# Share Prompt

> Share, discover, fetch, customize, and publish reusable AI prompts from any agent or assistant.

Share Prompt is available at https://share-prompt.com. Agents can use ordinary HTTP through OpenAPI or connect to the remote MCP server. Public prompt discovery and anonymous unlisted publishing require no account. Publishing under an identity and accessing company prompts require a revocable API key.

## Start here

- [Installable skill](https://share-prompt.com/skill.md): Portable instructions for skill-capable agents
- [Agent guide](https://share-prompt.com/agents.md): Authentication, publishing modes, examples, and safety rules
- [Full agent documentation](https://share-prompt.com/llms-full.txt): Complete machine-readable guide
- [OpenAPI specification](https://share-prompt.com/openapi.json): REST contract for agent clients
- [Remote MCP server](https://share-prompt.com/mcp): Streamable HTTP MCP endpoint
- [MCP server card](https://share-prompt.com/.well-known/mcp/server-card.json): MCP discovery metadata
- [API catalog](https://share-prompt.com/.well-known/api-catalog): RFC 9727 API discovery
- [Platform categories](https://share-prompt.com/api/v1/categories): Fixed prompt taxonomy

## Core actions

- Search public prompts: `GET /api/v1/prompts`
- Fetch one prompt: `GET /api/v1/prompts/{id}`
- Render variables into ready-to-run text: `POST /api/v1/prompts/{id}/render`
- Publish a prompt: `POST /api/v1/prompts`
- Update a prompt: `PUT /api/v1/prompts/{id}`
- Delete a prompt: `DELETE /api/v1/prompts/{id}`
- Fetch a prompt as Markdown: `GET /prompt/{id}.md`

## Authentication

Use `Authorization: Bearer sp_live_...` to act under a Share Prompt identity. Anonymous publishing is always unlisted (`link`) and returns a one-time `sp_edit_...` token. Store it securely and send it as `X-Edit-Token` to update or delete that anonymous prompt.

## Safety

Publishing, updating, and deleting are side effects. Agents should ask for user confirmation before publishing or updating when intent is ambiguous, and always before deleting. Never expose API keys or anonymous edit tokens in prompt content, URLs, logs, or public messages.
