# prompts.chat: PROMPTS.md is a generated export, and compose.yml ships a default password

> prompts.chat is a Next.js application on PostgreSQL that doubles as a public prompt library, a self-hostable instance generator, a CLI, a Claude Code plugin and an MCP server. The prompt list in git is an export of a live database rather than the source, and the default deployment path takes a documented shortcut on the database password.

**f/prompts.chat** — GitHub describes it as f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source , self-host for your organization with complete privacy.. The repository metadata lists HTML as its primary language. The metadata lists the NOASSERTION license. This article stays within the project description and details documented in the GitHub repository README.

- Repository: https://github.com/f/prompts.chat
- Website: https://prompts.chat
- Stars: 171,410 · Forks: 22,001
- Language: HTML
- License: NOASSERTION
- Published: 2026-08-13 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/f-prompts-chat

## PROMPTS.md is an export of a live database, not the source of truth

The contribution flow explains the whole architecture. Prompts are added at prompts.chat/prompts/new and they sync into the repository automatically, which means the file you read in git is downstream of a running site. The top-level manifest tells you what that site is: name prompts.chat-v2, version 0.1.0, marked private, with dev as next dev, build as prisma generate && next build, and a set of db:* scripts built on Prisma. So PROMPTS.md and prompts.csv, alongside the Hugging Face dataset, are generated artefacts of a PostgreSQL database. Two consequences. You cannot review a prompt change as a diff before it reaches the public list, because review happens on the website rather than in a pull request. And a self-hosted copy of PROMPTS.md has no update channel at all unless you reconnect it to a site that runs the sync, which means forks drift.

## npx prompts.chat new then npm run setup, and the wizard blocks automation

There are two documented ways to stand up your own instance. The quick start is two lines.

```bash
npx prompts.chat new my-prompt-library
cd my-prompt-library
```

The manual path clones the repository and hands you to a setup script.

```bash
git clone https://github.com/f/prompts.chat.git
cd prompts.chat
npm install && npm run setup
```

That script is node scripts/setup.js, and the wizard configures branding, theme, authentication through GitHub, Google or Azure AD, and features. The recommended database is PostgreSQL, with Neon named for hosted deployments. The cost of that convenience is interactivity: a wizard that asks questions is something a human can run and a provisioning pipeline cannot. If your infrastructure is described in files, expect to bypass the wizard and set environment variables yourself, and note that those variables are not the same names the example file uses.

## compose.yml starts a database with the password prompts

The Docker path is short: a postgres:17-bookworm service with a healthcheck running pg_isready, and an app service built from docker/Dockerfile or pulled as ghcr.io/f/prompts.chat:latest, mapped from ${PORT:-4444} to container port 3000, waiting on the database with depends_on and condition service_healthy. Read the database block closely. POSTGRES_USER is prompts, POSTGRES_DB is prompts, and POSTGRES_PASSWORD defaults to prompts, with a comment in the file itself saying to change it for production and pointing at the Security Considerations section of DOCKER.md. That is a public default in a copy-pasteable file, so anyone who runs docker compose up on a host with a route to it is running a database whose credentials are in the repository. Two smaller traps sit next to it: AUTH_SECRET defaults to an empty string, and the image tag is latest, so a pull can change what is running under a fixed deployment name.

## The two config files name the secret and the database differently

compose.yml passes AUTH_SECRET into the app, and .env.example documents NEXTAUTH_URL and NEXTAUTH_SECRET, with the example value your-super-secret-key-change-in-production. Nothing in the repository explains how the two names relate, so a self-hoster who copies the example file into a compose based deployment has to work out which variable the application actually reads, and getting it wrong produces a running instance with an absent session secret. The database name differs too: the example file points at a database called prompts_chat on localhost, while compose creates prompts. The rest of the example file is more disciplined. DIRECT_URL is documented for migrations that bypass the connection pooler, naming Neon, Supabase and PlanetScale as the reason it exists, and the header recommends adding connection_limit and pool_timeout in serverless or production environments. Both are easy to skip and hard to debug later.

## postinstall runs prisma generate, so npm install is not passive

Read the scripts block before provisioning anything. postinstall is prisma generate, so every npm install or npm ci generates a Prisma client, and the hook runs even in a build stage that has no database. build runs prisma generate && next build, so a production image cannot be produced without that step succeeding. The database path is a chain of its own, with db:setup defined as prisma generate && prisma migrate dev && prisma db seed, and a separate db:deploy using prisma migrate deploy, which is the one that belongs in a release pipeline. Two more matter for operations: db:seed fills a fresh instance with content, and db:resetadmin runs a script from prisma/reset-admin.ts, which is how you recover the first administrator on an instance whose credentials are gone. The test side is vitest, with test as vitest run and a vitest.setup.ts beside vitest.config.ts.

## AI features are gated in TypeScript, not by environment variables

The .env.example file separates three optional systems, and the first one is a single switch. ENABLED_STORAGE takes do-spaces, s3 or url, and the storage variables come in two flavours: S3_BUCKET, S3_REGION, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY and S3_ENDPOINT for S3 compatible services such as MinIO, plus DO_SPACES_BUCKET, DO_SPACES_REGION, DO_SPACES_ACCESS_KEY_ID, DO_SPACES_SECRET_ACCESS_KEY and an optional CDN endpoint, which matches the @aws-sdk/client-s3 dependency in the manifest. The AI features are the sharper case, because the file says to enable aiSearch and aiGeneration in prompts.config.ts. Setting OPENAI_API_KEY alone does nothing. Once the flags are on, you also choose OPENAI_BASE_URL for any OpenAI compatible API, OPENAI_EMBEDDING_MODEL, with text-embedding-3-small as the example, and OPENAI_GENERATIVE_MODEL, with gpt-4o-mini. Pointing that base URL at your own gateway means your prompt library and your credentials leave your network.

## The agent integrations point at the hosted site by default

The repository is also three integrations, and each has a documented default worth looking at before self-hosting. The CLI is npx prompts.chat. The Claude Code plugin is installed from this repository as a marketplace, with the documentation in CLAUDE-PLUGIN.md and a .claude-plugin/ directory at the top level, alongside .commandcode/ and .windsurf/ for other agent tools. The MCP server has two shapes, and the remote one is a URL with no local component at all.

```json
{
  "mcpServers": {
    "prompts.chat": {
      "url": "https://prompts.chat/api/mcp"
    }
  }
}
```

That is the configuration an editor will reach for by default, and it points at the hosted library rather than at an instance you run. The local form spawns the package with npx and an mcp argument instead. A self-hosted deployment therefore has two integrations to re-point after installation, and neither is automatic.

## MIT and CC0 both ship, and the license field says NOASSERTION

The top level carries LICENSE, LICENSE-MIT and LICENSE-CC0, while the repository metadata reports no recognised licence name. Any tool that reads the metadata field rather than the files will record this repository as unlicensed, which is the sort of finding an internal dependency scan raises. Opening the files settles it for a human who goes looking, and nothing in the repository states which of the two applies to the prompt text itself rather than to the surrounding application code. That ambiguity matters more here than in most projects, because the prompt collection is the part people copy into their own work. The same caution applies to the material shipped beside the code: the interactive book is described as free, its source sits in src/content/book, and the reading link points at a Gumroad page, with no price stated in the repository.

## Conclusion

Adopt prompts.chat when you want a searchable prompt library with a CLI, an MCP endpoint and self-hosting with your own identity provider, and when you are willing to treat the prompt text as untrusted input that a model will follow. Do not adopt it expecting a static list you can diff, and do not run the shipped compose file on a reachable host. Before the first deploy, read the Security Considerations section of DOCKER.md, replace the default POSTGRES_PASSWORD and AUTH_SECRET, and decide whether aiSearch and aiGeneration stay off, because each one sends your prompt library to an OpenAI compatible endpoint you configure by hand.

## FAQ

### how to use prompts chat

You can browse the library at prompts.chat/prompts, read it as PROMPTS.md or download prompts.csv, and install a self-hosted copy with npx prompts.chat new followed by npm install && npm run setup, which opens a wizard for branding, theme and authentication. The prompts were originally created for ChatGPT and are stated to work with Claude, Gemini, Llama and Mistral as well.

### how to use prompts chat gpt

Paste a prompt from the library into the chat window, or connect a tool to the library instead: the repository ships a CLI, a Claude Code plugin, and an MCP server with both a remote URL and a local npx form. The remote MCP configuration points at https://prompts.chat/api/mcp, so an agent using that endpoint reads the hosted collection.

### what is prompts chat

It is a curated collection of prompts for AI chat models, first published in December 2022 and formerly known as Awesome ChatGPT Prompts. What is unusual is the second half: the same repository is a Next.js application on PostgreSQL that you can self-host with your own branding and authentication, and it can be consumed as a CLI, a plugin or an MCP server.

### prompts chat alternative

The repository names no competing prompt library. The different approach it offers is running your own: a Next.js and Prisma application on PostgreSQL, with an MCP endpoint, a CLI and an interactive setup wizard, so an organisation can keep its prompts inside its own network rather than browsing the hosted site or reading a static Markdown file.

## Sources

- [Official documentation](https://prompts.chat)
- [Official README](https://github.com/f/prompts.chat#readme)
- [Project repository](https://github.com/f/prompts.chat)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/f-prompts-chat
