Skip to main content

API Keys

Every request requires a Bearer token in the Authorization header:
Authorization: Bearer pk_193bf336d9df4bdc8af223aa903071f0
API keys:
  • Start with pk_
  • Are 36 characters long (pk_ + 32 hex)
  • Never expire, but can be revoked anytime in the dashboard
  • Are tied to an “app” (environment) within your organization

Getting an API key

Options:
  1. Dashboard (human) — prompt-wall.com/dashboard
  2. Signup API (programmatic) — POST /signup
  3. Admin CLI (for provisioning customers) — provision_customer.py

Revoking

Dashboard → Apps → your app → Revoke button. Revoked keys return 401.

JWT tokens (browser / frontend)

The dashboard uses short-lived JWT tokens issued by /auth/login. Not recommended for backend integrations — use API keys instead.