publiq · Authentication Profile
Publiq Authentication
Authentication
publiq secures its APIs with apiKey, oauth2, and openIdConnect across 4 declared security schemes, as derived from its OpenAPI definitions.
CompanyCultureEventsLeisureBelgiumNon-ProfitOpen DataLoyalty Programs
Methods: apiKey, oauth2, openIdConnect
Schemes: 4
OAuth flows:
API key in: header
Security Schemes
CLIENT_ACCESS_TOKEN oauth2
· flows:
CLIENT_IDENTIFICATION apiKey
· in: header (x-client-id)
CUSTOM_TOKEN apiKey
· in: header (x-custom-token)
USER_ACCESS_TOKEN oauth2
· flows:
Source
Authentication Profile
generated: '2026-10-09'
method: searched
summary:
types:
- apiKey
- oauth2
- openIdConnect
api_key_in:
- header
schemes:
- name: CLIENT_ACCESS_TOKEN
type: oauth2
flows:
- clientCredentials
description: A client access token, obtained by exchanging your client id and client secret for a token via an HTTP request to publiq's authorization server using the **Client Credentials OAuth Flow**.
See the [authentication docs about client access tokens](https://docs.publiq.be/docs/authentication/methods/client-access-token) for more info.
sources:
- openapi/publiq-museumpassmusees-partner-openapi.yml
- openapi/publiq-uitdatabank-entry-openapi.yml
- openapi/publiq-uitdatabank-search-openapi.yml
- openapi/publiq-uitpas-openapi.yml
token_url: https://account.uitid.be/realms/uitid/protocol/openid-connect/token
token_url_test: https://account-test.uitid.be/realms/uitid/protocol/openid-connect/token
example_expires_in: 86400
- name: CLIENT_IDENTIFICATION
type: apiKey
in: header
parameter: x-client-id
sources:
- openapi/publiq-uitdatabank-search-openapi.yml
- openapi/publiq-uitpas-openapi.yml
alt_query_param: clientId
note: 'Docs: "Offers no real security, so only used in APIs that expose public information" (e.g. Search API).'
- name: CUSTOM_TOKEN
type: apiKey
in: header
parameter: x-custom-token
sources:
- openapi/publiq-uitpas-openapi.yml
note: 'UiTPAS kiosk endpoints: device id of the kiosk is passed in the x-custom-token header.'
- name: USER_ACCESS_TOKEN
type: oauth2
flows:
- authorizationCode
pkce: true
description: User access token obtained by logging the user in through publiq UiTiD (Authorization Code flow with code_verifier/code_challenge); renewable with a refresh token (scope offline_access).
sources:
- openapi/publiq-uitdatabank-entry-openapi.yml
- openapi/publiq-uitdatabank-search-openapi.yml
- openapi/publiq-uitpas-openapi.yml
derived_from: openapi/publiq-museumpassmusees-partner-openapi.yml, openapi/publiq-uitdatabank-entry-openapi.yml, openapi/publiq-uitdatabank-search-openapi.yml, openapi/publiq-uitpas-openapi.yml
source: https://docs.publiq.be/docs/authentication
authorization_servers:
test: https://account-test.uitid.be
production: https://account.uitid.be
implementation: Keycloak realm uitid (OpenID Connect); legacy /oauth/token path forwards to /realms/uitid/protocol/openid-connect/token
support_matrix:
- api: UiTdatabank Search API v3
client_identification: true
client_access_token: true
user_access_token: true
- api: UiTdatabank Entry API v3
client_identification: false
client_access_token: true
user_access_token: true
- api: UiTPAS API v4
client_identification: false
client_access_token: true
user_access_token: true
- api: museumPASSmusées Partner API v1
client_identification: false
client_access_token: true
user_access_token: false
- api: UiTdatabank Taxonomy API v3
none: true
docs: https://docs.publiq.be/docs/authentication/methods/overview
docs_pages:
- https://docs.publiq.be/docs/authentication/methods/overview
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/methods.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/client-access-token.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/user-access-token.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/client-identification.md
- https://github.com/cultuurnet/apidocs/blob/main/projects/authentication/docs/environments.md
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/publiq-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.