Performance and compatibility
SDK size, how it loads, extra requests, impact on the checkout and supported browsers.
The SDK is built not to slow down your checkout: the synchronous part is small and makes no network requests, and the rest loads asynchronously. This page shows the real numbers and what the SDK does on each page load.
Size
| Part | Uncompressed size | Gzipped size | How it loads |
|---|---|---|---|
| Bootstrapper | 4.3 KB | ~1.9 KB | Inline in the HTML, synchronous. |
shield.js SDK | 60 KB | ~19.6 KB | File from the CDN, with async. The CDN serves it with Brotli (~17 KB). |
The bootstrapper adds about 4.3 KB to each page's HTML before your server's compression. shield.js is cached in the
browser and on the CDN (1 hour on the stable channel, 5 minutes on latest).
Loading
- Bootstrapper: runs in under 1 ms and makes no requests. It only sets up the observation points.
shield.js: loaded withasync, it doesn't block the parser or page rendering.- Initialization: the SDK waits at most 2 seconds for the remote configuration before starting detections. The checkout doesn't wait for the SDK.
The SDK is built to never break the page: all of its code runs guarded against errors, and telemetry sends don't block anything.
Requests per page load
| Request | When | Note |
|---|---|---|
GET cdn.proteside.com/v1/shield.js | once | Usually served from cache. |
GET app.proteside.com/api/sdk/config | once | May be served from cache for 60 seconds. |
GET of the page itself | once, and on every pageChanged() | Reads the security headers. See the warning in CSP and headers. |
GET of the page's external scripts | up to 20, with a total limit of 1.5 s | To compute the content hash. Uses the browser cache whenever possible. |
POST app.proteside.com/api/sdk/events | roughly every 5 s, while there are events | Batches of up to 50 events; one final send when the customer leaves the page. |
Ongoing processing
While the page is open, the SDK:
- checks for overlays on the payment fields every 2 seconds (adjustable in Overlay check (ms), minimum 500 ms);
- checks the displayed payment codes at the same interval;
- looks for payment codes in the page text every 2 seconds during the first minute;
- watches for page changes to detect new scripts and payment codes.
On pages with many elements, a longer overlay interval reduces periodic work. Keep the default unless you have a reason to change it.
Supported browsers
| Browser | Minimum version |
|---|---|
| Chrome | 80 |
| Edge | 80 |
| Firefox | 78 |
| Safari | 14 |
Use HTTPS on your checkout
Hash computation depends on a browser API that only exists on HTTPS pages. Over HTTP, the SDK keeps working, but with no script content hashes, no trusted recipient verification and no security header reads.