ElevenLabs · Authentication Profile
Elevenlabs Authentication
Authentication
ElevenLabs secures its APIs with apiKey, oauth2, and bearer across 3 declared security schemes, as derived from its OpenAPI definitions.
Artificial IntelligenceText-to-SpeechSpeech-to-TextVoiceAudioMachine LearningConversational AIAgentsDubbingMusic GenerationReal-TimeVoice AIVoice Agents
Methods: apiKey, oauth2, bearer
Schemes: 3
OAuth flows:
API key in: header
Security Schemes
apiKeyAuth apiKey
· in: header (xi-api-key)
singleUseToken http
scheme: bearer
oauth2 oauth2
Source
Authentication Profile
generated: '2026-09-17'
method: searched
source: |
https://elevenlabs.io/docs/api-reference/authentication (docs),
https://api.elevenlabs.io/.well-known/oauth-authorization-server (RFC 8414, HTTP 200),
https://api.elevenlabs.io/.well-known/oauth-protected-resource (RFC 9728, HTTP 200),
https://elevenlabs.io/docs/eleven-api/resources/ip-allowlisting,
https://elevenlabs.io/docs/eleven-agents/operate/hosted-mcp.
Cross-checked against the derived apiKey scheme in the repo's OpenAPI files.
docs: https://elevenlabs.io/docs/api-reference/authentication
summary:
types:
- apiKey
- oauth2
- bearer
api_key_in:
- header
primary: API key in the xi-api-key header for the REST/WebSocket API; OAuth 2.0
authorization code + PKCE for the hosted MCP server and the CLI.
schemes:
- name: apiKeyAuth
type: apiKey
in: header
parameter: xi-api-key
description: |
The ElevenLabs API key, sent on every REST request as `xi-api-key: <key>`. The docs
state plainly that the key is a secret and must not be exposed in client-side code.
applies_to: the whole REST API surface (api.elevenlabs.io and the regional residency hosts)
docs: https://elevenlabs.io/docs/api-reference/authentication
controls:
- control: scope restriction
description: a key can be limited to a subset of API endpoints.
- control: credit quota
description: a key can carry a custom credit limit.
- control: IP allowlisting
description: a key can be bound to specific IP addresses or CIDR ranges; requests from
other addresses are rejected with 403.
docs: https://elevenlabs.io/docs/overview/administration/workspaces/api-keys#ip-allowlisting
- name: singleUseToken
type: http
scheme: bearer
description: |
Short-lived single-use tokens for endpoints that need to be called from a client
(browser, mobile) without shipping the API key. Issued by the Single Use Token
endpoints in the API reference.
docs: https://elevenlabs.io/docs/api-reference/tokens/create
applies_to: client-side realtime surfaces (agents/conversation tokens, signed URLs)
- name: oauth2
type: oauth2
flow: authorization_code
description: |
OAuth 2.0 with PKCE, published as RFC 8414 authorization-server metadata. Used by the
hosted MCP server and by `elevenlabs auth login` in the CLI. No API key is stored in
the client; access is revocable from the workspace.
metadata: https://api.elevenlabs.io/.well-known/oauth-authorization-server
issuer: https://api.us.elevenlabs.io
authorization_endpoint: https://elevenlabs.io/app/oauth/authorize
token_endpoint: https://api.us.elevenlabs.io/v1/oauth/token
revocation_endpoint: https://api.us.elevenlabs.io/v1/oauth/revoke
grant_types_supported:
- authorization_code
- refresh_token
response_types_supported:
- code
code_challenge_methods_supported:
- S256
token_endpoint_auth_methods_supported:
- none
- client_secret_post
- private_key_jwt
token_endpoint_auth_signing_alg_values_supported:
- RS256
authorization_response_iss_parameter_supported: true
client_id_metadata_document_supported: true
dynamic_client_registration: false
scopes: see scopes/elevenlabs-scopes.yml
protected_resources:
- resource: https://api.us.elevenlabs.io/v1/mcp
metadata: https://api.elevenlabs.io/.well-known/oauth-protected-resource
bearer_methods_supported:
- header
spec_gap:
observed: |
The provider's own published OpenAPI (https://api.elevenlabs.io/openapi.json, 301 paths /
390 operations) declares NO components.securitySchemes and applies no security to any
operation, even though every endpoint requires the xi-api-key header. The auth model is
documented in prose and in the OAuth discovery documents, not in the contract.
impact: an agent reading only the spec cannot tell how to authenticate.
remediation: add an apiKey securityScheme (header, xi-api-key) to components and a
top-level security requirement.
supporting_controls:
- control: static egress IP allowlisting
description: ElevenLabs publishes static egress IP ranges so customers can allowlist
inbound webhook and tool traffic.
docs: https://elevenlabs.io/docs/eleven-api/resources/ip-allowlisting
- control: zero retention mode
description: Enterprise option that stops ElevenLabs retaining request payloads.
docs: https://elevenlabs.io/docs/eleven-api/resources/zero-retention-mode
- control: webhook authentication modes
description: Outbound webhooks can be secured with HMAC, OAuth2 or mTLS (auth_type on the
workspace webhook object).
docs: https://elevenlabs.io/docs/eleven-api/resources/webhooks
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/elevenlabs-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.