System Prompt
In short
A system prompt is the instructions an app gives a language model before the conversation starts, setting its role, rules, tone and what it should know.
What is a system prompt?
Chat models receive messages with roles. The user's messages hold what the person types, the assistant's messages hold the model's earlier replies, and the system prompt, set by the developer, frames everything else: "You are a support assistant for a bookshop. Answer only questions about orders. Reply in the customer's language." The user usually never sees it.
A good system prompt describes who the model is acting as, what it should and shouldn't do, the format of its answers, and any context it needs, such as today's date, the user's plan or relevant documents. Products built on the same model can behave completely differently because of their system prompts.
APIs expose it in different ways: Anthropic's Messages API has a separate system parameter, while OpenAI's chat APIs use a message with the system or developer role. Models are trained to give these instructions more weight than ordinary user messages, which helps keep an assistant on task.
A common misconception is that a system prompt is a security boundary. Users can sometimes trick a model into ignoring or revealing its instructions, an attack known as prompt injection or jailbreaking. Secrets don't belong in a system prompt, and real permissions should be enforced in code, not only in words to the model.
Key takeaways
- The system prompt sets the model's role, rules and context before the chat.
- It is written by the developer and usually hidden from the user.
- Models give it more weight than ordinary user messages.
- Anthropic uses a system parameter; OpenAI uses a system or developer message.
- It is not a security boundary: never put secrets in it.
Example
import anthropic
client = anthropic.Anthropic()
message = client.messages.create(
model="claude-sonnet-5-5",
max_tokens=400,
system=(
"You are the help assistant for Software Dictionary. "
"Explain programming terms simply, in at most three sentences, "
"and suggest one related term at the end."
),
messages=[{"role": "user", "content": "What is a webhook?"}],
)
print(message.content[0].text)Readers ask
What is the difference between a system prompt and a user prompt?
The system prompt comes from the developer and sets the rules for the whole conversation. User prompts are the individual messages a person sends within those rules.
Can users see the system prompt?
Not normally, but it should not be treated as secret. A determined user can sometimes get a model to repeat its instructions, so keep passwords, keys and private data out of it.
How long should a system prompt be?
As long as it needs to be clear. Short prompts work for simple assistants, while products often use long ones with examples and rules. Everything in it uses part of the context window on every request.
See also
- PromptAI & Machine Learning, p. 35A prompt is the input text or instructions you give an AI model, such as an LLM, to tell it what task to perform and what kind of answer you want.
- Prompt EngineeringAI & Machine Learning, p. 36Prompt engineering is the practice of designing, testing, and refining the instructions given to an AI model so it produces accurate, consistent, useful output.
- LLMAI & Machine Learning, p. 25An LLM is a machine learning model trained on huge amounts of text that generates language by repeatedly predicting the next most likely piece of text.
- ChatbotAI & Machine Learning, p. 8A chatbot is a program that converses with people in text or speech, answering questions or helping with tasks, using scripted rules or a language model.
- Context WindowAI & Machine Learning, p. 12A context window is the maximum amount of text, measured in tokens, that an LLM can consider at once, including the prompt, conversation history, and its reply.
- Prompt InjectionSecurity, p. 29Prompt injection is an attack on LLM apps where attacker-written text is treated as instructions, so the model ignores its rules, leaks data or misuses tools.
- Context EngineeringAI & Machine Learning, p. 11Context engineering is the practice of choosing what an LLM sees on each call (instructions, documents, tool results, history) so it can do the task reliably.
Spotted a mistake or something missing on this page?Suggest an edit