Voicecan Developer Kit

Voicecan Developer Kit

$99.00 $189.00

Voicecan captures audio locally and gives developers a simple, reliable hardware platform for building their own applications and workflows.

  • 12.8 g ultra-lightweight design — small enough to wear
  • Up to 100 hours of battery life — built for long-running use cases
  • 64 GB internal storage — keep recordings on-device
  • Lookback Mode — save what just happened
  • Seamless Sync — automatically sync over wireless connections

Own Your Data

Your recordings stay under your control. Connect Voicecan to your own infrastructure and decide where your data goes, how it's processed, and what happens next.

Pre-order now — Shipping begins in late September.

Reserve your spot with a fully refundable $99 deposit. You'll receive:

  • 47.6% off the regular price — save $90.
  • Cancel your pre-order anytime before shipment

Voicecan recording devices in a softly lit product scene
Voicecan Developers

完整的自托管录音解决方案A complete self-hosted recording solution

从录音硬件,
到你的 Agent
From recording hardware
to your Agent

Voicecan 将录音设备、私有部署服务器、自动同步与开放平台集成在一起;录音保存在你自己的基础设施,并通过 MCP、REST 和 Webhook 接入应用与 AI 工作流 Voicecan combines recording hardware, a self-hosted server, automatic synchronization and an open platform; recordings stay on your infrastructure and connect to applications and AI workflows through MCP, REST and Webhooks

DeviceYour serverMCPAgent / App
AI INSTALL PROMPT
请安装并运行完整的 Voicecan 开发环境。

主程序包:
https://github.com/voicecan/device-platform

Demo 应用包:
https://github.com/voicecan/voicecan-studio

先完整阅读两个仓库的 README.md 和 AGENTS.md。
检查环境后先安装 Device Platform,再运行 Studio Demo。
完成后执行健康检查,并告诉我访问地址、验证结果和剩余手动步骤。Install and run the complete Voicecan developer environment.

Main platform package:
https://github.com/voicecan/device-platform

Demo application package:
https://github.com/voicecan/voicecan-studio

Read README.md and AGENTS.md in both repositories first.
Install Device Platform, then run Studio Demo.
Run the health checks and report the URLs, verification results and remaining manual steps.
Platform + Studio · 完整环境Platform + Studio · complete environment

Docs / Device Platform / Architecture

一段录音,如何进入你的应用 How a recording reaches your application

这套系统分成两个边界清晰的包:服务器平台负责数据与权限,Demo 应用负责把数据变成可审核、可继续处理的工作结果。 The system has two clear boundaries: the server platform owns data and permissions, while the Demo app turns that data into reviewable, actionable work.

01 · DEVICE PLATFORM

自托管服务器平台Self-hosted server platform

负责设备接入、录音同步、Group 授权边界,以及 MCP、REST 和 Webhook 接口。它是你自己部署、自己保存数据的基础设施。Owns device access, recording sync, Group authorization, and the MCP, REST and Webhook interfaces. This is the infrastructure you deploy and control.

voicecan/device-platform
02 · STUDIO DEMO

下游 Demo 应用Downstream Demo application

运行在平台之上,负责转写处理、场景选择、结果审核和动作预览。它使用独立 Application,不继承平台管理员权限。Runs on top of the platform for transcription, scene selection, review and action previews. It uses its own Application and never inherits platform-admin access.

voicecan/voicecan-studio

安装、初始化或连接过程中遇到问题?联系 support@voicecan.ai Need help with installation, setup or connecting the platform? Contact support@voicecan.ai

01
Voicecan DeviceBLE Provision · WSS Bind
在安全浏览器环境中通过 Web Bluetooth 完成配网;设备随后反向连接你部署的服务器。Provision through Web Bluetooth in a secure browser context; the device then opens a reverse connection to your server.
02
Device PlatformDiscover · Sync · Verify
发现录音、执行有序同步,并以长度和 SHA-256 校验不可变文件;完整录音不会被缓存在内存里。Discover recordings, run ordered synchronization, and verify immutable files by length and SHA-256 without buffering a complete recording in memory.
03
Your Disk / S3SQLite Edge · Production path
个人和小团队可从 SQLite + 本地文件起步;规模化部署可切换 PostgreSQL + S3 路径。Individuals and small teams can start with SQLite and local files, then move to the PostgreSQL and S3 production path.
04
MCP · REST · WebhookOne permission catalog
本地 stdio MCP、远程 OAuth MCP、REST 与签名 Webhook 共用权限、配额和审计;可搜索元数据、查询事件、触发同步并申请短时下载授权。Local stdio MCP, remote OAuth MCP, REST and signed Webhooks share permissions, quotas and audit for metadata search, events, reviewed sync and temporary download grants.
05
Studio Demo / Your AppYour processing boundary
平台在交付受控录音与事件后停止;转写、总结、检索、Agent 编排和业务出口由你的下游应用决定。The platform stops after controlled recording and event delivery; transcription, summaries, search, agent orchestration and business delivery belong to your downstream app.
MCP BOUNDARY

MCP 工具只返回录音元数据与一次性临时下载链接,不返回音频、Base64 或可被 Host 自动读取的持久资源;凭证只存在 Host 的安全环境中,不作为 Tool 参数传入。MCP tools return recording metadata and one-use temporary download links—not audio, Base64 or persistent resources a Host may auto-read. Credentials stay in the Host's secret environment, never in Tool arguments.

02 · Admin setup

首次初始化与管理边界First-time setup and administration boundaries

服务首次启动后会生成一个仅所有者可读的高熵 Setup Token。它只用于创建第一位 System Admin;初始化完成后,日常操作都在 /admin 中进行。On first start, the service creates a high-entropy, owner-readable Setup Token. It is used only to create the first System Admin; ongoing work then happens in /admin.

安全原则:Security rule: 日志只显示 Token 文件路径。不要把 Token 放进源代码、Shell 历史、聊天记录或支持包。Logs reveal only the token file path. Never place the token in source code, shell history, chat or support bundles.
01

创建第一位管理员Create the first administrator

打开 /admin,使用安装目录 data/setup-token 中的一次性 Token 完成初始化。Open /admin and complete setup with the one-use token stored at data/setup-token.

02

创建 GroupCreate a Group

Group 是设备、录音、事件和成员的授权边界。录音文件权限永远由设备当前所属的 Group 推导。A Group is the authorization boundary for devices, recordings, events and members. Recording access is always derived from the Device's current Group.

03

创建 ApplicationCreate an Application

每个下游应用、机器人或工作流都应拥有独立的 Application、通道、权限、配额与凭证。Give every downstream app, bot or workflow its own Application, channels, permissions, quotas and credentials.

04

只授予必要权限Grant least privilege

凭证只能选择 Application 权限的子集。密钥只显示一次;暂停 Application 或撤销凭证会在下一次请求立即生效。A credential can select only a subset of its Application permissions. Secrets are shown once; suspensions and revocations take effect on the next request.

03 · Connect a device

用浏览器连接一台设备Connect a device from the browser

Device Platform 的管理端负责授权,具备蓝牙的用户电脑负责 BLE 操作。服务器部署在 NAS 或无蓝牙主机上也没有关系。Admin owns authorization while the user's Bluetooth-capable computer performs BLE operations. The server itself can run on a NAS or another host without Bluetooth.

客户端要求:Client requirement: 使用支持 Web Bluetooth 的最新版 Chrome 或 Edge,并通过 HTTPS 访问。iOS/iPadOS、Safari、Firefox 和应用内 WebView 不属于支持范围。Use a current Chrome or Edge release with Web Bluetooth over HTTPS. iOS/iPadOS, Safari, Firefox and embedded WebViews are not supported.
01

创建绑定凭证Create a binding credential

在 /admin?view=provision 选择目标 Group,创建有效期 30 分钟、与来源绑定的设备绑定凭证。Select the target Group in /admin?view=provision and create a 30-minute, origin-bound binding credential.

02

选择附近设备Select a nearby device

点击页面按钮唤起浏览器设备选择器。连接页依次建立 GATT、读取身份、领取绑定 Token,并完成安全握手。Use the page button to open the browser device picker. The connector establishes GATT, reads identity, obtains a binding token and completes the secure handshake.

03

配置网络并等待上线Configure the network and wait online

保留现有网络或写入新的 Wi-Fi。设备必须能访问 Platform Server;页面会等待服务器确认设备上线。Keep the existing network or configure new Wi-Fi. The Device must be able to reach the Platform Server; the page waits for authoritative online confirmation.

04 · Applications & permissions

为应用开放最小必要能力Expose only the capabilities an application needs

REST、stdio MCP、远程 MCP 和 Webhook 使用同一套 Permission Catalog、配额与审计。Application 属于一个 Group,凭证不能越过这个边界。REST, stdio MCP, remote MCP and Webhooks share one Permission Catalog, quota and audit model. An Application belongs to one Group and its credentials cannot cross that boundary.

PERMISSION允许的能力CAPABILITY
devices:read读取设备元数据与已审核能力Read Device metadata and reviewed capabilities
devices:sync创建受控的录音同步命令Create the reviewed recording synchronization command
recordings:read搜索和读取录音元数据,不包含音频Search and read recording metadata without audio bytes
recordings:download_link:create创建一次性临时下载授权Create a one-use temporary download grant
events:read读取事件元数据Read event metadata
REST

服务到服务调用Service-to-service access

启用 rest,创建 api_token,并先调用 GET /api/v1/capabilities 确认可用能力。Enable rest, create an api_token, then call GET /api/v1/capabilities before enabling an integration.

Webhook

接收录音事件Receive recording events

按事件类型、设备或录音属性过滤签名 Webhook;消费端必须先验证原始请求体,再解析与去重。Filter signed Webhooks by event type, Device or recording attributes. Verify the raw request body before parsing and deduplicating.

05 · Studio Demo 配置05 · Studio Demo setup

把初始化页面里的每一个值准备好Prepare every value required by Studio setup

Studio 不是自动获得整个平台的权限。先在 Device Platform 为它创建一个独立 Application、一次性显示的 API Token 和签名 Webhook,再根据运行档位准备处理服务。下面的路径与字段和 Demo 当前界面一一对应。Studio does not inherit platform-wide access. Create a dedicated Application, a one-time API Token and a signed Webhook in Device Platform, then prepare processors for the selected deployment profile. The paths below map directly to the current Demo fields.

先创建平台侧三件套:Create these three platform resources first: Application、api_token、Webhook endpoint。只有 External 档位需要填写 HTTP ASR 与 Summary 服务。Application, api_token and a Webhook endpoint. Only the External profile requires HTTP ASR and Summary services.
01

创建 Studio ApplicationCreate the Studio Application

进入 /admin → Open platform → Create application,选择录音所在 Group,启用 rest 与 webhook,只授予 recordings:read 和 recordings:download_link:create。Open /admin → Open platform → Create application, select the recording Group, enable rest and webhook, then grant only recordings:read and recordings:download_link:create.

02

创建应用令牌Create the Application Token

在该 Application 的 Credentials 页创建 api_token。立即复制只显示一次的 vcd_app_...,填入 Studio 的「应用令牌」。Create an api_token in the Application's Credentials tab. Immediately copy the one-time vcd_app_... value into Studio's Application Token field.

03

创建签名 WebhookCreate the signed Webhook

在 Webhooks 页创建 https://<studio-host>/webhooks/voicecan,事件选择 file.synced 与 recording.deleted。复制只显示一次的 vce_... 到「Webhook 密钥」。Create https://<studio-host>/webhooks/voicecan in Webhooks and select file.synced plus recording.deleted. Copy the one-time vce_... value into Webhook Secret.

04

保存并运行 DoctorSave and run Doctor

External 首次启动打开 http://127.0.0.1:8811 填表;验证通过后配置以 0600 权限原子写入。保存后运行 Doctor,再刷新授权来源。On the first External start, open http://127.0.0.1:8811. Validated configuration is atomically written with 0600 permissions. Run Doctor, then refresh authorized sources.

Channels     rest, webhook
Permissions  recordings:read
             recordings:download_link:create
Webhook      https://<studio-host>/webhooks/voicecan
Events       file.synced, recording.deleted
Studio 字段Studio field从哪里获得Source填写规则How to fill
平台地址Platform URL已部署的 Device PlatformYour Device Platform deployment填写 API 基础地址,例如 https://device.example.com,末尾不需要斜杠。Use the API base URL, such as https://device.example.com, without a trailing slash.
应用令牌Application tokenApplication → CredentialsApplication → Credentials创建 api_token 后立即复制 vcd_app_...;现有 Secret 无法再次查看。Create an api_token and immediately copy vcd_app_...; an existing secret cannot be revealed again.
Webhook 密钥Webhook secretApplication → WebhooksApplication → Webhooks创建 Endpoint 时复制 vce_...。必须与指向 Studio 的 Endpoint 属于同一个 Application。Copy vce_... when creating the endpoint. It must belong to the same Application that points to Studio.
下一个 Webhook 密钥Next Webhook secretWebhooks → Rotate secretWebhooks → Rotate secret日常留空。轮换期间把新 Secret 放这里,使旧、新签名同时可验证;切换完成后再更新主密钥。Leave blank normally. During rotation, place the new secret here so old and new signatures both verify; promote it after activation.
ASR / Summary 地址与 KeyASR / Summary URLs and keys你的 HTTP 处理服务Your HTTP processors仅 External 使用;地址必须能被 Studio 主机访问。Key 是否必填由对应服务决定。External only. Endpoints must be reachable from the Studio host; whether keys are required depends on each processor.
摘要模型 / 提示词版本Summary model / prompt version你的 Summary 服务契约Your Summary service contract填写服务实际使用的模型标识和 Prompt 版本,用于结果溯源,不要随意沿用占位值。Use the actual model identifier and Prompt version for result lineage; do not retain placeholder values blindly.
Courier / Studio 公开地址Courier / Studio public URL可选外发配置Optional delivery configuration不需要消息外发时保持关闭。启用后填写 Courier Key;公开地址填写外部可访问的 Studio HTTPS 基础地址。Keep delivery disabled when unused. If enabled, provide a Courier key and the externally reachable Studio HTTPS base URL.
结果保留天数Result retention days你的数据保留策略Your retention policy默认 30 天;根据磁盘容量、备份与合规策略调整。Defaults to 30 days; adjust for storage, backup and compliance requirements.
External · :8811

连接已有处理服务Connect existing processors

浏览器 Setup 页面负责验证 Platform、HTTP ASR、HTTP Summary 与可选 Courier。适合已有模型 API 或需要独立扩缩容的部署。The browser Setup page validates Platform, HTTP ASR, HTTP Summary and optional Courier. Use it with existing model APIs or independently scaled processors.

Local Full · :8815

本地模型由安装脚本准备Local models are prepared by the installer

运行 studio/scripts/setup-local-linux.sh 或 Windows 安装脚本;Faster-Whisper、Qwen3-4B GGUF、模型路径与校验由脚本准备。仍需在 .env 提供平台地址、应用令牌和 Webhook 密钥。Run studio/scripts/setup-local-linux.sh or the Windows installer. It prepares Faster-Whisper, Qwen3-4B GGUF, model paths and verification. Platform URL, Application Token and Webhook Secret still belong in .env.

Voicecan Studio External setup and diagnostics form
VOICECAN STUDIO · SETUP & DIAGNOSTICS · REAL UIEXTERNAL PROFILE
06 · MCP

让 Agent 使用你的设备与录音数据Let agents use your device and recording data

平台提供两个互相隔离的 MCP 权限面:Local Admin MCP 用于操作本机安装;Application MCP 只暴露某个应用被授权的设备、录音、命令和事件能力。The platform exposes two isolated MCP permission planes: Local Admin MCP operates the local installation, while Application MCP exposes only the Device, recording, command and event capabilities granted to one Application.

Local operator

Local Admin MCP

使用所有者本地自动化通道管理服务状态、Doctor、绑定意图、Application 和 MCP 连接计划;不会提供破坏性命令。Use the owner-local automation channel for service status, Doctor, binding intents, Applications and MCP connection plans. Destructive commands are omitted.

Least privilege

Application MCP

为 Agent 创建独立 Application 与 mcp_stdio_token。它不能获得主机管理权限,也不能把凭证作为 Tool 参数传入。Create a dedicated Application and mcp_stdio_token for an agent. It cannot gain host administration or pass credentials as Tool arguments.

voicecan-device mcp connect --application <application-id> --client generic --output json

该命令创建 stdio 凭证,将它保存为仅所有者可读的 Secret Reference,并返回不含明文 Token 的 Host 配置。远程 MCP 则使用 OAuth、PKCE 与显式授权绑定到一个可访问的 Application。This command creates a stdio credential, stores it as an owner-only Secret Reference and returns a Host configuration without a plaintext token. Remote MCP instead uses OAuth, PKCE and explicit consent bound to an accessible Application.

Remote MCP · OAuth consent

Codex 连接前,先明确授权范围Define the permission boundary before Codex connects

远程连接会展示目标 Application、请求权限与本地回调地址。用户确认后,Agent 才能在这组明确的权限内访问设备、录音、命令和事件。The remote flow shows the target Application, requested permissions and local callback. Only after explicit consent can an agent access Devices, recordings, commands and events within that boundary.

  1. 01确认要连接的 ApplicationConfirm the target Application
  2. 02检查最小必要权限Review the minimum required permissions
  3. 03确认回调地址并授权连接Verify the callback and authorize
Codex remote MCP authorization page showing Application permissions and callback address
REMOTE MCP · CODEX AUTHORIZATION · REAL UI
devices.listdevices.getdevices.get_capabilitiesdevices.synccommands.getrecordings.searchrecordings.getrecordings.create_download_linkevents.list
07 · Recordings

安全获取一段录音Retrieve a recording safely

Open Platform API 和 MCP 都不会直接携带录音字节。应用先查询元数据,再创建短时、一次性的 Download Grant;授权消费时会重新检查 Application、凭证、录音状态与设备当前 Group。Neither Open Platform APIs nor MCP carry recording bytes. An app first queries metadata, then creates a short-lived, one-use Download Grant. Consumption rechecks the Application, credential, recording lifecycle and the Device's current Group.

POST /api/v1/recordings/file_xxx/download-links
Authorization: Bearer vcd_app_...
Idempotency-Key: stable-request-id
Content-Type: application/json

{"purpose":"download","ttl_seconds":300,"reason":"Reviewed export"}
01

搜索录音元数据Search recording metadata

根据 Device、状态、属性或时间范围搜索;响应包含不可变媒体信息与资源版本,不包含音频。Search by Device, status, attribute or time range. Responses include immutable media facts and resource versions, never audio bytes.

02

创建一次性授权Create a one-use grant

使用稳定的 Idempotency Key 创建 Download Grant。完整临时 URL 不进入日志、审计、Webhook 或 MCP Resource。Create a Download Grant with a stable Idempotency Key. Full temporary URLs are excluded from logs, audit, Webhooks and MCP Resources.

03

流式下载并校验Stream and verify

按返回的长度、SHA-256 与 Range 能力流式处理文件。授权过期后创建新的 Grant,不复用旧链接。Stream the file using its returned length, SHA-256 and Range capability. Create a new Grant after expiry rather than reusing an old URL.

08 · Operations

上线与日常运维Production and day-two operations

公开部署需要明确区分应用/API 地址和设备 WSS 地址。备份必须同时覆盖数据库、录音对象和部署密钥;只复制数据库不构成有效备份。Public deployments require explicit application/API and Device WSS URLs. A valid backup covers the database, recording objects and deployment keys; a database-only copy is not sufficient.

  • TLS / WSS通过经过审核的反向代理终止 TLS 1.2+,保留 /device/v1/ws 的 WebSocket Upgrade,并关闭大文件代理缓冲。Terminate TLS 1.2+ at a reviewed reverse proxy, preserve WebSocket Upgrade for /device/v1/ws, and disable proxy buffering for large files.
  • BACKUP定期执行 Backup Create 和 Verify;只在服务器停止时恢复到新的空目录,并抽样读取不可变录音验证结果。Run Backup Create and Verify regularly. Restore only while stopped into a new empty directory, then sample an immutable recording.
  • UPGRADE先停止或排空服务、验证备份、记录版本与校验信息,再显式执行迁移。不要让两个 SQLite 实例共享同一数据目录。Drain or stop, verify a backup, record versions and checksums, then run migrations explicitly. Never run two SQLite instances against one data directory.
  • LOGS / METRICS日志默认滚动并脱敏;将 /metrics 保留在内网、回环地址或 VPN 中,不要直接暴露到公网。Logs rotate and redact secrets by default. Keep /metrics on loopback, a private network or VPN rather than exposing it publicly.
01 · Individual · Studio workflow

一个人,也能拥有完整的录音工作台A complete recording workspace for one person

录音从设备进入自己的服务器,在 Studio 中完成处理、场景选择、结果审核和动作预览。适合采访、研究、巡检、创作等个人工作,不需要先搭建团队协作体系。Recordings move from the Device to your own server, then through processing, Scenario selection, review and action preview in Studio—without first building a team collaboration stack.

  • 01录音和处理结果保存在自己的服务器Keep recordings and results on your own server
  • 02按用途切换 Voice Inbox、Field Report 等场景Switch between Voice Inbox, Field Report and other Scenarios
  • 03人工确认后导出,或交给 Agent 继续处理Review before exporting or handing work to an agent
YOUR RECORDING → STUDIO → REVIEW → NEXT ACTION
Voicecan Studio recording processing, Field Report review and action preview interface