IDmeta Flutter Plugin

Flutter plugin for integrating IDmeta identity verification into your Flutter application.

⚠️ This plugin is currently in beta and intended for initial testing and integration.


Requirements

  • Flutter >=3.41.0 (required for iOS — Swift Package Manager / Regula DocType)
  • Dart >=3.11.0 <4.0.0 (bundled with Flutter 3.41+)

Android

Use your app’s normal Flutter Android setup: compileSdk = flutter.compileSdkVersion, minSdk / targetSdk from flutter.*, and an Android Gradle Plugin (AGP) version that matches Flutter’s Android build requirements and the AGP ↔ Gradle compatibility table.

This plugin is built against Android compileSdk 37. If your Flutter toolchain still reports flutter.compileSdkVersion below 37, set compileSdk to at least 37 until you upgrade Flutter—for example compileSdk = Math.max(flutter.compileSdkVersion as int, 37) in Groovy, or compileSdk = maxOf(flutter.compileSdkVersion, 37) in Kotlin DSL. The host app must use minSdk ≥ 24 (for example minSdk = Math.max(flutter.minSdkVersion as int, 24) when Flutter’s default is lower).

iOS

  • Flutter >=3.41.0 required — iOS builds use Swift Package Manager for several plugin dependencies (including Regula DocType). Flutter 3.38 and earlier do not provide the FlutterFramework SPM package those plugins expect.
  • Minimum deployment target: iOS 16.0
  • Add camera, photo library, and location usage descriptions to your app’s Info.plist (see example/ios/Runner/Info.plist for reference)

Installation

Choose the install path that matches your trust flows.

Install the core plugin from pub.flutter-io.cn:

flutter pub add idmeta_flutter

Or add manually to pubspec.yaml:

dependencies:
  idmeta_flutter: ^0.2.0

Then run:

flutter pub get

Path A — core only (no IAD)

Use this when your trust flows do not include IAD biometric steps.

dependencies:
  idmeta_flutter: ^0.2.0

Path B — with IAD

IAD (Injection Attack Detection) requires the additional native package below. Contact IDmeta for access if your trust flows include IAD.

dependencies:
  idmeta_flutter: ^0.2.0
  idmeta_iad:
    git:
      url: https://github.com/IDMeta/idmeta_iad.git
      ref: main

Then register once at app startup before starting verification:

import 'package:idmeta_iad/idmeta_iad.dart';

void main() {
  IdmetaIad.register();
  runApp(const MyApp());
}

The bundled example/ app ships as Path A (core only). Without idmeta_iad + IdmetaIad.register(), IAD steps fail with a clear “not registered” error (other flow steps still work).

CI access for Path B

Anonymous flutter pub get cannot clone a private git dependency. In GitHub Actions (or similar), configure HTTPS git auth with a secret that can read IDMeta/idmeta_iad (fine-scoped PAT with contents: read, or a machine-user token):

env:
  GIT_CONFIG_COUNT: 1
  GIT_CONFIG_KEY_0: url.https://x-access-token:${{ secrets.IDMETA_IAD_READ_TOKEN }}@github.com/.insteadOf
  GIT_CONFIG_VALUE_0: https://github.com/

Add repository secret IDMETA_IAD_READ_TOKEN, then run flutter pub get as usual.


Import

import 'package:idmeta_flutter/idmeta_flutter.dart';
// Path B only:
// import 'package:idmeta_iad/idmeta_iad.dart';

Quick Start

Call IdmetaFlutter.startVerification to launch the identity verification flow. The runnable app under example/ provides a form where you can enter the user token, trust flow ID, and client ID before starting verification.

For IAD (Path B), register the private package at startup — see Path B — with IAD above.

import 'package:flutter/material.dart';
import 'package:idmeta_flutter/idmeta_flutter.dart';

void main() {
  runApp(const MyApp());
}

class MyHomePage extends StatelessWidget {
  const MyHomePage({super.key});

  @override
  Widget build(BuildContext context) {
    return Scaffold(
      appBar: AppBar(
        title: const Text('IDmeta Plugin Example'),
      ),
      body: Center(
        child: ElevatedButton(
          onPressed: () {
            IdmetaFlutter.startVerification(
              context: context,
              userToken: '<USER_API_TOKEN>',
              trustFlowId: 123,
              clientId: '<CLIENT_ID>',
              metadata: {
                'referenceId': '1001',
              },
            );
          },
          child: const Text('Start Verification'),
        ),
      ),
    );
  }
}

Parameters

Parameter Type Description
context BuildContext Build context used to navigate into the verification flow.
userToken String The user API token retrieved from the user profile.
trustFlowId int ID of the verification trust flow to launch.
clientId String The client ID retrieved from the user profile page.
metadata Map<String, dynamic>? Optional key-value JSON sent back to your webhook.

Example Metadata

metadata: {
  'referenceId': '1001',
  'userId': 'USER-123',
  'environment': 'staging',
}

Platform Configuration

Configure your IDmeta account and backend to obtain the values used above:

  1. Create a Trust Flow and retrieve Trust Flow ID — Creating a Trust Flow
  2. Communication between IDmeta and your backend server via webhook — Adding Webhooks to Trust Flow
  3. Getting API Tokens — App Tokens
  4. Webhook responses follow the same structure as the IDmeta API — API Reference

Notes

  • The plugin requires an active internet connection during verification.
  • Metadata values are returned in webhook callbacks for tracking and reconciliation purposes.
  • IAD requires Path B (idmeta_iad + IdmetaIad.register()). Core-only installs keep other verification steps working.

Support

For integration support or issues, please contact the IDmeta team.


License

This plugin package is licensed under the MIT License.

IDmeta verification services require a valid IDmeta account, userToken, trustFlowId, and applicable customer agreement. Available verification features depend on your subscription and trust-flow configuration. Reseller, OEM, or multi-application deployment may require a separate written agreement with IDmeta.

Bundled third-party native SDKs are governed by their respective vendor licenses and your IDmeta license entitlements.

Libraries

fingerprint
Fingerprint capture contract and device registry for trust-flow integration.
idmeta_flutter
IDmeta identity verification SDK for Flutter.