theme accepts light or dark. When omitted, the SDK follows the device preference. Desktop clients render a modal. Narrow screens render a bottom sheet.
Security checks
The SDK accepts a message only when both conditions match:event.originequals the hosted session origin.event.sourceis the checkout iframe window.
parentOrigin. Register every production embedding origin in the service-client policy and Payments frame-ancestor configuration.
Status events
The SDK forwardsboxpressd:payments:status messages to onStatus. It closes automatically for these terminal interface statuses:
paid_pending_fulfillmentfulfilledcancelledfailed
Top-level redirect
You can redirect the browser to the same hosted URL when an iframe is not appropriate:returnUrl or cancelUrl stored in the session.