Skip to main content

Authenticate with a temporary token

If you need to authenticate on the client, you can avoid exposing your API key by using temporary authentication tokens. You should generate this token on your server and pass it to the client.
1
To generate a temporary token, make a POST request to the temporary token endpoint.Use the expires_in_seconds parameter to specify the duration for which the token will remain valid. Optionally, use the max_session_duration_seconds parameter to specify the desired maximum duration for the session initialized using this token.
expires_in_seconds must be a value between 1 and 600 seconds. If specified, max_session_duration_seconds must be a value between 60 and 10800 seconds (defaults to maximum session duration of 3 hours).
When a session reaches max_session_duration_seconds, the server doesn’t close it immediately. The session ends after the current turn ends, or up to 60 seconds later, whichever comes first. You’re billed for this extra time. To avoid it, run a client-side timer and terminate the session yourself before the limit.
2
The client should retrieve the token from the server and use the token to authenticate the transcriber.
A token stays valid until expires_in_seconds elapses. Until then, you can use the same token to start more than one session, including concurrent sessions. To limit how a token is used, request a new token for each session and keep expires_in_seconds short. Any usage associated with a temporary token will be attributed to the API key that generated it.
To use it, specify the token parameter as a query parameter in the WebSocket URL.