Appearance
Authentication
All API requests require an API key or an authenticated session token.
Create an API key
- Sign in to the Veriprompt dashboard.
- Go to Settings -> External API Users.
- Create a new API key for your project.
- Store it securely (use a secrets manager or environment variables).
Use the Authorization header
bash
curl https://app.veriprompt.tech/api/health \
-H "Authorization: Bearer YOUR_API_KEY"Session tokens (UI workflows)
If you are calling endpoints from the UI, the session cookie or token is used automatically.
Key rotation checklist
- Keep keys scoped to projects and environments.
- Rotate keys on a schedule or after staff changes.
- Never commit keys to Git.
Troubleshooting
- 401 errors usually mean a missing or invalid key.
- 403 errors indicate insufficient permissions for the key.
Multi-Factor Authentication (MFA)
For an extra layer of security, enable TOTP-based two-factor authentication on your account. When enabled, you will need a code from your authenticator app each time you sign in.
See the Multi-Factor Authentication guide for setup instructions.
Single Sign-On (SSO)
If your company has Enterprise SSO enabled, you sign in with your identity provider instead of a Veriprompt password:
- Type your work email on the sign-in page and use the Continue with … button that appears, or
- Open the login URL your admin published:
https://app.veriprompt.tech/login/sso/<slug>.
Company admins configure connectors, verified email domains, group-to-role mapping, and SCIM provisioning on Settings → Single Sign-On. Note that SSO logins do not use Veriprompt's TOTP second factor — MFA for SSO users is enforced at the identity provider.
See the Enterprise SSO guide for the full setup walkthrough.
