---
title: SDK Integration
slug: experience/sdk-integration
description: This article explains the details required, if you want us to integrate a SDK or other 3rd-party system for Purple Apps.
docTags: 
createdAt: 2024-04-29T14:05:37.510Z
---

At Purple, we are happy to integrate SDKs and third-party systems that we don't support out of the box. It adds variability and opportunity for our customers.

:::hint{type="info"}
**Not every third-party system is ready to integrate with the Purple platform.**

The requirements below describe what an SDK has to provide so that we can integrate it cleanly.
:::

## Context: how Purple builds apps

Purple is a **white-label app framework** (native Android and iOS). We pass a specific configuration into the framework and get a finished app as output, fully automated. For third-party integrations, we provide **abstraction layers**, for example, for analytics frameworks and consent management platforms.

Because the build runs automatically and unattended, any SDK we integrate must fit into this pipeline **without manual steps**.

## Requirements

An SDK integration must meet the following specifications.

### 1. Distributed via a standard package manager

We expect the SDK to be published as an artifact in a common package manager. **We do not include library code or drop-in frameworks by hand.**

**Android: Maven** A published `.aar` artifact in a Maven repository, so we can add it as a Gradle dependency, for example:

:::BlockQuote
implementation 'com.sourcepoint.cmplibrary\:cmplibrary:7.1.0'
:::

The Maven repository may be password-protected if needed.

**iOS: Swift Package Manager (SPM)** A published **Swift Package**, which we add to our Package.swift (SourcePoint as an example):

:::BlockQuote
*// Package dependency — we pin exact versions (exact:, not from:):*
.package(url: "https\://github.com/SourcePointUSA/ios-cmp-app", exact: "7.12.9"),

*// ... declared as a dependency of the relevant library target,*
*// since our app framework is itself a Swift package / library:*
.product(name: "ConsentViewController", package: "ios-cmp-app"),
:::

The package must resolve cleanly with current SwiftPM / Xcode.

If you don't want to publish your source code publicly, you can ship a **precompiled .xcframework as a binary Swift Package.&#x20;**&#x4C;ike ConsentManager (iubenda) does, which we consume via SPM (see https\://github.com/iubenda/cm-sdk-xcframework). This is also the recommended route for non-public SDKs, as it needs no repository nor SSH access.

:::BlockQuote
On iOS we support **Swift Package Manager exclusively.** Other integration methods are not supported.
:::

### 2. No SSH keys

Our builds run on various developer machines and CI/CD runners, and these change over time (e.g., when we add a new machine). We therefore **cannot use SSH keys** to access your artifacts. Please make them reachable without SSH. For example, via a password-/token-protected Maven repository (Android) or a binary .xcframework Swift Package (iOS).

### 3. A development environment

:::hint{type="warning"}
To ensure smooth development, we also need a development environment. It should be configured like a generic production environment and let us verify that our code and configuration work correctly.
:::

