# Using share-prompt.com from an agent

Portable skill URL: `https://share-prompt.com/skill.md`

Share Prompt provides a universal REST API and a remote MCP server. You do not need a Share Prompt account to search public prompts, fetch a shared prompt, render its variables, or publish an anonymous unlisted prompt.

## Interpret user requests

- "Share this prompt" means publish the supplied prompt only after the user has provided or approved the title, content, categories, and visibility.
- "Fetch this prompt" means extract the final path segment from a share-prompt.com URL and call `get_prompt` or `GET /api/v1/prompts/{id}`.
- "Run this prompt" means fetch it, collect any missing variable values, call `render_prompt` or `/render`, then use the returned `content` as the prompt for the current model. Share Prompt renders prompt text; it does not execute a model on the server.
- "Update this prompt" requires a Bearer API key with company access or the anonymous edit token returned at publish time.
- Always ask for explicit confirmation immediately before deleting a prompt.

## Remote MCP

Endpoint: `https://share-prompt.com/mcp`

Tools:

- `search_prompts`
- `get_prompt`
- `render_prompt`
- `publish_prompt`
- `update_prompt`
- `delete_prompt`

Connect without authentication for public reads and anonymous publishing. Add `Authorization: Bearer sp_live_...` to publish under identity, access company prompts, and manage company prompts.

## REST API

OpenAPI: `https://share-prompt.com/openapi.json`

Base URL: `https://share-prompt.com/api/v1`

Authenticated request:

```http
Authorization: Bearer sp_live_REDACTED
Content-Type: application/json
```

Anonymous prompt updates and deletes:

```http
X-Edit-Token: sp_edit_REDACTED
```

## Anonymous publishing

Anonymous prompts are forced to `link` visibility and are not listed publicly. The publish response contains an `editToken` exactly once. Treat it like a password. If it is lost, the anonymous prompt cannot be edited or deleted.

## Identity publishing

A signed-in user creates a key at `https://share-prompt.com/settings/agent`. API keys are shown once, stored only as hashes, and can be revoked at any time. Identity-backed prompts may use `private`, `company`, `link`, or `public` visibility. Private prompts are visible and manageable only by their creator.

## Prompt schema

```json
{
  "title": "Launch brief writer",
  "description": "Turn product details into a launch brief.",
  "content": "Write a launch brief for #product aimed at #audience.",
  "tags": ["Writing", "Marketing"],
  "variables": [
    { "name": "product", "label": "Product", "type": "text", "defaultValue": "" },
    { "name": "audience", "label": "Audience", "type": "text", "defaultValue": "" }
  ],
  "visibility": "link"
}
```

Use one to three categories from `GET /api/v1/categories`. `Miscellaneous` cannot be combined with another category.

## Security rules

- Never place API keys or edit tokens in URLs, prompt bodies, or published prompt content.
- Do not publish private conversation context unless the user explicitly asks and has reviewed it.
- Do not infer public visibility. When visibility is not stated, use anonymous `link` publishing or authenticated `private` publishing.
- Deletion is permanent and requires explicit user confirmation.
