Give your agent a reason to pause.
Before an AI agent or a robot pays, opens or changes an account on a voice instruction, ORAVYS scores the recording for signs of synthetic speech. A risk signal before an irreversible action, never a lock.
- API v1 and MCP server
- Consent required on every call
- Paid API key, sent in a header
- Recorded clips, not live streams
How it works
Record, score, then hold or step up.
The agent keeps doing the reversible work. Only the irreversible step waits for the result.
The person is told, and agrees.
The agent announces the recording and gets consent from the person who speaks. Every call must carry consent=true. Without it the API refuses the call and counts nothing.
One call, from your backend or through MCP.
POST /api/v1/verdict-only, or the MCP tool check_deepfake. For flows that can wait, submit to /api/v1/analyze/async and poll /api/v1/job/{job_id}.
The result decides the next check, not the action.
If the result is not clear, confirm through another channel before acting, for example a call back to a number you already know.
Timing: typically seconds when warm, longer on cold start; use the async job API for non-interactive flows.
Three possible answers
Each answer maps to a next step.
The result is advisory. It says whether synthetic speech signals were found in this recording, nothing more.
Strong synthetic signals
The recording shows strong signs of generated speech. Hold the irreversible action and confirm through another channel.
No strong synthetic signal (not a certification)
Nothing strong was found. This does not prove that the voice is human, nor who is speaking. Keep your usual controls.
Inconclusive
The clip could not be scored with confidence, or the service did not answer in time. Treat it as unknown, never as a pass.
What it is not
- Not a lock.Never make it the only gate on an action. It tells your agent when to ask for more.
- Not proof.A probabilistic output, not legal evidence and not an identity check. It does not tell who is speaking.
- Not emotion or intent reading.No stress, hesitation or intent scoring. The EU AI Act, Art. 5(1)(f), bars this kind of inference at work and in education.
- Not live call monitoring.It scores a recorded clip. There is no streaming endpoint.
Integration
The API you call, or the MCP server your agent uses.
Send the key in the X-API-Key header, or as Authorization: Bearer. Keys in the query string or in form fields are refused. Keep the key on your server, never inside a device or a client app.
curl -X POST https://app.oravys.com/api/v1/verdict-only \ -H "X-API-Key: $ORAVYS_API_KEY" \ -H "Idempotency-Key: order-4812-voice" \ -F "audio=@instruction.wav" \ -F "consent=true"
{"mcpServers": {"oravys": {
"command": "python",
"args": ["mcp_server.py"],
"env": {
"ORAVYS_API_URL": "https://app.oravys.com",
"ORAVYS_API_KEY": "..."}}}}
{"error": {
"code": "consent_required",
"message": "Consent attestation required: send
consent=true (or consent_data_processing=true and
consent_voice_processing=true), collected from the
person whose voice is analyzed."}}
{"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded.
Please retry later."}}
# Back off and retry. Do not count on a
# Retry-After header.
- ✓
check_deepfakecalls/api/v1/verdict-only: a short answer, no report. Limited to 10 calls per hour per key. - ✓
analyze_asyncsubmits a job and returns ajob_id;get_jobreads its status and result. Only the key that submitted a job can read it. - ✓
analyze_voiceruns a full analysis in one call and can take minutes: not for an agent that is waiting. - ✓The MCP server refuses locally, and sends nothing, unless
consent_data_processingandconsent_voice_processingare both true. It runs on your side over stdio; no remote MCP endpoint is offered.
Access
A paid key from the first call.
There is no free tier for automated agents: every analysis uses compute. Monthly quotas depend on the plan, and per-minute and per-day limits also apply. Access is opened on request.
Put a pause in front of the irreversible step.
Tell us what your agent does and which actions it takes on a voice instruction. We reply with access terms for the API and the MCP server.