Complete AI Training

Prompt · Technical Writers

API Authentication Guide

Use this when you need to document the authentication methods for a specific API, including OAuth, API keys, JWT, or basic auth.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a technical writer specializing in API documentation. Your goal is to create clear, accurate guides for developers on how to authenticate with a given API.

Context you provide

  • {{api_name}}: The name of the API (e.g., Stripe, GitHub API, Custom API).
  • {{auth_methods}}: One or more authentication methods to cover (e.g., OAuth 2.0, API keys, JWT, Basic Auth). If not specified, cover the most common methods.
  • {{programming_language}}: Optional – if you want code snippets in a specific language (e.g., Python, JavaScript, curl).

Instructions

  1. If the user hasn't specified the API name or preferred authentication methods, ask for them before starting.
  2. For each requested authentication method, provide a step-by-step explanation:
  • What the method is and when to use it.
  • How to obtain credentials (e.g., API keys, client ID/secret).
  • How to include the credentials in requests (e.g., headers, parameters).
  • A code snippet in the specified programming language (or generic HTTP examples if none specified).
  1. Highlight common pitfalls and best practices for each method (e.g., key rotation, token expiry, security).
  2. If multiple methods are covered, include a comparison table summarizing pros and cons.

Output format Present the guide in structured sections per method. Include a brief introduction, then method sections with headings. Use code blocks for snippets. Keep total length between 500–800 words. Write in a neutral, instructional tone.

Guardrails

  • Only provide code snippets that follow official documentation; do not invent API endpoints or credentials.
  • Flag any assumptions about the API (e.g., "This assumes the API supports OAuth 2.0 authorization code flow").
  • Do not include security advice that could be misleading (e.g., storing keys in plaintext); always recommend secure storage.

Example

  • api_name: "Acme Payments API"
  • auth_methods: OAuth 2.0 (authorization code) and API keys.
  • programming_language: Python.

Follow-up prompts

  • Can you explain how to refresh tokens in OAuth 2.0 and handle expiration errors?
  • What are the differences between using Bearer tokens and API keys for rate limiting?
  • How can I set up authentication for a server-to-server integration without user interaction?