From server-side code, authenticate the Cartesia TTS WebSocket with the X-API-Key header and a cartesia_version value. From browser or mobile clients, mint a short-lived access token server-side and pass that instead of the API key. Always include cartesia_version, and handle the done and flush-done responses so you know when a generation actually finished.

Context: Official Cartesia docs (TTS WebSocket API reference): documents the two-tier auth model agents get wrong. Calling the TTS WebSocket from a trusted server uses the X-API-Key header; calling from a browser or client app must use a short-lived access token instead, so the API key never ships to the client. The cartesia_version parameter is required on the connection, and the API reference lists the full message contract: generation requests, cancel-context requests, audio chunks, flush-done and done signals, plus word-level and phoneme-level timestamp responses.