ElevenLabs scores 83.8, band exemplar, up 2.3 points from 81.5 at its last scoring. Its Agent Readiness is 50.9, band agent-ready, and the record says something unusual about that band: it was gated down from agent-native. A voice-AI company that sells an agents platform has built nearly everything an agent needs to call it, except the parts that make a mistake undoable.
One contract, cut into 23 pages
ElevenLabs publishes a single first-party OpenAPI 3.1.0 covering 301 paths and 390 operations across its creative tools, its agents platform and its developer API. The network splits that one document into 23 API pages, from the full ElevenLabs API down to Text to Speech, Dubbing, Music Generation and the Agents API. All 22 contracts on record are provider-sourced, zero derived, and 100% of them are callable.
The realtime half is described too. Three AsyncAPI documents cover the Conversational AI WebSocket, the Text to Speech streaming socket, and the webhook events. For a product whose value is audio arriving while you are still sending text, that is the surface that matters, and it is on the record.
The facets
| Facet | Score |
|---|---|
| Access clarity | 100.0 |
| Operational transparency | 92.1 |
| Developer ergonomics | 78.6 |
| Discoverability | 75.0 |
| Contract quality | 66.2 |
| Contract governance | 45.5 |
Operational transparency at 92.1 is the standout. The domain-security record shows TLS 1.3, HSTS, DNSSEC and DMARC; there is a HackerOne disclosure program with a published security.txt; the trust center lists SOC 2, ISO 27001 and HIPAA; and 35 rate limits are documented. Contract governance at 45.5 is the weak facet. The two Spectral rulesets on file are small, one with 8 rules and one with 6.
What agents get, and what they do not
The agent layer is first-party where it counts. The MCP server and the Agent Skills are both marked first-party in the provenance, and the company’s own description counts ten skills and a hosted remote MCP server with four data-residency endpoints. Lit dimensions include served delegated identity, verified protected resource metadata, verified error semantics, a well-known catalog, and a documented rate-limit signal.
The agentic access profile maps 452 operations, 270 of them acting and only 4 flagged human-in-the-loop. That profile is derived, which means we generated it, so it earns ElevenLabs nothing here. What it shows is still worth reading: 270 operations that change something, and four checkpoints.
The unlit dimensions line up with that ratio. Idempotency is unlit. Reversibility is not documented. Dry-run mode is absent. Consent identity is unlit. OAuth 2.0 is one of three auth schemes on record, and the scopes record reads “no documented scopes.” An agent can find, authenticate against and call voice cloning, dubbing and agent configuration, but the record gives it no safe retry, no preview, no undo, and no narrow grant to ask for.
What would move the number
Contract governance is the cheapest facet to raise: a ruleset that governs the 390-operation contract itself, plus a stated versioning and deprecation policy. For the gated readiness band, the order is idempotency keys on the generate and create operations, documented OAuth scopes, and a dry-run or reversibility statement for the destructive ones. ElevenLabs already publishes the hard parts. What is missing is the paperwork that tells an agent where it is safe to be wrong.
See the full record at apis.io/providers/elevenlabs/.