Avalta docs
Avalta adds live beauty filters to your streaming app. This page covers how it fits into your app and how licensing works. The SDK package itself comes with your trial key.
Getting started
- Request a trial and tell us your app ID: the Android package name (for example
com.yourapp.live) or your website's domain. - We send a 14-day trial key and the SDK package for your platform.
- Add the SDK, give it the key and the camera, and publish its output with your streaming SDK.
- When you go live, pick a plan. Your key keeps working and the trial becomes a paid licence.
How it fits your app
Avalta sits between the camera and your streaming SDK. It takes the camera picture, applies beauty, makeup and a colour filter on the phone's GPU, and gives you a video track to publish instead.
camera → Avalta (on the phone) → your streaming SDK → viewersimport { Avalta } from "@avalta/beauty";
const beauty = await Avalta.start({
key: "AVL-XXXXX-XXXXX-XXXXX-XXXXX",
appId: "com.yourapp.live",
camera: cameraStream, // a MediaStream from getUserMedia
});
streamingSdk.publish(beauty.track); // a normal video track
beauty.openPanel(); // Studio and Network: the built-in panel
beauty.set({ smooth: 0.4, whiten: 0.5, look: "rose-tint" }); // or drive it yourselfLicence keys
A key looks like AVL-7KQ2M-X9PDA-4HRTC-WN3EZ. Each key is tied to your app IDs, so a key copied into someone else's app does not work. We store only a hash of it, so if you lose it we issue a new one rather than look it up.
Verify API
The SDK calls this for you. It is documented here so your developers know what leaves the app.
POST https://avalta.online/api/v1/licenses/verify
Content-Type: application/json
{
"key": "AVL-7KQ2M-X9PDA-4HRTC-WN3EZ",
"appId": "com.yourapp.live",
"device": "a random id created on install"
}A licence that can run returns 200:
{ "ok": true, "token": "eyJhbGciOiJFUzI1NiIs…", "expiresAt": 1767225600 }One that cannot returns 403 with a reason, listed under Errors. The endpoint allows 60 checks a minute from one address; the SDK makes about one a day per install.
The token
The token is a standard JWT signed with ES256. The SDK checks the signature on the phone against our public key, which is built into the SDK and published at /api/v1/keys. An edited token fails the check.
| Claim | Meaning |
|---|---|
app | The app ID this token is for |
plan | starter, studio, network or trial |
grants | The features switched on, listed below |
exp | When the token stops working: 7 days after it was issued, or when the licence ends, whichever is sooner |
lic_exp | When the licence itself ends |
Features by plan
| Grant | What it switches on | Starter | Studio | Network | Trial |
|---|---|---|---|---|---|
beauty | Skin sliders: smoothing, whitening, ruddy, glow, contour, clarity, dark circles, smile lines, teeth, bright eyes | Yes | Yes | Yes | Yes |
filters | The 13 colour filters | Yes | Yes | Yes | Yes |
looks:basic | 20 makeup looks | Yes | |||
looks:all | All 74 makeup looks, including looks for men | Yes | Yes | Yes | |
reshape | Face, eye, nose and mouth reshape sliders | Yes | Yes | Yes | |
panel | The ready-made beauty panel UI | Yes | Yes | Yes | |
custom-looks | Looks made for your app | Yes |
Offline and cancellation
- The SDK refreshes the token about once a day.
- With no network it keeps running on the saved token until the token expires, up to 7 days. A streamer on a weak connection is never cut off mid-stream by a licence check.
- When a licence is paused, cancelled or ends, the next check fails and the beauty features turn off. The camera and the rest of your app keep working.
Errors
| Code | What it means | What to do |
|---|---|---|
unknown_key | No licence has this key | Check the key was copied in full |
app_not_allowed | The key is not registered for this app ID | Ask us to add the app ID |
suspended | The licence is paused, usually for an unpaid invoice | Contact us |
expired | The licence or trial has ended | Renew or pick a plan |
revoked | The licence was cancelled | Contact us for a new one |
rate_limited | Too many checks from one address | Wait a minute. The SDK backs off by itself |
What we collect
No video, no images and no face data ever leave the phone. Each licence check sends the key, the app ID and a random install ID. We keep a hashed install ID, the IP address and the time of each check, to count active installs on your licence and to stop keys being guessed. See the privacy policy.