Neon for AI agents

Neon is a serverless Postgres platform for building scalable applications with branchable databases and instant compute that scales to zero when idle. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Databases and spreadsheetsAPI keyMCP + RESTneon.tech
AUDIT LOG · NEONPOLICY: acme-support
09:41:07 · claude · u_8f2read
neon.list_api_keys
List api keys✓ allowed · 212ms
09:41:08 · claude · u_8f2read
neon.get_auth
Get auth✓ allowed · 164ms
09:41:09 · claude · u_8f2write
neon.create_auth_keys
Create Auth Provider SDK Keys✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
neon.delete_auth_user
Delete auth user✕ blocked · policy: deny
EVERY NEON CALL, ON THE RECORD
01 · USE CASES

What agents do in Neon.

01

Check a project's branches

Count and list branches on a project to see what environments currently exist, read-only.

02

Create a database branch

Create a new branch of a database for a feature or test environment.

03

Approve before deleting a database

Require approval before deleting a database from a branch, since it removes its data permanently.

02 · ACTIONS

110 Neon actions, graded by risk.

Every Neon action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

46

Look things up. Allowed by default.

  • neon.get_auth
    Get auth
  • neon.list_api_keys
    List api keys
  • neon.list_auth_domains
    List auth domains
  • neon.get_project_branches
    Get project branches
  • neon.list_shared_projects
    List shared projects
  • neon.get_branches_data_api
    Get Neon Data API for branch
  • neon.get_user_organizations
    Get user organizations
  • neon.list_vpc_vpc_endpoints
    List VPC endpoints for organization
  • neon.get_auth_email_provider
    Get auth email provider
  • neon.get_project_branch_role
    Get project branch role
  • neon.list_projects_snapshots
    List project snapshots
  • neon.get_auth_allow_localhost
    Get auth allow localhost
  • neon.get_branches_for_project
    Get branches for project
  • neon.get_vpc_region_endpoints
    Get vpc region endpoints
  • neon.get_organization_api_keys
    Get organization api keys
  • neon.list_auth_oauth_providers
    List auth oauth providers
+ 30 MORE

write

43

Create and change things. Allow, or ask the user first.

  • neon.create_auth_keys
    Create Auth Provider SDK Keys
  • neon.create_auth_user
    Create auth user
  • neon.add_role_to_branch
    Add role to branch
  • neon.create_new_api_key
    Create New API Key
  • neon.create_branches_auth
    Enable Neon Auth for branch
  • neon.send_auth_test_email
    Send auth test email
  • neon.create_branch_database
    Create branch database
  • neon.create_compute_endpoint
    Create compute endpoint
  • neon.create_branches_data_api
    Create Neon Data API
  • neon.create_branches_snapshot
    Create branch snapshot
  • neon.update_branches_data_api
    Update branches data API
  • neon.create_new_project_branch
    Create new project branch
  • neon.create_vpc_endpoint_label
    Set VPC endpoint restriction
  • neon.update_projects_snapshots
    Update project snapshot
  • neon.update_auth_email_provider
    Update branch auth email provider
  • neon.update_auth_allow_localhost
    Update auth allow localhost
+ 27 MORE

destructive

21

Delete, cancel or archive. Ask first, or deny outright.

  • neon.delete_auth_user
    Delete auth user
  • neon.delete_auth_domains
    Delete auth domains
  • neon.delete_api_key_by_id
    Delete api key by id
  • neon.delete_project_by_id
    Delete project by id
  • neon.delete_branch_data_api
    Delete branch data API
  • neon.delete_project_endpoint
    Delete project endpoint
  • neon.delete_project_snapshot
    Delete project snapshot
  • neon.delete_project_jwks_by_id
    Delete project jwks by id
  • neon.delete_project_permission
    Delete project permission
  • neon.delete_auth_oauth_provider
    Delete OAuth provider
  • neon.delete_organization_member
    Delete organization member
  • neon.delete_project_branch_role
    Delete project branch role
  • neon.delete_vpc_endpoint_by_ids
    Delete vpc endpoint by ids
  • neon.delete_database_from_branch
    Delete database from branch
  • neon.delete_organization_api_key
    Delete organization api key
  • neon.delete_project_branch_by_id
    Delete project branch by id
+ 5 MORE
03 · HOW IT WORKS

Neon in three steps.

  1. 01Your users connect NeonThey add their Neon api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Auth Provider SDK Keys” can wait for the user, and “delete auth user” can be denied outright.
  3. 03Any agent can actYour agent calls Neon through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('neon', {
  read: 'allow',
  write: 'ask',        // create_auth_keys
  destructive: 'deny',  // delete_auth_user
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Neon connects.

Users add their Neon api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Neon connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Neon from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Neon and Arc0, answered.

Q01

Can I use Neon with Claude, ChatGPT or Cursor?

Yes. Connect Neon to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Neon actions you allow.

Q02

How do users connect Neon?

Users add their Neon api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Neon actions can my agent take?

110 in total: 46 read, 43 write and 21 destructive, such as “create Auth Provider SDK Keys”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Neon?

Yes. Actions like “delete auth user” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Neon too?

Yes. The same Neon connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Neon into your agent.

Your users connect Neon once, under your brand. Your agent gets 110 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan