Langfuse for AI agents
Langfuse is an open source observability platform engineers use to trace, evaluate, and manage prompts for LLM applications running in production. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Langfuse.
Query LLM usage metrics
Query cost and latency metrics for a model over a date range, a read-only lookup.
Pull a prompt's current version
Look up the live version of a managed prompt before referencing it elsewhere.
Review flagged trace scores
List scores attached to recent observations to find traces flagged for review.
13 Langfuse actions, graded by risk.
Every Langfuse action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
11Look things up. Allowed by default.
- langfuse.get_promptGet Prompt
- langfuse.list_modelsList Models
- langfuse.list_scoresList Scores
- langfuse.list_datasetsList Datasets
- langfuse.query_metricsQuery Metrics
- langfuse.list_experimentsList Experiments
- langfuse.list_observationsList Observations
- langfuse.list_dataset_itemsList Dataset Items
- langfuse.get_annotation_queueGet Annotation Queue
- langfuse.list_annotation_queuesList Annotation Queues
- langfuse.list_dataset_run_itemsList Dataset Run Items
write
2Create and change things. Allow, or ask the user first.
- langfuse.create_scoreCreate Score
- langfuse.upsert_llm_connectionUpsert LLM Connection
destructive
0Delete, cancel or archive. Ask first, or deny outright.
- No destructive actions.
Langfuse in three steps.
- 01Your users connect LangfuseThey add their Langfuse api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, and writes like “create Score” can wait for the user to approve.
- 03Any agent can actYour agent calls Langfuse through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('langfuse', { read: 'allow', write: 'ask', // create_score destructive: 'deny', }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Langfuse connects.
Users add their Langfuse api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Langfuse connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Langfuse from any agent.
Langfuse and Arc0, answered.
Can I use Langfuse with Claude, ChatGPT or Cursor?
Yes. Connect Langfuse to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Langfuse actions you allow.
How do users connect Langfuse?
Users add their Langfuse api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Langfuse actions can my agent take?
13 in total: 11 read, 2 write and 0 destructive, such as “create Score”. Your policies decide which of them each agent may call.
Can I make my agent read-only in Langfuse?
Yes. Allow read actions and deny writes in the Langfuse policy. Your agent can still look things up, and any write it attempts is blocked and logged.
Can my own backend call Langfuse too?
Yes. The same Langfuse connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Langfuse into your agent.
Your users connect Langfuse once, under your brand. Your agent gets 13 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan