Local API authentication
Localhost, LAN sharing and remote self-hosting for the desktop API.
On localhost
Requests from 127.0.0.1, ::1 or localhost need no credential. OpenAI SDKs
still want a non-empty api_key, so pass anything, such as local.
On a remote or shared server
Set OMNIVOICE_API_KEY on the machine running VoiceStudio and send it as a
Bearer token. Use TLS or Tailscale: plain HTTP exposes the key.
export OMNIVOICE_API_KEY="$(python -c 'import secrets; print(secrets.token_urlsafe(24))')"
uv run uvicorn backend.main:app --host 0.0.0.0 --port 3900For quick sharing there is also a temporary six-digit PIN for non-loopback HTTP:
X-VoiceStudio-Pin: 123456The PIN doesn't cover WebSockets or admin routes. Remote dictation and remote
administration need the API key. /system/* and /api/settings/* are stricter
than speech routes, and a trusted-network exemption never grants admin access.
Keep keys out of URLs
Query-string credentials end up in history and proxy logs. Use
Authorization: Bearer … wherever the client allows.
VoiceStudio Cloud
No Cloud credentials are issued and no production server is advertised while the hosted API is unreleased. See the Cloud preview.