Sign inSign up

hwdsl2/whisper-live-server

By hwdsl2

β€’Updated 4 days ago

ScribeCrate Live: real-time transcription with WhisperLive. WebSocket + OpenAI-compatible REST API.

Image
Machine learning & AI
Developer tools
Data science
1

10K+

hwdsl2/whisper-live-server repository overview

⁠ScribeCrate Live

Open-source, self-hosted real-time transcription server.

Build Status Β Docker Pulls Β Open In Colab

GitHub: https://github.com/hwdsl2/scribecrate-live⁠

ScribeCrate Live is a self-hosted real-time speech-to-text server powered by WhisperLive⁠ and faster-whisper⁠. It provides WebSocket transcription for live microphone audio and audio streams, plus an OpenAI-compatible REST API for audio files. Deploy with Docker on CPU or an NVIDIA GPU. The image is based on Debian (python:3.12-slim).

Previously known as docker-whisper-live, maintained by hwdsl2⁠. The Docker image remains hwdsl2/whisper-live-server.

Features:

  • Real-time WebSocket transcription: transcribe live microphone audio or audio streams with progressive segment updates.
  • OpenAI-compatible API: POST /v1/audio/transcriptions for uploaded-file transcription from compatible OpenAI SDKs and apps.
  • Private, local processing: audio stays on your server and is not sent to third parties.
  • Voice activity detection (VAD): automatically skips silence for faster, cleaner transcription.
  • Whisper models: supports all Whisper models, including tiny, base, small, medium, large-v3, large-v3-turbo and more.
  • CPU and GPU support: run on CPU or use the :cuda image for NVIDIA GPU acceleration.
  • Offline operation: run without internet access using pre-cached models (WHISPERLIVE_LOCAL_ONLY).
  • Automated builds: images are automatically built and published through GitHub Actions⁠.

Also available as part of the Self-Hosted AI Stack⁠, which deploys a complete self-hosted AI stack with a single command.

πŸ“˜ The Self-Hosted AI Builder’s Guide⁠ is a practical guide to building, securing, and operating your own private AI stack.

Also available:

⁠Quick start

Use this command to set up a ScribeCrate Live server:

docker run \
    --name whisper-live \
    --restart=always \
    -v whisper-live-data:/var/lib/whisper-live \
    -p 9090:9090 \
    -p 8000:8000 \
    -d hwdsl2/whisper-live-server
GPU quick start (NVIDIA CUDA)

If you have an NVIDIA GPU, use the :cuda image for hardware-accelerated inference:

docker run \
    --name whisper-live \
    --restart=always \
    --gpus=all \
    -v whisper-live-data:/var/lib/whisper-live \
    -p 9090:9090 \
    -p 8000:8000 \
    -d hwdsl2/whisper-live-server:cuda

Requirements: NVIDIA GPU, NVIDIA driver⁠ 575.57.08+ (Linux) or 576.57+ (Windows), and the NVIDIA Container Toolkit⁠ installed on the host. The :cuda image is linux/amd64 only.

Note: For internet-facing deployments, use a reverse proxy⁠ to add HTTPS. Also replace -p 9090:9090 -p 8000:8000 with -p 127.0.0.1:9090:9090 -p 127.0.0.1:8000:8000 in the docker run command above, to prevent direct access to the unencrypted ports.

The Whisper base model (~145 MB) is downloaded and cached on first client connection. Check the logs to confirm the server is ready:

docker logs whisper-live

Once you see "ScribeCrate Live real-time transcription server is ready":

Fresh persistent installations enable API-key authentication automatically. Retrieve the key:

scribe_live_api_key="$(docker exec whisper-live whisper_live_manage --getkey)"

Connect a real-time WebSocket client:

ws://your_server_ip:9090/?token=YOUR_API_KEY

Or transcribe a file via the REST API:

curl http://your_server_ip:8000/v1/audio/transcriptions \
    -H "Authorization: Bearer $scribe_live_api_key" \
    -F [email protected] \
    -F model=whisper-1

Response:

{"text": "Your transcribed text appears here."}

Tip: Need a sample audio file to test the REST API? Download this English speech sample (WAV, MIT License) from the Azure Samples⁠ repository:

curl -L -o sample_speech.wav \
    "https://github.com/Azure-Samples/cognitive-services-speech-sdk/raw/master/sampledata/audiofiles/katiesteve.wav"

curl http://your_server_ip:8000/v1/audio/transcriptions \
    -H "Authorization: Bearer $scribe_live_api_key" \
    -F file=@sample_speech.wav \
    -F model=whisper-1

⁠ScribeCrate vs. ScribeCrate Live

ScribeCrate⁠ScribeCrate Live
Use caseTranscribe complete audio filesLive microphone / real-time audio streaming
ProtocolHTTP RESTWebSocket (streaming) + HTTP REST
LatencyJSON after processing; segments via SSEProgressive segment updates
Best forMeeting recordings, uploaded audioBrowser capture, RTSP streams, live captions
Image size~190 MB (~3.1 GB for :cuda)~750 MB (~4.5 GB for :cuda)

⁠Community

Self-hosted VPN & networking projects

⁠Requirements

  • A Linux server (local or cloud) with Docker installed
  • Supported architectures: amd64 (x86_64), arm64 (e.g. Raspberry Pi 4/5, AWS Graviton)
  • Minimum RAM: ~700 MB free for the default base model (see model table⁠)
  • Internet access for the initial model download (the model is cached locally afterwards). Not required if using WHISPERLIVE_LOCAL_ONLY=true with pre-cached models.

For GPU acceleration (:cuda image):

For internet-facing deployments, see Using a reverse proxy⁠ to add HTTPS.

⁠Download

Get the trusted build from the Docker Hub registry⁠:

docker pull hwdsl2/whisper-live-server

For NVIDIA GPU acceleration, pull the :cuda tag instead:

docker pull hwdsl2/whisper-live-server:cuda

Alternatively, you may download from Quay.io⁠:

docker pull quay.io/hwdsl2/whisper-live-server
docker image tag quay.io/hwdsl2/whisper-live-server hwdsl2/whisper-live-server

Supported platforms: linux/amd64 and linux/arm64. The :cuda tag supports linux/amd64 only.

⁠Environment variables

All variables are optional. Fresh installs with a mounted /var/lib/whisper-live volume auto-generate an API key. Existing installs without a key remain open for backward compatibility.

This Docker image uses the following variables, that can be declared in an env file (see example⁠):

VariableDescriptionDefault
WHISPERLIVE_MODELWhisper model to use. See model table⁠ for options.base
WHISPERLIVE_LANGUAGEDefault transcription language. BCP-47 code (e.g. en, fr, de, zh, ja) or auto to autodetect.auto
WHISPERLIVE_PORTWebSocket port for real-time streaming clients (1–65535).9090
WHISPERLIVE_REST_PORTHTTP port for the OpenAI-compatible REST API (1–65535).8000
WHISPERLIVE_MAX_CLIENTSMaximum number of simultaneous WebSocket client connections.4
WHISPERLIVE_MAX_CONNECTION_TIMEMaximum WebSocket connection duration in seconds. Clients exceeding this are disconnected.600
WHISPERLIVE_USE_VADVoice Activity Detection default. For the faster_whisper backend, VAD is controlled per WebSocket client via the connection handshake use_vad field.true
WHISPERLIVE_THREADSCPU threads for inference. Set to the number of physical cores for best latency.2
WHISPERLIVE_LOG_LEVELLog level: DEBUG, INFO, WARNING, ERROR, CRITICAL.INFO
WHISPERLIVE_API_KEYOptional API key. Fresh persistent installs auto-generate one. REST requests must include Authorization: Bearer <key>; WebSocket clients can use ?token=<key>. Set explicitly empty to disable authentication.Auto-generated for fresh persistent installs
WHISPERLIVE_LOCAL_ONLYWhen set to any non-empty value (e.g. true), disables all HuggingFace model downloads. For offline or air-gapped deployments with pre-cached models.(not set)
WHISPERLIVE_DISABLE_USAGE_COUNTSSet to 1 to disable anonymous aggregate usage counts.(not set)

Note: In your env file, you may enclose values in single quotes, e.g. VAR='value'. Do not add spaces around =. If you change WHISPERLIVE_PORT or WHISPERLIVE_REST_PORT, update the -p flags in the docker run command accordingly.

Example using an env file:

cp whisper-live.env.example whisper-live.env
# Edit whisper-live.env with your settings, then:
docker run \
    --name whisper-live \
    --restart=always \
    -v whisper-live-data:/var/lib/whisper-live \
    -v ./whisper-live.env:/whisper-live.env:ro \
    -p 9090:9090 \
    -p 8000:8000 \
    -d hwdsl2/whisper-live-server

The env file is bind-mounted into the container, so changes are picked up on every restart without recreating the container.

Alternatively, pass it with --env-file
docker run \
    --name whisper-live \
    --restart=always \
    -v whisper-live-data:/var/lib/whisper-live \
    -p 9090:9090 \
    -p 8000:8000 \
    --env-file=whisper-live.env \
    -d hwdsl2/whisper-live-server

⁠Using docker-compose

cp whisper-live.env.example whisper-live.env
# Edit whisper-live.env as needed, then:
docker compose up -d
docker logs whisper-live

Example docker-compose.yml (already included):

services:
  whisper-live:
    image: hwdsl2/whisper-live-server
    container_name: whisper-live
    restart: always
    ports:
      - "9090:9090/tcp"  # WebSocket β€” for a host-based reverse proxy, change to "127.0.0.1:9090:9090/tcp"
      - "8000:8000/tcp"  # REST API  β€” for a host-based reverse proxy, change to "127.0.0.1:8000:8000/tcp"
    volumes:
      - whisper-live-data:/var/lib/whisper-live
      - ./whisper-live.env:/whisper-live.env:ro

volumes:
  whisper-live-data:
    name: whisper-live-data

Note: For internet-facing deployments, use a reverse proxy⁠ to add HTTPS. Also change "9090:9090/tcp" and "8000:8000/tcp" to their 127.0.0.1: equivalents in docker-compose.yml.

Using docker-compose with GPU (NVIDIA CUDA)

A separate docker-compose.cuda.yml is provided for GPU deployments:

cp whisper-live.env.example whisper-live.env
# Edit whisper-live.env as needed, then:
docker compose -f docker-compose.cuda.yml up -d
docker logs whisper-live

Example docker-compose.cuda.yml (already included):

services:
  whisper-live:
    image: hwdsl2/whisper-live-server:cuda
    container_name: whisper-live
    restart: always
    ports:
      - "9090:9090/tcp"  # WebSocket β€” for a host-based reverse proxy, change to "127.0.0.1:9090:9090/tcp"
      - "8000:8000/tcp"  # REST API  β€” for a host-based reverse proxy, change to "127.0.0.1:8000:8000/tcp"
    volumes:
      - whisper-live-data:/var/lib/whisper-live
      - ./whisper-live.env:/whisper-live.env:ro
    deploy:
      resources:
        reservations:
          devices:
            - driver: nvidia
              count: 1
              capabilities: [gpu]

volumes:
  whisper-live-data:
    name: whisper-live-data

⁠WebSocket streaming

See WebSocket streaming⁠.

⁠REST API reference

The REST API at port 8000 is compatible with OpenAI's audio transcription endpoint⁠. For clients using the OpenAI SDK, configure the base URL and your server's API key:

Fresh persistent installations require an API key. Retrieve it for the following examples:

scribe_live_api_key="$(docker exec whisper-live whisper_live_manage --getkey)"

export OPENAI_BASE_URL="http://your_server_ip:8000/v1"
export OPENAI_API_KEY="$scribe_live_api_key"

If API key authentication is disabled, omit the Authorization header in curl examples. OpenAI SDK clients still require a nonempty key; set OPENAI_API_KEY=unused.

⁠Transcribe audio
POST /v1/audio/transcriptions
Content-Type: multipart/form-data

Parameters:

ParameterTypeRequiredDescription
filefileβœ…Audio file. Supported formats: mp3, mp4, m4a, wav, webm, ogg, flac and all other formats supported by ffmpeg.
modelstringβœ…Pass whisper-1 (value is accepted but ignored; the active WHISPERLIVE_MODEL is always used).
languagestringβ€”BCP-47 language code (e.g. en, fr, zh). If omitted, language is autodetected.

Example:

curl http://your_server_ip:8000/v1/audio/transcriptions \
    -H "Authorization: Bearer $scribe_live_api_key" \
    -F [email protected] \
    -F model=whisper-1 \
    -F language=en

Response:

{"text": "Your transcribed text appears here."}
⁠Interactive API docs

An interactive Swagger UI is available at:

http://your_server_ip:8000/docs

When API-key authentication is enabled, /docs, /openapi.json, and API requests all require Authorization: Bearer <key>. An ordinary browser visit returns 401. To use Swagger UI in a browser, arrange for the header to be sent on the documentation, schema, and API requests; the token query parameter only authenticates WebSocket connections.

⁠Persistent data

All server data is stored in the Docker volume (/var/lib/whisper-live inside the container):

/var/lib/whisper-live/
β”œβ”€β”€ models--Systran--faster-whisper-*/   # Cached Whisper model files (downloaded from HuggingFace)
β”œβ”€β”€ .ws_port              # Active WebSocket port (used by whisper_live_manage)
β”œβ”€β”€ .rest_port            # Active REST API port (used by whisper_live_manage)
β”œβ”€β”€ .model                # Active model name (used by whisper_live_manage)
└── .server_addr          # Cached server IP (used by whisper_live_manage)

Back up the Docker volume to preserve downloaded models. Models are large (145 MB – 3 GB) and can take several minutes to download on first client connection; preserving the volume avoids re-downloading on container recreation.

Tip: The /var/lib/whisper-live volume uses the same HuggingFace cache layout as ScribeCrate's /var/lib/whisper volume. If you have already downloaded a model with ScribeCrate, you can bind-mount the same volume directory to avoid re-downloading.

⁠Managing the server

Use whisper_live_manage inside the running container to inspect and manage the server.

Show server info:

docker exec whisper-live whisper_live_manage --showinfo

List available models:

docker exec whisper-live whisper_live_manage --listmodels

Pre-download a model:

docker exec whisper-live whisper_live_manage --downloadmodel large-v3-turbo

⁠Switching models

To change the active model:

  1. (Optional but recommended) Pre-download the new model while the server is running:

    docker exec whisper-live whisper_live_manage --downloadmodel large-v3-turbo
    
  2. Update WHISPERLIVE_MODEL in your whisper-live.env file (or add -e WHISPERLIVE_MODEL=large-v3-turbo to your docker run command).

  3. Restart the container:

    docker restart whisper-live
    

See available models and approximate memory requirements⁠. Models are cached in the /var/lib/whisper-live Docker volume.

⁠Securing your server

See Securing your server⁠.

⁠Using a reverse proxy

For internet-facing deployments, place a reverse proxy in front of the server to handle HTTPS and WSS (secure WebSocket) termination.

Use one of the following addresses to reach the container from your reverse proxy:

  • whisper-live:9090 / whisper-live:8000 β€” if your reverse proxy runs as a container in the same Docker network.
  • 127.0.0.1:9090 / 127.0.0.1:8000 β€” if your reverse proxy runs on the host and the ports are published.

Example with Caddy⁠ (Docker image⁠) (automatic TLS, WebSocket proxying in the same Docker network):

Caddyfile:

whisper-live.example.com {
  # WebSocket streaming (wss://)
  handle /ws* {
    reverse_proxy whisper-live:9090
  }
  # REST API (https://)
  reverse_proxy whisper-live:8000
}

Example with nginx (reverse proxy on the host):

server {
    listen 443 ssl;
    server_name whisper-live.example.com;

    ssl_certificate     /path/to/cert.pem;
    ssl_certificate_key /path/to/key.pem;

    # REST API
    location /v1/ {
        proxy_pass         http://127.0.0.1:8000;
        proxy_set_header   Host $host;
        proxy_set_header   X-Real-IP $remote_addr;
        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header   X-Forwarded-Proto $scheme;
        proxy_read_timeout 300s;
    }

    # WebSocket streaming
    location / {
        proxy_pass         http://127.0.0.1:9090;
        proxy_http_version 1.1;
        proxy_set_header   Upgrade $http_upgrade;
        proxy_set_header   Connection "upgrade";
        proxy_set_header   Host $host;
        proxy_read_timeout 600s;
    }
}

Important: WebSocket proxying requires proxy_http_version 1.1 and the Upgrade/Connection headers. Without these, real-time streaming will not work through nginx.

Adding extra authentication at the proxy layer

The server supports native API-key authentication via WHISPERLIVE_API_KEY. For internet-facing deployments, you can also add Bearer token or basic auth at the reverse proxy layer as defense in depth. Example with Caddy (basicauth protects the REST API):

whisper-live.example.com {
  handle /v1/* {
    basicauth {
      user $2a$14$<bcrypt-hash-of-password>
    }
    reverse_proxy whisper-live:8000
  }
  handle /ws* {
    reverse_proxy whisper-live:9090
  }
  reverse_proxy whisper-live:8000
}

Example with nginx (auth_basic on the REST API location):

location /v1/ {
    auth_basic           "WhisperLive";
    auth_basic_user_file /etc/nginx/.htpasswd;
    proxy_pass           http://127.0.0.1:8000;
    proxy_set_header     Host $host;
    proxy_read_timeout   300s;
}

Non-browser WebSocket clients can authenticate with an Authorization header. Because the browser WebSocket API cannot set arbitrary headers, browser clients can use ?token=<key>. For defense in depth, keep port 9090 bound to 127.0.0.1 behind the reverse proxy.

⁠Update Docker image

To update the Docker image and container, first download⁠ the latest version:

docker pull hwdsl2/whisper-live-server

If the Docker image is already up to date, you should see:

Status: Image is up to date for hwdsl2/whisper-live-server:latest

Otherwise, it will download the latest version. Remove and re-create the container:

docker rm -f whisper-live
# Then re-run the docker run command from Quick start with the same volumes and ports.

Your downloaded models are preserved in the whisper-live-data volume.

⁠Using with other AI services

ScribeCrate Live can be used as the real-time speech-to-text service in a broader self-hosted AI setup.

For full and lightweight Docker Compose stacks, manual docker run examples, and voice/RAG/MCP pipeline examples with SpeakCrate, EmbedCrate, GatewayCrate, InferCrate, ParseCrate, and UplinkCrate, see Self-Hosted AI Stack⁠.

⁠Usage counts

See Usage counts⁠.

⁠Technical details

  • Base image: python:3.12-slim (Debian)
  • Runtime: Python 3 (virtual environment at /opt/venv)
  • STT engine: WhisperLive⁠ + faster-whisper⁠ with CTranslate2 (INT8 on CPU, FP16 on CUDA)
  • VAD: Silero VAD⁠ via PyTorch (CPU or CUDA, auto-detected)
  • WebSocket server: Python websockets library
  • REST API framework: FastAPI⁠ + Uvicorn⁠
  • Data directory: /var/lib/whisper-live (Docker volume)
  • Model storage: HuggingFace Hub format inside the volume β€” downloaded once, reused on restarts

⁠License

Note: The software components inside the pre-built image (such as WhisperLive, faster-whisper, PyTorch, and their dependencies) are under the respective licenses chosen by their respective copyright holders. As for any pre-built image usage, it is the image user's responsibility to ensure that any use of this image complies with any relevant licenses for all software contained within.

Copyright (C) 2026 Lin Song
This work is licensed under the MIT License⁠.

WhisperLive is Copyright (C) Vineet Suryan, Collabora Ltd., and is distributed under the MIT License⁠.

faster-whisper is Copyright (C) SYSTRAN, and is distributed under the MIT License⁠.

This project is an independent Docker setup and is not affiliated with, endorsed by, or sponsored by OpenAI, Collabora, or SYSTRAN.

Tag summary

Content type

Image

Digest

sha256:95e8d9434…

Size

804.1 MB

Last updated

4 days ago

docker pull hwdsl2/whisper-live-server