generated: '2026-09-05' method: searched source: >- Registry searches of npm, PyPI, RubyGems, crates.io, NuGet, Maven Central and pkg.go.dev; the gravity-legal GitHub organization; and https://docs.confidolegal.com/ provider: Confido Legal providerId: confido-legal description: >- Confido Legal ships two first-party browser SDKs, both distributed as unpinned single files from its own S3/CloudFront CDN rather than through any package registry. There is no server-side SDK in any language — partners write GraphQL against api.gravity-legal.com directly. registry_searches: - registry: npm queries: [confido, confidolegal, confido-legal, gravity-legal] result: no first-party package - registry: PyPI result: no first-party package - registry: RubyGems result: no first-party package - registry: crates.io result: no first-party package - registry: NuGet result: no first-party package - registry: Maven Central result: no first-party package - registry: pkg.go.dev result: no first-party package packages: - name: hosted-fields.js official: true language: JavaScript platform: browser registry: cdn url: https://js.gravity-legal.com/hosted-fields.js sandbox_url: https://js.sandbox.gravity-legal.com/hosted-fields.js install: '' global: window.confidoHostedFields version: null published: null version_note: >- CHECKED, NOTHING TO RECORD. The distribution is unpinned: there is no version in the URL, no versioned alias, no registry metadata endpoint, and no version constant in the bundle (the only version string inside is React 18.0.1, a bundled dependency). The file floats to whatever is current. The only currency signal available to a consumer is the HTTP Last-Modified header — 2026-08-29 on production, 2026-08-28 on sandbox — served with cache-control max-age=0 from AmazonS3 behind CloudFront. A consumer cannot pin a version, cannot pin an integrity hash against a stable artifact, and cannot tell what they are getting; neither can we. size_bytes: 387894 last_modified: '2026-08-29' docs: https://docs.confidolegal.com/hosted-fields-js/overview purpose: >- Injects Confido-hosted iframes into divs on the partner's page to collect card and ACH data, keeping the partner out of PCI scope. Singleton per window. Posts confido_hosted_fields_script_loaded via window.postMessage when ready. - name: onboarding.js official: true language: JavaScript platform: browser registry: cdn url: https://js.gravity-legal.com/onboarding.js sandbox_url: https://js.sandbox.gravity-legal.com/onboarding.js install: '' global: window.confidoOnboarding version: null published: null version_note: >- CHECKED, NOTHING TO RECORD. Same unpinned CDN distribution as hosted-fields.js — no version in the URL, no registry, no version constant. Last-Modified 2026-08-29. size_bytes: 1156002 last_modified: '2026-08-29' docs: https://docs.confidolegal.com/onboarding-js/overview purpose: >- Renders the Confido firm-onboarding application form into a div in the partner's own app via renderForm, so the firm never leaves the partner UI. sample_code: - name: legal-wave official: true kind: example application language: TypeScript repository: https://github.com/gravity-legal/legal-wave description: An example application that showcases the Gravity Legal payments platform. last_pushed: '2024-05-14' archived: false registry: null version: null published: '2024-05-14' note: >- Not a client library — a demo app. It is the ONLY public repository in the gravity-legal GitHub organization, and it has not been touched since May 2024, well before the voids-and-refunds async migration and the FirmStatus.DECLINED addition. Any integrator copying from it is copying pre-migration patterns. docs: https://docs.confidolegal.com/examples/legal-wave postman: workspace: https://www.postman.com/confido/lexicon-gravity-legal-demo publisher_handle: confido publisher_name: Confido Legal publisher_type: team public: true collections: 1 created: '2023-06-21' last_updated: '2023-06-21' method: searched source: Postman public search index (collaboration.workspace), queried 2026-09-05 note: >- A real first-party public Postman workspace exists, but it is a 2023 demo ("Lexicon/Gravity Legal Demo") with a single collection and has not been touched in three years — it predates the voids-and-refunds async migration entirely. A separate "Confido Legal" workspace carrying 10 collections is published by the handle postman-atlas (Postman's own curated index), NOT by Confido, and is deliberately not credited to the provider. github: organization: https://github.com/gravity-legal public_repos: 1 note: >- The org is still under the pre-rebrand name. github.com/confidolegal does not exist (GitHub API returns 404). findings: - >- No server-side SDK exists in any language. Every partner integrating Confido writes raw GraphQL against api.gravity-legal.com, which makes the schema and this repo's graphql/confido-legal.graphql the entire integration surface. - >- Both browser SDKs are unpinned. That is a supply-chain and reproducibility gap a consumer cannot work around: no SRI hash is stable, no version can be locked, and a change ships to every partner's production page the moment the S3 object is replaced.