spicy/face-swap
Face Swap — puts the face from one picture onto another.
Two images in, one out.
| Slug | spicy/face-swap |
| Kind | image |
| Vendor | sociaro |
| Endpoint | POST /v1/spicy/generations |
Charged per job from what the generator reports it rendered — your Logs show the exact figure for each one; see balance and billing.
Calling it
curl https://api.sociaro.com/v1/spicy/generations \
-H "Authorization: Bearer $SOCIARO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "spicy/face-swap",
"prompt": "a paper boat on a rain-soaked street"
}'
# then poll the job id it returns:
curl https://api.sociaro.com/v1/spicy/generations/JOB_ID \
-H "Authorization: Bearer $SOCIARO_API_KEY"Parameters
Face Swap — put one face onto another picture
| Field | Type | Required | Default | Values | What it does |
|---|---|---|---|---|---|
image | string | yes | — | https url or base64 | The TARGET — the picture whose face gets replaced. |
face_image | string | yes | — | https url or base64 | The SOURCE — the face to put in. |
seed | integer | no | random | — |
Anything not listed here is refused rather than ignored, so a typo fails loudly instead of quietly producing something else.
Worked example
curl https://api.sociaro.com/v1/spicy/generations \
-H "Authorization: Bearer $SOCIARO_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "model": "spicy/face-swap",
"image": "https://your-cdn.example.com/scene.jpg",
"face_image": "https://your-cdn.example.com/face.jpg" }'The two fields are easy to swap by accident and there is no way for us to tell which you meant:
image is the scene, face_image is the face. Getting them the wrong way round produces a
perfectly good render of the wrong thing, and it is billed.
This model puts a real person's face onto another image. You are responsible for having the consent of the people depicted, and for the age and terms of the service you build on it.
How a job runs
Generation takes longer than a request should wait, so it goes in three moves: submit, then poll, then collect.
# 1. submit — the model id plus the fields above
curl -sS https://api.sociaro.com/v1/spicy/generations \
-H "Authorization: Bearer $SOCIARO_API_KEY" -H "Content-Type: application/json" \
-d '{ "model": "…", "prompt": "…" }'
# -> { "job_id": "<id>", "status": "submitted" }
# 2. poll every 3-5 s for images, 5-10 s for video
curl -sS https://api.sociaro.com/v1/spicy/generations/<id> \
-H "Authorization: Bearer $SOCIARO_API_KEY"
# -> { "job_id": "…", "status": "processing" }
# -> { "job_id": "…", "status": "completed", "model": "…",
# "media_url": "https://api.sociaro.com/v1/media/<media_id>" }
# -> { "job_id": "…", "status": "failed", "model": "…", "error": { "code": …, "message": … } }
# 3. collect within the hour — the opaque id IS the credential, no header needed
curl -sSL "https://api.sociaro.com/v1/media/<media_id>" -o out.mp4
Use the job_id verbatim as the path segment when polling: the two names are the same value.
Which submit and poll URL this model uses is at the top of this page, under Calling it.
Reading the poll
status is one of processing · completed · failed. Only completed carries media_url,
only failed carries error.
Gate on status, never on the poll's HTTP code. A poll-time failure is HTTP 200 with
status: "failed" and an error object of { "code", "message" }, plus provider_code when the
generator supplied one — on every failure branch, including one where the result could not be
delivered. A submit-time rejection is different: it comes back as its own HTTP status with the
reason in the body.
code is ours and stable; message is the generator's. Match on code: it comes from a small
fixed set, and provider_failed still means what it always meant. A rejection of what you sent —
a size out of range, an unusable input — additionally sets code: "invalid_request", because that is
a different thing for your code to do. message now carries the generator's own sentence, and
provider_code its own code (OutputVideoSensitiveContentDetected.PolicyViolation,
IPInfringementSuspect), so a moderated generation, a copyright refusal and a broken renderer are
finally distinguishable. Treat provider_code as informational: the vendors change these strings
without telling us, so branch on ours.
message is variable text, capped at 400 characters. It used to be a single fixed
43-character sentence, so if you compare it by equality or keep it in a narrower column, that needs
changing — match on code, and on provider_code when you need the finer distinction.
Two things that text is not. It does not name the generator behind the model: the names of the
services and hosts that actually run your job are substituted out before you see it, so do not parse
it for one. What it does not hide is a name you already have — the halves of the model id you
called (alibaba, bytedance, wan, qwen, seedance, seedream, happyhorse) stay as written,
because blanking those would garble the message exactly where it is useful: Model
alibaba/wan-2-7-image not found has to survive intact. And the text can quote your own request
back: a moderation message often contains the fragment it objected to. That is why we do not write
it into our own logs, and why forwarding or storing a failed poll's message is your decision to
make rather than something to do by default.
Collecting the result
media_url points at our host, not the generator's. It is a capability: the opaque id is the
credential, so no Authorization header is needed and anyone holding the link can fetch it. It
expires within the hour — download rather than store the link.
A job that asked for a second asset gets one beside the first on the same terms: Seedance's
return_last_frame arrives as last_frame_url, a decomposition's layers as layers[]. Treat
them as optional: they appear when you asked, the generator returned one, and the link passes the
same delivery check the main asset passed. If it does not, we omit the field rather than hand you
a link /v1/media would refuse — and the main asset is unaffected.
/v2 jobs do not return the Seedance still yet: return_last_frame is accepted there, but the
closing frame is not delivered, so a /v2 job's result carries the clip alone. Use /v1 when you
need the still.
Several images are not optional extras. An Alibaba image model asked for more than one picture
(n above 1) is charged for the number of pictures the generator reports making, and every link it
returns is delivered, never fewer than that number: media_urls lists
all of them in the generator's order (present on every image result, even a single one) and
media_url is the first. Each has its own link and its own expiry. If any one of them cannot be
delivered the job is reported failed and nothing is charged — unlike a still or a layer, an
image you paid for is never left out.
Rules the gateway adds
Two fields are ours and never reach the generator:
| Field | Notes |
|---|---|
model |
which model to run |
user |
your own end-user id. Recorded against this job's spend so you can attribute cost per end user, and stripped before the request leaves us, so the generator never sees it. Validated BEFORE the job is created, so a rejection is free: a string of at most 128 characters, no control characters, valid UTF-8. Omitting it, or sending null, is fine and simply records no end user |
An unknown field is always a 400. Most generators reject one themselves; some accept it,
ignore it, render something other than what you asked for and bill you — so we refuse it for you.
Either way you get 400 unknown field(s): [...] naming the offender, never a surprise render.
Ranges and enums are the generator's own and we do not re-validate most of them, so an
out-of-range value comes back as its rejection, in its wording and with its numbers. The one thing
we DO check ourselves is resolution, because an unsupported tier is silently ignored rather than
refused: you would ask for the higher tier, be handed a lower one, and be charged. The tiers on
this page are read from what the vendor prices, so they change when the vendor publishes one.
Authentication
Authorization: Bearer <your-api-key> on submit and on poll. The key must be valid AND granted
this model — 403 otherwise.
One deliberate exception on poll: a key that is over budget may still poll and collect a job it already submitted, so work you have already paid for is never stranded by a budget that ran out mid-generation. While the key is over budget the gateway cannot read its model list at all, so the per-model grant is not re-checked on those polls — a grant revoked after submit still collects that job. Ownership is always enforced: a job can only be polled by the key that created it, and submit is always refused in that state.