Skip to content

Authentication ​

All API requests require an API key or an authenticated session token.

Create an API key ​

  1. Sign in to the Veriprompt dashboard.
  2. Go to Settings -> External API Users.
  3. Create a new API key for your project.
  4. Store it securely (use a secrets manager or environment variables).

Use the Authorization header ​

bash
curl https://app.veriprompt.tech/api/health \
  -H "Authorization: Bearer YOUR_API_KEY"

Session tokens (UI workflows) ​

If you are calling endpoints from the UI, the session cookie or token is used automatically.

Key rotation checklist ​

  • Keep keys scoped to projects and environments.
  • Rotate keys on a schedule or after staff changes.
  • Never commit keys to Git.

Troubleshooting ​

  • 401 errors usually mean a missing or invalid key.
  • 403 errors indicate insufficient permissions for the key.

Multi-Factor Authentication (MFA) ​

For an extra layer of security, enable TOTP-based two-factor authentication on your account. When enabled, you will need a code from your authenticator app each time you sign in.

See the Multi-Factor Authentication guide for setup instructions.

Single Sign-On (SSO) ​

If your company has Enterprise SSO enabled, you sign in with your identity provider instead of a Veriprompt password:

  • Type your work email on the sign-in page and use the Continue with … button that appears, or
  • Open the login URL your admin published: https://app.veriprompt.tech/login/sso/<slug>.

Company admins configure connectors, verified email domains, group-to-role mapping, and SCIM provisioning on Settings → Single Sign-On. Note that SSO logins do not use Veriprompt's TOTP second factor — MFA for SSO users is enforced at the identity provider.

See the Enterprise SSO guide for the full setup walkthrough.

Next steps ​