---
title: Installation
description: Configure the CSP, install the Web SDK package, and download the resource files required for liveness capture.
canonical: https://developer.unico.io/dual-api/developers/sdks-and-tools/web/web-sdk/installation/
locale: en
generated_by: markdown-export
---

## Add the dependency and configure the package manager

****Step 1** — Configure Content Security Policy (CSP)**

The Web SDK uses Web Workers for security and performance. Add the following configuration to your CSP:

  ```html
  <meta
    http-equiv="Content-Security-Policy"
    content="
        script-src 'self' 'unsafe-eval' *.googleapis.com *.acesso.io *.unico.run *.unico.io *.unico.app *.sentry.io *.launchdarkly.com *.newrelic.com bam.nr-data.net;
        worker-src 'self' blob:;
        child-src 'self' blob:;
        style-src 'self' 'unsafe-inline' *.googleapis.com *.acesso.io *.unico.run *.unico.io *.unico.app;
        font-src 'self' https://fonts.gstatic.com *.acesso.io *.unico.run *.unico.io *.unico.app;
        img-src 'self' data: blob: *.acesso.io *.unico.run *.unico.io *.unico.app;
        media-src 'self' data: *.acesso.io *.unico.run *.unico.io *.unico.app;
        script-src-elem 'self' 'unsafe-inline' blob: *.googleapis.com *.acesso.io *.unico.run *.unico.io *.unico.app;
        connect-src *.googleapis.com *.acesso.io *.unico.run *.unico.io *.unico.app *.sentry.io *.launchdarkly.com *.newrelic.com bam.nr-data.net"
  />
  ```

  :::warning
  If your application has a CSP, this configuration is mandatory to ensure correct functioning of the SDK.
  :::

  :::info[Why each directive is required]
  - **`'unsafe-eval'`** (script-src) — required by the liveness detection engine to compile WebAssembly and dynamically evaluate its security routines at runtime.
  - **`'unsafe-inline'`** (style-src, script-src-elem) — required by the SDK's inline styles and inline script bootstrapping. Removing it breaks the capture UI.
  - **`*.acesso.io`** — legacy Unico infrastructure domain, still load-bearing for assets and API calls.
  - **`*.unico.run` / `*.unico.io` / `*.unico.app`** — current Unico service domains (CDN, API, and app subdomains).
  - **`*.googleapis.com`** (script-src, style-src, script-src-elem, connect-src) — required to load the Google Fonts stylesheet (`@font-face` CSS via `fonts.googleapis.com`) and other Google API resources used by the capture UI.
  - **`fonts.gstatic.com`** (font-src) — serves the Google Fonts binary font files referenced by the stylesheet loaded from `fonts.googleapis.com`.
  - **`*.sentry.io`** — Unico uses Sentry for SDK error tracking. Required in `script-src` and `connect-src` to allow the error reporting calls.
  - **`*.launchdarkly.com`** — Unico uses LaunchDarkly for feature-flag evaluation controlling SDK behavior (e.g., camera engine selection). Required in `script-src` and `connect-src` to allow flag streaming and evaluation calls.
  - **`*.newrelic.com` / `bam.nr-data.net`** — Unico uses New Relic Browser for SDK performance monitoring. Required in `script-src` (agent script) and `connect-src` (beacon calls).
  - **`blob:`** (worker-src, child-src, script-src-elem) — required because Web Workers and certain SDK sub-resources are created as Blob URLs at runtime.
  :::

****Step 2** — Install the package**

The Web SDK is provided through an npm package or CDN.

  ### npm

    ```bash
    npm install unico-webframe
    ```

### yarn

    ```bash
    yarn add unico-webframe
    ```

### CDN

Download the SDK and import it into your project:

    - [Download version `3.23.7`](https://cdn.unico.io/sdk/check/bio/unico-webframe-3.23.7.zip)

****Step 3** — Import the SDK**

After installing, import the SDK into your project.

  ### From npm

    ```javascript
    import {
      UnicoCheckBuilder,
      SelfieCameraTypes,
      UnicoThemeBuilder,
      DocumentCameraTypes,
      UnicoConfig,
      LocaleTypes
    } from 'unico-webframe'
    ```

### From CDN

    ```javascript
    import {
      UnicoCheckBuilder,
      SelfieCameraTypes,
      UnicoThemeBuilder,
      DocumentCameraTypes,
      UnicoConfig,
      LocaleTypes
    } from 'UnicoCheckBuilder.min.js'
    ```

****Step 4** — Download additional resource files**

Additional resource files are required to perform Liveness capture. Download the file matching your SDK version and include it in your project:

  :::warning[Upgrade checklist]
  The resource files are version-locked to the SDK. Every time you bump `unico-webframe`, you **must** re-download the matching resources from the table below — using mismatched versions causes a runtime error during liveness capture.

  **Alternatively**, since SDK 3.18.0 the SDK can auto-fetch these files at initialization time, eliminating the manual download step. See [Initialization](/dual-api/developers/sdks-and-tools/web/web-sdk/initialization) for the `setResourceDirectory` option.
  :::

  | SDK version | FaceTec resources |
  |---|---|
  | 3.23.7 | [9.7.114](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.114/resources.zip) |
  | 3.23.3 → 3.23.6 | [9.7.107](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.107/resources.zip) |
  | 3.23.0 → 3.23.1 | [9.7.102](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.102/resources.zip) |
  | 3.22.6 → 3.22.7 | [9.7.100](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.100/resources.zip) |
  | 3.22.5 | [9.7.99](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.99/resources.zip) |
  | 3.22.3 → 3.22.4 | [9.7.98](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.98/resources.zip) |
  | 3.22.2 | [9.7.96](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.96/resources.zip) |
  | 3.22.1 | [9.7.93](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.93/resources.zip) |
  | 3.22.0 | [9.7.90](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.90/resources.zip) |
  | 3.21.3 → 3.21.4 | [9.7.85](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.85/resources.zip) |
  | 3.21.2 | [9.7.82](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.82/resources.zip) |
  | 3.21.1 | [9.7.80](https://cdn.unico.io/sdk/check/facetec/v2-browser-v9.7.80/resources.zip) |
  | 3.20.10 → 3.21.0 | [9.7.76](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.76/resources.zip) |
  | 3.20.9 | [9.7.75](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.75/resources.zip) |
  | 3.20.8 | [9.7.73](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.73/resources.zip) |
  | 3.20.7 | [9.7.68](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.68/resources.zip) |
  | 3.20.5 → 3.20.6 | [9.7.65](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.65/resources.zip) |
  | 3.20.3 → 3.20.4 | [9.7.64](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.64/resources.zip) |
  | 3.20.2 | [9.7.63](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.63/resources.zip) |
  | 3.20.1 | [9.7.61](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.61/resources.zip) |
  | 3.20.0 | [9.7.55](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.55/resources.zip) |
  | 3.19.0 → 3.19.3 | [9.7.45 → 9.7.51](https://cdn.unico.io/sdk/check/facetec/browser-v9.7.51/resources.zip) |
  | 3.18.x | 9.6.92 → 9.7.41 (see legacy table) |

  Also download the **AI files** for the SDK: [models.zip](https://cdn.unico.io/sdk/check/bio/models.zip).

  :::warning[Public path]
  All additional files must be hosted in a public location, visible to the Web within your project.
  :::