Appearance
API Authentication
VeriPrompt supports two authentication methods: Gateway API Keys for programmatic access and Session Cookies for browser-based CRUD operations.
VeriPrompt Keys vs. Provider Keys
VeriPrompt uses two separate types of API keys — mixing them up is the most common integration error:
| Key | Where to use | Example prefix |
|---|---|---|
| VeriPrompt gateway key | Authorization header in API requests | sk-vp-... or vp-gw_sk_... |
| Provider API key (OpenAI, Anthropic, etc.) | Configured in Settings > Provider Models | sk-..., sk-ant-..., etc. |
Your provider API keys are never sent in the Authorization header. They are stored securely in VeriPrompt and used internally when routing requests to providers.
Gateway API Key Authentication
All external API requests use Bearer token authentication with a VeriPrompt key.
Header Format
text
Authorization: Bearer sk-vp-your-key-hereAPI Key Types
| Key Prefix | Type | Use Case |
|---|---|---|
sk-vp- | Gateway Key | Primary key format for all API endpoints |
vp-gw_sk_ | Gateway Key (legacy) | Older format, fully supported |
Key Scopes
Gateway keys can be configured with different permission scopes:
| Scope | Capabilities |
|---|---|
| Full Access | Read, write, and execute operations |
| Read Only | List and retrieve resources |
| Execute Only | Execute prompts and chat completions |
Example Request
bash
curl https://app.veriprompt.tech/api/v1/chat/completions \
-H "Authorization: Bearer sk-vp-your-key-here" \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-4o",
"messages": [{"role": "user", "content": "Hello"}]
}'Session Authentication
CRUD operations (creating, updating, deleting prompts, projects, and webhooks) require session authentication via the VeriPrompt dashboard. These operations are performed through the web interface.
For programmatic CRUD access, use the MCP tool endpoints with a gateway key:
bash
# Execute a stored prompt via MCP
curl -X POST https://app.veriprompt.tech/api/mcp \
-H "Authorization: Bearer sk-vp-your-key-here" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"method": "tools/call",
"params": {
"name": "execute_stored_prompt",
"arguments": { "promptId": "prompt_..." }
},
"id": 1
}'Create an API Key
- Log in to the VeriPrompt dashboard.
- Navigate to Settings > External API Users.
- Click Create Key and select the appropriate scope.
- Copy the key immediately - it is only shown once.
- Store the key securely in your secrets manager or environment variables.
Key Security Best Practices
- Never expose API keys in client-side code or version control.
- Rotate keys regularly via the dashboard.
- Use the minimum scope required for your integration.
- Monitor key usage in the Analytics section.
