Authentication & Rate Limiting
Before exposing the gateway beyond localhost, lock it down with a key and rate limits.
At a glance
- Bearer API-key auth.
- Consider LAN binding carefully.
- Per-IP rate limiting.
API key (Bearer)
Authenticate requests with a Bearer token. Send Authorization: Bearer <key> on each call.
curl -H "Authorization: Bearer $STUDIO_API_KEY" \
http://127.0.0.1:8123/api/v1/tts/engines
LAN binding & rate limits
Binding to a LAN address exposes the gateway to your network. Use the API key, apply per-IP rate limiting, and consider a reverse proxy. See Headless & LAN Exposure.