Skip to main content

Troubleshooting: voice inference credential rejected

When you register a new speech-to-text (STT) or text-to-speech (TTS) provider key — or rotate an existing one — under Settings → Voice inference provider, the request can return a 422 with error code VOICE_CREDENTIAL_PROVIDER_REJECTED. This page tells you why it happens and how to fix it.

Symptom

You open Settings → Voice inference provider, select a provider (Deepgram for STT, Cartesia or ElevenLabs for TTS), paste the API key, and submit. The request fails with:
The same error fires on credential rotation (POST /voice-provider-credential/:kind/rotate) as well as initial registration — the two operations share the same live-probe step.

What it means

Orbit probes every credential against the provider’s API before it is persisted. When you submit a key on the register or rotate endpoint, the platform sends a lightweight validation request to the provider (for example, a Deepgram project-list call or a Cartesia voice-list call). If the provider rejects that probe — returning an HTTP 401, 403, or similar — the platform returns VOICE_CREDENTIAL_PROVIDER_REJECTED and the key never reaches the dashboard. This probe guards against saved-but-unusable credentials: a key that the provider refuses at registration time will also fail at inference time, and a broken credential silently degrades every STT or TTS call your agents make. Probe-first registration catches the problem before any call is affected. The probe response body — including the HTTP status the provider returned — is available in details.provider_status on the error envelope, matching what you would see if you called the provider directly with that key.

Fix

  1. Verify the key in the provider dashboard. Log in to the provider’s console (for example, the Deepgram console at console.deepgram.com) and confirm the key you pasted is active, not expired, and not revoked.
  2. Check the key scope. The key must have permissions for the inference feature you are registering:
    • STT keys (Deepgram) need access to the transcription or speech-to-text API.
    • TTS keys (Cartesia, ElevenLabs) need access to the text-to-speech or voice-synthesis API. A key scoped only to billing or account management will be rejected.
  3. Re-run the register or rotate operation with the corrected key. If the provider accepts the probe this time, the credential is saved and your agents use it on the next turn.

What not to do

Do not try to work around this by editing a provider label or toggling a different field in the inference-provider settings. The probe runs on every register and rotate call, not on label edits, and a key the provider refuses will never be used for inference — bypassing the probe would mean your agents fail silently at runtime with a harder-to-triage error.

See also