
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
open-transcribe-mcp
Advanced tools
Own the recorder. Choose the intelligence.
OpenTranscribe is an open-source MCP server that routes audio to the speech-to-text model of your choice and returns one provider-independent transcript schema.
It is built around a simple idea: buying a great recorder should not lock you into one transcription subscription. Use Plaud, a phone, an open-source wearable, or any other audio source you are authorized to access, then choose Microsoft MAI, ElevenLabs Scribe, or Groq Whisper without changing the downstream workflow.
OpenTranscribe does not jailbreak hardware or bypass access controls. It works only with audio the operator is authorized to access.
OpenTranscribe keeps the integration boundary stable: the recorder supplies an audio file or HTTPS URL, the server selects or calls the requested speech-to-text provider, and downstream tools receive the same canonical transcript shape.
/mcp, with stateless operation and bearer authenticationtranscribe_audio, list_transcription_models, estimate_transcription_cost, get_transcript_chunk, and delete_transcriptMAI-Transcribe-2, ElevenLabs scribe-v2, and Groq Whisper adaptersRequirements: Python 3.12 and uv, or Docker.
git clone https://github.com/fbossiere/open-transcribe-mcp.git
cd open-transcribe-mcp
cp .env.example .env
Edit .env with one provider credential and a strong random MCP bearer token. For Microsoft:
OT_MICROSOFT__ENDPOINT=https://YOUR-RESOURCE.cognitiveservices.azure.com
OT_MICROSOFT__API_KEY=YOUR-KEY
OT_SECURITY__BEARER_TOKEN=YOUR-RANDOM-TOKEN
Start the server:
uv sync
uv run open-transcribe-mcp
The MCP endpoint is http://localhost:8000/mcp; probes are available at /healthz and /readyz.
Run the included bilingual, two-voice synthetic recording through the connected provider:
uv run python examples/transcribe.py --token YOUR-RANDOM-TOKEN
The fixture and reference transcript are non-sensitive and redistributable. Pass another authorized public HTTPS audio URL as the first argument to use your own source.
Connect a FastMCP client:
import asyncio
from fastmcp import Client
async def main() -> None:
async with Client("http://localhost:8000/mcp", auth="YOUR-RANDOM-TOKEN") as client:
models = await client.call_tool("list_transcription_models", {})
print(models)
result = await client.call_tool(
"transcribe_audio",
{
"request": {
"source": {"type": "url", "url": "https://example.org/authorized-audio.mp3"},
"provider": "auto",
"routing_policy": "quality",
"diarization": True,
"timestamps": "segment",
"transcript_style": "clean",
}
},
)
print(result)
asyncio.run(main())
Provider choice does not alter the response contract. Set provider and model to switch explicitly, or use auto with default, quality, cost, or latency routing.
docker build -t open-transcribe-mcp:1.1.0 .
docker run --rm -p 8000:8000 \
-e OT_ENVIRONMENT=prod \
-e OT_MICROSOFT__ENDPOINT="https://YOUR-RESOURCE.cognitiveservices.azure.com" \
-e OT_MICROSOFT__API_KEY="YOUR-KEY" \
-e OT_SECURITY__AUTH_MODE=bearer \
-e OT_SECURITY__BEARER_TOKEN="YOUR-RANDOM-TOKEN" \
open-transcribe-mcp:1.1.0
The published image is also available as ghcr.io/fbossiere/open-transcribe-mcp:1.1.0.
All settings use the OT_ prefix and __ for nesting. See .env.example. Provider credentials are server-side environment variables and are never accepted as MCP tool arguments.
Temporary storage is disabled by default. result_mode=stored requires:
OT_RESULT_STORE__BACKEND=memory # local/test only; use s3 for horizontally scaled production
OT_RESULT_STORE__CURSOR_SECRET=ANOTHER-RANDOM-SECRET
For Scaleway Object Storage, install the s3 extra and configure the S3 bucket/endpoint variables documented in the deployment guide.
The reference Scaleway deployment is codified in infra/scaleway. It provisions a private image registry, a scale-to-zero Serverless Container, health probes, HTTPS-only ingress, and an optional TTL-bound result bucket with a dedicated runtime identity.
Read SECURITY.md, the threat model, and the retention policy before exposing the service publicly.
OpenTranscribe v1.0 targets self-hosted, single-tenant installations. Provider feature parity is deliberately not guaranteed; capability negotiation exposes differences instead of hiding them. URL ingestion is the only remote input type. Synchronous provider limits still apply. OIDC and asynchronous jobs are planned for later releases. The memory store is neither durable nor horizontally scalable. S3 lookups prioritize a simple deployment contract over very-large-bucket indexing; dedicate the result prefix and enforce lifecycle deletion.
Application controls do not replace network policy. Internet-facing operators should still combine exact source-host allow-listing with egress firewall rules.
Provider prices, APIs, and capabilities change. The checked-in metadata is informational, not a contractual quote.
OpenTranscribe processes audio supplied by the operator. Recording and transcribing people may be subject to consent, privacy, employment, telecommunications, or data-protection laws. Operators are responsible for ensuring they have the necessary rights and consent.
Transcript content is untrusted data. OpenTranscribe never interprets it as instructions; downstream agents must preserve the same boundary.
The canonical documentation site is fbossiere.github.io/open-transcribe-mcp.
Contributions are welcome. Start with the contribution guide; open a feature issue before substantial work, and report vulnerabilities only through the private process in SECURITY.md.
OpenTranscribe is an independent open-source project maintained by its contributors. It is not affiliated with, endorsed by, or sponsored by Plaud, Microsoft, ElevenLabs, Groq, or any transcription provider.
Plaud and all provider product names are trademarks of their respective owners.
Apache License 2.0. See LICENSE.
FAQs
Provider-independent speech-to-text over MCP.
The pypi package open-transcribe-mcp receives a total of 55 weekly downloads. As such, open-transcribe-mcp popularity was classified as not popular.
We found that open-transcribe-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.