Enter your email and we'll send a reset link to your inbox. The link expires in 1 hour.
Choose a strong password for your Prompt Firewall account.
Create a password so you can log in with your email next time — no API key needed.
Give this key a label so you know which app or team member it belongs to (e.g. "Production Bot", "Staging", "Mobile App").
Everything you need to get the most out of Prompt Firewall.
Welcome! Here is how to protect your AI chatbot in 3 steps.
When you subscribed, we sent an email to your inbox with a key that looks like pf_abc...xyz. Keep this safe — it is your access token.
Before writing any code, use the Sandbox panel on your dashboard. Type any message and instantly see BLOCKED or PASSED. Try typing "ignore previous instructions" to see it in action.
Works with any language that can make HTTP requests. Choose your language below:
Python
JavaScript / Node.js
C#
PHP
Every blocked attack appears in your Security Log. Click the Blocked tab to see attacks, click any row to expand it and see full details including latency, user ID, and the reason it was blocked.
You have access to 10,000 request screenings per month and 1 API key.
Click the Blocked tab to see attacks — this is your main view. Click any row to expand it and see the full details including the reason it was blocked. Click Passed to see safe messages that went through.
Your usage bar shows how much of your monthly 10,000 requests you have used. When it turns red you are close to the limit. You can enable the Overages toggle in the billing widget to stay live past your limit at $0.50 per 1,000 extra requests. Or upgrade to Pro to get 100,000 requests.
The Sandbox panel lets you test any message instantly without writing code. Type a message, click Test Message, and see whether it would be BLOCKED or PASSED — and exactly why.
Everything in Starter plus 100,000 requests, up to 3 API keys, false positive reporting, and Shadow Mode.
If you have more than one chatbot or team member, generate separate keys for each one. Click Generate New Key in the API Keys panel, give it a label like "Production Bot", and share that key with the relevant developer. You can revoke any key instantly if it is ever leaked.
Available on all plans. If the firewall blocks a harmless message, expand the log entry and click Mark as false positive. It moves to your False Positives tab. You can unmark it anytime to move it back to the Blocked list.
Enable Shadow Mode in the Settings panel to put the firewall into monitoring-only mode. Attacks are still logged but nothing is blocked. This is useful when you are testing new rules or onboarding a new chatbot and want to observe without disrupting users.
Each log entry shows which API key was used. This helps you see if attacks are targeting a specific app or environment.
Everything in Pro plus unlimited requests, unlimited API keys, and full team management.
Generate as many API keys as you need — one per developer, one per product, one per environment. Each key has its own label and can be revoked individually without affecting the others.
Because each key has a label, your Security Log will show you exactly which product or environment is being targeted. If your mobile app key is getting hit with SQL injection but your web app is fine, you will see that immediately.
Pass a user_id field in your API request to track which of your end users is repeatedly attempting attacks:
This appears in your log so you can identify and ban repeat attackers.
Pass a target_model field to track which AI model the prompt was heading toward:
Requests over the limit return a 429 error. We email you before you hit the limit so you have time to upgrade.
Either your account was cancelled, your key was revoked (by you or an admin), or your subscription lapsed. Email info@invenova.tech for help.
Click the row in your Security Log, expand it, and click Mark as false positive. This moves it to your False Positives tab. You can unmark it anytime to move it back to the Blocked list.
Yes — Prompt Firewall works with GPT-4, Claude, Gemini, Llama, or any other model. It is completely model-agnostic.
Choose a plan that fits your usage. Your API key stays the same after upgrading — no code changes needed.
After payment your plan updates automatically. Questions? info@invenova.tech
Are you sure? Your API key stays active until the end of your current billing period. You can reactivate anytime.