From 3e8d565e41ada2fc5eff61e87e3c42e4e2b22f34 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=B8ren=20Bramer=20Schmidt?= Date: Wed, 30 Sep 2026 23:21:46 +0700 Subject: [PATCH 1/2] feat(docs): guide agent enrollment through MCP --- .../prisma-compute/agent-enrollment.mdx | 234 ++++++------------ 1 file changed, 73 insertions(+), 161 deletions(-) diff --git a/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx b/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx index be73fdaeea2..d829f108b47 100644 --- a/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx +++ b/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx @@ -1,225 +1,137 @@ --- title: Enroll your agent -description: Give a coding agent its own Prisma credential and a permission policy you control, so it asks you before sensitive API actions and every request it makes is logged. +description: Connect your coding agent through Prisma MCP, choose its workspaces, and control sensitive actions with approvals. url: /prisma-compute/agent-enrollment -metaTitle: "Agent enrollment: give your AI agent its own Prisma credential" -metaDescription: Enroll a coding agent into Prisma with a pairing code. The agent gets its own credential and permission policy, asks for your approval before production writes, and every request it makes is audited. +metaTitle: "Agent enrollment: connect your coding agent to Prisma" +metaDescription: Install the Prisma MCP connection and enrollment skill. Give your coding agent access to selected workspaces, approve sensitive actions, and review its activity. --- -Enrolling a coding agent lets it set up Prisma for you: it can create projects and databases, connect a GitHub repository, and configure deploys through the [Prisma REST API](/rest-api). It does this with a credential of its own, and you decide which of its actions need your approval first. +An enrolled agent manages Prisma through the Prisma MCP server with its own identity and permission policy. You can approve sensitive actions, review its activity, and pause or revoke its access in Prisma Console. -Without enrollment, an agent uses your signed-in CLI session, so to Prisma the agent is you. It has all of your access, the audit log records its actions as yours, and you can only stop it by signing yourself out. - -An enrolled agent gets its own credential instead, so you can pause or revoke it without affecting your own access. It also gets a permission policy: by default it works freely on [preview branches](/compute/branching), the non-production copies of a project with their own apps and databases, and asks you before it changes production or does anything destructive. The person who approves the enrollment becomes the agent's sponsor, and every request the agent makes is recorded under its own name with that sponsor attached. +The person who authorizes the connection becomes its sponsor. A new agent can reach only the sponsor's default workspace. The sponsor can change that workspace list later. ## Prerequisites -- A [Prisma account](https://pris.ly/pdp). You approve the enrollment while signed in to [Prisma Console](https://console.prisma.io), Prisma's web dashboard. -- A coding agent that can make HTTP requests and write files in your project, such as Claude Code, Codex, or Cursor. -- To deploy, a GitHub repository for your app. An enrolled agent deploys through a GitHub Actions workflow. - -## How enrollment works - -Enrollment pairs the agent with your account through a short code, the same way you sign in to a streaming app on a TV. The agent never sees your password or your session. - - - -## 1. Copy the enrollment instructions - -Prisma Console gives you a block of instructions that an agent follows to enroll itself. In Prisma Console, open any of your workspaces (it doesn't matter which), go to **Settings → Agents**, and click **Enroll agent**. You can also open [console.prisma.io/enroll](https://console.prisma.io/enroll) directly. - -Under **No pairing code yet?**, click **Copy instructions**. The instructions tell the agent how to: - -- request a pairing code and wait for your approval -- save its credential to a file that Git ignores (the instructions suggest `.prisma/agent-token`), and reuse the credential in later sessions -- handle requests that need your approval -- connect a GitHub repository and deploy through GitHub Actions - -## 2. Give the instructions to your agent - -Paste the instructions into your agent's chat. The agent starts an enrollment and shows you an eight-character pairing code, such as `KQ7M-R4TX`. - -The code expires after 10 minutes. While it waits, the agent keeps checking with Prisma for your approval, so leave the session running. - -:::tip - -After the agent is enrolled, also paste the same instruction block into your project's `AGENTS.md` or `CLAUDE.md`, as its own section, so future sessions reuse the credential. The block starts by telling the agent to use its saved credential when the file exists, and to enroll again only when the file is missing or Prisma rejects the credential. +- A [Prisma account](https://pris.ly/pdp). +- An MCP client with remote HTTP servers and OAuth sign-in, such as Codex, Claude Code, or Cursor. +- Node.js and a project directory where you can install the connection and skill. +- A GitHub repository if you want to deploy through GitHub Actions. -::: +## 1. Install the connection and skill -## 3. Approve the pairing code +From your project directory, run: -Back in Prisma Console, enter the code on the **Enroll agent** page and click **Continue**. Before you approve, check that: - -- the code on screen matches the one your agent showed you -- **Client** and **Device** name your agent (for example, Claude Code) and your machine -- **Workspaces** shows what the agent will be able to reach: every workspace you belong to. You can't limit the agent to fewer workspaces. After enrollment you can hide individual projects from it with a [project override](#what-the-agent-can-do), but the agent can still reach projects created later until you add an override for them too. - -When you click **Approve enrollment**, you become the agent's sponsor. Within a few seconds, the agent receives its credential and saves it. - -If anything doesn't match, click **Deny**, and the agent gets no credential. If the page says **Enrollment expired**, more than 10 minutes passed. Ask the agent to start again, then enter the new code. - -## 4. Confirm the agent is connected - -Ask your agent to list your Prisma workspaces. It should answer with the workspaces you saw in step 3. - -The agent checks that Git ignores its credential file before saving it, but it's worth confirming, because a committed credential would give anyone with the repository the agent's access. If your agent saved the credential somewhere other than `.prisma/agent-token`, ask it for the path and use that in the commands below. - -First, check that Git isn't already tracking the file: - -```bash -git ls-files .prisma/agent-token +```npm +npx prisma@latest agent install ``` -If the command prints nothing, the file isn't tracked. If it prints the path, the credential is committed, and an ignore rule won't remove it. [Revoke the agent](#pause-or-revoke-an-agent), because the credential stays in your Git history. Then stop tracking the file with `git rm --cached .prisma/agent-token`, add `.prisma/` to `.gitignore`, and enroll the agent again. - -Then check that Git ignores the file: - -```bash -git check-ignore -v .prisma/agent-token -``` +This adds the Prisma MCP connection and the `prisma-agent-enrollment` skill for Codex, Claude Code, and Cursor. It preserves other servers and comments, and refuses to overwrite a conflicting Prisma connection or a skill that Prisma does not manage. -When the file is ignored, the output names the `.gitignore` rule that covers it: +To install for one client: -```text no-copy -.gitignore:12:.prisma/ .prisma/agent-token +```npm +npx prisma@latest agent install --client codex ``` -If the command prints nothing, the file is not ignored. Add `.prisma/` to `.gitignore` before your next commit. - -In Prisma Console, the agent now appears as **Active** under **Settings → Agents**: - -![The Agents page in Prisma Console, listing four enrolled agents with their sponsors, permission policies, and statuses, plus two pending approval requests waiting for review.](/img/prisma-compute/agent-enrollment/agents-list.png) - -Every member of a workspace can see the agents listed there. The agent has one policy for all of your workspaces. You, or an admin of any workspace the agent can reach, can change that policy, pause the agent, or revoke it, and the change applies in all of them. - -## What the agent can do +Supported values are `codex`, `claude`, `cursor`, and `all`. The skill teaches the agent to check its identity, use MCP for cloud operations, handle approvals, and reuse the connection in later sessions. You no longer need to copy a long instruction block into chat or `AGENTS.md`. -Every agent starts with the default policy, which decides what happens to each REST API request the agent makes: +## 2. Authorize the connection -| Rule | Covers | Default | -| -------------------------- | ----------------------------------------------------------------------------------------------- | ------- | -| Preview branches | Viewing, creating, and changing anything on a preview branch, such as databases, apps, buckets (file storage), and environment variables | Allow | -| Production branches, read | Viewing anything on a production branch | Allow | -| Production branches, write | Creating or changing anything on a production branch, including linking a GitHub repository to the project | Ask | -| Admin actions | Deleting anything, creating a workspace, and creating service tokens (workspace API keys) or database connection strings | Ask | +Restart your client to load the connection and skill. Follow its Prisma MCP sign-in flow. Sign in with the Prisma account that should sponsor the agent and review the authorization. -These rules refer to the branches of a Prisma project. The branch a project starts with (usually `main`) is its production branch, and every other branch is a preview branch with its own databases and apps. See [Branching](/compute/branching) for how they relate to your Git branches. +Your MCP client stores and refreshes its credential. The installer does not sign in or copy your CLI credential. The connection enrolls automatically and keeps its identity when its credential refreshes. -A preview app still connects to whatever database its `DATABASE_URL` points to. If a preview's `DATABASE_URL` points at your production database, changes the policy allows on that preview can reach production data. Give each preview its own preview-scoped `DATABASE_URL`, as described in [Environment variables](/compute/environment-variables). +For clients configured through connector settings, add this URL manually: -Deleting anything or creating a connection string asks even on a preview branch, because both are admin actions; a connection string is a lasting credential for the database. Creating a project doesn't ask. Creating a database on a preview branch doesn't ask either, but creating one on the production branch does, and a database created without choosing a branch counts as production. +```text +https://mcp.prisma.io/mcp +``` -The policy covers the agent's REST API requests only. When the agent pushes code, the deploy runs in GitHub Actions and signs in to Prisma separately, not with the agent's credential, so the policy can't stop it. See [Build and deploy with your agent](#build-and-deploy-with-your-agent). +OAuth enrollment works independently of the installer. -:::warning +## 3. Confirm identity and access -Enrolling an agent doesn't sign you out. If you're signed in to the Prisma CLI on the same machine, an agent can still run CLI commands as you, outside its policy, and the same goes for a Prisma MCP server you connected to your agent with your own account. The policy also doesn't cover database connection strings the agent can already read, such as `DATABASE_URL` in your `.env` file: with one of those, the agent connects to the database directly. The enrollment instructions tell the agent to use its own credential. If you want the policy to be the only way the agent reaches Prisma, sign out of the Prisma CLI while the agent works: +Ask your agent: -```npm -npx prisma@latest auth logout +```text +Use Prisma MCP to show your agent identity, workspace access, and permission policy. ``` -Sign back in with `npx prisma@latest auth login` when you want to deploy from your terminal again. - -::: - -To change the policy, open the agent from **Settings → Agents** and select the **Permissions** tab. Set each rule to **Allow**, **Ask**, or **Block**; each change saves as soon as you click. A blocked request fails right away, without asking you. +The agent calls `get_agent_connection`. Check its sponsor and workspace. New connections receive only the sponsor's default workspace, or their earliest workspace membership when no default is saved. -![The Permissions tab for an agent, showing the default policy: preview branches and production reads set to Allow, production writes and admin actions set to Ask.](/img/prisma-compute/agent-enrollment/permissions.png) +Open **Settings → Agents** in Prisma Console and select the agent to review its permissions, approvals, and activity. -To make an exception for a single project, use **Project overrides** below the rules: choose a project, choose **Full access** or **No access**, and click **Add override**. +## Change workspace access -- **Full access** allows every request in that project, production writes included. -- **No access** hides the project from the agent entirely. +On the **Permissions** tab, the sponsor can allow or block each workspace they belong to. Changes save immediately. Blocking every workspace removes cloud access while keeping the agent's history. -## Approve requests - -When a request matches an **Ask** rule, Prisma doesn't run it. It waits for your decision, and after you approve, the agent sends the same request again and continues its task. +An agent can reach only allowed workspaces that its sponsor still belongs to. A project override cannot grant access to another workspace. Workspace admins can manage action permissions and approvals; only the sponsor can change the workspace list. - +Existing agents keep their previous workspace scope until the sponsor changes it. The pairing-code enrollment page also lets you choose workspaces and initially selects only your default workspace. -The agent sends you a link to the request in its chat. The request also appears in Prisma Console as an approvals counter in the header, in the **Pending approvals** list on the Agents page, and on the agent's **Approvals** tab. Each card shows what the agent wants to do, the exact API request, whether it targets production, and the agent's reason when it gave one: +## What the agent can do -![An approval card showing that an agent wants to create a database, with operation and production-branch chips, the exact API request, the agent's stated reason, and Approve once, Approve for 1 hour, and Deny buttons.](/img/prisma-compute/agent-enrollment/approval-card.png) +Prisma checks policy before each cloud action through MCP: -Choose one of three responses: +| Rule | Covers | Default | +| --- | --- | --- | +| Preview branches | Reading, creating, and changing preview resources | Allow | +| Production reads | Reading production resources | Allow | +| Production writes | Creating or changing production resources | Ask | +| Admin actions | Deleting resources or creating lasting credentials | Ask | -| Response | What it allows | -| ---------------------- | ---------------------------------------------------------------------------------------------- | -| **Approve once** | This exact request, one time. | -| **Approve for 1 hour** | The same action for the next hour, such as creating databases, in the same project and on the same kind of branch (production or preview). | -| **Deny** | Nothing. The request is not run, and the agent learns that you denied it. | +The first branch in a project is production; later branches are previews. See [Branching](/compute/branching). -Use **Approve for 1 hour** when the agent will repeat a step, so you don't approve each request separately. Requests of any other kind still ask. +On **Permissions**, set each rule to **Allow**, **Ask**, or **Block**. A blocked action stops immediately. **Project overrides** provide **Full access** or **No access** within an allowed workspace. -You don't need to tell the agent what you decided, because it checks for your decision on its own. +The skill uses MCP for cloud operations and local tools for code edits and builds. CLI sessions, database URLs, and GitHub credentials have their own access controls. Give preview apps a preview database URL: a preview app with a production `DATABASE_URL` can still reach production data. See [Environment variables](/compute/environment-variables). -Each request waits 5 minutes for your decision, and the card shows a countdown. If you miss it, the agent tries again and a new card appears for you to approve. For 24 hours, you can also approve an expired request from the history on the agent's **Approvals** tab by clicking **Approve anyway**, and the next time the agent sends that request, it goes through. If the agent has stopped, ask it to retry. +## Approve requests -The agent's sponsor or an admin of the workspace the request targets can decide. Requests that don't belong to a workspace yet, such as creating a new workspace, can only be decided by the sponsor. +An action that needs approval returns `approval_required`, an approval ID, a Console link, and an expiry. It has not run. The agent shows you the link and waits. -## Review what the agent did +| Response | What it allows | +| --- | --- | +| **Approve once** | One retry of the exact tool and arguments | +| **Approve for 1 hour** | The same tool in the same workspace, project, and branch role | +| **Deny** | No action | -Open an agent from **Settings → Agents** to see its history. The **Activity** tab lists every request the agent made and what the policy decided: allowed, approved, approval required (paused for your decision), or denied. Requests that a **Block** rule stopped show as denied. You can filter by decision and time range, and export the list as CSV. +The sponsor or an admin of the target workspace can decide. After approval, the agent reads the current status and retries with `approvalId`. Changed arguments need another approval. -The **Approvals** tab shows what the agent asked for, who decided, and the outcome. A check mark next to **Approved** means the agent used the approval. Expand a row to see the agent's reason and the full timeline. +Requests wait five minutes. The agent stops waiting after denial or expiry. For 24 hours, you can approve an expired request from its history; ask the agent to retry if it has stopped. -![The approval history table for an agent, showing requests with their targets and outcomes: approved with a check mark showing the agent used it, approved for one hour, denied, and expired.](/img/prisma-compute/agent-enrollment/approval-history.png) +### Events and polling -Agent requests also appear in the workspace audit log under **Settings → Audit log**. +When both server and harness support MCP Events, the harness subscribes to `prisma.approval.resolved`. Prisma sends a signed webhook when a request is decided or expires. The harness handles callback verification, signatures, subscription refresh, and cleanup. -## Pause or revoke an agent +Prisma advertises Events only when delivery is enabled. Ordinary MCP support does not imply Events support. Without Events, the skill calls `get_agent_approval` every five seconds until a decision or expiry. It also reads status after subscribing to cover a decision made while the subscription was being established. -Both controls are at the bottom of the agent's **Permissions** tab: +## Review activity, pause, or revoke -- **Pause agent** makes Prisma reject all of the agent's requests, starting immediately. The credential stays valid, and **Resume agent** restores access. To the agent, a paused credential looks like a rejected one, so it may start a new enrollment. Deny any pairing code it shows you while paused; after you resume, its existing credential works again. -- **Revoke agent** permanently cancels the agent's credential. Its activity and approval history stay. To reconnect the agent, enroll it again. +The **Activity** tab and workspace audit log attribute MCP actions and decisions to the agent. **Approvals** shows who decided each request and whether the agent used it. -An agent also loses access when: +On **Permissions**, **Pause agent** rejects new calls; **Resume agent** restores access. **Revoke agent** permanently disables the identity. Refreshing or signing in again to the same MCP client does not restore a revoked identity. Enroll a new connection instead. -- its credential expires, about 90 days after enrollment. Prisma then rejects the credential, so the agent starts a new enrollment for you to approve. Each enrollment creates a new agent with the default policy, so reapply any policy changes and project overrides afterward. -- you leave a workspace. Your agents lose access to that workspace at the same time. -- you delete your Prisma account. +Access also ends when the sponsor's account is deactivated or the sponsor leaves an allowed workspace. History is retained. ## Build and deploy with your agent -With the agent enrolled, ask it to deploy your app: - -```text -Deploy this app to Prisma Compute from its GitHub repository, using your enrolled Prisma credential. -``` - -If you already deployed the app from your terminal, tell the agent the names of the project and database to use, as shown in Prisma Console, so it doesn't create new ones. The agent works through the REST API and pauses where your policy asks: - -1. It finds or creates a workspace and a project. Creating a workspace asks for your approval. -2. It creates a Prisma Postgres database for production, which asks for your approval. -3. It connects your GitHub repository. If the Prisma GitHub App isn't installed on the repository yet, the agent gets a link from Prisma for you to open and install it. Linking the repository to the project also asks. -4. It adds a `.github/workflows/prisma-deploy.yml` workflow that runs [prisma/cloud-deploy-action](https://github.com/prisma/cloud-deploy-action). Because the repository is connected to Prisma, the workflow can sign in to Prisma without a token stored in the repository. -5. It pushes to GitHub, using the Git access already set up on your machine. Pushes to your default Git branch deploy to the project's production branch, and pushes to other Git branches deploy to preview branches. - -:::warning - -A push to your default Git branch deploys to production without asking you, because the deploy runs with the workflow's credential, not the agent's. To review production deploys first, [protect your default branch](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches) in GitHub and tell the agent to open pull requests instead of pushing to it. You can put that rule in your prompt or in `AGENTS.md`, for example: `Never push to main. Open a pull request for every change.` - -::: +Ask the agent to use MCP to find or create a project, prepare databases and environment variables, connect its GitHub repository, and inspect deployments. It asks where the policy requires approval. -See [Deploy on push](/compute/deploy-on-push) for how the workflow deploys and cleans up preview branches. +For GitHub deployment, install the Prisma GitHub App and connect the repository. The agent can prepare a workflow using [prisma/cloud-deploy-action](https://github.com/prisma/cloud-deploy-action), which signs in through GitHub OIDC. Do not give the workflow a service token or the agent's MCP credential. -## Limitations +GitHub Actions has its own identity. A push can deploy independently of the MCP policy. Protect your default branch and require pull requests to review production changes first. See [Deploy on push](/compute/deploy-on-push). -- Agent credentials work with the Prisma REST API. The Prisma MCP server (Prisma's tool server for AI assistants) doesn't accept them yet. -- You learn about pending approvals from the link the agent sends you and from Prisma Console. Email and mobile notifications aren't available yet. -- Prisma doesn't offer agents read-only connection strings for production databases yet. Creating any connection string is an admin action, so each one asks for your approval. +## For MCP client builders -## For agent builders +Discover tools and Events at runtime. Cloud tools accept `workspaceId` to select an allowed workspace. `get_agent_connection` returns the granted IDs and policy. Use `reason` to explain an action and preserve the original arguments when retrying with `approvalId`. -The enrollment instructions already teach an agent how to handle approvals. If you build your own integration, a request that needs approval fails with the error code `approval_required`, and the response carries a link for the sponsor and an approval to poll. Send the link to the sponsor, then [poll the approval](/rest-api/endpoints/agents/get-agent-approvals-by-approval-id) until the sponsor decides. After an approval, send the original request again, unchanged. +The `prisma.approval.resolved` event takes `{ "approvalId": "..." }` and follows the [MCP Events protocol](https://developers.openai.com/plugins/build/mcp-events), including webhook verification and Standard Webhooks signatures. Subscriptions belong to the agent and callback, have a bounded lifetime, and require refresh before `refreshBefore`. Repeating a subscription refreshes it. Unsubscribe when finished and read authoritative status after a notification. -To show the sponsor why the agent needs an action, send a `Prisma-Agent-Reason` header with one sentence of justification. It appears on the approval card. +Existing device-enrolled credentials also work with Prisma MCP. Store them in the client's credential store and send them as bearer credentials. The [REST API](/rest-api) remains available for existing integrations. ## Next steps -- [Deploy on push](/compute/deploy-on-push): how the GitHub workflow deploys production and preview branches. -- [REST API](/rest-api): the API your agent calls. -- [Deploy your first app](/prisma-compute/deploy): deploy from your own terminal instead. +- [Deploy on push](/compute/deploy-on-push) +- [Environment variables](/compute/environment-variables) +- [Deploy your first app](/prisma-compute/deploy) From 3cd40c7fb56a70dd438481bec5cb083799c46280 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=B8ren=20Bramer=20Schmidt?= Date: Thu, 1 Oct 2026 12:33:59 +0700 Subject: [PATCH 2/2] docs(agent): clarify setup and Pi support Address CodeRabbit findings on the device-enrollment screen link and the OpenAI MCP Events guide. Include native Pi installation and OAuth sign-in. --- .../(index)/prisma-compute/agent-enrollment.mdx | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx b/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx index d829f108b47..93916fe972d 100644 --- a/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx +++ b/apps/docs/content/docs/(index)/prisma-compute/agent-enrollment.mdx @@ -13,7 +13,7 @@ The person who authorizes the connection becomes its sponsor. A new agent can re ## Prerequisites - A [Prisma account](https://pris.ly/pdp). -- An MCP client with remote HTTP servers and OAuth sign-in, such as Codex, Claude Code, or Cursor. +- An MCP client with remote HTTP servers and OAuth sign-in, such as Codex, Claude Code, Pi, or Cursor. - Node.js and a project directory where you can install the connection and skill. - A GitHub repository if you want to deploy through GitHub Actions. @@ -25,7 +25,7 @@ From your project directory, run: npx prisma@latest agent install ``` -This adds the Prisma MCP connection and the `prisma-agent-enrollment` skill for Codex, Claude Code, and Cursor. It preserves other servers and comments, and refuses to overwrite a conflicting Prisma connection or a skill that Prisma does not manage. +This adds the Prisma MCP connection and the `prisma-agent-enrollment` skill for Codex, Claude Code, Pi, and Cursor. It preserves other servers and comments, and refuses to overwrite a conflicting Prisma connection or a skill that Prisma does not manage. To install for one client: @@ -33,7 +33,7 @@ To install for one client: npx prisma@latest agent install --client codex ``` -Supported values are `codex`, `claude`, `cursor`, and `all`. The skill teaches the agent to check its identity, use MCP for cloud operations, handle approvals, and reuse the connection in later sessions. You no longer need to copy a long instruction block into chat or `AGENTS.md`. +Supported values are `codex`, `claude`, `pi`, `cursor`, and `all`. The skill teaches the agent to check its identity, use MCP for cloud operations, handle approvals, and reuse the connection in later sessions. You no longer need to copy a long instruction block into chat or `AGENTS.md`. ## 2. Authorize the connection @@ -47,7 +47,7 @@ For clients configured through connector settings, add this URL manually: https://mcp.prisma.io/mcp ``` -OAuth enrollment works independently of the installer. +OAuth enrollment works independently of the installer. Pi users need a version with [native MCP and OAuth support](https://pi.dev/docs/latest/mcp). Run `pi mcp login prisma` after trusting the project, then `/reload` in an existing session. ## 3. Confirm identity and access @@ -67,7 +67,7 @@ On the **Permissions** tab, the sponsor can allow or block each workspace they b An agent can reach only allowed workspaces that its sponsor still belongs to. A project override cannot grant access to another workspace. Workspace admins can manage action permissions and approvals; only the sponsor can change the workspace list. -Existing agents keep their previous workspace scope until the sponsor changes it. The pairing-code enrollment page also lets you choose workspaces and initially selects only your default workspace. +Existing agents keep their previous workspace scope until the sponsor changes it. The [Console device-enrollment screen](https://console.prisma.io/enroll) also lets you choose workspaces and initially selects only your default workspace. ## What the agent can do @@ -126,9 +126,9 @@ GitHub Actions has its own identity. A push can deploy independently of the MCP Discover tools and Events at runtime. Cloud tools accept `workspaceId` to select an allowed workspace. `get_agent_connection` returns the granted IDs and policy. Use `reason` to explain an action and preserve the original arguments when retrying with `approvalId`. -The `prisma.approval.resolved` event takes `{ "approvalId": "..." }` and follows the [MCP Events protocol](https://developers.openai.com/plugins/build/mcp-events), including webhook verification and Standard Webhooks signatures. Subscriptions belong to the agent and callback, have a bounded lifetime, and require refresh before `refreshBefore`. Repeating a subscription refreshes it. Unsubscribe when finished and read authoritative status after a notification. +The `prisma.approval.resolved` event takes `{ "approvalId": "..." }` and follows the [OpenAI's MCP Events guide](https://developers.openai.com/plugins/build/mcp-events), including webhook verification and Standard Webhooks signatures. Subscriptions belong to the agent and callback, have a bounded lifetime, and require refresh before `refreshBefore`. Repeating a subscription refreshes it. Unsubscribe when finished and read authoritative status after a notification. -Existing device-enrolled credentials also work with Prisma MCP. Store them in the client's credential store and send them as bearer credentials. The [REST API](/rest-api) remains available for existing integrations. +Existing device-enrollment credentials also work with Prisma MCP. Store them in the client's credential store and send them as bearer credentials. The [REST API](/rest-api) remains available for existing integrations. ## Next steps