Prompt store
Store reusable system prompts centrally, then reference one or more of them and add inline instructions at request time.
Turn it on for an app
Enter a Prompt ID and Prompt content, then click Save prompt. Prompt changes apply immediately, without Save settings, and are recorded in the app's Audit Log.
Variable names can contain letters, numbers, underscores and hyphens. Callers must supply every variable as a string.
How it works
- Create - Store a prompt with a unique ID (e.g.,
code-reviewer) - Reference - Use it as the system message content:
quilrai-prompt-store-code-reviewer - Gateway Resolves - The gateway resolves the prompt and sends the full text to the LLM
Combining prompts and instructions
A system message is not limited to a single reference. The gateway scans it for quilrai-prompt-store-<id> reference tokens and replaces each one in place with that prompt's resolved content, leaving any other text exactly where you wrote it. So one system message can:
- Reference several prompts - list multiple
quilrai-prompt-store-<id>tokens and the gateway combines their resolved content in the order written. - Mix in your own instructions - add freeform text around the references to extend the stored prompt for a single request, without editing the stored prompt itself.
System message your app sends:
quilrai-prompt-store-startup-advisor
Be concise, practical, and honest. Always answer in English.
Stored prompt startup-advisor:
You are an experienced startup advisor, venture capitalist, product strategist, and entrepreneur.
Your role is to challenge assumptions, identify risks, and provide actionable recommendations.
Resolved prompt sent to the LLM:
You are an experienced startup advisor, venture capitalist, product strategist, and entrepreneur.
Your role is to challenge assumptions, identify risks, and provide actionable recommendations.
Be concise, practical, and honest. Always answer in English.
Referencing multiple prompts works the same way - each token resolves independently and the surrounding layout is preserved:
quilrai-prompt-store-base-policy
quilrai-prompt-store-code-reviewer
Only review the security-sensitive files in this diff.
References and inline text are combined from top to bottom in the order they appear. Put foundational prompts first and request-specific instructions last so the model reads them in a natural order.
Template variables
Prompts support {{variable}} placeholders. Pass values via the X-Prompt-Variables header, keyed by the reference each set of values belongs to.
Prompt template (code-reviewer):
You are a {{tone}} code reviewer for {{language}}.
X-Prompt-Variables header:
{"quilrai-prompt-store-code-reviewer": {"tone": "formal", "language": "Python"}}
Resolved prompt sent to LLM:
You are a formal code reviewer for Python.
When a system message references several prompts, give each one its own entry - the gateway applies each variable set only to its matching reference:
{
"quilrai-prompt-store-code-reviewer": {"tone": "formal", "language": "Python"},
"quilrai-prompt-store-base-policy": {"region": "EU"}
}
Enforce system prompts
Enforce system prompts from store, in the app's prompt settings, ensures every request's system message includes at least one managed Prompt Store reference, so no request runs without a reviewed base prompt.
This applies uniformly across Chat Completions, Anthropic Messages (both the top-level system field and any system-role messages), Vertex/Gemini, and the OpenAI Responses API. Useful when every system prompt should build on a reviewed base from the Prompt Store while still allowing per-request instructions.
Code examples
OpenAI
from openai import OpenAI
client = OpenAI(
base_url='https://guardrails-usa-2.quilr.ai/openai_compatible/',
api_key='sk-quilr-xxx'
)
response = client.chat.completions.create(
model='gpt-4o-mini',
messages=[
{'role': 'system', 'content': 'quilrai-prompt-store-code-reviewer'},
{'role': 'user', 'content': 'Review this code'}
],
extra_headers={
'X-Prompt-Variables': '{"quilrai-prompt-store-code-reviewer": {"tone": "formal", "language": "Python"}}'
}
)
Anthropic
import anthropic
client = anthropic.Anthropic(
base_url='https://guardrails-usa-2.quilr.ai/anthropic_messages/',
api_key='sk-quilr-xxx'
)
message = client.messages.create(
model='claude-sonnet-4-5',
max_tokens=1024,
system='quilrai-prompt-store-code-reviewer',
messages=[
{'role': 'user', 'content': 'Review this code'}
],
extra_headers={
'X-Prompt-Variables': '{"quilrai-prompt-store-code-reviewer": {"tone": "formal", "language": "Python"}}'
}
)
Going further with the Policy Engine
The Prompt Store and Enforcement card in Policy Engine > LLM Gateway holds two things: the organization-wide Global Prompt Store, and the Require store prompt policy. When the engine is on for the LLM Gateway, the app's store-prompt enforcement freezes and the card's policies decide it. App prompts themselves stay editable. See What happens to classic settings.
Global Prompt Store
The Global Prompt Store is one prompt library for your whole organization, reusable by every LLM Gateway app. Open Policy Engine > LLM Gateway and click Prompt Store on the Prompt Store and Enforcement card.
The drawer lists every prompt with its ID, variables and content. Search by ID or content, or use Add prompt, Edit and Delete. IDs and {{variable}} rules are the same as for app prompts. Changes apply immediately across the organization: they are not part of the policy draft and do not require publishing.
How the two stores relate:
- The global list also shows the prompts of your active apps. When apps share an ID, the newest app version is the default and conflicting versions get alias IDs.
- Saving an app-derived ID in the global store creates an organization-level version that takes priority over the app copies.
- Deleting an app-derived ID in the global store hides it from the global list.
Require store prompt
Require adds a configuration with Require store prompt set to Required, Not required (exempts a narrower scope) or Leave as is. It applies on chat, responses and vertex. The highest-priority matching configuration wins; new configurations start at 500. Edits join the shared draft and apply once you publish a revision.
Scenarios:
- Production only. Require a store prompt when request metadata marks the environment as production, and leave development free to experiment.
- Tenant-wide with exceptions. Require it for Everyone, then set Not required for one Application, App tag or Smart group.
- Per model or provider. Require it only for a Requested model or Provider.
runs on requestpriority 600