RadiumOne is the SDK’s factory class. You get an instance either synchronously from the CDN global, or asynchronously via the npm loader.
RadiumOne.init() is synchronous — don’t await it. loadRadiumOne() (npm only) is the async one, since it also injects the CDN script.
RadiumOne.init(publishableKey, options?)
Create a RadiumOne instance from a publishable key (CDN usage). npm users call loadRadiumOne instead.
Accepted keys depend on the bundle’s channel: - Production bundle (js.radiumone.io): r1pk_prod_* only. - Sandbox bundle (js-sandbox.radiumone.io): r1pk_test_* and r1pk_mock_* (the mock suffix must be 1–32 characters of a-z, 0-9, _ or -).
r1pk_test_* keys use the sandbox API; r1pk_mock_* keys never call the API (see BindResult.mock).
string
required
Your publishable key. Never pass a secret key.
RadiumOneInitOptions
Locale and other init options.
RadiumOne — A new RadiumOne instance.
Throws:
api:invalid_key(api_error) — key missing or not a string.api:secret_key_used(api_error) — a secret key (r1sk_*) was passed.api:test_key_in_prod_build(api_error) —r1pk_test_*key on the production bundle.api:prod_key_in_staging_build(api_error) —r1pk_prod_*key on the sandbox bundle.api:invalid_key_format(api_error) — any other malformed key.
Instance
string
required
The loaded SDK version, for example
'1.6.0'. Useful in support logs.elements(options?)
Create a group of card Elements.
ElementsOptions
Appearance and locale for the group.
Elements — A new Elements group.
threeDS()
Create a 3D Secure coordinator for this key.
Use one instance per concurrent 3DS flow. Unlike card Elements, 3DS runs on your page, so your CSP must allow the gateway API origin in connect-src and challenge origins in frame-src / form-action; see docs/reference/csp.json.
Returns ThreeDS — A new ThreeDS instance.
loadRadiumOne(publishableKey, options?)
Load the SDK bundle from the RadiumOne CDN and initialize it with a publishable key. The npm entry point.
- Injects a version-pinned
<script>with Subresource Integrity:js.radiumone.ioforr1pk_prod_*keys,js-sandbox.radiumone.ioforr1pk_test_*/r1pk_mock_*keys. Your CSP must allow that origin inscript-srcandframe-src(seedocs/reference/csp.json). - Reuses an SDK already loaded via<script>instead of injecting another. - One instance per page: later calls return the first promise; a different key logs a warning and is ignored. - Returnsnullwhenwindowis undefined (server-side rendering). - Rejects if the script does not load within 10 seconds; a failed load can be retried.
RadiumOne.init() runs are plain Errors (no code): missing key, secret key, unrecognised prefix, CDN load failure or timeout, and a package built for the other channel (message contains loader:integrity_unset).
string
required
Your publishable key (
r1pk_prod_*, r1pk_test_* or r1pk_mock_*).RadiumOneInitOptions
Locale and other init options.
Promise<RadiumOne | null> — The RadiumOne instance, or null during server-side rendering.
Throws:
Error— invalid or secret key, CDN load failure, timeout, or channel mismatch (see remarks).api:*— key rejected byRadiumOne.init.
Constants
"r1pk_mock_demo"
Public mock-mode key for demos and documentation. Works only with the sandbox bundle; tokenization is simulated and
BindResult.mock is true.string
Version of the installed npm package. Equals
RadiumOne.version of the CDN bundle it loads."urn:radiumone:auth:invalid-script-hash"
ElementsError.code when the gateway rejects the card iframe’s script attestation (urn:radiumone:auth:invalid-script-hash). Not retryable; there is no customerMessage, so show your own copy.Co-defined (kept in sync) in iframe-host bind-client.ts.Example
Errors
See Elements SDK errors for the fullElementsError reference.