TranscriptFetch · Authentication Profile

Transcriptfetch Authentication

Authentication

TranscriptFetch secures its APIs with http and oauth2 (MCP surface) across 2 declared security schemes, as derived from its OpenAPI definitions.

TranscriptsSpeech-to-TextCaptionsYouTubeTikTokInstagramPodcastsMCPllms-txtOpenAPITranscriptionVideoAI/LLMRAGAgentsDeveloper ToolsMediaContentSpotifyApple Podcasts
Methods: http, oauth2 (MCP surface) Schemes: 2 OAuth flows: API key in:

Security Schemes

bearerAuth http
scheme: bearer
mcp-oauth oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-09-09'
method: searched
source: openapi/transcriptfetch-api-v1-openapi.json, openapi/transcriptfetch-api-v2-openapi.json
docs: https://transcriptfetch.com/docs/api-reference
summary:
  types:
  - http
  - oauth2 (MCP surface)
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  description: 'Send your API key as `Authorization: Bearer <key>`.'
  key_prefix: tf_live_
  sources:
  - openapi/transcriptfetch-api-v1-openapi.json
  - openapi/transcriptfetch-api-v2-openapi.json
  notes:
  - Keys are created in the dashboard; a SHA-256 hash is stored server-side, never the plaintext, so a key cannot be shown again after creation.
  - Multiple keys per account, independently revocable (immediate), each with its own rate limit — rotation without downtime.
  - Send keys only in the Authorization header, never a query string or browser JavaScript; the API deliberately sends no CORS headers.
- name: mcp-oauth
  type: oauth2
  surface: MCP server only (https://transcriptfetch.com/mcp)
  description: >-
    OAuth 2.0 authorization-code with PKCE (S256) against the Clerk-run authorization
    server at clerk.transcriptfetch.com, with dynamic client registration. RFC 9728
    protected-resource metadata at /.well-known/oauth-protected-resource names the MCP
    endpoint as the resource. The MCP server also accepts the same tf_live_ bearer keys.
  metadata:
  - well-known/transcriptfetch-oauth-protected-resource.json
  - well-known/clerk-transcriptfetch-oauth-authorization-server.json
public_endpoints:
- GET /api/v2/health and /api/v2/health/deep need no key.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/transcriptfetch-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.