ElevenLabs Hosted MCP Server
Control your agents workspace via OAuth: create, configure, and manage agents directly from Claude and other MCP clients.
- Skill Road
- ElevenLabs Hosted MCP Server
Categories
Description
The ElevenLabs Hosted MCP Server is a remote Model Context Protocol server operated by ElevenLabs that exposes agent management tools to AI assistants. According to ElevenLabs documentation, a connected assistant such as Claude can create, configure, and manage agents in your workspace entirely without any local installation. The endpoint is https://api.elevenlabs.io/v1/mcp and uses OAuth for authentication.
Workspace and agent management
Once an MCP client is connected, ElevenLabs documents the following capabilities: creating new agents by describing what you want, updating any agent setting including the system prompt, voice, language, and first message, listing your agents and inspecting or comparing their configurations, reviewing an agent's recent conversations and reading full transcripts, exploring the topics your agents' conversations cover, duplicating and deleting agents. Additional capabilities include estimating an agent's expected LLM usage and cost before making changes, retrieving an agent's widget configuration and shareable link, checking the size of an agent's knowledge base, and generating speech audio from text returned as a short-lived download link.
OAuth authentication and data residency
Authentication is exclusively through OAuth. When connecting, you sign in with your ElevenLabs account and grant the assistant scoped access to your workspace; no API key is copied into the client configuration. According to ElevenLabs, the OAuth permissions cover read and write access to ElevenAgents as well as Text to Speech.
For workspaces in isolated data-residency environments — EU, India, Singapore — separate server URLs are documented:
EU: https://api.eu.residency.elevenlabs.io/v1/mcp
India: https://api.in.residency.elevenlabs.io/v1/mcp
Singapore: https://api.sg.residency.elevenlabs.io/v1/mcp
These environments are separate workspaces with separate accounts. The Hosted MCP Server is also published in the Claude Desktop directory under Settings > Connectors.
Mutations, destructive actions, and prompt injection
The server supports write-capable agent mutations: a connected assistant can change system prompts, swap voices, adjust language settings, duplicate agents, and delete agents. Deleting an agent is a destructive action per ElevenLabs documentation. MCP clients such as Claude let you enable or disable individual tools and set whether a tool runs automatically or requires manual confirmation before each call.
Workspace administrators can configure these tool settings for everyone in their organization; individual users can apply stricter but not more permissive settings. A tool disabled by an administrator cannot be re-enabled by an individual user.
Conversation transcripts, knowledge-base content, and agent configurations are external data that may contain prompt-injection text. Treat all content from these sources as untrusted data, not as instructions. Review mutating tool calls — especially agent updates and deletions — independently from the model before authorizing them.
Data path: client, model, and ElevenLabs
The data path when using the Hosted MCP Server: requests travel from the MCP client through the OAuth-secured endpoint to ElevenLabs; responses contain agent metadata, configuration details, conversation transcripts, or audio download links. This data returns to the client context and therefore enters the context of the connected model provider. Audio data is returned as short-lived download links per the documentation. Check whether your MCP client, model provider, and any logging systems further process or retain this data.
Security boundaries and access control
ElevenLabs documentation describes two control layers: first, the OAuth permissions granted at connection time, which determine what operations the assistant may perform at all; second, the tool controls in the MCP client, which enable, disable, or require manual approval for individual server tools. Access is scoped to the workspace you sign in with during the OAuth flow. Connections can be revoked at any time from the MCP client or from your ElevenLabs account settings.
FAQ
Is the ElevenLabs Hosted MCP Server fully remote? Yes. No local process or installation is required; the endpoint is remotely available at https://api.elevenlabs.io/v1/mcp.
How do I authenticate? Exclusively through OAuth. On the first connection, you complete the OAuth flow with your ElevenLabs account. No API key is copied into the client.
Can an assistant delete agents? According to documentation, yes — deletion is flagged as a destructive action. Manually review such tool calls in your MCP client and restrict deletion-capable tools to workspace members who genuinely need that access.
The ElevenLabs Hosted MCP Server does not have a publicly available source-code repository; the official primary source is ElevenLabs documentation at https://elevenlabs.io/docs/eleven-agents/operate/hosted-mcp.
Requirements
An MCP-capable client with Remote MCP and Streamable HTTP support; an ElevenLabs account for the OAuth flow.
Installation instructions
Claude Desktop: Settings > Connectors, search for ElevenLabs and choose Connect, complete the OAuth flow with your ElevenLabs account. Other MCP client: enter https://api.elevenlabs.io/v1/mcp as the server URL and complete OAuth. For data-residency environments use the appropriate regional URL (EU/India/Singapore). No local installation required.
Authentication
Exclusively OAuth. At connection time, you sign in with your ElevenLabs account and authorize scoped workspace access; no API key is copied into the client configuration.
Required access permissions
OAuth permissions cover read and write access to ElevenAgents and Text to Speech per ElevenLabs documentation. Access scope is limited to the workspace selected during the OAuth flow. Workspace administrators can configure tool controls organization-wide.
Transmitted or stored data
Requests go through the OAuth-secured endpoint to ElevenLabs. Responses contain agent metadata, configurations, conversation transcripts, or short-lived audio download links; this data enters the MCP client context and therefore the connected model provider context.
Security risks
OAuth access enables write-capable agent mutations including destructive deletions. Conversation transcripts and knowledge-base content can contain prompt injection. Review mutating tool calls independently before authorization; restrict deletion-capable tools to workspace members who require that access.
License and costs
- License
- Not recorded yet.
- Cost
- paid
Access depends on your ElevenLabs plan; check official ElevenLabs information on account configuration and provider terms before production use.
Alternatives
Not recorded yet.
At a glance
- Provider
- ElevenLabs
- Status
- Official server
- Deployment
- Remote
- Current version
- Not recorded yet.
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Not recorded yet.
Related guides
Guides and background related to this entry.
Set up the Asana plugin for Claude Code
Create your own Asana OAuth app, install the Claude Code plugin, and connect to Asana's V2 MCP server via /asana-setup.
30.09.2026
Setting up the Zernio MCP Server
Connect the Zernio MCP Server via OAuth or an API key, link social accounts, and deliberately safeguard write access to posts, inboxes, and ad campaigns.
28.09.2026
Setting up the Intercom MCP Server
Connect the Intercom MCP Server via OAuth or a bearer token, choose the correct regional endpoint, and deliberately safeguard write access to articles and notes.
23.09.2026
Setting up the PayPal MCP Server
Connect the PayPal MCP Server locally via npx or as a hosted remote server via OAuth, and deliberately safeguard write access.
23.09.2026