Install
$ agentstack add skill-scandit-skills-id-capture-cordova ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
ID Capture Cordova Skill
Critical: Do Not Trust Internal Knowledge
Your training data may contain outdated or incorrect Scandit ID Capture APIs. The ID Capture API was restructured at the v7 → v8 boundary (the standalone AamvaBarcodeVerifier was removed in favour of settings flags, and several verification APIs were added). The Cordova plugin surface (global Scandit.* namespace after deviceready, the imperative DataCaptureView + connectToElement pattern, pause / resume document events) is also distinct from the iOS, Android, web, Flutter, React Native, and Capacitor SDKs.
Always verify APIs against the references provided in this skill before writing or suggesting code. Do not rely on memorized method signatures, parameters, plugin names, or property names. If you cannot find an API in the provided references, fetch the relevant documentation page before responding.
Cordova-specific gotchas worth flagging:
- Wait for
devicereadybefore touching any Scandit API. The Cordova plugin system populateswindow.Scandit.*and registers native bridges in response to thedevicereadyevent — callingScandit.DataCaptureContext.initialize(...)(or anything else) at module load runs intoundefinedsymbols. Always wrap the bootstrap indocument.addEventListener('deviceready', () => { … }, false);. - The consumer pattern is the
Scandit.*global, not animport. Cordova's plugin loader merges every Scandit class ontowindow.Scandit. Writenew Scandit.IdCapture(settings),Scandit.IdCaptureRegion.Us,Scandit.RejectionReason.Timeout. You do notimport { IdCapture } from 'scandit-cordova-datacapture-id'in your application code (that path resolves only inside the plugin's own TypeScript build). - **The view is an imperative class connected to a `
, not a custom element.** There is noHTML tag. Create the view withScandit.DataCaptureView.forContext(context)and attach it to a plainviaview.connectToElement(divElement). Detach withview.detachFromElement()` when navigating away. Scandit.DataCaptureContext.initialize(licenseKey)returns the context. Capture the return value:const context = Scandit.DataCaptureContext.initialize('');. There is nosharedInstancepattern in the Cordova sample.- Camera is constructed with
Scandit.Camera.withSettings(...), returningCamera | null. UseScandit.Camera.withSettings(Scandit.IdCapture.createRecommendedCameraSettings())and guard the result for null before dereferencing it. - Enums use PascalCase member names with camelCase wire values (same TypeScript convention as RN / Capacitor). Write
Scandit.IdCaptureRegion.Us,Scandit.IdImageType.CroppedDocument,Scandit.IdSide.Front,Scandit.RejectionReason.Timeout,Scandit.IdAnonymizationMode.FieldsAndImages,Scandit.IdFieldType.DocumentNumber,Scandit.IdLayoutStyle.Rounded,Scandit.FrameSourceState.On/.Off,Scandit.AamvaBarcodeVerificationStatus.Authentic. Never use the lowercase Dart/Flutter form. CapturedIdMRZ/VIZ getters aremrzResult/vizResult(notmrz/viz— that's Flutter). Other source-specific getters:barcode,mobileDocument,mobileDocumentOcr.- Images come back as base64 strings.
images.face,images.frame,images.getCroppedDocument(Scandit.IdSide.Front),images.getFrame(Scandit.IdSide.Front)each return astring | null. Render with ``. They are not URIs, files, or HTMLImageElements. - Listener is a plain object literal.
Scandit.IdCaptureListeneris a TypeScript interface with two optional methods — writeconst listener = { didCaptureId(_, captured) { … }, didRejectId(_, rejected, reason) { … } }. Do not create a class withimplements IdCaptureListener— that's the Dart/Flutter style. - There is no
VisaLetterdocument class on Cordova. OnlyVisaIcaoships. (On Flutter both exist; on Cordova / RN / Capacitor only the ICAO visa is modelled.) - Lifecycle uses Cordova's
pause/resumedocument events. Subscribe withdocument.addEventListener('pause' / 'resume', …)to stop / restart the camera and toggleidCapture.isEnabled. There is no ReactAppState(that's RN) and no@capacitor/appplugin (that's Capacitor). - Camera permission is declared by the plugin and resolved by the native side. The Cordova ID plugin doesn't ship a JS-side permission request — install
cordova-plugin-android-permissions(or call the camera-permission API of whatever permissions plugin the project already uses) and requestCAMERAbefore mounting the scan view if you want to control the prompt timing; otherwise the OS will prompt on first camera use.
Forbidden APIs (commonly hallucinated — do NOT emit these)
These either don't exist or were removed. Use the right-hand form:
| Do NOT write | Use instead | |---|---| | import { IdCapture } from 'scandit-cordova-datacapture-id' in application code | new Scandit.IdCapture(settings) after deviceready (Cordova merges symbols onto window.Scandit) | | Scandit.IdCapture.forContext(context, settings) | new Scandit.IdCapture(settings) then context.setMode(idCapture) | | Scandit.IdCaptureOverlay.withIdCapture(...) / .withIdCaptureForView(...) | new Scandit.IdCaptureOverlay(idCapture) then view.addOverlay(overlay) | | IdDocumentType enum / settings.supportedDocuments | settings.acceptedDocuments (document classes) + settings.scanner = new Scandit.IdCaptureScanner(new Scandit.FullDocumentScanner()) | | capturedId.documentType | capturedId.document?.documentType (IdCaptureDocumentType) or capturedId.isPassport() / isDriverLicense() / … | | capturedId.isVisa() / capturedId.isVisaLetter() | capturedId.isVisaIcao() (Cordova ships only the ICAO visa) | | capturedId.mrz / capturedId.viz (Flutter names) | capturedId.mrzResult / capturedId.vizResult | | Scandit.IdCaptureRegion.us / Scandit.IdSide.front / Scandit.AamvaBarcodeVerificationStatus.authentic (lowercase Dart form) | Scandit.IdCaptureRegion.Us / Scandit.IdSide.Front / Scandit.AamvaBarcodeVerificationStatus.Authentic — every Scandit enum member on Cordova is PascalCase, including RejectionReason.*, IdImageType.*, IdAnonymizationMode.*, IdFieldType.*, FrameSourceState.*, IdLayoutStyle.*, and the verification status / reasons | | capturedId.images.croppedDocument | capturedId.images.getCroppedDocument(Scandit.IdSide.Front) (also .face, .frame, getFrame(Scandit.IdSide.Front)) | | Treating images.face like a URI / file / HTMLImageElement | It's a base64 string — ` or imgEl.src = '...' | | Scandit.AamvaBarcodeVerifier (class) | settings.rejectForgedAamvaBarcodes = true + capturedId.verificationResult.aamvaBarcodeVerification | | DrivingLicenseCategory.categoryCode | DrivingLicenseCategory.code (plus dateOfIssue / dateOfExpiry) | | custom element or any framework-component wrapper | Scandit.DataCaptureView.forContext(context) + view.connectToElement(document.getElementById('...')) | | Camera.default (RN / Flutter idiom) | Scandit.Camera.withSettings(Scandit.IdCapture.createRecommendedCameraSettings()) — and guard the Camera \| null return | | Touching Scandit.* before deviceready fires | wrap your bootstrap in document.addEventListener('deviceready', () => { … }, false);` |
Product Guidance
Apply these rules whenever the user is making a design decision, not just an API question.
- Accept only the documents you actually need. A narrow
acceptedDocumentslist (e.g. justnew Scandit.DriverLicense(Scandit.IdCaptureRegion.Us)) is faster and more accurate thanIdCaptureRegion.Anyacross all document types. Ask the user which documents and regions they expect before defaulting to "everything". - Pick the scanner that matches the data you need.
new Scandit.FullDocumentScanner()reads front and back automatically (best for most ID/DL use cases).new Scandit.SingleSideScanner(barcode, machineReadableZone, visualInspectionZone)reads a single side from the zone(s) you enable. UseScandit.MobileDocumentScannerfor mobile driver's licenses / mDL. - Handle
didRejectId, not justdidCaptureId. Rejections (Scandit.RejectionReason.Timeout,NotAcceptedDocumentType,DocumentExpired,DocumentVoided,ForgedAamvaBarcode, …) are how the user learns why a scan didn't succeed. A production integration must surface a message for them. - Anonymize by default if you don't need every field.
IdCaptureSettings.anonymizationModeand per-fieldaddAnonymizedFieldkeep regulated data (e.g. document images, sensitive fields) out of the result unless you opt in. - Hand off to the
data-capture-sdkskill for non-ID-Capture questions. If the user asks about another Scandit product (Barcode Capture, SparkScan, MatrixScan, Label Capture, etc.) or about choosing between products, defer to thedata-capture-sdkskill instead of guessing.
Intent Routing
Based on the user's request, load the appropriate reference file before responding:
- Integrating ID Capture from scratch ("add ID scanning to my Cordova app", "scan a passport / driver's license", "read the MRZ", "extract the holder's name and date of birth") → read
references/integration.mdand follow it. - One of the three add-on capabilities ("reject voided / cancelled IDs", "detect punched-hole / voided licenses", "decode the back of a European driving license", "read vehicle categories", "verify the AAMVA barcode / detect forged US licenses") → read
references/supplementary-modules.md. - Migrating or upgrading an existing ID Capture integration ("upgrade ID Capture to the latest SDK", "migrate v7 to v8", "
AamvaBarcodeVerifieris gone", "what changed in ID Capture between versions") → readreferences/migration.md.
API Usage Policy
Only use APIs that are explicitly documented in the Scandit references below. Do not invent or guess method signatures, parameters, property names, or globals. If unsure whether an API exists or how it is called — or if a TypeScript compiler / runtime error occurs — fetch the relevant reference page before responding. Do not tell the user to check the docs themselves. After answering, always include the relevant link so the user can explore further.
Never construct or guess documentation URLs. When you need a specific class or property's API page:
- First check whether the page you already fetched contains a direct hyperlink to it — topic pages link directly to relevant API symbols. Always request links alongside content in your fetch prompt.
- If no direct link was found, fetch the API index (see Full API reference in the table below), extract the actual link from it, and follow that.
URL structures vary across SDK versions and package paths and guessing will lead to 404s.
Framework variant policy
Examples in this skill are in plain JavaScript / TypeScript (no UI-framework bindings) because the official IdCaptureSimpleSample is plain www/js/*.js running after deviceready. If the project uses a UI framework on top of Cordova (jQuery Mobile, Onsen UI, an older Ionic v1 / Ionic v3 setup, Framework7), keep the same bootstrap and Scandit calls and wire view.connectToElement(...) into a host `` in the framework's view template. Do not introduce a new framework just for ID Capture.
References
Direct users to the right resource based on their question:
| Topic | Resource | |---|---| | Cordova integration | Get Started · Sample (IdCaptureSimpleSample) | | Advanced topics (anonymization, verification, scanners, overlay) | Advanced Configurations | | Migration between major SDK versions | 7 → 8 | | Full API reference | ID Capture API |
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Scandit
- Source: Scandit/skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.