Neon for AI agents
Neon is a serverless Postgres platform for building scalable applications with branchable databases and instant compute that scales to zero when idle. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Neon.
Check a project's branches
Count and list branches on a project to see what environments currently exist, read-only.
Create a database branch
Create a new branch of a database for a feature or test environment.
Approve before deleting a database
Require approval before deleting a database from a branch, since it removes its data permanently.
110 Neon actions, graded by risk.
Every Neon action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
46Look things up. Allowed by default.
- neon.get_authGet auth
- neon.list_api_keysList api keys
- neon.list_auth_domainsList auth domains
- neon.get_project_branchesGet project branches
- neon.list_shared_projectsList shared projects
- neon.get_branches_data_apiGet Neon Data API for branch
- neon.get_user_organizationsGet user organizations
- neon.list_vpc_vpc_endpointsList VPC endpoints for organization
- neon.get_auth_email_providerGet auth email provider
- neon.get_project_branch_roleGet project branch role
- neon.list_projects_snapshotsList project snapshots
- neon.get_auth_allow_localhostGet auth allow localhost
- neon.get_branches_for_projectGet branches for project
- neon.get_vpc_region_endpointsGet vpc region endpoints
- neon.get_organization_api_keysGet organization api keys
- neon.list_auth_oauth_providersList auth oauth providers
write
43Create and change things. Allow, or ask the user first.
- neon.create_auth_keysCreate Auth Provider SDK Keys
- neon.create_auth_userCreate auth user
- neon.add_role_to_branchAdd role to branch
- neon.create_new_api_keyCreate New API Key
- neon.create_branches_authEnable Neon Auth for branch
- neon.send_auth_test_emailSend auth test email
- neon.create_branch_databaseCreate branch database
- neon.create_compute_endpointCreate compute endpoint
- neon.create_branches_data_apiCreate Neon Data API
- neon.create_branches_snapshotCreate branch snapshot
- neon.update_branches_data_apiUpdate branches data API
- neon.create_new_project_branchCreate new project branch
- neon.create_vpc_endpoint_labelSet VPC endpoint restriction
- neon.update_projects_snapshotsUpdate project snapshot
- neon.update_auth_email_providerUpdate branch auth email provider
- neon.update_auth_allow_localhostUpdate auth allow localhost
destructive
21Delete, cancel or archive. Ask first, or deny outright.
- neon.delete_auth_userDelete auth user
- neon.delete_auth_domainsDelete auth domains
- neon.delete_api_key_by_idDelete api key by id
- neon.delete_project_by_idDelete project by id
- neon.delete_branch_data_apiDelete branch data API
- neon.delete_project_endpointDelete project endpoint
- neon.delete_project_snapshotDelete project snapshot
- neon.delete_project_jwks_by_idDelete project jwks by id
- neon.delete_project_permissionDelete project permission
- neon.delete_auth_oauth_providerDelete OAuth provider
- neon.delete_organization_memberDelete organization member
- neon.delete_project_branch_roleDelete project branch role
- neon.delete_vpc_endpoint_by_idsDelete vpc endpoint by ids
- neon.delete_database_from_branchDelete database from branch
- neon.delete_organization_api_keyDelete organization api key
- neon.delete_project_branch_by_idDelete project branch by id
Neon in three steps.
- 01Your users connect NeonThey add their Neon api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Auth Provider SDK Keys” can wait for the user, and “delete auth user” can be denied outright.
- 03Any agent can actYour agent calls Neon through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('neon', { read: 'allow', write: 'ask', // create_auth_keys destructive: 'deny', // delete_auth_user }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Neon connects.
Users add their Neon api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Neon connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Neon from any agent.
More databases and spreadsheets apps.
Neon and Arc0, answered.
Can I use Neon with Claude, ChatGPT or Cursor?
Yes. Connect Neon to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Neon actions you allow.
How do users connect Neon?
Users add their Neon api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Neon actions can my agent take?
110 in total: 46 read, 43 write and 21 destructive, such as “create Auth Provider SDK Keys”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Neon?
Yes. Actions like “delete auth user” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Neon too?
Yes. The same Neon connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Neon into your agent.
Your users connect Neon once, under your brand. Your agent gets 110 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan