INTEGRATION ASSISTANT
Your stack. One clear path.
Choose a client, connect your backend and inspect the service configuration. Your server owns the customer binding, keys and final decision.
Alethic branding stays with capture. Your permanent business key stays on your backend.
Build your integration
These are integration templates for the local SDK packages. Connect your existing authentication and persistent database. Packages and production hosting are separate release steps.
import { Alethic } from '@alethic/sdk';
import { createMerchantHandler } from '@alethic/sdk/merchant';
const alethic = new Alethic({
baseUrl: process.env.ALETHIC_API_URL,
apiKey: process.env.ALETHIC_SERVER_KEY,
});
// Connect your existing authenticated-user resolver and durable binding store.
// authorize must return { customerId, subjectReference } from your session.
// store.get(ownerId, requestId) reads your database.
// store.putIfAbsent(ownerId, requestId, binding) atomically returns the winner.
export const handle = createMerchantHandler({
client: alethic,
origin: process.env.YOUR_WEBSITE_ORIGIN,
authorize: yourAuthenticatedCustomer,
store: yourPersistentBindings,
captureMode: 'image',
});
// Mount handle at /api/verification/session and /api/verification/result.
// Forward the original Request. Never trust a client-supplied customer ID.Need an RC record without a photo?
Use the RC lookup REST flow or the Node SDK on your backend: createVehicleRcSession, then explicitly confirm the server quote before submitVehicleRcLookup. Read the original receipt and getVehicleRcResult for the private registry details. This path does not capture an image, train a model or verify a face or identity.
The RC lookup price and activation flag are separate from document photo checks. An unavailable price cannot start a paid lookup.
Read the RC lookup contract →Check your connection
Checks read the configured service. They do not start a paid verification, add funds or send images.
Find the next safe action
Register the exact website origin
Ask the Alethic operator to approve your HTTPS website origin. Keep the API key on your backend. Do not use a wildcard or disable browser security.
