
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@audivo/mcp
Advanced tools
Official Audivo MCP server: one call from an episode link to its transcript. Podcast search, episode discovery, transcripts, and on the local server YouTube audio, for Claude, ChatGPT, Codex, Cursor, and any other MCP client.
Podcast transcripts for Claude, ChatGPT, Codex, Cursor, and any other MCP client, backed by the Audivo API. Ask for an episode; get the transcript back.
Transcribe the latest episode of Acquired and summarise it.
Two ways to connect. The hosted endpoint serves ten tools. The local server serves the same ten, with
transcribe also taking a file on your machine or a YouTube link, plus upload_audio and
youtube_search.
| Hosted | Local | |
|---|---|---|
| Where it runs | Audivo's servers | Your machine, spawned by the client |
| Transport | Streamable HTTP at https://api.audivo.dev/mcp | stdio via npx -y @audivo/mcp |
| Credential | Sign in with OAuth, or Authorization: Bearer hk_live_… | AUDIVO_API_KEY environment variable |
| Good for | Claude on the web and desktop, ChatGPT, anything that takes a URL | Claude Code, Codex, Cursor, VS Code, and every client that spawns a process |
| YouTube | No | Yes, downloaded on your machine with yt-dlp |
| Tool | What it does | Spends credits |
|---|---|---|
transcribe | The default. One episode in, its transcript out, a page at a time | Yes, about one per audio minute |
search_shows | Find shows by name, host, or topic | No |
chart_shows | The current chart for a category | No |
list_episodes | A show's episodes, newest first | No |
quote | Price a selection of many episodes before anything runs | No |
confirm | Turn a quote into a job group | Yes, up to the quote's ceiling |
group_status | Where a group's jobs are, and which transcripts are ready | No |
list_groups | Your recent groups | No |
cancel_group | Stop what has not started and release its credits | No |
read_transcript | A job's transcript, a page at a time; waits for a running job | No |
upload_audio | Announce and upload a file from this machine | No (local only) |
youtube_search | Find an episode on YouTube when it has no podcast feed | No (local only) |
transcribePass one episode: an Apple Podcasts link, feed_url with guid, an episode_id from
list_episodes, or an upload_id — and on the local server, a YouTube link or an absolute path.
transcribe waits for it inside the call: up to 20 seconds on the
hosted server, whose gateway allows 29, and 50 by default on the local one, which reports progress
to clients that ask for it. If it is still running, the answer is the job_id and
read_transcript waits the rest.max_credits refuses the call, before anything is spent, if it could cost more. A job holds its
ceiling (the estimate plus 25%) and settles at the audio it measured, never above.For many episodes at once — a chart, a back catalogue — use quote and then confirm, which
refuses unless the model restates the quote's total.
npxYou need an API key from the Audivo dashboard. Keys are shown once. Set the key in the environment the client starts the server with, then add the server.
Claude Code (or install the Audivo plugin, which adds this server and the skill together)
claude mcp add --scope user audivo -e AUDIVO_API_KEY=hk_live_... -- npx -y @audivo/mcp
Codex
codex mcp add audivo --env AUDIVO_API_KEY=hk_live_... -- npx -y @audivo/mcp
Cursor, Claude Desktop, Windsurf, and other JSON-configured clients
{
"mcpServers": {
"audivo": {
"command": "npx",
"args": ["-y", "@audivo/mcp"],
"env": { "AUDIVO_API_KEY": "hk_live_..." }
}
}
}
VS Code (.vscode/mcp.json)
{
"servers": {
"audivo": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@audivo/mcp"],
"env": { "AUDIVO_API_KEY": "hk_live_..." }
}
}
}
Keep files that contain a real key out of Git and shared chats.
| Variable | Required | Meaning |
|---|---|---|
AUDIVO_API_KEY | Yes | Your API key. Bearer in front of it is accepted and normalised. |
AUDIVO_API_BASE_URL | No | The API origin. Defaults to https://api.audivo.dev. Must be a public https origin: no userinfo, no loopback or private address. |
AUDIVO_YTDLP_PATH | No | A yt-dlp binary to use for YouTube, instead of one on PATH or the managed copy. |
AUDIVO_CACHE_DIR | No | Where the managed yt-dlp is kept. Defaults to your user cache directory (~/Library/Caches/audivo-mcp, ~/.cache/audivo-mcp, …). |
The server writes nothing to stdout except protocol messages. Log lines go to stderr as JSON, and the key never appears in them.
When a show has no public RSS feed — many exist only on YouTube — search_shows finds nothing.
On the local server, youtube_search finds the episode and transcribe takes its link:
Find the Costco episode of Acquired on YouTube and transcribe it
transcribe downloads the video's audio on your machine with yt-dlp,
audio only and with no transcoding, uploads it to Audivo as your own upload, and transcribes it. The
transcript is private to your account.
yt-dlp is found in this order: AUDIVO_YTDLP_PATH; a yt-dlp on your PATH; otherwise the project's
official standalone binary for your platform, downloaded once from its GitHub releases into your user
cache directory and checked against that release's SHA2-256SUMS before it is made executable. The
package has no install script: nothing is downloaded until the first YouTube call. A managed copy
that stops working is updated to the latest release once and the call retried; a yt-dlp you
installed yourself is never touched. yt-dlp is given the Node running this server as its JavaScript
runtime.
You run the download, on your machine, under your own account; you are responsible for having the rights to transcribe what you download, as with any upload. Audivo's servers never fetch from YouTube, which is why the hosted server does not offer any of this.
A recording you made, an interview, or any file you already have on disk:
Transcribe /Users/alex/Downloads/interview.m4a
transcribe with path announces the file to Audivo (its hash, size, content type, and duration),
uploads the bytes straight to Audivo's storage with the signed URL the announcement returns, and
transcribes it. upload_audio does only the first two steps and returns an upload_id, for when you
want to quote several uploads together. The path must be absolute.
Limits: 1 byte to 5 GiB, up to 10 hours, and one of these content types: audio/mpeg, audio/mp3,
audio/mp4, audio/m4a, audio/x-m4a, audio/aac, audio/x-aac, audio/ogg, audio/opus,
audio/flac, audio/x-flac, audio/wav, audio/x-wav, audio/webm. An upload is kept for 7
days, and its transcript is private to your account; each account may hold up to 10 GiB across 100
unexpired uploads at a time. See the uploads guide.
| Setting | Value |
|---|---|
| MCP URL | https://api.audivo.dev/mcp |
| Transport | Streamable HTTP |
| Authentication | OAuth (sign in to Audivo), or Authorization: Bearer hk_live_... |
Clients that support MCP authorization — Claude, ChatGPT, Claude Code, VS Code — need only the URL: they open an Audivo sign-in page, you approve the connection, and it appears under Connected apps in the dashboard, where you can revoke it. For example, in Claude Code:
claude mcp add --transport http --scope user audivo https://api.audivo.dev/mcp
For clients that take a fixed header instead, or for automation, send an API key:
claude mcp add --transport http --scope user audivo https://api.audivo.dev/mcp \
--header "Authorization: Bearer hk_live_..."
Per-client instructions are in the connection guide. The hosted
server is this package's lambda export, deployed by Audivo.
transcribe spends within the job's ceiling and the caller's max_credits; confirm
compares the total the model states with the total the quote carried and refuses on a mismatch
without sending anything. The API applies both checks on its side too.src/contract/types.ts is generated from the published OpenAPI spec in
contract/openapi.yaml; a test fails the build when the two drift.upload_audio, youtube_search, and the file and YouTube inputs of transcribe
run on your machine; the hosted server never sees your files and never fetches from third-party
sites.npm ci
npm test # vitest
npm run typecheck
npm run lint
npm run build # dist/
To pick up a spec change: npm run contract:sync fetches the published spec and regenerates the
types. Run it locally against a key with:
AUDIVO_API_KEY=hk_live_... node dist/bin.js
Bump version in package.json, both version fields in server.json, and SERVER_INFO in
src/server.ts (a test fails until they agree), add a CHANGELOG.md entry, commit, then tag
v<version> and push the tag. The release workflow publishes to npm with provenance and lists the
release in the MCP Registry as
io.github.AudivoDotDev/mcp.
FAQs
Official Audivo MCP server: one call from an episode link to its transcript. Podcast search, episode discovery, transcripts, and on the local server YouTube audio, for Claude, ChatGPT, Codex, Cursor, and any other MCP client.
The npm package @audivo/mcp receives a total of 682 weekly downloads. As such, @audivo/mcp popularity was classified as not popular.
We found that @audivo/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.