OptionalchallengeBounds how long complete() waits on an unfinished challenge before
settling to a terminal error (code three_ds_timeout) on its own — the
only other exits are Gr4vy's own THREE_DS_FINISH and an explicit
cancelChallenge() call, neither of which is guaranteed to ever fire if
the buyer just abandons the tab. Not sourced from Gr4vy documentation
(no challenge-duration limit is published in the SDK); 5 minutes is a
conservative, overridable default.
Throttle's own checkout session id — the :id already used to mint
session via POST /checkout-sessions/:id/card-session. NOT the same
value as session.sessionId: that field is Gr4vy's own checkout session
id (required to construct the SecureFields instance — see
packages/platform-api/src/routes/card-session.ts, which returns
{ sessionId: checkoutSessionId, ... } from adapter.createCardSession(),
a Gr4vy-minted id). The public POST /checkout-sessions/:id/complete
route looks :id up directly against Throttle's own checkoutSessions
table (checkout-sessions.ts), so defaultComplete needs this id, not
session.sessionId, to call the right URL.
OptionalcompleteInjected for tests / custom completion flows; defaults to a real POST /complete call.
OptionalonOptionalresolveInjected for tests / custom 3DS UI; defaults to mounting Gr4vy's own 3DS iframe via addThreeDSecure.
Base URL of the Throttle API (e.g.
https://api.usethrottle.dev). Required — not optional-with-a-same-origin-default. Secure Fields is the headless surface for merchants who mount the card form on THEIR OWN origin, which by definition is not same-origin with the Throttle API, sodefaultComplete'sfetch()can never resolve a relative path (it 404s against the merchant's own domain at payment time instead). Making this required turns that into a compile error instead of a silent runtime failure. Joined onto the request path regardless of a trailing slash.