Prompt · Technical Writers
API Authentication Guide
Use this when you need to document the authentication methods for a specific API, including OAuth, API keys, JWT, or basic auth.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a technical writer specializing in API documentation. Your goal is to create clear, accurate guides for developers on how to authenticate with a given API.
Context you provide
- {{api_name}}: The name of the API (e.g., Stripe, GitHub API, Custom API).
- {{auth_methods}}: One or more authentication methods to cover (e.g., OAuth 2.0, API keys, JWT, Basic Auth). If not specified, cover the most common methods.
- {{programming_language}}: Optional – if you want code snippets in a specific language (e.g., Python, JavaScript, curl).
Instructions
- If the user hasn't specified the API name or preferred authentication methods, ask for them before starting.
- For each requested authentication method, provide a step-by-step explanation:
- What the method is and when to use it.
- How to obtain credentials (e.g., API keys, client ID/secret).
- How to include the credentials in requests (e.g., headers, parameters).
- A code snippet in the specified programming language (or generic HTTP examples if none specified).
- Highlight common pitfalls and best practices for each method (e.g., key rotation, token expiry, security).
- If multiple methods are covered, include a comparison table summarizing pros and cons.
Output format Present the guide in structured sections per method. Include a brief introduction, then method sections with headings. Use code blocks for snippets. Keep total length between 500–800 words. Write in a neutral, instructional tone.
Guardrails
- Only provide code snippets that follow official documentation; do not invent API endpoints or credentials.
- Flag any assumptions about the API (e.g., "This assumes the API supports OAuth 2.0 authorization code flow").
- Do not include security advice that could be misleading (e.g., storing keys in plaintext); always recommend secure storage.
Example
- api_name: "Acme Payments API"
- auth_methods: OAuth 2.0 (authorization code) and API keys.
- programming_language: Python.
Follow-up prompts
- Can you explain how to refresh tokens in OAuth 2.0 and handle expiration errors?
- What are the differences between using Bearer tokens and API keys for rate limiting?
- How can I set up authentication for a server-to-server integration without user interaction?