generated: '2026-09-17' method: searched source: >- https://docs.banuba.com/far-sdk/tutorials/capabilities/token_management, https://docs.banuba.com/far-sdk/tutorials/development/basic_integration, https://www.banuba.com/banuba-pricing-face-ar-sdk (FAQ "Where can I find my client token?"), https://tintvto.com/ (widget parameters), https://github.com/Banuba/BanubaGenAIVideos-iOS (AI Talking Photo SDK README) — read 2026-09-17. docs: https://docs.banuba.com/far-sdk/tutorials/capabilities/token_management surface: sdk note: >- Banuba publishes no OpenAPI, so nothing here is a securityScheme in the OpenAPI sense. What the docs document is SDK licence activation: every SDK (Face AR, WebAR, Video Editor, Photo Editor, AR Cloud) is initialised with a per-customer client token issued by Banuba sales / the account manager. The AI Talking Photo API — the one hosted API Banuba markets — uses "a Banuba trial token" but its API docs are only available on request through Support, so its HTTP auth mechanism is not publicly documented and is NOT described here. schemes: - id: client_token type: licence-token applies_to: [Face AR SDK, WebAR SDK, Video Editor SDK, Photo Editor SDK, AR Cloud SDK, AI Talking Photo SDK] how: >- A generated .txt token unique to each client, passed to the SDK at initialisation (e.g. the token string in BanubaClientToken.swift / the `clientToken` argument of the WebAR Player). It activates the licensed feature set; it is validated on-device and is not a bearer credential for an HTTP API. obtain: >- Demo token: request via the website form (https://www.banuba.com/facear-sdk/face-filters#form) or a sales manager — valid 14 days. Commercial token: issued by the account manager after payment, valid for the prepaid period. expiry: 14 days (demo) / prepaid licence period (commercial); one-month watermark grace, then the SDK stops (see lifecycle/) storage_guidance: store server-side so renewals do not require a store release; never ship demo tokens in live apps - id: tint_publishable_key type: publishable-key applies_to: [TINT virtual try-on widget ()] how: >- The embeddable widget is configured with a merchantId or a publishableKey (query/attribute) plus an optional token and short code `q`; it calls the Tint public API (api.tintvto.com/api/v1/public) on the merchant's behalf. The key format and the API's server-side auth are undocumented; merchants get them from the app.tintvto.com admin. - id: tint_admin_session type: session (Clerk) applies_to: [app.tintvto.com admin] how: Merchant sign-in via accounts.tintvto.com (Clerk-hosted); not a developer credential. oauth: false api_keys: false mutual_tls: false gated: - surface: AI Talking Photo API note: HTTP auth undocumented publicly; "request access for AI Talking Photo specific docs via Support" (BanubaGenAIVideos-iOS README).