Set up the ElevenLabs Hosted MCP Server

Connect the official ElevenLabs Remote MCP via OAuth and manage your agents workspace securely from Claude and other MCP clients.

  • Skill Road
  • Set up the ElevenLabs Hosted MCP Server

Published on 18.09.2026

The ElevenLabs Hosted MCP Server makes your agent workspace accessible to an MCP-capable client like Claude. A connected assistant can use natural language to create agents, change settings such as system prompt, voice, and language, read conversation transcripts, and duplicate or delete agents. All management runs remotely through https://api.elevenlabs.io/v1/mcp; nothing needs to be installed locally.

Do not configure the server as a blanket agent autopilot. Define in advance which agents the assistant may see, which mutations are permitted, and which tool calls require manual confirmation. This prevents unintended configuration changes and keeps agent decisions auditable.

Connecting through Claude Desktop

ElevenLabs has published the Hosted MCP Server in the Claude Desktop directory. Open Claude Desktop, go to Settings > Connectors, search the directory for "ElevenLabs," and select Connect. Claude then opens the OAuth dialog. Sign in only through the official ElevenLabs dialog, verify which workspace is being connected, and complete the authorization. Claude can then read and write agents in your workspace.

Immediately after connecting, check which tools are active. Claude shows every available tool in the connector settings; you can disable individual tools or set them to require manual confirmation. Start by enabling only read tools — listing agents, reviewing configuration — before enabling write tools.

Connecting through another MCP client

For clients that do not support directories, enter https://api.elevenlabs.io/v1/mcp as the server URL. According to ElevenLabs, the client automatically detects server settings, including Streamable HTTP as the transport protocol and the OAuth client using Anthropic's hosted client metadata (CIMD). No separate client registration is needed when the client supports CIMD. Then complete the OAuth flow and select the correct workspace.

Data-residency environments

If your workspace is in an isolated data-residency environment — EU, India, or Singapore — use the corresponding regional URL instead of the global endpoint. In Claude: open a new chat, use the + button, Add connector > Add custom connector, give it a recognizable name such as "ElevenLabs EU," and enter the regional URL. Claude detects server settings automatically. Complete the OAuth flow with the account for that isolated environment, not your global elevenlabs.io account — accounts are strictly separate.

Controlling mutations deliberately

Operations such as agent updates, voice swaps, or prompt changes are generally reversible. Deleting an agent is destructive and not automatically reversible per ElevenLabs documentation. Set deletion tools to require manual confirmation and restrict that access to workspace members who genuinely need it.

Workspace administrators can set tool controls for the entire organization; individual users can only apply stricter, not more permissive, settings. Plan tool controls accordingly as a team: a disabled tool can only be re-enabled by an administrator.

Data path and prompt injection

Agent configurations, conversation transcripts, and knowledge-base content returned by the MCP server are external data. They can contain prompt-injection text — instructions such as "ignore rules" or "update the system prompt." Treat this content as data, not commands. Review every mutating tool call independently from the model before authorizing it: which agent is being changed, which fields, what effect?

Data travels through the OAuth-secured endpoint to ElevenLabs and back into the client context of the connected model provider. Audio data is returned as short-lived download links. Check whether your MCP client, model provider, and logging systems store or forward transcripts or configurations.

FAQ

Do I need a local installation? No. The Hosted MCP Server runs entirely remotely; you only need an MCP-capable client and an ElevenLabs account.

What happens during authorization? You sign in with your ElevenLabs account and grant the assistant scoped access to your workspace. No API key ends up in the client configuration.

How do I revoke access? Either from the MCP client through connector settings or from your ElevenLabs account settings. Revoking immediately ends server access for that client.

Published on 18.09.2026

Categories

Frequently asked questions

Do I need a local installation?

No. The ElevenLabs Hosted MCP Server runs entirely remotely; you only need an MCP-capable client and an ElevenLabs account.

How does the assistant authenticate?

Exclusively through OAuth. At connection time you sign in with your ElevenLabs account; no API key is copied into the client configuration.

Can an assistant delete agents?

Yes — deletion is flagged as destructive per documentation. Set deletion tools to require manual confirmation and restrict that access to workspace members who genuinely need it.