Skip to content

API Authentication ​

VeriPrompt supports two authentication methods: Gateway API Keys for programmatic access and Session Cookies for browser-based CRUD operations.

VeriPrompt Keys vs. Provider Keys

VeriPrompt uses two separate types of API keys — mixing them up is the most common integration error:

KeyWhere to useExample prefix
VeriPrompt gateway keyAuthorization header in API requestssk-vp-... or vp-gw_sk_...
Provider API key (OpenAI, Anthropic, etc.)Configured in Settings > Provider Modelssk-..., sk-ant-..., etc.

Your provider API keys are never sent in the Authorization header. They are stored securely in VeriPrompt and used internally when routing requests to providers.

Gateway API Key Authentication ​

All external API requests use Bearer token authentication with a VeriPrompt key.

Header Format ​

text
Authorization: Bearer sk-vp-your-key-here

API Key Types ​

Key PrefixTypeUse Case
sk-vp-Gateway KeyPrimary key format for all API endpoints
vp-gw_sk_Gateway Key (legacy)Older format, fully supported

Key Scopes ​

Gateway keys can be configured with different permission scopes:

ScopeCapabilities
Full AccessRead, write, and execute operations
Read OnlyList and retrieve resources
Execute OnlyExecute prompts and chat completions

Example Request ​

bash
curl https://app.veriprompt.tech/api/v1/chat/completions \
  -H "Authorization: Bearer sk-vp-your-key-here" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-4o",
    "messages": [{"role": "user", "content": "Hello"}]
  }'

Session Authentication ​

CRUD operations (creating, updating, deleting prompts, projects, and webhooks) require session authentication via the VeriPrompt dashboard. These operations are performed through the web interface.

For programmatic CRUD access, use the MCP tool endpoints with a gateway key:

bash
# Execute a stored prompt via MCP
curl -X POST https://app.veriprompt.tech/api/mcp \
  -H "Authorization: Bearer sk-vp-your-key-here" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "method": "tools/call",
    "params": {
      "name": "execute_stored_prompt",
      "arguments": { "promptId": "prompt_..." }
    },
    "id": 1
  }'

Create an API Key ​

  1. Log in to the VeriPrompt dashboard.
  2. Navigate to Settings > External API Users.
  3. Click Create Key and select the appropriate scope.
  4. Copy the key immediately - it is only shown once.
  5. Store the key securely in your secrets manager or environment variables.

Key Security Best Practices ​

  • Never expose API keys in client-side code or version control.
  • Rotate keys regularly via the dashboard.
  • Use the minimum scope required for your integration.
  • Monitor key usage in the Analytics section.