publiq · Authentication Profile

Publiq Authentication

Authentication

publiq secures its APIs with apiKey, oauth2, and openIdConnect across 4 declared security schemes, as derived from its OpenAPI definitions.

CompanyCultureEventsLeisureBelgiumNon-ProfitOpen DataLoyalty Programs
Methods: apiKey, oauth2, openIdConnect Schemes: 4 OAuth flows: API key in: header

Security Schemes

CLIENT_ACCESS_TOKEN oauth2
· flows:
CLIENT_IDENTIFICATION apiKey
· in: header (x-client-id)
CUSTOM_TOKEN apiKey
· in: header (x-custom-token)
USER_ACCESS_TOKEN oauth2
· flows:

Source

Authentication Profile

Raw ↑
generated: '2026-10-09'
method: searched
summary:
  types:
  - apiKey
  - oauth2
  - openIdConnect
  api_key_in:
  - header
schemes:
- name: CLIENT_ACCESS_TOKEN
  type: oauth2
  flows:
  - clientCredentials
  description: A client access token, obtained by exchanging your client id and client secret for a token via an HTTP request to publiq's authorization server using the **Client Credentials OAuth Flow**.
    See the [authentication docs about client access tokens](https://docs.publiq.be/docs/authentication/methods/client-access-token) for more info.
  sources:
  - openapi/publiq-museumpassmusees-partner-openapi.yml
  - openapi/publiq-uitdatabank-entry-openapi.yml
  - openapi/publiq-uitdatabank-search-openapi.yml
  - openapi/publiq-uitpas-openapi.yml
  token_url: https://account.uitid.be/realms/uitid/protocol/openid-connect/token
  token_url_test: https://account-test.uitid.be/realms/uitid/protocol/openid-connect/token
  example_expires_in: 86400
- name: CLIENT_IDENTIFICATION
  type: apiKey
  in: header
  parameter: x-client-id
  sources:
  - openapi/publiq-uitdatabank-search-openapi.yml
  - openapi/publiq-uitpas-openapi.yml
  alt_query_param: clientId
  note: 'Docs: "Offers no real security, so only used in APIs that expose public information" (e.g. Search API).'
- name: CUSTOM_TOKEN
  type: apiKey
  in: header
  parameter: x-custom-token
  sources:
  - openapi/publiq-uitpas-openapi.yml
  note: 'UiTPAS kiosk endpoints: device id of the kiosk is passed in the x-custom-token header.'
- name: USER_ACCESS_TOKEN
  type: oauth2
  flows:
  - authorizationCode
  pkce: true
  description: User access token obtained by logging the user in through publiq UiTiD (Authorization Code flow with code_verifier/code_challenge); renewable with a refresh token (scope offline_access).
  sources:
  - openapi/publiq-uitdatabank-entry-openapi.yml
  - openapi/publiq-uitdatabank-search-openapi.yml
  - openapi/publiq-uitpas-openapi.yml
derived_from: openapi/publiq-museumpassmusees-partner-openapi.yml, openapi/publiq-uitdatabank-entry-openapi.yml, openapi/publiq-uitdatabank-search-openapi.yml, openapi/publiq-uitpas-openapi.yml
source: https://docs.publiq.be/docs/authentication
authorization_servers:
  test: https://account-test.uitid.be
  production: https://account.uitid.be
  implementation: Keycloak realm uitid (OpenID Connect); legacy /oauth/token path forwards to /realms/uitid/protocol/openid-connect/token
support_matrix:
- api: UiTdatabank Search API v3
  client_identification: true
  client_access_token: true
  user_access_token: true
- api: UiTdatabank Entry API v3
  client_identification: false
  client_access_token: true
  user_access_token: true
- api: UiTPAS API v4
  client_identification: false
  client_access_token: true
  user_access_token: true
- api: museumPASSmusées Partner API v1
  client_identification: false
  client_access_token: true
  user_access_token: false
- api: UiTdatabank Taxonomy API v3
  none: true
docs: https://docs.publiq.be/docs/authentication/methods/overview
docs_pages:
- https://docs.publiq.be/docs/authentication/methods/overview
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/methods.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/client-access-token.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/user-access-token.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/client-identification.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/environments.md

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/publiq-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.