Make a cleared song
Music for ads, games and creators with a paper trail. A prompt guard refuses or strips named artists, songs, labels and voice imitation (code rules, then one receipted typed judgment), the track renders on MiniMax-Music3 or ACE-Step, and a CPU check scores it against a catalogue of openly licensed recordings. Each track ships with a C2PA credential and a signed certificate that states the model, seed, checks, similarity score and the exact licence.
- For
- Teams in music and creative and media.
- Time per task43 stypical (median) on the sample
- Cost per task~$0.011 per trackmeasured, at list price
- Accuracy100% (48/48)Prompt guard precision (refuse)All results and caveats
Result
LiveWrite a brief and generate. The prompt check runs first; a refused prompt never reaches the GPU.
Check any track
Score a file from anywhere against the reference catalogue: 240 openly licensed recordings from the Free Music Archive. Try a pitch-shifted copy of one of them to see it flag. The file is checked in memory and not kept (20 MB at most).
Watch: briefs checked, rendered and certified
Replay · not liveRecorded on 2026-09-30 from real runs on production (api.decosa.ai): the prompt check on Qwen3.8-27B through our gateway, renders on MiniMax-Music3 and ACE-Step 1.5 through the studio queue on one shared GPU, the similarity check on CPU. Replayed here faster; the audio is the delivered file with its C2PA credential.
Watch the code layer find "Taylor Swift" and the style phrase around it, remove both, and the typed judgment clear what is left; the track renders on MiniMax-Music3 with its credit, scores clear against the catalogue, and the certificate records the stripped prompt's hash.
Brief: Upbeat pop in the style of Taylor Swift with bright acoustic guitars and a big chorus
Write a brief and generate. The prompt check runs first; a refused prompt never reaches the GPU.
Get an API key
- Call the rights-cleared music generation API from your own code in minutes.
- Every model answer carries a signed receipt.
- Nothing to install; we run the models.
Run it yourself, on request
- The same open models and app, on About 50 GB free on one 96 GB card for MiniMax-Music3 (ACE-Step needs about 15 GB); the similarity check runs on CPU.
- Data never leaves your machines, and there are no Decosa charges.
- One prompt for Claude Code or Codex assembles the whole stack.
- Early access: the container images are not public yet and the source needs access; the prompt says how to ask.
Build with it
Paste one of these into Claude Code, Codex or another coding agent. The first wires your project to the hosted API with your DECOSA_API_KEY. The second pulls our containers and runs the same stack on your own GPU, with no Decosa charges.
- Base URL
- https://api.decosa.ai
- Auth
Authorization: Bearer $DECOSA_API_KEY(or a demo session token)- Tool id
- music-gen-cleared
Use the hosted API
# Decosa rights-cleared music generation: use the hosted API
You are wiring Decosa's rights-cleared music generation into this project. It takes a music brief (genre, era, mood,
tempo, instruments, and optionally lyrics the user wrote), checks it for named artists, songs, labels and voice
imitation, renders it on MiniMax-Music3 or ACE-Step 1.5, scores the result against a reference catalogue of openly
licensed recordings, and returns the MP3 with a C2PA credential and a signed licence certificate. The prompt check is
one model call with its own signed receipt. Use only what is listed below. If you need something else, stop and ask me.
- Base URL: `https://api.decosa.ai`
- Health check: `GET https://api.decosa.ai/healthz`.
- A guard and a triage check, not a rights clearance. The similarity check covers 240 Creative Commons tracks only.
No copyright in the output is claimed or transferred.
- Any UI that plays MiniMax-Music3 output must show "Powered by MiniMax-Music3" (the response's `notice`). Disclose the
track as AI-generated wherever it is published.
## Auth: API key (or a demo session)
1. Preferred: an API key (`dk_…`) from "Get an API key" on the tool page. Keep it in `DECOSA_API_KEY`, never in
code. Send `Authorization: Bearer $DECOSA_API_KEY`. A key renders 3 tracks per UTC day on the shared GPU.
2. Without a key: `POST https://api.decosa.ai/demo/session` with `{"vertical": "music-gen-cleared"}` returns `{"token", ...}`.
a limited number of sessions per network per hour (the current limits are in `demo_sessions` of GET /healthz), 3 renders per session. Over a limit: HTTP 429 with `Retry-After`.
## Endpoints
- `POST /music/generate` (token). Body: `{"prompt": "...", "lyrics"?: "...", "engine"?: "music3"|"acestep", "seconds"?: 10-60, "seed"?: int, "mode"?: "refuse"|"strip"}`.
- 202 `{run_id, guard, receipts, usage, notice, poll}`; 422 `{error, category, refusal_id, guard}` when the brief names
someone (`category`: `artist`, `work`, `voice`, `label`, or `unavailable` when the check could not run: fail closed).
- `mode: "strip"` removes a named artist or a "in the style of <name>" phrase and checks the rest again;
`guard.rendered_prompt` is what was rendered.
- Limits: prompt 600 characters, lyrics 1,500. The check takes one model call (about 450 tokens).
- `GET /music/runs/{run_id}` (token): poll every 3-5 s until `status` is `done` or `failed`. Renders wait their turn on
one GPU. `done` has `audio_url` (relative: prefix `https://api.decosa.ai`), `file_sha256`, `credential: "c2pa"`,
`render_receipt_url`, `similarity` (`verdict`: `clear`, `review` or `near_copy`; `score`; `top` references with their
licences) and `certificate` (`url`, `markdown`).
- `GET /music/certificates/{run_id}` (no token): the signed certificate (verify it at `POST /record/verify` with
`{"record": ...}`); `?format=md` for a readable copy to hand to a client or platform.
- `POST /music/runs/{run_id}/compare` (token): body = a reference audio file (the client's temp track), up to 20 MB,
`Content-Type: application/octet-stream`. Compared in memory, not kept.
- `POST /music/check` (token): body = any audio file; its similarity to the reference catalogue.
- `POST /music/guard` (token): the prompt check alone, no render. `GET /music/guard/log`: your refusals (hashes only).
- `GET /music/info`, `GET /music/samples` (no token).
## Example: generate, wait, save the track and its certificate (Python, `pip install httpx`)
```python
import httpx, os, pathlib, time
API = "https://api.decosa.ai"
H = {"Authorization": f"Bearer {os.environ['DECOSA_API_KEY']}"}
r = httpx.post(f"{API}/music/generate", headers=H, timeout=120,
json={"prompt": "Warm acoustic pop for a bakery ad, ukulele and hand claps, instrumental", "seconds": 30})
if r.status_code == 422:
raise SystemExit(f"refused: {r.json()['error']}")
r.raise_for_status()
run_id = r.json()["run_id"]
while True:
time.sleep(4)
run = httpx.get(f"{API}/music/runs/{run_id}", headers=H, timeout=120).json()
if run["status"] in ("done", "failed"):
break
if run["status"] == "failed":
raise SystemExit(run.get("error"))
pathlib.Path("track.mp3").write_bytes(httpx.get(API + run["audio_url"]).content)
pathlib.Path("certificate.md").write_text(httpx.get(API + run["certificate"]["markdown"]).text)
print(run["notice"], run["similarity"]["verdict"])
```
## Honest limits
- The guard missed about 1 in 50 artist-referencing briefs in the held-out test (a nickname like "the Boss"), and it only
reads text: it cannot hear whether a melody you hum into lyrics resembles a song.
- The similarity check flagged about 4 in 5 planted near-copies (pitch-shifted, time-stretched, excerpted) of catalogue
tracks, with about 2% false alarms on unrelated tracks; it knows only its 240 references and the files you compare.
- Rendering shares one GPU with other demos; a 30 s MiniMax-Music3 track takes a minute or more.
Run it yourself (containers)
On request. The container images and the compose file aren’t public yet. Ask for self-host access and Decosa sends the registry (DECOSA_REGISTRY) and the compose file’s URL (DECOSA_COMPOSE_URL) these steps use. They are the steps we tested end to end on a fresh machine.
# Decosa rights-cleared music generation: run it yourself (containers)
You are setting up Decosa's rights-cleared music generation on this machine: a prompt guard, MiniMax-Music3 or
ACE-Step 1.5 renders with C2PA credentials, a CPU similarity check and signed licence certificates. Briefs, renders and
references stay here; nothing is sent to Decosa's hosted API.
Status: the container images (${DECOSA_REGISTRY}/decosa-*) and the compose file are on request while self-host is in early access (not on a public registry yet): ask at https://decosa.ai/contact?topic=self-host, and Decosa sends the registry as DECOSA_REGISTRY, the compose file URL as DECOSA_COMPOSE_URL, and pull access. If a pull fails with
"not found", "denied" or "unauthorized", stop and tell me. Do not substitute other images or models.
Ask me before any command that needs sudo, and show me the command first.
## Step 0: set up with a coding agent, rehearse on mock data, then go private
This prompt is for a coding agent running on the machine that will host the service. We recommend Claude Code with
Claude Opus 5.5; any capable coding agent works. Work in this order:
1. Set up on mock data only. During the whole setup you (the agent) work with the synthetic sample bundle below and
nothing else. Do not ask me for real data, and do not open, read, list or copy files that hold real data, even to
"test with something realistic".
2. Rehearse. When the steps below are done and the service is healthy, fetch the mock-data bundle for this tool,
https://decosa.ai/samples/music-gen-cleared.zip (506 KB, 12 checks, synthetic or openly licensed: see `licence` in expected.json),
show me what is in it, and run the rehearsal against the local API:
`docker compose exec api python scripts/rehearse.py music-gen-cleared` (the api image carries the same bundle under /app/rehearsal/music-gen-cleared/;
with no key set, the script asks the local API for a short demo token). From a decosa-api checkout instead:
`python scripts/rehearse.py music-gen-cleared --bundle music-gen-cleared.zip --base-url http://127.0.0.1:<PORT>`.
It sends the mock inputs to the local API and prints PASS or FAIL for each expected property (for example: "the named-artist brief is refused", "the refusal comes from the code rules, with no model call", "no model call is spent on the named-artist refusal"). Show me
the full output. Every check must pass. If one fails, fix the install and run it again; never edit `expected.json`
to make a check pass.
3. Stop there. Once the rehearsal passes, tell me, and I will run my own data against the local API myself, on this
machine.
For the person running this: a coding agent that runs in the cloud sees everything in its context, including files it
reads, command output and anything pasted into the chat. Keep real data out of the chat and out of anything the agent
can read. Switch to your own data only after the rehearsal has passed and the agent's work is done.
## Licences first
- MiniMax-Music3 Community License: show "MiniMax-Music3" in any commercial UI that uses it; get MiniMax's written
authorization above USD 20M yearly revenue; a hosted service must keep safeguards against infringing uses (keep the
guard on); follow its Acceptable Use Policy. ACE-Step 1.5 is MIT. Qwen3.8-27B and LAION CLAP are Apache-2.0.
## Steps
1. Docker and the NVIDIA container toolkit: if `docker compose version` or
`docker run --rm --gpus all nvidia/cuda:12.8.0-base-ubuntu24.04 nvidia-smi` fails, install them from the official
instructions. You need about 50 GB of free VRAM for MiniMax-Music3 (15 GB for ACE-Step only) plus about 20 GB for
the guard's text model, or an existing Qwen3.8-27B server.
2. Fetch the compose file: `mkdir -p ~/decosa && cd ~/decosa && curl -fsSL "${DECOSA_COMPOSE_URL}" -o compose.yaml`. Keep the
`llm`, `comfyui`, `embed` (CPU similarity) and `api` services. For `api` set `DECOSA_LLM_ROUTE=direct`,
`DECOSA_STUDIO_WORKER=command`, `DECOSA_MUSIC_EMBED_URL=http://embed:8486`; use named volumes; bind every port to 127.0.0.1.
3. `docker compose pull && docker compose up -d`; wait for the health checks (the first start downloads the weights).
4. Smoke test: a token from `POST /demo/session {"vertical":"music-gen-cleared"}`; `POST /music/guard {"prompt":"Upbeat
pop in the style of Taylor Swift"}` must be refused by code; `POST /music/generate` with the `ad-bed` sample from
`GET /music/samples`, poll `GET /music/runs/{id}` to `done`, and check `credential: "c2pa"`, a similarity verdict,
and that `POST /record/verify` accepts `GET /music/certificates/{id}`.
5. Report back: the signing key id (`GET /attest/signing-key`), the render time and the similarity score.
No NVIDIA GPU? Parts of this tool also run on an Apple Silicon Mac (MLX, 64 GB of unified memory or more): use https://decosa.ai/prompts/music-gen-cleared-mac.md instead.
Run it on your own GPU
Same app, same pinned models, your hardware. Nothing goes to our servers and there are no Decosa charges.
Hardware check
Check your own hardware- CPU only, 64 GB RAMDoesn't fit
Qwen3.8-27B (NVFP4) needs a GPU.
- GeForce RTX 4090Doesn't fit
Needs about 70 GB of GPU memory at the smallest settings; 24 GB available.
- GeForce RTX 5090Doesn't fit
Needs about 78 GB of GPU memory at the smallest settings; 32 GB available.
- 2x GeForce RTX 5090lite tierRuns with a smaller tier
The standard tier does not fit: Needs about 78 GB of GPU memory at the smallest settings; 64 GB available. The lite tier fits with changes.
- L40SDoesn't fit
Needs about 83.6 GB of GPU memory at the smallest settings; 48 GB available.
- H100 80 GB (SXM)lite tierRuns with a smaller tier
The standard tier does not fit: Needs about 83.6 GB of GPU memory at the smallest settings; 80 GB available. The lite tier fits with changes.
- RTX PRO 6000 Blackwell 96 GBstandard tierRuns
The standard tier fits with changes: Qwen3.8-27B (NVFP4): run it at its smallest setting (about 28 GB instead of 57.6 GB), with a shorter context and fewer parallel sessions.
- 2x RTX PRO 6000 Blackwell 96 GBstandard tierRuns
The standard tier fits (122.2 of 192 GB).
- Apple M3 Ultra (Mac Studio), 96 GBstandard tierRuns
The standard tier fits with changes: ACE-Step on a Mac is untested
- Apple M5 Max, 64 GBstandard tierRuns
The standard tier fits with changes: ACE-Step on a Mac is untested
Memory per component comes from measured footprints, the tool's stack.json, or an estimate from its parameter count, and each is labelled that way below. Only an RTX PRO 6000 and an M3 Ultra Mac Studio have actually been run.
On request. The container images and the compose file aren’t public yet. Ask for self-host access and Decosa sends the registry (DECOSA_REGISTRY) and the compose file’s URL (DECOSA_COMPOSE_URL) these steps use. They are the steps we tested end to end on a fresh machine.
- 1
Check the GPU, Docker and the NVIDIA Container Toolkit
The driver must see the GPU, and Docker must be able to pass it into a container.
nvidia-smi docker compose version docker run --rm --gpus all ubuntu nvidia-smi
- 2
Fetch the compose file
One file describes the API and the language model as services.
mkdir -p ~/decosa && cd ~/decosa curl -fsSL "${DECOSA_COMPOSE_URL}" -o compose.yaml - 3
Pull and start
The first start downloads pinned model weights, tens of gigabytes.
docker compose pull docker compose up -d
- 4
Check health
Wait until the API reports ok with the language model loaded. Then point your app at the local base URL.
curl -fsS http://localhost:<PORT>/healthz # {"ok": true, "llm": true, ...} curl -fsS -X POST http://localhost:<PORT>/demo/session \ -H 'Content-Type: application/json' -d '{"vertical":"music-gen-cleared"}'
Set up with a coding agent, rehearse on mock data, then go private
- Set up with a coding agent. Paste the self-host prompt into a coding agent on the machine that will run the service. We recommend Claude Code with Claude Opus 5.5; any capable coding agent works.
- Rehearse on mock data. The agent runs the tool on a bundle of synthetic inputs and checks each answer against the bundle's
expected.json. Every check must print PASS. - Go private. Only then do you run your own data against the local API, yourself, on that machine. Never give the agent real data during setup: a coding agent that runs in the cloud sees everything in its context, so keep real data out of the chat and out of the files it reads.
docker compose exec api python scripts/rehearse.py music-gen-cleared
Download the mock-data bundle (506 KB, 12 checks)expected.json
Three music briefs and two audio files. A brief naming an artist must be refused by code with no model call, the same brief in strip mode must come back with the name removed, a brief that describes an artist without naming it must be refused by the typed judgment, and an original brief must be allowed with a signed receipt. A pitch-shifted copy of a catalogue track must be flagged as a near-copy of that track and a synthetic tone must come back clear. No render: renders take about a minute of shared GPU and the runner cannot yet poll a queued job, so the certificate (and its tamper check) is exercised in the hosted demo, not here.
What the rehearsal checks
- the named-artist brief is refused
- the refusal comes from the code rules, with no model call
- no model call is spent on the named-artist refusal
- in strip mode the named-artist brief comes back as stripped, not refused
- in strip mode the artist's name is removed from the prompt that would be rendered
- the described-but-unnamed artist is refused
- the original brief is allowed
- the original brief's check has a model receipt
- the pitch-shifted copy is flagged as a near-copy
- its closest catalogue match is the track it was copied from (Breeze Funk)
- the synthetic tone is clear of the catalogue
- every model call has a signed receipt
Licence: Prompts: written for Decosa (CC0). near-copy-breeze-funk-pitch-up-2.mp3: "Breeze Funk" by Malaventura, Free Music Archive (fma_small, track 113025), Public Domain Mark 1.0, pitch-shifted +2 semitones for the Decosa eval. original-tone.wav: synthetic tones generated by code (CC0).
Prompt for your coding agent
# Decosa rights-cleared music generation: run it yourself (containers)
You are setting up Decosa's rights-cleared music generation on this machine: a prompt guard, MiniMax-Music3 or
ACE-Step 1.5 renders with C2PA credentials, a CPU similarity check and signed licence certificates. Briefs, renders and
references stay here; nothing is sent to Decosa's hosted API.
Status: the container images (${DECOSA_REGISTRY}/decosa-*) and the compose file are on request while self-host is in early access (not on a public registry yet): ask at https://decosa.ai/contact?topic=self-host, and Decosa sends the registry as DECOSA_REGISTRY, the compose file URL as DECOSA_COMPOSE_URL, and pull access. If a pull fails with
"not found", "denied" or "unauthorized", stop and tell me. Do not substitute other images or models.
Ask me before any command that needs sudo, and show me the command first.
## Step 0: set up with a coding agent, rehearse on mock data, then go private
This prompt is for a coding agent running on the machine that will host the service. We recommend Claude Code with
Claude Opus 5.5; any capable coding agent works. Work in this order:
1. Set up on mock data only. During the whole setup you (the agent) work with the synthetic sample bundle below and
nothing else. Do not ask me for real data, and do not open, read, list or copy files that hold real data, even to
"test with something realistic".
2. Rehearse. When the steps below are done and the service is healthy, fetch the mock-data bundle for this tool,
https://decosa.ai/samples/music-gen-cleared.zip (506 KB, 12 checks, synthetic or openly licensed: see `licence` in expected.json),
show me what is in it, and run the rehearsal against the local API:
`docker compose exec api python scripts/rehearse.py music-gen-cleared` (the api image carries the same bundle under /app/rehearsal/music-gen-cleared/;
with no key set, the script asks the local API for a short demo token). From a decosa-api checkout instead:
`python scripts/rehearse.py music-gen-cleared --bundle music-gen-cleared.zip --base-url http://127.0.0.1:<PORT>`.
It sends the mock inputs to the local API and prints PASS or FAIL for each expected property (for example: "the named-artist brief is refused", "the refusal comes from the code rules, with no model call", "no model call is spent on the named-artist refusal"). Show me
the full output. Every check must pass. If one fails, fix the install and run it again; never edit `expected.json`
to make a check pass.
3. Stop there. Once the rehearsal passes, tell me, and I will run my own data against the local API myself, on this
machine.
For the person running this: a coding agent that runs in the cloud sees everything in its context, including files it
reads, command output and anything pasted into the chat. Keep real data out of the chat and out of anything the agent
can read. Switch to your own data only after the rehearsal has passed and the agent's work is done.
## Licences first
- MiniMax-Music3 Community License: show "MiniMax-Music3" in any commercial UI that uses it; get MiniMax's written
authorization above USD 20M yearly revenue; a hosted service must keep safeguards against infringing uses (keep the
guard on); follow its Acceptable Use Policy. ACE-Step 1.5 is MIT. Qwen3.8-27B and LAION CLAP are Apache-2.0.
## Steps
1. Docker and the NVIDIA container toolkit: if `docker compose version` or
`docker run --rm --gpus all nvidia/cuda:12.8.0-base-ubuntu24.04 nvidia-smi` fails, install them from the official
instructions. You need about 50 GB of free VRAM for MiniMax-Music3 (15 GB for ACE-Step only) plus about 20 GB for
the guard's text model, or an existing Qwen3.8-27B server.
2. Fetch the compose file: `mkdir -p ~/decosa && cd ~/decosa && curl -fsSL "${DECOSA_COMPOSE_URL}" -o compose.yaml`. Keep the
`llm`, `comfyui`, `embed` (CPU similarity) and `api` services. For `api` set `DECOSA_LLM_ROUTE=direct`,
`DECOSA_STUDIO_WORKER=command`, `DECOSA_MUSIC_EMBED_URL=http://embed:8486`; use named volumes; bind every port to 127.0.0.1.
3. `docker compose pull && docker compose up -d`; wait for the health checks (the first start downloads the weights).
4. Smoke test: a token from `POST /demo/session {"vertical":"music-gen-cleared"}`; `POST /music/guard {"prompt":"Upbeat
pop in the style of Taylor Swift"}` must be refused by code; `POST /music/generate` with the `ad-bed` sample from
`GET /music/samples`, poll `GET /music/runs/{id}` to `done`, and check `credential: "c2pa"`, a similarity verdict,
and that `POST /record/verify` accepts `GET /music/certificates/{id}`.
5. Report back: the signing key id (`GET /attest/signing-key`), the render time and the similarity score.
No NVIDIA GPU? Parts of this tool also run on an Apple Silicon Mac (MLX, 64 GB of unified memory or more): use https://decosa.ai/prompts/music-gen-cleared-mac.md instead.
Help me customise for my hardware
Pick your GPU or Mac, or enter its memory. You get the tier that fits, the model swaps it needs, measured speed where we have it, and a setup prompt with those choices written in.
GeForce RTX 5090: 32 GB GDDR7, 1,792 GB/s, FP8 and NVFP4. NVIDIA product page
Doesn't fitRights-cleared music generation on GeForce RTX 5090
Needs about 78 GB of GPU memory at the smallest settings; 32 GB available.
Lite · MIT engine, about 15 GB of GPU: what changesuses estimates
- Needs about 42.6 GB of GPU memory at the smallest settings; 32 GB available.
Memory per component
- Prompt guard, code layer: decosa-api music module (decosa_api/verticals/music). CPU. Runs on CPU (vram_gb 0 in stack.json).
- Prompt guard, typed judgment: Qwen3.8-27B (NVFP4). ~57.6 GB (at least ~28 GB), weights 21.4 GB (from stack.json). Qwen3.8-27B NVFP4: Weights 19.9 GiB (21.4 GB), measured (field stack.json). The compose file gives the server 0.60 of a 96 GB card (57.6 GB) so the rest is FP8 KV cache for several sessions. The 28 GB minimum is an estimate: weights plus a short-context KV cache, which is why several stacks list a 32 GB RTX 5090 as 'estimate'. (stack.json lists 20 GB for this component.)
- Music generation: ACE-Step 1.5 turbo + 5Hz LM 1.7B. ~14.6 GB, loaded while a job runs (from stack.json). vram_gb 14.6 in stack.json.
- Similarity check: LAION CLAP larger_clap_music + librosa chroma (services/music_embed). CPU. Runs on CPU (vram_gb 0 in stack.json).
Expected speed
Not measured.
Not measured on this hardware. The only measured setups are an RTX PRO 6000 Blackwell and a Mac Studio M3 Ultra.
Setup prompt for this hardware
The self-host prompt for Rights-cleared music generation, with a hardware plan for GeForce RTX 5090 added after Step 0. Loading the full prompt; until then it points your agent at the prompt's URL.
# Set up Rights-cleared music generation on my hardware Fetch https://decosa.ai/prompts/music-gen-cleared-selfhost.md and follow it (including Step 0: rehearse on mock data first), with the hardware plan below applied. ## Hardware plan for this machine (from https://decosa.ai/self-host/hardware?use=music-gen-cleared) Target machine: GeForce RTX 5090 (32 GB of GPU memory; CUDA, FP8 and NVFP4). Quality tier: Lite · MIT engine, about 15 GB of GPU (lite). Fit check: doesn't fit; some memory numbers are estimates, not measurements. First, check the machine: run `nvidia-smi` (or `rocm-smi`, or `sysctl hw.memsize` on a Mac) and confirm the GPUs and free memory match the line above. If they do not, stop and tell me before pulling anything. Use these components (the setup below describes the standard tier; change it to match): - Prompt guard, code layer: decosa-api music module (decosa_api/verticals/music), CPU - Prompt guard, typed judgment: Qwen3.8-27B (NVFP4) (nvidia/Qwen3.8-27B-NVFP4), 57.6 GB - Music generation: ACE-Step 1.5 turbo + 5Hz LM 1.7B (ACE-Step/Ace-Step1.5), 14.6 GB - Similarity check: LAION CLAP larger_clap_music + librosa chroma (services/music_embed) (laion/larger_clap_music), CPU Warning: the fit check says this tier does not fit: Needs about 42.6 GB of GPU memory at the smallest settings; 32 GB available. Tell me before going further. During the rehearsal, watch GPU memory. If a model fails to load or runs out of memory, lower its --max-model-len and --max-num-seqs first, then its memory share, and tell me what you changed. The stack's own component list and compose layout: https://decosa.ai/prompts/music-gen-cleared-assemble.md
Partly on a Mac
Some parts run natively on Apple Silicon (64 GB or more); the rest needs a CUDA GPU or a hosted API. Measured speeds and what runs where
- ACE-Step on a Mac is untested
- Music3 runs through a community MLX port, not the ComfyUI path the hosted route uses
From a checkout of decosa-api, one command sets up the models and the API: scripts/mac/setup.sh
Mac prompt for your coding agent
# Decosa Rights-cleared music generation: run it on this Mac (Apple Silicon, no NVIDIA GPU) You are setting up the Decosa Rights-cleared music generation on this Mac, natively on Apple Silicon. The models run on the Mac's GPU through MLX and decosa-api runs from a git checkout with `uv`. Docker is not used for the models, because Docker on macOS cannot reach the GPU. Nothing is sent to Decosa's hosted API. Only part of this tool runs on a Mac (see the gaps below). The parts that do need 64 GB of unified memory or more. Ask me before any command that needs sudo or installs software with Homebrew, and show me the command first. Never stop or kill a process this setup did not start; if a port is taken, pick another one. ## Step 0: set up with a coding agent, rehearse on mock data, then go private This prompt is for a coding agent running on the machine that will host the service. We recommend Claude Code with Claude Opus 5.5; any capable coding agent works. Work in this order: 1. Set up on mock data only. During the whole setup you (the agent) work with the synthetic sample bundle below and nothing else. Do not ask me for real data, and do not open, read, list or copy files that hold real data, even to "test with something realistic". 2. Rehearse. When the steps below are done and the service is healthy, fetch the mock-data bundle for this tool, https://decosa.ai/samples/music-gen-cleared.zip (506 KB, 12 checks, synthetic or openly licensed: see `licence` in expected.json), show me what is in it, and run the rehearsal against the local API: `.venv/bin/python scripts/rehearse.py music-gen-cleared` in the decosa-api checkout (the key comes from ~/.decosa-mac/api.key). It sends the mock inputs to the local API and prints PASS or FAIL for each expected property (for example: "the named-artist brief is refused", "the refusal comes from the code rules, with no model call", "no model call is spent on the named-artist refusal"). Show me the full output. Every check must pass. If one fails, fix the install and run it again; never edit `expected.json` to make a check pass. 3. Stop there. Once the rehearsal passes, tell me, and I will run my own data against the local API myself, on this machine. For the person running this: a coding agent that runs in the cloud sees everything in its context, including files it reads, command output and anything pasted into the chat. Keep real data out of the chat and out of anything the agent can read. Switch to your own data only after the rehearsal has passed and the agent's work is done. ## What runs where | Part | On an NVIDIA GPU | On this Mac | Status | |---|---|---|---| | Prompt guard, code layer: gazetteer of well-known names, look-alike folding, cover/cloning/type-beat patterns, a genre and era allow-list; the certificate and refusal log (CPU) | Python on CPU | The same Python module, run with uv | Runs, measured | | Prompt guard, typed judgment: names the category (artist, work, voice, label or none) with a calibrated probability; one call per brief | NVFP4 on vLLM 0.29 (Blackwell) | MLX 4-bit (EigenLabs/Qwen3.8-27B-4bit) on mlx_lm.server 0.31.3; oMLX 0.6.1 with MTP as an option | Runs, measured | | Music generation: songs with vocals and lyrics (default engine) | ComfyUI on CUDA | Community MLX port (PocketAiHub/MiniMax-Music3-MLX, INT8) | Runs, measured | | Music generation: fast drafts and instrumentals (MIT engine) | PyTorch on CUDA | PyTorch on MPS | Untested on a Mac | | Similarity check (CPU): melody by chroma alignment across keys and tempos, sound by CLAP window embeddings, both normalised per reference | PyTorch on CPU | PyTorch on CPU | Runs, not measured | Not on a Mac: - ACE-Step on a Mac is untested. - Music3 runs through a community MLX port, not the ComfyUI path the hosted route uses. ## Steps 1. Check the machine: `uname -m` must print `arm64` (an M-series chip; Intel Macs cannot run MLX), and `sysctl -n hw.memsize` should be at least 64 GB for this tool. Check about 30 GB of free disk with `df -h ~`. Show me the chip (`sysctl -n machdep.cpu.brand_string`) and the memory. 2. Tools: `uv --version`. If it is missing, ask me, then `brew install uv`. 3. Code: `git clone <decosa-api source: on request at https://decosa.ai/contact?topic=self-host> ~/decosa-api` (access required) and `cd ~/decosa-api`. Check that `scripts/mac/setup.sh` exists; if it does not, the checkout is too old: stop and tell me. 4. Start everything with one command: `scripts/mac/setup.sh`. It creates `.venv` (decosa-api) and `.venv-mac` (MLX, mlx-lm, mlx-audio), downloads the weights with the Hugging Face CLI (about 16 GB for the language model), starts the model servers and decosa-api on 127.0.0.1, and mints a local API key into `~/.decosa-mac/api.key` (mode 0600). The first run takes a while because of the downloads; later runs reuse them. If a download fails with 401 or 403, ask me for a Hugging Face token and set `HF_TOKEN`. The script sets up only the language model. The parts listed under "Not on a Mac" still need the GPU stack or the hosted API (see https://decosa.ai/prompts/music-gen-cleared-assemble.md); the smoke test in step 6 will report them as failures. Tell me which checks passed and which need the GPU. 5. Check health: `scripts/mac/setup.sh status` shows each server, and `curl -fsS http://127.0.0.1:8445/healthz` must report `"llm": true`. `curl -fsS http://127.0.0.1:8445/attest/signing-key` shows this Mac's public key: show it to me, because it is what others pin to check the receipts and records this Mac signs. 6. Smoke test: `.venv/bin/python scripts/mac/bench_usecases.py music-gen-cleared`. It runs the tool's own sample end to end against the local API with the local key and prints `ok`, the wall time, the model calls and the receipts. `ok=True` is the pass condition. If it fails, read `~/.decosa-mac/logs/*.log` and tell me what you found. 7. Point the app at it: the API is `http://127.0.0.1:8445` with `Authorization: Bearer $(cat ~/.decosa-mac/api.key)`, the same routes as the hosted API. To stop everything: `scripts/mac/setup.sh stop`. 8. Report back: the chip and memory, the public key, the smoke-test result and its time, and the output of `scripts/mac/setup.sh status`. ## Good to know - Receipts: every model call is signed with this Mac's own Ed25519 key and names the exact MLX weights (`qwen3.8-27b-mlx-4bit` with a hash of the downloaded files). There is no gateway countersignature on a self-hosted Mac. - The weights are a 4-bit MLX build of the same open models, not the NVFP4 build the hosted route and the published evals use. Expect small differences in wording and scores. - Faster drafting: `scripts/mac/setup.sh stop && scripts/mac/setup.sh --engine omlx` serves the model with oMLX and multi-token prediction (about 2x faster for a single long answer, no faster for many parallel calls; typed judgments then use sampling because oMLX returns no log-probabilities). - The guard and the model questions run on the Mac; Music3 renders through the MLX port (measured). - Measured speeds for a Mac Studio M3 Ultra and the memory each tool needs: https://decosa.ai/mac. Full details: `docs/self-host-mac.md` in the checkout.
Get an API key
- Call the rights-cleared music generation API from your own code in minutes.
- Every model answer carries a signed receipt.
- Nothing to install; we run the models.
Run it yourself, on request
- The same open models and app, on About 50 GB free on one 96 GB card for MiniMax-Music3 (ACE-Step needs about 15 GB); the similarity check runs on CPU.
- Data never leaves your machines, and there are no Decosa charges.
- One prompt for Claude Code or Codex assembles the whole stack.
- Early access: the container images are not public yet and the source needs access; the prompt says how to ask.
Music for ads, games and creators, with a prompt guard, a similarity check and a signed licence certificate for every track.
A brief goes through a prompt guard that refuses or strips named artists, songs, labels and voice imitation, then renders on MiniMax-Music3 or ACE-Step 1.5. A CPU check scores the track against 240 openly licensed recordings, or against the reference a client sent. Each track ships with a C2PA credential and a signed certificate that states the model, seed, checks, similarity result and the exact licence. It is for agencies, game studios and anyone who hosts MiniMax-Music3 and needs the safeguards its licence asks for.
- Deployment
- Hosted or self-host
- Regulatory
- Not legal advice and not a rights clearance. Licences, read from the licence files on 25 Sep 2026: MiniMax-Music3 Community License (commercial use allowed; show "MiniMax-Music3" prominently in a commercial UI, §3.1; prior written authorization from MiniMax above USD 20M yearly revenue, §3.2; a hosted service must implement, test and review safeguards against infringing uses and outputs and is responsible for its downstream users, §4; the Acceptable Use Policy in Exhibit A applies, including disclosure of machine-generated content published in public places, item 11, and no impersonation without consent, item 12). ACE-Step 1.5: MIT. Qwen3.8-27B and LAION CLAP: Apache-2.0. Copyright: the US Copyright Office's Part 2 report on copyrightability (29 Jan 2025) says AI outputs are protected only where a human author determined sufficient expressive elements and that prompts alone are not enough; the certificate claims no copyright. Other countries differ. Reference catalogue: 240 Free Music Archive tracks under CC BY, CC BY-SA, CC0 or public domain (per-track licence in the catalogue), stored as vectors only. Style is not protected by copyright in the US, but a soundalike can still infringe a composition or a recording, and imitating a singer's voice can raise right-of-publicity claims: the guard refuses both kinds of request rather than judging them.
Text description
A brief (prompt and optional lyrics) enters decosa-api. The prompt guard runs code rules first, then one typed judgment by Qwen3.8-27B (Apache-2.0) through our gateway with a signed receipt; a refused brief stops there and is logged by hash. An allowed brief goes to the studio queue, which renders on one GPU with MiniMax-Music3 (community licence, shown as Powered by MiniMax-Music3) or ACE-Step 1.5 (MIT). The file gets a C2PA credential and a render receipt. A CPU service compares the track with 240 openly licensed Free Music Archive recordings using chroma alignment for melody and LAION CLAP (Apache-2.0) for sound. Outputs: the MP3, a similarity report, the refusal log and a signed licence certificate with the prompt hash, guard results, model, seed, similarity verdict and licence terms. Self-hosted, everything stays on your machine.
At a glance
- Data retention
- The prompt and lyrics are kept only while the job is queued; runs, certificates and the refusal log hold hashes, rules and settings. Rendered audio stays in the studio's media folder. Compared reference files are not kept.
- What leaves the box
- Hosted: the brief goes to the text model through our gateway and its render service. Self-host: nothing.
- Licence per track
- Each certificate names the model's licence: the MiniMax-Music3 Community License (credit "Powered by MiniMax-Music3", USD 20M revenue threshold, use policy) or MIT for ACE-Step 1.5.
- Cost per track
- A fraction of a cent of model time for the prompt check (measured); GPU time on your own card when self-hosted.
- Typical time
- Under a minute from brief to a certified track on a quiet queue (measured); the similarity check takes seconds on CPU.
- Outputs
- MP3 with a C2PA credential, a similarity report naming the closest references and their licences, and a signed certificate (JSON and Markdown) that verifies at /record/verify.
Pick the tier for the quality you need
Same app at every tier. What changes is the models, the hardware they need, and whether receipts are signed. Scores are measured with the source named, or marked not measured.
- In the hosted demo
Lite
MIT engine, about 15 GB of GPU
ACE-Step 1.5 renders with the full guard, similarity check and certificate. No community-licence terms, but instrumentals and drafts below Music3's quality.
- Models
- decosa-api music module (decosa_api/verticals/music)
- Qwen3.8-27B (NVFP4)
- ACE-Step 1.5 turbo + 5Hz LM 1.7B
- LAION CLAP larger_clap_music + librosa chroma (services/music_embed)
- Hardware
- 1× 24-32 GB card for ACE-Step, plus the guard's model (or a remote one); CPU for the similarity check
- Quality evidence
- Prompt guard on held-out prompts (79: 30 safe, 26 overt, 23 sneaky)precision 100%, recall 98% (48 of 49), 0 of 30 safe prompts refuseddecosa-api docs/evals/music-gen-cleared.md, 2026-09-25; prompts hand-written for the eval
- Planted near-copies flagged (held-out test, 240 clips)80.8% at 2.3% false alarms on unrelated tracks (2 of 88)decosa-api docs/evals/music-gen-cleared.md, 2026-09-25; threshold set on the dev split
- Music qualitynot measured yet
- Latency
- measured: ACE-Step renders in seconds once loaded (studio, 2026-09-23); the guard's call and the similarity check as for standard
- Verification
- Proof: partial
- In the hosted demo
Standard
the hosted demo, MiniMax-Music3 on a 96 GB card
MiniMax-Music3 songs with vocals (community licence, stated on every certificate) and ACE-Step, with the same guard, check and certificate.
- Models
- decosa-api music module (decosa_api/verticals/music)
- Qwen3.8-27B (NVFP4)
- MiniMax-Music3
- ACE-Step 1.5 turbo + 5Hz LM 1.7B
- LAION CLAP larger_clap_music + librosa chroma (services/music_embed)
- Hardware
- 1× RTX PRO 6000 Blackwell 96 GB (about 50 GB free for Music3), CPU for the similarity check
- Quality evidence
- Prompt guard on held-out prompts (79)precision 100%, recall 98%; code rules alone: recall 55%decosa-api docs/evals/music-gen-cleared.md, 2026-09-25
- Planted near-copies flagged, by change (held-out)pitch +2: 75%, pitch -1: 85%, tempo 0.92: 83%, tempo 1.08: 85%, pitch +1 and tempo 1.05: 85%, 12 s excerpt pitched -2: 73%decosa-api docs/evals/music-gen-cleared.md, 2026-09-25
- Music qualitynot measured yet
- Latency
- measured on our server: the prompt check in seconds to half a minute on a saturated shared gateway, a track in about a minute to render, the similarity check in seconds
- Verification
- Proof: partial
Every model in the stack
| Model | Tiers | Params · VRAM | Verification | Details |
|---|---|---|---|---|
Prompt guard, code layer: gazetteer of well-known names, look-alike folding, cover/cloning/type-beat patterns, a genre and era allow-list; the certificate and refusal log (CPU)decosa-api music module (decosa_api/verticals/music) 0 GBProof: partial | LiteStandard | 0 GB | Proof: partial | |
| ||||
Prompt guard, typed judgment: names the category (artist, work, voice, label or none) with a calibrated probability; one call per briefQwen3.8-27B (NVFP4)nvidia/Qwen3.8-27B-NVFP4 on Hugging Face (opens in a new tab) 27.8B · 20 GBProof: strongIn the hosted demo | LiteStandard | 27.8B · 20 GB | Proof: strongIn the hosted demo | |
| ||||
Music generation: songs with vocals and lyrics (default engine)MiniMax-Music3MiniMaxAI/MiniMax-Music3 on Hugging Face (opens in a new tab) 8.58B LM + 2.43B flow transformerProof: partialIn the hosted demo | Standard | 8.58B LM + 2.43B flow transformer | Proof: partialIn the hosted demo | |
| ||||
Music generation: fast drafts and instrumentals (MIT engine)ACE-Step 1.5 turbo + 5Hz LM 1.7BACE-Step/Ace-Step1.5 on Hugging Face (opens in a new tab) 2.39B DiT + 1.85B LM · 14.6 GBProof: partialIn the hosted demo | LiteStandard | 2.39B DiT + 1.85B LM · 14.6 GB | Proof: partialIn the hosted demo | |
| ||||
Similarity check (CPU): melody by chroma alignment across keys and tempos, sound by CLAP window embeddings, both normalised per referenceLAION CLAP larger_clap_music + librosa chroma (services/music_embed)laion/larger_clap_music on Hugging Face (opens in a new tab) 0 GBNo proof yet | LiteStandard | 0 GB | No proof yet | |
| ||||
Tools, services and hardware
Tools
- Free Music Archive dataset (fma_small subset) (opens in a new tab)Code MIT, metadata CC BY 4.0; each track under its artist's licence: only CC BY, CC BY-SA, CC0 and public-domain tracks are used
The 240-track reference catalogue (vectors only) and the eval: 64 catalogue tracks with 6 planted near-copies each, 80 held-out tracks and 132 tracks by artists not in the catalogue.
- c2pa-python (opens in a new tab)MIT OR Apache-2.0
The C2PA content credential on every MP3 (via the provenance kit, vertical 07/provenance).
- ComfyUI (opens in a new tab)GPL-3.0
Runs the MiniMax-Music3 graph for the studio worker.
- FFmpeg (rubberband filter) (opens in a new tab)LGPL-2.1+ (rubberband GPL-2.0+ in the build used for the eval only)
MP3 encoding, audio decoding for the similarity check, and the planted pitch and tempo changes in the eval.
Services
- decosa-api:8445
${DECOSA_REGISTRY}/decosa-api:<tag>GET /music/info, /music/samples; POST /music/guard, /music/generate, /music/check, /music/runs/{id}/compare; GET /music/runs/{id}, /music/certificates/{id}, /music/guard/log. Needs FFmpeg in the image for the studio worker.
- decosa-music-embed:8486
CPU similarity service (services/music_embed/Dockerfile, built locally): /v1/match, /v1/features, /v1/pair, /v1/embed. Holds the catalogue as vectors; never stores audio.
- comfyui:8188
MiniMax-Music3 renders for the studio worker (see the studio tool).
- vLLM:8114
vllm/vllm-openai@sha256:c2914767605584b6d8f45686b82de173ecc99e781897aa3d0a66dacd72c51ae1Qwen3.8-27B NVFP4 for the typed judgment, behind our gateway (hosted) or called directly (self-host).
Hardware
- 1× RTX PRO 6000 Blackwell 96 GB, shared Fits
Measured on our server 2026-09-25: Music3 renders on GPU0 beside the live-demo services (about 25 GB free before the job, ComfyUI unloading between jobs); the guard's model runs on GPU1; the similarity check on CPU.
- 1× 24-32 GB card
Not tested. ACE-Step (14.6 GB peak, measured) fits; MiniMax-Music3 does not; the guard's model needs its own ~20 GB or a remote server.
- CPU only Fits
The prompt guard's code layer and the similarity check run on CPU (about 2 s per 30 s track, measured); rendering needs a GPU.
Latency per lane
- Prompt check (typed judgment), hosted gateway route30.3 s
Measuredmeasured on our server 2026-09-25: median 30 s over 120 eval prompts while other evaluation jobs saturated the shared gateway (p90 46 s); 0.4-1.6 s in the recorded runs once it was quiet; a refusal by the code layer takes milliseconds and makes no call
- Brief to finished track with certificate, 30 s track42.7 s
Measuredmeasured on our server 2026-09-25: median of 7 recorded runs (33.8-65.6 s), gateway route, queue empty
- 30 s MiniMax-Music3 track, render only43.3 s
Measuredmeasured on our server 2026-09-25: 29.5-43.3 s over 7 recorded runs (Music3 33.5-43.3 s, ACE-Step 29.5-36.2 s) on shared GPU0, model load included; one earlier Music3 render took 74.2 s; 21.4 s in the self-host check
- Similarity check, 30 s track2.0 s
Measuredmeasured on our server 2026-09-25: 1.7-2.4 s on CPU (8 threads), 240 references
Notes
- The similarity check knows only its 240 references and the files you compare with it: a clear result says nothing about the millions of commercial recordings it has never seen.
- Music3 output is labelled "Powered by MiniMax-Music3" in the console and in the certificate.
Run this exact stack on your machine
Paste into Claude Code / Codex to assemble this stack locally. The prompt checks your GPU, pulls the pinned models, writes the compose file and runs a smoke test.
# Assemble Decosa rights-cleared music generation on this machine
You are setting up a music generator with a paper trail: a prompt guard that refuses (or strips) named artists, songs,
labels and voice imitation; renders on MiniMax-Music3 or ACE-Step 1.5; a CPU similarity check against a catalogue of
openly licensed recordings; and for every track a C2PA credential and a signed licence certificate. Work step by step,
show me each command before you run anything with `sudo`, and stop to ask if a check fails.
## Step 0: set up with a coding agent, rehearse on mock data, then go private
This prompt is for a coding agent running on the machine that will host the service. We recommend Claude Code with
Claude Opus 5.5; any capable coding agent works. Work in this order:
1. Set up on mock data only. During the whole setup you (the agent) work with the synthetic sample bundle below and
nothing else. Do not ask me for real data, and do not open, read, list or copy files that hold real data, even to
"test with something realistic".
2. Rehearse. When the steps below are done and the service is healthy, fetch the mock-data bundle for this tool,
https://decosa.ai/samples/music-gen-cleared.zip (506 KB, 12 checks, synthetic or openly licensed: see `licence` in expected.json),
show me what is in it, and run the rehearsal against the local API:
`docker compose exec api python scripts/rehearse.py music-gen-cleared` (the api image carries the same bundle under /app/rehearsal/music-gen-cleared/;
with no key set, the script asks the local API for a short demo token). From a decosa-api checkout instead:
`python scripts/rehearse.py music-gen-cleared --bundle music-gen-cleared.zip --base-url http://127.0.0.1:<PORT>`.
It sends the mock inputs to the local API and prints PASS or FAIL for each expected property (for example: "the named-artist brief is refused", "the refusal comes from the code rules, with no model call", "no model call is spent on the named-artist refusal"). Show me
the full output. Every check must pass. If one fails, fix the install and run it again; never edit `expected.json`
to make a check pass.
3. Stop there. Once the rehearsal passes, tell me, and I will run my own data against the local API myself, on this
machine.
For the person running this: a coding agent that runs in the cloud sees everything in its context, including files it
reads, command output and anything pasted into the chat. Keep real data out of the chat and out of anything the agent
can read. Switch to your own data only after the rehearsal has passed and the agent's work is done.
## 0. Ground rules and licences
- Music models: **MiniMax-Music3** (MiniMax-Music3 Community License) and **ACE-Step 1.5** (MIT). Text model for the
guard: Qwen3.8-27B (Apache-2.0). Similarity: LAION CLAP `laion/larger_clap_music` (Apache-2.0) and librosa (ISC), CPU.
- MiniMax-Music3 duties, from its LICENSE: show "MiniMax-Music3" prominently in any commercial UI that uses it (§3.1);
get MiniMax's written authorization above USD 20M yearly revenue (§3.2); a hosted service must keep and review
safeguards against infringing uses (§4) - this stack is that safeguard, so do not turn the guard off on a service
others use; follow the Acceptable Use Policy (Exhibit A), including disclosing machine-generated content (item 11).
- Be honest about what it does: the similarity check covers 240 Creative Commons tracks from the Free Music Archive (or
the references you give it). It is a triage signal, not a rights clearance. The certificate claims no copyright: the US
Copyright Office holds that prompts alone do not make an output protectable (Part 2 report, 29 Jan 2025).
- Bind every port to 127.0.0.1. Logs carry hashes, never prompts; keep it that way.
## 1. Check the machine
1. `nvidia-smi`: MiniMax-Music3 needs about 50 GB of free VRAM (measured on an RTX PRO 6000 96 GB); ACE-Step about
15 GB. The guard's text model needs about 20 GB more (Qwen3.8-27B NVFP4), or point it at a server you already run.
The similarity service is CPU only (about 2 GB of RAM, 8 threads).
2. `docker --version`, `docker compose version`. If Docker or the NVIDIA container toolkit is missing, ask me, then
install them from the official repositories and run `docker run --rm --gpus all nvidia/cuda:12.8.0-base-ubuntu24.04 nvidia-smi`.
3. Disk: about 60 GB (Music3 about 25 GB, ACE-Step about 10 GB, Qwen3.8-27B NVFP4 about 20 GB, CLAP 0.8 GB).
## 2. The render side (ComfyUI for Music3, optional ACE-Step)
Follow the Decosa **studio** assemble prompt, steps 2-4, for the MiniMax-Music3 weights (Comfy-Org/MiniMax-Music-3 @
`6baad88896848433857c170ba4f05d2ea9d5f218`), ComfyUI at commit `30bdda1ef13a3a34fce2cd2fec633f15d832122a`, and, if you
want the MIT engine, ACE-Step 1.5 (`ace-step/ACE-Step-1.5` @ `75fcfbdd`, weights `ACE-Step/Ace-Step1.5` @ `19671f40`).
You need ComfyUI answering on `http://127.0.0.1:8188` (or `8189`) with the `music3.api.json` graph from
`services/studio/workflows/`. decosa-api's own worker (`scripts/studio_worker.py`) sends the jobs; no render service.
## 3. Images
- `${DECOSA_REGISTRY}/decosa-api:<tag>` (**publishing soon**). If the pull fails, build from source:
`git clone <decosa-api source: on request at https://decosa.ai/contact?topic=self-host>` (access required), check out a release that contains
`decosa_api/verticals/music/`, and build `docker build -f docker/api/Dockerfile -t decosa-api:local .`.
The studio worker needs FFmpeg in the api container, and the C2PA credential needs c2pa-python (the base image does
not install the provenance extra), so add a layer (the image runs as uid 10001; install as root):
```dockerfile
# ./api-ffmpeg/Dockerfile
FROM decosa-api:local
USER root
RUN apt-get update && apt-get install -y --no-install-recommends ffmpeg && rm -rf /var/lib/apt/lists/*
RUN pip install --no-cache-dir "c2pa-python>=0.37" "pillow>=10"
USER decosa
```
`docker build -t decosa-api:music ./api-ffmpeg`.
- The similarity service, from the same checkout: `docker build -f services/music_embed/Dockerfile -t decosa-music-embed:local .`
(CPU torch 2.14.0, transformers 5.17.0, librosa 1.0.0; the 240-track catalogue ships inside it as vectors, no audio).
## 4. docker-compose.yml
Write this in `~/decosa/music/`. `network_mode: host` lets the api reach ComfyUI and your model server on 127.0.0.1;
with bridge networking, use service names instead and publish only 127.0.0.1 ports.
```yaml
services:
embed:
image: decosa-music-embed:local
network_mode: host
environment: { MUSIC_EMBED_HOST: 127.0.0.1, MUSIC_EMBED_PORT: "8486", MUSIC_EMBED_THREADS: "8" }
volumes: ["hf-cache:/hf"]
healthcheck: { test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8486/health', timeout=4)"], interval: 30s, retries: 20, start_period: 600s }
api:
image: decosa-api:music
network_mode: host
environment:
DECOSA_HOST: 127.0.0.1
DECOSA_PORT: "8445"
DECOSA_DATA_DIR: /data
DECOSA_LLM_ROUTE: direct
DECOSA_LLM_URL: http://127.0.0.1:8114/v1 # your Qwen3.8-27B server (vLLM, served name qwen3.8-27b)
DECOSA_LLM_MODEL: qwen3.8-27b
DECOSA_STUDIO_WORKER: command
DECOSA_STUDIO_WORKER_CMD: python /app/scripts/studio_worker.py
DECOSA_STUDIO_COMFY_URL: http://127.0.0.1:8188
DECOSA_STUDIO_WORK_DIR: /work
DECOSA_STUDIO_ALLOW_ACESTEP: "0" # "1" only if ACE-Step is installed where the worker can run it
DECOSA_MUSIC_EMBED_URL: http://127.0.0.1:8486
DECOSA_MUSIC_ENGINES: music3 # add ",acestep" with ACE-Step
DECOSA_PROVENANCE_DIR: /provenance
volumes: ["decosa-data:/data", "decosa-work:/work", "decosa-provenance:/provenance"]
depends_on: { embed: { condition: service_healthy } }
healthcheck: { test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8445/music/info', timeout=4)"], interval: 30s, retries: 10 }
volumes:
decosa-data:
decosa-work:
decosa-provenance:
hf-cache:
```
Use named volumes, never host folders: the api runs as uid 10001 and a host folder Docker creates is root's
(`PermissionError: '/data/keys.sqlite'`). The embed service downloads CLAP (`laion/larger_clap_music` @
`a0b4534a14f58e20944452dff00a22a06ce629d1`) on its first start; after that you can set `HF_HUB_OFFLINE: "1"`.
`docker compose up -d`, then wait for both health checks. Create the C2PA signing material once, then restart the api:
`docker compose exec api python scripts/provenance_devcert.py && docker compose restart api`; `GET /provenance/status`
must show `"c2pa": true`. It is a development CA: public C2PA validators show the signature as valid and the issuer as
untrusted. A trust-list certificate is your own purchase. On first start the api creates this box's Ed25519 key in
`decosa-data` (`/data/attest/`): back it up with `docker compose cp api:/data/attest ./attest-backup`, keep it private,
never print it. Certificates and render receipts are signed with it (an attestation by you, the operator).
## 5. Smoke test
```bash
B=http://127.0.0.1:8445
T=$(curl -s -XPOST $B/demo/session -H 'content-type: application/json' -d '{"vertical":"music-gen-cleared"}' | jq -r .token)
curl -s -XPOST $B/music/guard -H "authorization: Bearer $T" -H 'content-type: application/json' \
-d '{"prompt":"Upbeat pop in the style of Taylor Swift"}' | jq '.guard | {decision, decided_by}' # refused, by code
curl -s -XPOST $B/music/guard -H "authorization: Bearer $T" -H 'content-type: application/json' \
-d '{"prompt":"Upbeat pop in the style of Taylor Swift, bright guitars","mode":"strip"}' | jq '.guard | {decision, rendered_prompt}'
R=$(curl -s -XPOST $B/music/generate -H "authorization: Bearer $T" -H 'content-type: application/json' \
-d '{"prompt":"Warm acoustic pop for a bakery ad, ukulele and hand claps, instrumental","engine":"music3","seconds":30,"seed":5501}' | jq -r .run_id)
until curl -s $B/music/runs/$R -H "authorization: Bearer $T" | jq -e '.status=="done" or .status=="failed"' >/dev/null; do sleep 5; done
curl -s $B/music/runs/$R -H "authorization: Bearer $T" | jq '{status, credential, similarity: .similarity.verdict, certificate}'
curl -s $B/music/certificates/$R | jq '{record: .}' | curl -s -XPOST $B/record/verify -H 'content-type: application/json' -d @- | jq .ok
```
Expect: the first prompt refused by code with no model call; the second stripped to "Upbeat pop, bright guitars"; the
render `done` with `credential: "c2pa"`, a similarity verdict (`clear` for a fresh track) and a certificate that verifies
(`true`). Then take one catalogue track's audio if you have it, pitch-shift it (`ffmpeg -i in.mp3 -af rubberband=pitch=1.12246 out.mp3`)
and `POST /music/check` it as the body: expect a high score with that track named. Report the times you measure; on our
RTX PRO 6000 a 30 s Music3 track rendered in 21-74 s on a shared card and the similarity check took about 2 s on CPU.
## 6. Use your own references
The strongest use is checking against the references a client sent. For one track, `POST /music/runs/{id}/compare`
with the reference file as the body (compared in memory, not kept). For a standing set, rebuild the catalogue from your
own licensed files with `scripts/music_build_catalog.py` then `--augment`, and mount it at `/catalog` in the embed service.
## 7. Point the app at the local API
Set `NEXT_PUBLIC_DECOSA_API=http://127.0.0.1:8445` in the site's `.env.local`. Contract: `API_CONTRACT.md`, section
"Rights-cleared music generation". Any UI that plays Music3 output must show "Powered by MiniMax-Music3".What it does, in shortWho it's for, where it runs and the key results
Music for ads, games and creators with a paper trail. A prompt guard refuses or strips named artists, songs, labels and voice imitation (code rules, then one receipted typed judgment), the track renders on MiniMax-Music3 or ACE-Step, and a CPU check scores it against a catalogue of openly licensed recordings. Each track ships with a C2PA credential and a signed certificate that states the model, seed, checks, similarity score and the exact licence.
In short
Last reviewed
- What it is
- Music for ads, games and creators, with a prompt guard, a similarity check and a signed licence certificate for every track.
- Who it's for
- Teams in music and creative and media.
- Where it runs
- Hosted or self-host
- Key numbers
- 100% (48/48) Prompt guard precision (refuse) (test split, n = 79)
- 98.0% (48/49) Prompt guard recall (refuse) (test split, n = 79)
- 0 of 30 Safe prompts refused (test split, n = 30)
- 42.7 s Median end-to-end run, hosted (QA sweep 2026-09-25)
How we tested itEnd-to-end checks, hosted and self-hosted, with dates
Verified end to end
Hosted: verified 25 Sep 2026 · measured 25 Sep 2026: · p50 43 s · ~<$0.001 per run · 1 receipt
Loading the nightly status…
Self-host: verified 25 Sep 2026 · Fresh clone of the branch into a clean directory, docker build of the api image plus the documented FFmpeg and c2pa-python layer and of services/music_embed, compose with named volumes, pointed at the already-running local vLLM (direct route) and ComfyUI; then torn down.
Measured cost to run: about $0.011 per track (hosted, 25 Sep 2026). Self-hosting is free: the code is open and the models are open-weight. You pay only for your own hardware and power.
The guard refused and stripped as documented, a 30 s MiniMax-Music3 render finished in 21.4 s with a similarity verdict and a certificate that verified (and failed when edited), a planted near-copy scored 11.6 against the catalogue, and no prompt text reached the logs. Found on the way: the api image has no c2pa-python, so the first render had no C2PA credential; with the layer and the dev certificate, stamping inside the container produced a credential that validates.
Known limits (5)
- The similarity check knows only 240 Creative Commons tracks and the files you compare; it flagged 81% of planted near-copies at 2% false alarms, and a clear result says nothing about commercial catalogues.
- The guard reads text only: 98% recall on held-out prompts, and it cannot hear a melody someone describes or hums.
- Renders share one GPU with the live demos: 3 per demo session, 3 per API key per day.
- C2PA credentials are signed by a development CA: valid signature, untrusted issuer in public validators.
- No copyright is claimed in the output; the certificate records checks and licence terms, not ownership.
Eval results, nightly checks and cost per run · held-out eval
Technical detailsModels, where it runs, labels, what it is built from
- Models
- MiniMax-Music3 · ACE-Step 1.5 · Qwen3.8-27B · LAION CLAP
- Where
- Hosted or self-host
- Checks
- Receipted prompt check; C2PA credential and signed licence certificate
- Industry
- Music · Creative and media
- Output
- Media · Signed record or verdict
- Data
- No sensitive data
- Hardware
- 1× 96 GB GPU
- Licence
- Includes community-licence models
- Part of
- Decosa Studio: Music
- Runs in
- Decosa hosted · Self-host
- Built from
- Studio render · Typed judgment · Content credentials · Signed record
Every result carries a signed record of which model produced it, so you can check it later. How that works
Questions people ask
Does this clear the rights in a generated track?
No. It is not legal advice and not a rights clearance. The similarity check compares the track with 240 openly licensed Free Music Archive recordings, or with a reference you send; a clear result says nothing about commercial catalogues it has never seen.
What happens if I ask for a named artist's sound?
The prompt guard refuses the request, or in strip mode removes the name and re-checks what is left. On 79 held-out synthetic prompts it refused 48 of 49 imitation prompts and none of 30 safe ones. Every refusal is logged with its rule.
Which licence covers each track?
The certificate names it: MIT for ACE-Step 1.5, or the MiniMax-Music3 Community License, which allows commercial use but requires showing "MiniMax-Music3" in a commercial UI, prior written authorization above USD 20M yearly revenue, and its acceptable use policy.
Is AI-generated music copyrighted?
The certificate claims no copyright. The US Copyright Office's Part 2 report (29 Jan 2025) says AI output is protected only where a human author determined sufficient expressive elements, and prompts alone are not enough. Other countries differ.
How well does the near-copy check work?
On the test split it flagged 80.8% of planted near-copies at the flag threshold (90.4% at the review threshold) with 2.3% false flags on unrelated tracks by new artists. About one planted copy in five slips under the flag, and lyrics are not compared.
Can I run it on my own GPU?
Yes. Self-hosted, nothing leaves your machine. Hosted, the brief goes to the text model through our gateway and to Decosa's render service; the prompt check costs about $0.0002 of model time per track.
Ask a question or leave feedbackWe read every message and publish useful answers
Ask about Rights-cleared music generation
We read every message. Questions, comments and our answers show here once we have reviewed and approved them.
Loading questions…