Skip to main content
RadiumOne is the SDK’s factory class. You get an instance either synchronously from the CDN global, or asynchronously via the npm loader.
RadiumOne.init() is synchronous — don’t await it. loadRadiumOne() (npm only) is the async one, since it also injects the CDN script.

RadiumOne.init(publishableKey, options?)

Create a RadiumOne instance from a publishable key (CDN usage). npm users call loadRadiumOne instead. Accepted keys depend on the bundle’s channel: - Production bundle (js.radiumone.io): r1pk_prod_* only. - Sandbox bundle (js-sandbox.radiumone.io): r1pk_test_* and r1pk_mock_* (the mock suffix must be 1–32 characters of a-z, 0-9, _ or -). r1pk_test_* keys use the sandbox API; r1pk_mock_* keys never call the API (see BindResult.mock).
string
required
Your publishable key. Never pass a secret key.
RadiumOneInitOptions
Locale and other init options.
Returns RadiumOne — A new RadiumOne instance. Throws:

Instance

string
required
The loaded SDK version, for example '1.6.0'. Useful in support logs.

elements(options?)

Create a group of card Elements.
ElementsOptions
Appearance and locale for the group.
Returns Elements — A new Elements group.

threeDS()

Create a 3D Secure coordinator for this key. Use one instance per concurrent 3DS flow. Unlike card Elements, 3DS runs on your page, so your CSP must allow the gateway API origin in connect-src and challenge origins in frame-src / form-action; see docs/reference/csp.json. Returns ThreeDS — A new ThreeDS instance.

loadRadiumOne(publishableKey, options?)

Load the SDK bundle from the RadiumOne CDN and initialize it with a publishable key. The npm entry point.
  • Injects a version-pinned <script> with Subresource Integrity: js.radiumone.io for r1pk_prod_* keys, js-sandbox.radiumone.io for r1pk_test_* / r1pk_mock_* keys. Your CSP must allow that origin in script-src and frame-src (see docs/reference/csp.json). - Reuses an SDK already loaded via <script> instead of injecting another. - One instance per page: later calls return the first promise; a different key logs a warning and is ignored. - Returns null when window is undefined (server-side rendering). - Rejects if the script does not load within 10 seconds; a failed load can be retried.
Errors thrown before RadiumOne.init() runs are plain Errors (no code): missing key, secret key, unrecognised prefix, CDN load failure or timeout, and a package built for the other channel (message contains loader:integrity_unset).
string
required
Your publishable key (r1pk_prod_*, r1pk_test_* or r1pk_mock_*).
RadiumOneInitOptions
Locale and other init options.
Returns Promise<RadiumOne | null> — The RadiumOne instance, or null during server-side rendering. Throws:
  • Error — invalid or secret key, CDN load failure, timeout, or channel mismatch (see remarks).
  • api:* — key rejected by RadiumOne.init.

Constants

"r1pk_mock_demo"
Public mock-mode key for demos and documentation. Works only with the sandbox bundle; tokenization is simulated and BindResult.mock is true.
string
Version of the installed npm package. Equals RadiumOne.version of the CDN bundle it loads.
"urn:radiumone:auth:invalid-script-hash"
ElementsError.code when the gateway rejects the card iframe’s script attestation (urn:radiumone:auth:invalid-script-hash). Not retryable; there is no customerMessage, so show your own copy.Co-defined (kept in sync) in iframe-host bind-client.ts.

Example

Errors

See Elements SDK errors for the full ElementsError reference.
Last modified on September 15, 2026