Prisma for AI agents
Prisma Data Platform provides database tooling including a global cache, AI-driven query optimization, and managed PostgreSQL. Development teams use it to manage databases and projects programmatically. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Prisma.
Inspect a database schema
Look up a database's schema read-only before writing a migration or query.
Check database usage metrics
Pull usage metrics for a database to see if it is approaching plan limits.
Delete a database with approval
Remove a Prisma database only after confirming backups exist and it is no longer used.
22 Prisma actions, graded by risk.
Every Prisma action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
11Look things up. Allowed by default.
- prisma.get_projectGet Prisma Project
- prisma.get_databaseGet Prisma Database
- prisma.list_backupsList Database Backups
- prisma.list_projectsList Prisma Projects
- prisma.list_databasesList Project Databases
- prisma.list_workspacesList Prisma Workspaces
- prisma.list_connectionsList Database Connections
- prisma.get_database_usageGet Database Usage Metrics
- prisma.list_postgres_regionsList Prisma Postgres Regions
- prisma.list_accelerate_regionsList Prisma Accelerate Regions
- prisma.list_workspace_integrationsList Workspace Integrations
write
8Create and change things. Allow, or ask the user first.
- prisma.create_projectCreate Prisma Project
- prisma.create_databaseCreate Project Database
- prisma.create_connectionCreate Database Connection
- prisma.restore_backupRestore Database Backup
- prisma.transfer_projectTransfer Prisma Project
- prisma.execute_sql_queryExecute SQL Query
- prisma.execute_sql_commandExecute SQL Command
- prisma.inspect_database_schemaInspect Database Schema
destructive
3Delete, cancel or archive. Ask first, or deny outright.
- prisma.delete_projectDelete Prisma Project
- prisma.delete_databaseDelete Prisma Database
- prisma.delete_connectionDelete Database Connection
Prisma in three steps.
- 01Your users connect PrismaThey sign in to Prisma on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create Prisma Project” can wait for the user, and “delete Prisma Project” can be denied outright.
- 03Any agent can actYour agent calls Prisma through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('prisma', { read: 'allow', write: 'ask', // create_project destructive: 'deny', // delete_project }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Prisma connects.
Users sign in to Prisma on Arc0 Connect and approve the scopes you request. Build with Arc0’s Prisma OAuth app, or bring your own so the Prisma consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Prisma connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key · OAuth 2.0
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Prisma from any agent.
More databases and spreadsheets apps.
Prisma and Arc0, answered.
Can I use Prisma with Claude, ChatGPT or Cursor?
Yes. Connect Prisma to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Prisma actions you allow.
How do users connect Prisma?
Users sign in to Prisma on Arc0 Connect and approve the scopes you request. Build with Arc0’s Prisma OAuth app, or bring your own so the Prisma consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Prisma actions can my agent take?
22 in total: 11 read, 8 write and 3 destructive, such as “create Prisma Project”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Prisma?
Yes. Actions like “delete Prisma Project” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Prisma too?
Yes. The same Prisma connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Prisma into your agent.
Your users connect Prisma once, under your brand. Your agent gets 22 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan