Vendor APIs About 3 min read

Genetec Security Center SDK and Web API

Choose the appropriate Security Center SDK or web API interface. Check licensing, versions and roles against the functions required by your application.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Inherited check dated 10 September 2026. Supporting evidence for this inherited check has not been independently confirmed.

Recorded scope: The official Security Center SDK overview was checked for video, access, intrusion and ALPR integration scope and developer programme access. Restricted API contracts were not accessed.

Public Genetec developer and technical documentation reviewed on 25 August 2026; full package contents, partner entitlements, exact SDK/product compatibility, API methods, licences, and deployment support require DAP and target system confirmation.

Verification and testing

Overview#

Vendor APIs / VMS and cloud video / Genetec

Genetec documents a broad Security Center SDK for native platform integration and a separate Web SDK for HTTP oriented applications. Product specific web APIs, such as the Mission Control Web API, are separate contracts. Don't use “Genetec Web API” as if it names one universal endpoint set.

Documented interface map#

Surface Documented purpose Access/licence boundary
Security Center SDK Integrates video, access control, intrusion, ALPR and Security Center platform workflows SDK package and development licence supplied through the Development Acceleration Program (DAP); deployment licences/features apply
Platform, Media, Workspace and Plugin samples Illustrate distinct native integration areas Public sample catalogue; full package and target compatibility remain DAP/product controlled
Security Center Web SDK Platform/framework neutral web access to many Security Center functions Public overview; Web SDK option/licence and system configuration required
Web Player/media surfaces Browser oriented video/media integration Separate media authorisation, browser/codec and licence boundary
Mission Control Web API Incident management integration for Genetec Mission Control Product specific; not a synonym for Security Center Web SDK

Development programme and versions#

The DAP description states that an SDK package includes documentation and samples and provides a one year development licence. That development entitlement isn't a production deployment licence and doesn't guarantee access to every product module.

The public sample catalogue includes .NET Framework 4.8 and .NET 8 sample sets. A public release page exists for the Security Center 5.13.1.0 SDK, while Genetec product documentation also contains later Security Center product lines. Therefore, don't call 5.13.1 “latest” or combine sample runtimes across releases. Pin the installed Security Center build, SDK package, target framework, architecture and applicable licence together.

Capability and authority boundaries#

Security Center unifies multiple physical security domains, but authorisation must remain domain and action specific:

  • live view, playback, export, audio and camera/PTZ control;
  • access control identities, credentials, doors and commands;
  • intrusion, alarms and acknowledgement;
  • ALPR records and privacy sensitive searches;
  • configuration, federation and system administration;
  • plugin hosting and client workspace extension.

The Web SDK overview publicly describes high impact capabilities including door operations. A web integration identity must not inherit broad operator rights merely for convenience. Require explicit site/entity scope, purpose and immutable command audit.

Authentication and deployment#

Use only identity modes documented for the exact Security Center/Web SDK release. Verify TLS and server identity, use unique non human accounts where supported, store secrets in an approved vault and separate development from production credentials. Web browser clients shouldn't receive a confidential client secret or unconstrained long lived token.

For a native SDK application, follow the official connection, threading, object lifetime and event subscription contract. For an in process plugin, treat the host as a shared privileged process: bound work, fail closed, protect configuration and design uninstall/rollback. For Web SDK, enforce origin, session, CSRF and authorisation controls in the application tier; the SDK doesn't replace application security.

Events, media, and failure#

Establish whether an event subscription is transient, resumable or replayable and how initial state is obtained. Preserve Genetec entity identity, source and ingest time, event ID/type and correlation. Reconcile after Directory failover, token expiry and connection loss.

Media viewing and evidence export are different workflows. Don't log or cache media session details indiscriminately, and don't present a convenience export as forensic evidence without the documented export/integrity path.

For a door, alarm or other high impact command that times out, don't blindly retry. Query current state and audit history or require operator resolution; the first request may have succeeded.

Lifecycle and compatibility#

Review the SDK release notes, Security Center compatibility, licence options, known issues and DAP terms for each target. Public product guides are versioned; use the correct version selector rather than a search result from another release.

Primary sources#

Section overview · Wiki home