Skip to content

Developers

Authentication

API keys and access tokens for the REST API

API base URL

https://api.promptcache.app

Every REST request to PromptCache uses HTTPS and an Authorization: Bearer … header. There are two credential types:

CredentialLooks likeUse when
API keyStarts with pk_Scripts, backends, CI, automation
Access token (JWT)Returned from sign-inPublish, fork, and dashboard-style flows

The API base URL is shown at the top of this page.

API keys

Create keys in the dashboard: API Keys → New key. Each key belongs to one workspace and has permission scopes.

Scopes

ScopeAllows
prompts:readRead prompts, list versions, invoke, inject
prompts:writeCreate, update, and delete prompts
organization:readRead workspace metadata
organization:writeChange workspace settings and membership

Give each integration the smallest scope it needs.

Key safety

  • Keys are shown once at creation. Store them in a password manager or secrets store.
  • If you lose a key, revoke it and create a new one.
  • Never commit keys to git or log full Authorization headers.

Send your API key

Pass the key on every request:

curl -s \
  -H 'Authorization: Bearer pk_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx' \
  -H 'Accept: application/json' \
  'https://api.promptcache.app/api/v1/prompts?page=1&limit=20'

With an API key, the server knows which workspace you belong to. You usually do not need to pass a separate organization id.

User access tokens (JWT)

Sign in with POST /api/v1/auth/login using email and password. Use the returned access token as Authorization: Bearer <token>.

You need a user token (not API-key-only) for:

  • POST /api/v1/prompts/:id/publish
  • POST /api/v1/prompts/:id/versions/:versionId/fork
  • POST /api/v1/public/prompts/:id/fork

For everyday automation, list, get, create, update, invoke, an API key is enough.

When using a JWT, pass organizationId in the query string or body where the API expects a workspace (see each route in Prompts API).

Rate limits and expiry

API keys can have per-window rate limits. Optional expiry dates reject expired keys with 401.

Common errors

SituationTypical response
Missing Authorization header401
Wrong or revoked key401
Key lacks scope403
No access to the workspace404 on org-scoped resources

For unauthenticated public reads, see Public catalog API.