ElevenLabs · Authentication Profile

Elevenlabs Authentication

Authentication

ElevenLabs secures its APIs with apiKey, oauth2, and bearer across 3 declared security schemes, as derived from its OpenAPI definitions.

Artificial IntelligenceText-to-SpeechSpeech-to-TextVoiceAudioMachine LearningConversational AIAgentsDubbingMusic GenerationReal-TimeVoice AIVoice Agents
Methods: apiKey, oauth2, bearer Schemes: 3 OAuth flows: API key in: header

Security Schemes

apiKeyAuth apiKey
· in: header (xi-api-key)
singleUseToken http
scheme: bearer
oauth2 oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: |
  https://elevenlabs.io/docs/api-reference/authentication (docs),
  https://api.elevenlabs.io/.well-known/oauth-authorization-server (RFC 8414, HTTP 200),
  https://api.elevenlabs.io/.well-known/oauth-protected-resource (RFC 9728, HTTP 200),
  https://elevenlabs.io/docs/eleven-api/resources/ip-allowlisting,
  https://elevenlabs.io/docs/eleven-agents/operate/hosted-mcp.
  Cross-checked against the derived apiKey scheme in the repo's OpenAPI files.
docs: https://elevenlabs.io/docs/api-reference/authentication
summary:
  types:
  - apiKey
  - oauth2
  - bearer
  api_key_in:
  - header
  primary: API key in the xi-api-key header for the REST/WebSocket API; OAuth 2.0
    authorization code + PKCE for the hosted MCP server and the CLI.
schemes:
- name: apiKeyAuth
  type: apiKey
  in: header
  parameter: xi-api-key
  description: |
    The ElevenLabs API key, sent on every REST request as `xi-api-key: <key>`. The docs
    state plainly that the key is a secret and must not be exposed in client-side code.
  applies_to: the whole REST API surface (api.elevenlabs.io and the regional residency hosts)
  docs: https://elevenlabs.io/docs/api-reference/authentication
  controls:
  - control: scope restriction
    description: a key can be limited to a subset of API endpoints.
  - control: credit quota
    description: a key can carry a custom credit limit.
  - control: IP allowlisting
    description: a key can be bound to specific IP addresses or CIDR ranges; requests from
      other addresses are rejected with 403.
    docs: https://elevenlabs.io/docs/overview/administration/workspaces/api-keys#ip-allowlisting
- name: singleUseToken
  type: http
  scheme: bearer
  description: |
    Short-lived single-use tokens for endpoints that need to be called from a client
    (browser, mobile) without shipping the API key. Issued by the Single Use Token
    endpoints in the API reference.
  docs: https://elevenlabs.io/docs/api-reference/tokens/create
  applies_to: client-side realtime surfaces (agents/conversation tokens, signed URLs)
- name: oauth2
  type: oauth2
  flow: authorization_code
  description: |
    OAuth 2.0 with PKCE, published as RFC 8414 authorization-server metadata. Used by the
    hosted MCP server and by `elevenlabs auth login` in the CLI. No API key is stored in
    the client; access is revocable from the workspace.
  metadata: https://api.elevenlabs.io/.well-known/oauth-authorization-server
  issuer: https://api.us.elevenlabs.io
  authorization_endpoint: https://elevenlabs.io/app/oauth/authorize
  token_endpoint: https://api.us.elevenlabs.io/v1/oauth/token
  revocation_endpoint: https://api.us.elevenlabs.io/v1/oauth/revoke
  grant_types_supported:
  - authorization_code
  - refresh_token
  response_types_supported:
  - code
  code_challenge_methods_supported:
  - S256
  token_endpoint_auth_methods_supported:
  - none
  - client_secret_post
  - private_key_jwt
  token_endpoint_auth_signing_alg_values_supported:
  - RS256
  authorization_response_iss_parameter_supported: true
  client_id_metadata_document_supported: true
  dynamic_client_registration: false
  scopes: see scopes/elevenlabs-scopes.yml
  protected_resources:
  - resource: https://api.us.elevenlabs.io/v1/mcp
    metadata: https://api.elevenlabs.io/.well-known/oauth-protected-resource
    bearer_methods_supported:
    - header
spec_gap:
  observed: |
    The provider's own published OpenAPI (https://api.elevenlabs.io/openapi.json, 301 paths /
    390 operations) declares NO components.securitySchemes and applies no security to any
    operation, even though every endpoint requires the xi-api-key header. The auth model is
    documented in prose and in the OAuth discovery documents, not in the contract.
  impact: an agent reading only the spec cannot tell how to authenticate.
  remediation: add an apiKey securityScheme (header, xi-api-key) to components and a
    top-level security requirement.
supporting_controls:
- control: static egress IP allowlisting
  description: ElevenLabs publishes static egress IP ranges so customers can allowlist
    inbound webhook and tool traffic.
  docs: https://elevenlabs.io/docs/eleven-api/resources/ip-allowlisting
- control: zero retention mode
  description: Enterprise option that stops ElevenLabs retaining request payloads.
  docs: https://elevenlabs.io/docs/eleven-api/resources/zero-retention-mode
- control: webhook authentication modes
  description: Outbound webhooks can be secured with HMAC, OAuth2 or mTLS (auth_type on the
    workspace webhook object).
  docs: https://elevenlabs.io/docs/eleven-api/resources/webhooks

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/elevenlabs-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.