Skip to main content
The Maven JS SDK is a thin wrapper that mounts the secure iframe into your page and forwards lifecycle events to callbacks. It does not ship business logic — all the heavy lifting (tokenization, gateway charging) happens server-side.

Installation

After load, the global Maven object is available.
The SDK is served with Cache-Control: public, max-age=31536000, immutable — the versioned URL (/v1/widget.js) never changes, so browsers cache it for a year. Bump the major version only for breaking changes.

Maven.createPayment(options)

Creates a widget controller. Does not mount until you call .mount(target).

Options

Theme, labels, and fields are set per-project in the dashboard — not on the SDK call. See Customization.

Returns

A controller object:

controller.mount(target)

Inserts the iframe into the DOM.
The iframe fills 100% of the target’s width and auto-grows its height via maven:resize postMessage — your container controls the width, Maven handles the height.

onSuccess(result)

Fires when the gateway charge succeeds.

onFailure(error)

Fires when the charge is declined or errors.
The widget itself shows the failure state (red “Payment Failed” box + “Try Again” button). Your onFailure callback is for doing things in your UI — sending a follow-up chat message, tracking the failure in analytics, etc.

Cleanup

When the chat bubble unmounts (user navigates away, chat closes, etc.), destroy the widget to remove listeners:

Full example

Security model

  • The iframe is served from Maven’s domain, not yours — your page’s JavaScript cannot read the card inputs or inspect the form (enforced by the browser’s same-origin policy).
  • Communication between your page and the iframe is one-way via postMessage — the iframe posts events up, the SDK listens. No DOM access.
  • The sessionId is a single-use credential. It expires after a short TTL (default 5 minutes) and can only be used to charge the specific amount on the specific project it was created for.

Next

Customization

Theme, labels, fields, sizing.

Webhooks

Server-side confirmation events.