Banuba · Authentication Profile
Banuba Authentication
Authentication
Banuba declares 3 security scheme(s) across its OpenAPI definitions.
ARAugmented RealityBeautyFace RecognitionFacialSDKVideo
Methods:
Schemes: 3
OAuth flows:
API key in:
Security Schemes
licence-token
publishable-key
session (Clerk)
Source
Authentication Profile
generated: '2026-09-17'
method: searched
source: >-
https://docs.banuba.com/far-sdk/tutorials/capabilities/token_management, https://docs.banuba.com/far-sdk/tutorials/development/basic_integration,
https://www.banuba.com/banuba-pricing-face-ar-sdk (FAQ "Where can I find my client token?"), https://tintvto.com/ (widget parameters),
https://github.com/Banuba/BanubaGenAIVideos-iOS (AI Talking Photo SDK README) — read 2026-09-17.
docs: https://docs.banuba.com/far-sdk/tutorials/capabilities/token_management
surface: sdk
note: >-
Banuba publishes no OpenAPI, so nothing here is a securityScheme in the OpenAPI sense. What the docs document is
SDK licence activation: every SDK (Face AR, WebAR, Video Editor, Photo Editor, AR Cloud) is initialised with a
per-customer client token issued by Banuba sales / the account manager. The AI Talking Photo API — the one hosted
API Banuba markets — uses "a Banuba trial token" but its API docs are only available on request through Support,
so its HTTP auth mechanism is not publicly documented and is NOT described here.
schemes:
- id: client_token
type: licence-token
applies_to: [Face AR SDK, WebAR SDK, Video Editor SDK, Photo Editor SDK, AR Cloud SDK, AI Talking Photo SDK]
how: >-
A generated .txt token unique to each client, passed to the SDK at initialisation (e.g. the token string in
BanubaClientToken.swift / the `clientToken` argument of the WebAR Player). It activates the licensed feature
set; it is validated on-device and is not a bearer credential for an HTTP API.
obtain: >-
Demo token: request via the website form (https://www.banuba.com/facear-sdk/face-filters#form) or a sales
manager — valid 14 days. Commercial token: issued by the account manager after payment, valid for the prepaid period.
expiry: 14 days (demo) / prepaid licence period (commercial); one-month watermark grace, then the SDK stops (see lifecycle/)
storage_guidance: store server-side so renewals do not require a store release; never ship demo tokens in live apps
- id: tint_publishable_key
type: publishable-key
applies_to: [TINT virtual try-on widget (<tint-vto>)]
how: >-
The embeddable widget is configured with a merchantId or a publishableKey (query/attribute) plus an optional
token and short code `q`; it calls the Tint public API (api.tintvto.com/api/v1/public) on the merchant's behalf.
The key format and the API's server-side auth are undocumented; merchants get them from the app.tintvto.com admin.
- id: tint_admin_session
type: session (Clerk)
applies_to: [app.tintvto.com admin]
how: Merchant sign-in via accounts.tintvto.com (Clerk-hosted); not a developer credential.
oauth: false
api_keys: false
mutual_tls: false
gated:
- surface: AI Talking Photo API
note: HTTP auth undocumented publicly; "request access for AI Talking Photo specific docs via Support" (BanubaGenAIVideos-iOS README).
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/banuba-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.