The agent receives the API key and the human only supplies the emailed OTP.
Sign up
Ask for the owner’s email and a workspace name:
Store api_key immediately using the matching Codex,
OpenCode, Hermes, or
OpenClaw guide. Prism returns it once. Never repeat it to the
human or include it in the final response.
Verify
Ask the human for the six-digit code Prism emails, then call:
The OTP expires after five minutes and allows three attempts. A successful
response is { "verified": true }.
The key expires after 30 days and cannot run inference before verification.
Repeating signup for an unverified email rotates the previous key and OTP. For
errors, follow the returned fix field instead of retrying unchanged. Last modified on September 16, 2026