# SDKs

SecurySign integrations use server libraries for authenticated API requests and capture SDKs for document photos and live face capture. Server libraries run on the backend, where application credentials are stored. Capture SDKs run in the browser or mobile app and send requests through that backend.

| Component | Where you use it | How you obtain it |
|---|---|---|
| Server library | Your Node.js, PHP, Python or Java backend, for signing tokens, OpenID Connect (OIDC) login and webhook verification. | Download the source file for your language. |
| Web capture SDK | Your HTTPS page, for document photos and the live face capture. | Install `@securysign/identity-capture@0.2.0`. |
| Mobile capture SDK | Your iOS, Android, Flutter, React Native or .NET MAUI app. | Request the native package for your application, or embed the web component. |
| Signing iframe | Your web page, for document review and passkey approval. | Embed the SecurySign frame URL. |

## Choose your SDK

For signing on a web page, request a token on the backend and open the [signing iframe](#/docs/iframe). The token request can use a server library or a direct HTTP call. The [Hash signing API](#/docs/api-hash-signing) and [PAdES signing API](#/docs/api-pades-signing) cover signing requests created on the backend and completed through the frame.

For identity verification, the web SDK captures document photos and runs a liveness session obtained through the backend. Mobile integrations can use native capture, a WebView or a browser tab. A hosted capture page is also available: open its link in the app and poll the result from the backend.

See the [SDK reference](#/docs/sdk-reference) for installation, backend routes, capture examples, component events, Content Security Policy settings and mobile permissions.
