Turbot Pipes for AI agents
Turbot Pipes hosts cloud infrastructure data and dashboards for DevOps teams, used to query, snapshot, and share views of cloud resources and security posture. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Turbot Pipes.
List actor connections
Pull the cloud connections available to the current user, a read-only inventory check.
Create a workspace snapshot
Save a snapshot of a dashboard's current state for later reference.
Confirm before deleting an organization
Check with the user before deleting an organization, since its workspaces and connections go with it.
170 Turbot Pipes actions, graded by risk.
Every Turbot Pipes action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
99Look things up. Allowed by default.
- turbot_pipes.get_orgGet Organization
- turbot_pipes.get_userGet User
- turbot_pipes.get_tenantGet Tenant
- turbot_pipes.list_tenantsList Tenants
- turbot_pipes.get_org_memberGet Organization Member
- turbot_pipes.get_user_emailGet User Email
- turbot_pipes.list_org_usageList Organization Usage
- turbot_pipes.get_user_ai_keyGet User AI Key
- turbot_pipes.list_user_usageList User Usage
- turbot_pipes.get_user_processGet User Process
- turbot_pipes.list_org_processList Organization Processes
- turbot_pipes.list_user_emailsList User Emails
- turbot_pipes.get_auth_providerGet Auth Provider
- turbot_pipes.get_tenant_avatarGet Tenant Avatar
- turbot_pipes.get_user_passwordGet User Database Password
- turbot_pipes.list_user_ai_keysList User AI Keys
write
56Create and change things. Allow, or ask the user first.
- turbot_pipes.update_userUpdate User
- turbot_pipes.update_org_memberUpdate Organization Member Role
- turbot_pipes.update_user_tokenUpdate User Token
- turbot_pipes.create_auth_signupCreate User Signup
- turbot_pipes.create_user_ai_keyCreate User AI Key
- turbot_pipes.update_user_ai_keyUpdate User AI Key
- turbot_pipes.create_user_notifierCreate User Notifier
- turbot_pipes.create_user_passwordCreate User Password
- turbot_pipes.create_org_connectionCreate org connection
- turbot_pipes.update_org_connectionUpdate Org Connection
- turbot_pipes.update_user_workspaceUpdate User Workspace
- turbot_pipes.create_user_connectionCreate User Connection
- turbot_pipes.update_user_connectionUpdate User Connection
- turbot_pipes.create_user_integrationCreate User Integration
- turbot_pipes.update_user_integrationUpdate User Integration
- turbot_pipes.update_user_preferencesUpdate User Preferences
destructive
15Delete, cancel or archive. Ask first, or deny outright.
- turbot_pipes.delete_orgDelete Organization
- turbot_pipes.delete_user_avatarDelete User Avatar
- turbot_pipes.delete_org_workspaceDelete Organization Workspace
- turbot_pipes.delete_conversation_orgDelete Org Workspace Conversation
- turbot_pipes.delete_user_integrationDelete User Integration
- turbot_pipes.delete_user_workspace_notifierDelete User Workspace Notifier
- turbot_pipes.delete_user_workspace_pipelineDelete User Workspace Pipeline
- turbot_pipes.delete_org_billing_subscriptionDelete Org Billing Subscription
- turbot_pipes.delete_org_connection_permissionDelete Org Connection Permission
- turbot_pipes.delete_user_connection_deprecatedDelete User Connection (Deprecated)
- turbot_pipes.delete_org_workspace_mod_variable_settingDelete Org Workspace Mod Variable Setting
- turbot_pipes.delete_user_workspace_mod_variable_settingDelete User Workspace Mod Variable Setting
- turbot_pipes.user_tokens_deleteDelete User Token
- turbot_pipes.uninstall_flowpipe_modUninstall Flowpipe Mod
- turbot_pipes.uninstall_org_workspace_flowpipe_modUninstall Org Workspace Flowpipe Mod
Turbot Pipes in three steps.
- 01Your users connect Turbot PipesThey add their Turbot Pipes api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create User Signup” can wait for the user, and “delete Organization” can be denied outright.
- 03Any agent can actYour agent calls Turbot Pipes through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('turbot_pipes', { read: 'allow', write: 'ask', // create_auth_signup destructive: 'deny', // delete_org }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Turbot Pipes connects.
Users add their Turbot Pipes api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Turbot Pipes connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Turbot Pipes from any agent.
Turbot Pipes and Arc0, answered.
Can I use Turbot Pipes with Claude, ChatGPT or Cursor?
Yes. Connect Turbot Pipes to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Turbot Pipes actions you allow.
How do users connect Turbot Pipes?
Users add their Turbot Pipes api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Turbot Pipes actions can my agent take?
170 in total: 99 read, 56 write and 15 destructive, such as “create User Signup”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Turbot Pipes?
Yes. Actions like “delete Organization” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Turbot Pipes too?
Yes. The same Turbot Pipes connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Turbot Pipes into your agent.
Your users connect Turbot Pipes once, under your brand. Your agent gets 170 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan