API
Authentication and API keys
How to create, scope and revoke ChatPRD API keys, and how to send them with each request.
ChatPRD API keys are personal: each key acts as the user who created it and sees exactly what that user can see in the app, including the teams they belong to.
Creating a key
- Open Settings β API Keys in ChatPRD (Pro, Team or Enterprise plan).
- Give the key a name, ideally the name of the tool or agent that will use it, so you can revoke it on its own later.
- Keys are read-only by default. Turn on Allow write only if the tool needs to create or edit documents.
- Copy the key. It is shown once and cannot be retrieved again.
Sending the key
Send the key as a Bearer token on every request:
GET /api/connectors/v1/me HTTP/1.1
Host: app.chatprd.ai
Authorization: Bearer <CHATPRD_API_KEY>Scopes
| Scope | Granted by | Allows |
|---|---|---|
connector:read | every key | GET endpoints: read, list and search |
connector:write | keys created with Allow write | POST /documents and PATCH /documents/{id} |
A read-only key used on a write endpoint receives 401 unauthorized. Check a key's scopes with GET /me.
Plans
The API requires a Pro, Team or Enterprise plan. Requests from accounts without one receive 402 plan_required.
Revoking a key
Revoke keys from Settings β API Keys. Revocation takes effect immediately; further requests with that key receive 401 unauthorized.
Good practice
- Store keys in a secret manager or environment variable; never commit them or paste them into prompts.
- Create one key per tool or agent.
- Prefer read-only keys unless the integration needs to create or edit documents.
Ready to get started? You can try ChatPRD for free πSign Up Now