Banuba · Authentication Profile

Banuba Authentication

Authentication

Banuba declares 3 security scheme(s) across its OpenAPI definitions.

ARAugmented RealityBeautyFace RecognitionFacialSDKVideo
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

licence-token
publishable-key
session (Clerk)

Source

Authentication Profile

banuba-authentication.yml Raw ↑
generated: '2026-09-17'
method: searched
source: >-
  https://docs.banuba.com/far-sdk/tutorials/capabilities/token_management, https://docs.banuba.com/far-sdk/tutorials/development/basic_integration,
  https://www.banuba.com/banuba-pricing-face-ar-sdk (FAQ "Where can I find my client token?"), https://tintvto.com/ (widget parameters),
  https://github.com/Banuba/BanubaGenAIVideos-iOS (AI Talking Photo SDK README) — read 2026-09-17.
docs: https://docs.banuba.com/far-sdk/tutorials/capabilities/token_management
surface: sdk
note: >-
  Banuba publishes no OpenAPI, so nothing here is a securityScheme in the OpenAPI sense. What the docs document is
  SDK licence activation: every SDK (Face AR, WebAR, Video Editor, Photo Editor, AR Cloud) is initialised with a
  per-customer client token issued by Banuba sales / the account manager. The AI Talking Photo API — the one hosted
  API Banuba markets — uses "a Banuba trial token" but its API docs are only available on request through Support,
  so its HTTP auth mechanism is not publicly documented and is NOT described here.
schemes:
  - id: client_token
    type: licence-token
    applies_to: [Face AR SDK, WebAR SDK, Video Editor SDK, Photo Editor SDK, AR Cloud SDK, AI Talking Photo SDK]
    how: >-
      A generated .txt token unique to each client, passed to the SDK at initialisation (e.g. the token string in
      BanubaClientToken.swift / the `clientToken` argument of the WebAR Player). It activates the licensed feature
      set; it is validated on-device and is not a bearer credential for an HTTP API.
    obtain: >-
      Demo token: request via the website form (https://www.banuba.com/facear-sdk/face-filters#form) or a sales
      manager — valid 14 days. Commercial token: issued by the account manager after payment, valid for the prepaid period.
    expiry: 14 days (demo) / prepaid licence period (commercial); one-month watermark grace, then the SDK stops (see lifecycle/)
    storage_guidance: store server-side so renewals do not require a store release; never ship demo tokens in live apps
  - id: tint_publishable_key
    type: publishable-key
    applies_to: [TINT virtual try-on widget (<tint-vto>)]
    how: >-
      The embeddable widget is configured with a merchantId or a publishableKey (query/attribute) plus an optional
      token and short code `q`; it calls the Tint public API (api.tintvto.com/api/v1/public) on the merchant's behalf.
      The key format and the API's server-side auth are undocumented; merchants get them from the app.tintvto.com admin.
  - id: tint_admin_session
    type: session (Clerk)
    applies_to: [app.tintvto.com admin]
    how: Merchant sign-in via accounts.tintvto.com (Clerk-hosted); not a developer credential.
oauth: false
api_keys: false
mutual_tls: false
gated:
  - surface: AI Talking Photo API
    note: HTTP auth undocumented publicly; "request access for AI Talking Photo specific docs via Support" (BanubaGenAIVideos-iOS README).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/banuba-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.