Blog
4 min read

What Is a System Prompt? How to Give an AI Its Instructions

The system prompt is the standing instruction that shapes every answer an AI model gives in your app — its role, rules, tone and format. How it differs from user messages, what to put in one, a template you can adapt, and why it's not a security boundary.

When you build an AI feature into your app, two kinds of text go to the model:

  • User messages — what the person typed: "Can I get a refund?"
  • The system prompt — your standing instructions that apply to the whole conversation: who the assistant is, what it should and shouldn't do, and how to answer.

The user never sees the system prompt. It's how you turn a general-purpose model into your support bot, your writing assistant, or your data extractor.

Where it goes

In the Claude API it's a separate system field:

await client.messages.create({
  model: 'claude-haiku-4-5',
  max_tokens: 500,
  system: 'You are the support assistant for Acme Invoicing...',
  messages: [{ role: 'user', content: 'Can I get a refund?' }],
})

OpenAI's APIs use an instructions field or a message with the system/developer role. Same idea. (OpenAI API vs Claude API)

What to put in one

A good system prompt answers the questions a new employee would ask on their first day:

  1. Role and context. Who are you, who are you talking to, what's the product?
  2. The task. What should you help with?
  3. Rules and limits. What's out of scope? When should you hand over to a human?
  4. Knowledge. Facts the model needs: policies, prices, product details.
  5. Tone. Friendly? Formal? Brief?
  6. Output format. Plain text, Markdown, JSON, a maximum length?

A template

You are the support assistant for Acme Invoicing, a web app that helps
freelancers create and send invoices.

You help customers with questions about using the app, billing and
their account. You are talking to customers, who may not be technical.

Rules:
- Only answer questions about Acme Invoicing. For anything else, say
  politely that you can only help with Acme.
- Never promise refunds or discounts. Explain the policy below and offer
  to connect them with the team at support@acme.example.
- If you don't know the answer, say so. Do not guess.

Refund policy: Annual plans can be refunded within 14 days of purchase.
Monthly plans are not refunded but can be cancelled at any time.

Style: friendly, plain English, short paragraphs. Under 120 words unless
the customer asks for detail.

Notice what makes this work: specific facts, explicit "don't" rules with an alternative action, and a clear format.

Tips that actually help

  • Explain why. "Keep answers short, because customers read them on their phones" works better than "BE SHORT."
  • Be specific. "Don't guess" beats "be accurate."
  • Give examples of good answers for tricky cases.
  • Use structure. Headings or XML-style tags (<policy>…</policy>) help the model find things in long prompts.
  • Put long reference material first, instructions after it.
  • Test with real questions, including awkward ones, and adjust.

What a system prompt can't do

It's not a security boundary. Users can try to talk the model out of its instructions ("ignore previous instructions…"), and sometimes they'll succeed. This is prompt injection. (Prompt injection in coding agents)

So:

  • Assume the system prompt may leak. Don't put API keys, passwords or secret business logic in it.
  • Enforce real rules in code. If users mustn't see other users' data, the code fetching data must check permissions — not the prompt.
  • Limit what tools can do. If the model can call functions, those functions should only do safe things for that user. (Function calling explained)

System prompts and caching

The system prompt is sent with every request, so long ones cost tokens every time. Prompt caching makes repeated prompts much cheaper. (Prompt caching explained)

The summary

  • The system prompt is your standing instructions; the user doesn't see it.
  • Cover role, task, rules, knowledge, tone and format.
  • Be specific, explain why, and test with real questions.
  • It's guidance, not security — enforce rules in code and keep secrets out of it.

EasySpawn runs your AI features on your own server, so system prompts, API keys and permission checks stay on the backend where they belong. See how it works or join the waitlist.

Related: How to Add an AI Chatbot to Your App · What Is an LLM? · LLM Temperature Explained · How to Write Good Prompts for AI Coding Tools

Keep reading