Skip to main content
The hosted capture page and the API are served from one origin, so calls to /v1 from the page need no CORS configuration. TLS is required to test the verification flow. The hosted capture page calls getUserMedia, which browsers refuse outside a secure context, so a deployment serving plain HTTP cannot exercise the camera step at all. A local deployment that issues certificates from its own CA still shows a browser warning until that root is trusted, which is not the same as running without TLS. Both self-hosted and cloud deployments need TLS for browser camera access, durable storage, secret management, and backups.