# iOS SDK

## Overview

## Installation

## Start the SDK

## Send Location Updates

## iOS Webview

## Shopify Checkout Kit

## Licensing

## Changelog

# Android SDK

## Android SDK Overview

## Installation

## Start the SDK

## Integration Guide

## forterMobileUID

### [Why does Forter need a Unique Identifier?](https://docs.forter.com/mobile-sdks/fortermobileuid#why-does-forter-need-a-unique-identifier)

Forter's SDK requires a unique mobile device identifier to connect the activity and behavioral data collected by the SDK to the specific device and user. This identifier should be specific to Android device.

### [In the Order API](https://docs.forter.com/mobile-sdks/fortermobileuid#in-the-order-api)

If/when a customer makes a purchase from the mobile app, the unique Identifier **must** be included as the forterMobileUID value in the connectionInformation object of the [Forter Orders API](https://docs.forter.com/reference/order-v3 "Forter Orders API"). Since the Orders API call is made entirely from your system's backend, this ID should be retrievable from the HTTPS request headers and in the **same casing** as the value generated in the Forter SDK.

In the case of native mobile app orders, make sure that the following fields are populated:

1. **orderType**: "MOBILE", "iOS", or "ANDROID" depending on your OS (mobile can be used for either OS)

2. **forterMobileUID**: should be populated instead of the forterTokenCookie if your app is fully native, including your checkout page

3. **mobileAppVersion**: should reflect the version of the app the user is on

```json
{
  "orderId": "Example_order_fdse0gb449",
  "orderType": "ANDROID",
  "timeSentToForter": 1415287568000,
  "checkoutTime": 1415273168,
  "connectionInformation": {
    "customerIP": "174.255.8.151",
    "userAgent": "testStore 4.92.203 rv:203 (Android; Linux: 24 7.0; en_US; LGL158VL)",
    "forterMobileUID": "2f37b5d22ca986caaaaa4d3b7e02fc152c93186bd4_c2Vzc2lvbnRva2VuaGVyZQ==_CF4_ES4",
    "mobileAppVersion": "4.70.103"
  },
  "totalAmount": {
    "amountUSD": "99.95"
  }
}
```

### [Getting the right identifier](https://docs.forter.com/mobile-sdks/fortermobileuid#getting-the-right-identifier)

**For SDK version 3.0.0 and above:**

- The value returned by ForterSDK.getInstance().getForterToken() should be used as the forterMobileUID in the [connectionInformation](https://portal.forter.com/api/data-objects/ConnectionInformation "connectionInformation") object of the server-side Order API.

Do not store or reuse a previously retrieved token. The token is refreshed throughout the SDK lifecycle, so you must always call ForterSDK.getInstance().getForterToken()**at checkout** and send the **latest value** to the server-side Order API.

**For SDK versions prior to 3.0.0:**

- The value returned by ForterIntegrationUtils.getDeviceUID() should be used as the forterMobileUID in the [connectionInformation](https://portal.forter.com/api/data-objects/ConnectionInformation "connectionInformation") object of the server-side Order API.

### [Casing](https://docs.forter.com/mobile-sdks/fortermobileuid#casing)

Ensure that the forterMobileUID is passed to the Order API in **exactly the same casing** as returned by the SDK. Forter does not enforce uppercase or lowercase, but any mismatch will prevent correct linkage between SDK device data and backend Order API data.

### [Passing Account Identifiers](https://docs.forter.com/mobile-sdks/fortermobileuid#passing-account-identifiers)

### [At Login](https://docs.forter.com/mobile-sdks/fortermobileuid#at-login)

Please provide the user's existing account ID **upon login** to the Android app using:

```java
ForterSDK.getInstance().setAccountUID(ForterAccountIDType.MERCHANT_ACCOUNT_ID, accountUid);
```

### [Upon Logout](https://docs.forter.com/mobile-sdks/fortermobileuid#upon-logout)

Please call the same setAccountUID method with an empty string for the account ID.

Account Identifiers should be passed to the accountOwner.accountId field in the Order API and _not_ the forterMobileUID field.

**Do not provide**[**personally identifiable information (PII)**](https://en.wikipedia.org/wiki/Personally_identifiable_information "personally identifiable information (PII)")**as an identifier**. If you use the user's email address as an ID, encode/hash it before sending.
