Developers
Authentication
API keys and access tokens for the REST API
API base URL
https://api.promptcache.app
Every REST request to PromptCache uses HTTPS and an Authorization: Bearer … header. There are two credential types:
| Credential | Looks like | Use when |
|---|---|---|
| API key | Starts with pk_ | Scripts, backends, CI, automation |
| Access token (JWT) | Returned from sign-in | Publish, fork, and dashboard-style flows |
The API base URL is shown at the top of this page.
API keys
Create keys in the dashboard: API Keys → New key. Each key belongs to one workspace and has permission scopes.
Scopes
| Scope | Allows |
|---|---|
prompts:read | Read prompts, list versions, invoke, inject |
prompts:write | Create, update, and delete prompts |
organization:read | Read workspace metadata |
organization:write | Change workspace settings and membership |
Give each integration the smallest scope it needs.
Key safety
- Keys are shown once at creation. Store them in a password manager or secrets store.
- If you lose a key, revoke it and create a new one.
- Never commit keys to git or log full
Authorizationheaders.
Send your API key
Pass the key on every request:
curl -s \
-H 'Authorization: Bearer pk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx' \
-H 'Accept: application/json' \
'https://api.promptcache.app/api/v1/prompts?page=1&limit=20'With an API key, the server knows which workspace you belong to. You usually do not need to pass a separate organization id.
User access tokens (JWT)
Sign in with POST /api/v1/auth/login using email and password. Use the returned access token as Authorization: Bearer <token>.
You need a user token (not API-key-only) for:
POST /api/v1/prompts/:id/publishPOST /api/v1/prompts/:id/versions/:versionId/forkPOST /api/v1/public/prompts/:id/fork
For everyday automation, list, get, create, update, invoke, an API key is enough.
When using a JWT, pass organizationId in the query string or body where the API expects a workspace (see each route in Prompts API).
Rate limits and expiry
API keys can have per-window rate limits. Optional expiry dates reject expired keys with 401.
Common errors
| Situation | Typical response |
|---|---|
Missing Authorization header | 401 |
| Wrong or revoked key | 401 |
| Key lacks scope | 403 |
| No access to the workspace | 404 on org-scoped resources |
For unauthenticated public reads, see Public catalog API.
