAR files and place them in
android/app/libs/cybersource/. - Signifyd: Download the Signifyd AAR files and place them in
android/app/libs/signifyd/. - Accertify: Download the Accertify AAR files (
inmobileandinmobile-common) and place them inandroid/app/libs/accertify/.
- Cybersource: Download the Cybersource AAR files and place them in
-
Add only the dependencies for the providers you require inside
android/app/build.gradleunderdependencies { ... }:
dependencies {
// --- Add ONLY the providers you use ---
// Mercado Pago
implementation("com.mercadolibre.android.device:sdk:4.0.1")
// Riskified
implementation("com.riskified:android-sdk:1.11.0:nogoogle@aar")
// CyberSource (AARs placed in app/libs/cybersource)
implementation(fileTree(dir: "libs/cybersource", include: ["*.aar"]))
// Signifyd (AARs placed in app/libs/signifyd)
implementation(fileTree(dir: "libs/signifyd", include: ["*.aar"]))
// Accertify (AARs placed in app/libs/accertify + required transitive dependencies)
implementation(fileTree(dir: "libs/accertify", include: ["*.aar"]))
implementation("io.insert-koin:koin-core:3.5.6")
implementation("androidx.biometric:biometric:1.1.0")
implementation("org.jetbrains.kotlinx:kotlinx-serialization-json:1.6.3")
// Kount
implementation("com.kount:kount-data-collector:4.1.0")
// Sift
implementation("sift-android:sift-android:0.14.0")
}- Accertify Configuration Assets (Android & iOS):
- Android: Place
server_keys_message_hosted.jsonandinmobile.propertiesin yourandroid/app/src/main/assets/directory. - iOS: Add
server_keys_message_hosted.jsonandInMobile.plistto your Xcode project under your app's Copy Bundle Resources target.
- Android: Place
iOS (ios/Podfile)
ios/Podfile)Inside your target 'YourApp' do block, add only the subspecs for the providers you need:
target 'YourApp' do
# Add ONLY the subspecs you need:
pod 'DeunaSDK/MercadoPago'
pod 'DeunaSDK/Riskified'
pod 'DeunaSDK/Cybersource'
pod 'DeunaSDK/Signifyd'
pod 'DeunaSDK/Kount'
pod 'DeunaSDK/Sift'
pod 'DeunaSDK/Accertify'
endThen run:
pod installProvider Details & Constraints
RISKIFIED
- Required:
storeDomain - Example config:
{ "RISKIFIED": { "storeDomain": "yourdomain.com" } }
iOS Simulator NoteThe third-party
RiskifiedBeaconiOS library excludes native ARM64 simulators. When testing on Apple Silicon simulators, run with anx86_64(Rosetta) simulator destination or test on a physical iOS device.
CYBERSOURCE
- Required:
orgId,merchantId - Optional:
fpServer(default:h.online-metrix.net) - Example config:
{ "CYBERSOURCE": { "orgId": "your_org_id", "merchantId": "your_merchant_id" } }
SIGNIFYD
- Required:
orgId - Optional:
fpServer(default:imgs.signifyd.com) - Example config:
{ "SIGNIFYD": { "orgId": "your_org_id" } }
Android Incompatibility: Cybersource and Signifyd
CYBERSOURCEandSIGNIFYDuse conflicting variants of the LexisNexis ThreatMetrix SDK (TMXProfiling-rlvsTMXProfiling). You cannot link both in the same Android app simultaneously. Use only one.
ACCERTIFY
- Optional:
locationConsent(default:true),phoneConsent(default:true) - Required Files: The public encryption key file
server_keys_message_hosted.jsonand endpoint properties (inmobile.propertiesin Androidsrc/main/assets/andInMobile.plistin the iOS bundle resources) must be obtained from Accertify during merchant onboarding. - Transitive Dependencies (Android): The Accertify AAR requires Koin DI (
io.insert-koin:koin-core:3.5.6), AndroidX Biometric (androidx.biometric:biometric:1.1.0), and Kotlinx Serialization (org.jetbrains.kotlinx:kotlinx-serialization-json:1.6.3) to run without runtime exceptions. - Example config:
{ "ACCERTIFY": { "locationConsent": true, "phoneConsent": false } }
KOUNT
- Required:
merchantId,clientId,dataCollectorUrl,environment - Example config:
{ "KOUNT": { "merchantId": "your_merchant_id", "clientId": "your_client_id", "dataCollectorUrl": "https://...", "environment": "TEST" } }
SIFT
- Required:
accountId,beaconKey - Example config:
{ "SIFT": { "accountId": "your_account_id", "beaconKey": "your_beacon_key" } }
MERCADOPAGO
- Required: None (
{}) - Android: Requires the MercadoLibre Maven repository (
https://artifacts.mercadolibre.com/repository/android-releases/) and dependencycom.mercadolibre.android.device:sdk:4.0.1. - iOS: Linked via
pod 'DeunaSDK/MercadoPago'. - Example config:
{ "MERCADOPAGO": {} }
Early Background Initialization
Crucial for PerformanceCertain anti-fraud providers, especially Mercado Pago, require up to 3.5 seconds to perform hardware profiling and generate device fingerprint tokens.
To avoid delays during checkout, call
DeunaSDK.initializeFraudProviders(...)as early as possible—such as when the user enters the shopping cart screen, when mounting the main store view, or on initial app load.
Because initializeFraudProviders is a static method, it can be executed in the background before instantiating or launching any checkout widget:
import { useEffect } from 'react';
import { DeunaSDK } from '@deuna/react-native-sdk';
const CartScreen = () => {
useEffect(() => {
// Pre-warm fraud SDKs as soon as the cart or store view mounts
DeunaSDK.initializeFraudProviders({
MERCADOPAGO: {},
});
}, []);
return (
// Your cart UI components
);
};Implementation in TypeScript
Option 1: Direct Call via Instance Method (deunaSDK.generateFraudId)
deunaSDK.generateFraudId)generateFraudId is an instance method on your initialized DeunaSDK instance. It automatically uses your configured publicApiKey and environment:
import { DeunaSDK } from '@deuna/react-native-sdk';
const deunaSDK = new DeunaSDK({
publicApiKey: 'YOUR_PUBLIC_API_KEY',
environment: 'production',
});
// Example: Calling generateFraudId on the SDK instance
async function getFraudToken() {
const fraudId = await deunaSDK.generateFraudId({
RISKIFIED: {
storeDomain: 'yourdomain.com',
},
MERCADOPAGO: {},
});
// Returns a Base64-encoded JSON string or null
console.log('Base64 Fraud ID:', fraudId);
if (fraudId) {
const decoded = atob(fraudId);
console.log('Decoded Tokens:', JSON.parse(decoded));
}
}Option 2: Pass fraudCredentials Directly to Widgets
fraudCredentials Directly to WidgetsWhen using DEUNA payment widgets (initPaymentWidget, initElements, initNextAction, initVoucherWidget), pass your provider configuration directly via fraudCredentials. The SDK will call generateFraudId internally at purchase time:
await deunaSDK.initPaymentWidget({
orderToken: 'YOUR_ORDER_TOKEN',
mode: Mode.MODAL,
callbacks: {
onSuccess: (data) => console.log('Payment success:', data),
onError: (error) => console.error('Payment error:', error),
onClosed: () => console.log('Widget closed'),
},
fraudCredentials: {
RISKIFIED: {
storeDomain: 'yourdomain.com',
},
MERCADOPAGO: {},
},
});Behavior Notes
- Zero-bloat & Crash-safe: If a provider is included in the JSON request but its native dependency was not added to the app, the native reflection safely ignores it without crashing.
- Parallel Execution: All requested providers profile concurrently on background threads.
- Fallback Behavior: If no valid providers are configured or available on the device,
generateFraudIdresolves tonull.