Sign in
Signing in is the same OAuth step as creating an account — new users land on the sign-up screen.1
Sign in
The default flow opens your browser for OAuth and captures the token on a loopback port:For CI or headless machines, save a long-lived API key instead:
2
Confirm what's configured
--json for { configured, recommended_action, offline_engines } in scripts.~/.heygen/credentials (mode 0600) — no per-repo .env to manage. Browser OAuth is a hyperframes auth login feature. The separate heygen CLI (its own install — there’s no npx heygen) is API-key-only, so heygen auth login just stores a key you paste. Both read the same ~/.heygen/credentials, so signing in with one carries to the other.
How the HeyGen credential resolves
Bundled media workflows use the HeyGen credential for hosted TTS and music / sound retrieval. It resolves first-match-wins:HEYGEN_API_KEY— environment variableHYPERFRAMES_API_KEY— alias, for parity with other tools~/.heygen/credentials— written byhyperframes auth login(orheygen auth login)
HEYGEN_CONFIG_DIR, or a different backend with HEYGEN_API_URL.
Providers used by agent workflows
After the workflow’s sign-in preflight, each media capability uses the first available provider in its order. Voice, music, and sound have offline fallbacks; capture descriptions are optional and are skipped when no supported vision key is available.
Run
npx hyperframes doctor to check which local dependencies are installed.
The media workflows run hyperframes auth status before generation and tell
you which path they will use.
For Gemini narration, explicitly ask your agent to use Gemini TTS. The shared
audio workflow supports 3.8 Flash and Flash-Lite, 3.1 Flash Preview, and 2.5 Pro
and Flash Preview. Gemini remains an explicit choice; configuring credentials
does not change the automatic voice-provider order above.
Choose one authentication method:
- API key: set
GEMINI_API_KEYorGOOGLE_API_KEYin your environment or project.env. This path needs no Python dependencies. - Service account: install
google-authandrequestsin your Python 3 environment, then setGOOGLE_APPLICATION_CREDENTIALSto the absolute path of your service-account JSON file. Alternatively, inject the JSON throughGCS_CREDSfrom your secret manager. SetGOOGLE_CLOUD_PROJECTto the quota project when it differs from the service account’s project.
generative-language.retriever scope. Keys and tokens
are never placed in compositions or saved audio metadata.
Both methods call the Gemini Developer Interactions API. Your project needs
access to that API and the requested model. Cloud Text-to-Speech and Vertex AI
have separate model availability. This helper accepts service-account JSON,
not user ADC files or metadata-server credentials.
See Gemini voiceover.
npx hyperframes tts itself is the local Kokoro CLI. Hosted HeyGen and
ElevenLabs and Gemini voices are selected by the bundled media workflow helpers, not by
that command.Working offline
No key configured is a normal state for local work. After their dependencies and model files are installed, these fallbacks run locally:- Voice — Kokoro-82M (54 voices), with Whisper for word-level caption alignment.
- Music — MusicGen (
facebook/musicgen-small). - Sound effects — a bundled library.
Publishing without an account
npx hyperframes publish works while signed out. It uploads the project and
prints a URL containing a claim token. Open that URL and authenticate in the web
app to claim the project.
Sign in with npx hyperframes auth login before publishing when you want the CLI
to own the project immediately, update the same URL with --update, or publish
to a shared space with --space.