openapi: 3.0.3 info: title: Cartesia Agents Auth API description: 'The Cartesia REST API for real-time voice AI - text-to-speech and voice-changer generation (single-shot bytes or Server-Sent Events), batch speech-to-text transcription, voice management and cloning, audio infill, custom datasets, pronunciation dictionaries, API keys and scoped access tokens, the Voice Agents platform (agents, calls, call batches, phone numbers, telephony providers, webhooks, deployments, knowledge base documents/folders, and evaluation metrics), and usage reporting. All requests require a `Cartesia-Version` header and an `Authorization: Bearer` API key (`sk_car_...`) or short-lived access token. The lowest-latency, streaming surface for TTS and STT is a separate WebSocket protocol documented in the companion AsyncAPI document at asyncapi/cartesia-ai-asyncapi.yml.' version: '2026-03-01' contact: name: Cartesia url: https://cartesia.ai license: name: API documentation - Cartesia Terms of Service url: https://cartesia.ai/terms-of-service servers: - url: https://api.cartesia.ai description: Cartesia production API security: - bearerAuth: [] tags: - name: Auth description: Short-lived, scoped access token generation. paths: /access-token: post: operationId: generateAccessToken tags: - Auth summary: Generate a New Access Token description: Generates a short-lived (max 3600s) access token scoped by grants for making API requests, suitable for use in browser clients. parameters: - $ref: '#/components/parameters/CartesiaVersion' requestBody: content: application/json: schema: type: object properties: grants: type: object properties: tts: type: boolean stt: type: boolean agent: type: boolean expires_in: type: integer maximum: 3600 description: Token validity in seconds. responses: '200': description: The generated access token. content: application/json: schema: type: object required: - token properties: token: type: string '401': $ref: '#/components/responses/Unauthorized' components: responses: Unauthorized: description: Missing, invalid, or expired API key / access token. content: application/json: schema: $ref: '#/components/schemas/Error' parameters: CartesiaVersion: name: Cartesia-Version in: header required: true description: API version date, e.g. 2026-03-01. schema: type: string example: '2026-03-01' schemas: Error: type: object properties: title: type: string message: type: string error_code: type: string status_code: type: integer doc_url: type: string request_id: type: string securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: sk_car_... API key or short-lived access token description: 'Cartesia API key (sk_car_...) or a short-lived access token minted via POST /access-token, passed as Authorization: Bearer . Every request also requires the Cartesia-Version header.'