Enable
OPENAI_API_KEY only on the server. Browser clients receive ephemeral client secrets minted by the Web server.
Tools
Default behavior: Realtime tools are disabled.get_current_timediscover_capabilities
Privacy boundary
Realtime sends browser voice/text to OpenAI only when enabled and used. It does not reuse genericAPI_KEY, and it does not put the standard API key in browser code.
Use /capabilities or the Web capabilities endpoint to confirm what is enabled before testing.