Prisma for AI agents

Prisma Data Platform provides database tooling including a global cache, AI-driven query optimization, and managed PostgreSQL. Development teams use it to manage databases and projects programmatically. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Databases and spreadsheetsOAuth 2.0MCP + RESTprisma.io
AUDIT LOG · PRISMAPOLICY: acme-support
09:41:07 · claude · u_8f2read
prisma.list_backups
List Database Backups✓ allowed · 212ms
09:41:08 · claude · u_8f2read
prisma.get_project
Get Prisma Project✓ allowed · 164ms
09:41:09 · claude · u_8f2write
prisma.create_project
Create Prisma Project✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
prisma.delete_project
Delete Prisma Project✕ blocked · policy: deny
EVERY PRISMA CALL, ON THE RECORD
01 · USE CASES

What agents do in Prisma.

01

Inspect a database schema

Look up a database's schema read-only before writing a migration or query.

02

Check database usage metrics

Pull usage metrics for a database to see if it is approaching plan limits.

03

Delete a database with approval

Remove a Prisma database only after confirming backups exist and it is no longer used.

02 · ACTIONS

22 Prisma actions, graded by risk.

Every Prisma action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

11

Look things up. Allowed by default.

  • prisma.get_project
    Get Prisma Project
  • prisma.get_database
    Get Prisma Database
  • prisma.list_backups
    List Database Backups
  • prisma.list_projects
    List Prisma Projects
  • prisma.list_databases
    List Project Databases
  • prisma.list_workspaces
    List Prisma Workspaces
  • prisma.list_connections
    List Database Connections
  • prisma.get_database_usage
    Get Database Usage Metrics
  • prisma.list_postgres_regions
    List Prisma Postgres Regions
  • prisma.list_accelerate_regions
    List Prisma Accelerate Regions
  • prisma.list_workspace_integrations
    List Workspace Integrations

write

8

Create and change things. Allow, or ask the user first.

  • prisma.create_project
    Create Prisma Project
  • prisma.create_database
    Create Project Database
  • prisma.create_connection
    Create Database Connection
  • prisma.restore_backup
    Restore Database Backup
  • prisma.transfer_project
    Transfer Prisma Project
  • prisma.execute_sql_query
    Execute SQL Query
  • prisma.execute_sql_command
    Execute SQL Command
  • prisma.inspect_database_schema
    Inspect Database Schema

destructive

3

Delete, cancel or archive. Ask first, or deny outright.

  • prisma.delete_project
    Delete Prisma Project
  • prisma.delete_database
    Delete Prisma Database
  • prisma.delete_connection
    Delete Database Connection
03 · HOW IT WORKS

Prisma in three steps.

  1. 01Your users connect PrismaThey sign in to Prisma on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create Prisma Project” can wait for the user, and “delete Prisma Project” can be denied outright.
  3. 03Any agent can actYour agent calls Prisma through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('prisma', {
  read: 'allow',
  write: 'ask',        // create_project
  destructive: 'deny',  // delete_project
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Prisma connects.

Users sign in to Prisma on Arc0 Connect and approve the scopes you request. Build with Arc0’s Prisma OAuth app, or bring your own so the Prisma consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Prisma connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key · OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Prisma from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Prisma and Arc0, answered.

Q01

Can I use Prisma with Claude, ChatGPT or Cursor?

Yes. Connect Prisma to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Prisma actions you allow.

Q02

How do users connect Prisma?

Users sign in to Prisma on Arc0 Connect and approve the scopes you request. Build with Arc0’s Prisma OAuth app, or bring your own so the Prisma consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Prisma actions can my agent take?

22 in total: 11 read, 8 write and 3 destructive, such as “create Prisma Project”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Prisma?

Yes. Actions like “delete Prisma Project” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Prisma too?

Yes. The same Prisma connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Prisma into your agent.

Your users connect Prisma once, under your brand. Your agent gets 22 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan