Prisma · Authentication Profile

Prisma Authentication

Authentication

Prisma secures its APIs with apiKey, http, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

DatabasePostgreSQLORMDeveloper ToolsApplication HostingServerlessObject StorageTypeScriptMCPAI AgentsProvisioningData Platform
Methods: apiKey, http, oauth2 Schemes: 3 OAuth flows: authorizationCode API key in: header

Security Schemes

bearerAuth http
scheme: bearer
apiKeyAuth apiKey
· in: header (Authorization)
OAuth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: https://www.prisma.io/docs/rest-api/authentication, https://auth.prisma.io/.well-known/oauth-authorization-server
  (HTTP 200), openapi/prisma-postgres-management-api-openapi.json
summary:
  types:
  - apiKey
  - http
  - oauth2
  api_key_in:
  - header
  oauth2_flows:
  - authorizationCode
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  bearerFormat: JWT
  description: Authentication via service token or OAuth 2.0 access token. Service tokens are created
    in the Prisma Console under workspace settings.
  sources:
  - openapi/prisma-api-keys-api-openapi.yml
  - openapi/prisma-connections-api-openapi.yml
  - openapi/prisma-database-backups-api-openapi.yml
  - openapi/prisma-database-usage-api-openapi.yml
  - openapi/prisma-databases-api-openapi.yml
  - openapi/prisma-environments-api-openapi.yml
  - openapi/prisma-integrations-api-openapi.yml
  - openapi/prisma-members-api-openapi.yml
  - openapi/prisma-postgres-management-api-openapi.json
  - openapi/prisma-projects-api-openapi.yml
  - openapi/prisma-workspaces-api-openapi.yml
- name: apiKeyAuth
  type: apiKey
  in: header
  parameter: Authorization
  description: API key for Accelerate authentication, provided as a Bearer token. Generated from the Prisma
    Data Platform Console for each environment.
  sources:
  - openapi/prisma-cache-api-openapi.yml
  - openapi/prisma-events-api-openapi.yml
  - openapi/prisma-health-api-openapi.yml
  - openapi/prisma-metrics-api-openapi.yml
  - openapi/prisma-queries-api-openapi.yml
  - openapi/prisma-recommendations-api-openapi.yml
  - openapi/prisma-sessions-api-openapi.yml
  - openapi/prisma-streams-api-openapi.yml
  - openapi/prisma-subscriptions-api-openapi.yml
- name: OAuth2
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://auth.prisma.io/authorize
    tokenUrl: https://auth.prisma.io/token
    scopes: 2
  description: OAuth2 authentication
  sources:
  - openapi/prisma-postgres-management-api-openapi.json
docs: https://www.prisma.io/docs/rest-api/authentication
credentials:
- kind: service-token
  header: 'Authorization: Bearer <token>'
  issued_from: Prisma Console -> workspace Settings -> Service Tokens
  expiry: none
  revocation: DELETE /v1/workspaces/{workspaceId}/service-tokens/{serviceTokenId}
  management_operations:
  - getV1WorkspacesByWorkspaceIdService-tokens
  - postV1WorkspacesByWorkspaceIdService-tokens
  - deleteV1WorkspacesByWorkspaceIdService-tokensByServiceTokenId
  note: The docs warn explicitly that service tokens NEVER EXPIRE and a leaked token stays valid until
    revoked. The token value is returned exactly once at creation and is never stored, so a caller that
    loses it must mint a new one.
  prefix: null
  prefix_note: No documented test/live or environment prefix on the token value.
- kind: oauth2
  flow: authorization_code
  pkce: S256
  pkce_requirement: mandatory for public clients; optional for confidential clients, but a flow started
    with PKCE must complete with PKCE
  authorization_url: https://auth.prisma.io/authorize
  token_url: https://auth.prisma.io/token
  discovery: https://auth.prisma.io/.well-known/oauth-authorization-server
  dynamic_client_registration: https://auth.prisma.io/register
  access_token_ttl: 1 hour
  refresh: offline_access scope; single-use rotation with replay detection — reusing an invalidated refresh
    token revokes every token on that authorization
  scopes:
  - workspace:admin
  - offline_access
  client_registration: Prisma Console -> Integrations -> Published Applications -> New Application
  dev_redirect_uris:
  - localhost (any port)
  - 127.0.0.1 (any port)
  - '[::1] (any port)'
  token_endpoint_auth_methods:
  - client_secret_basic
  - client_secret_post
  - none
- kind: oidc-workload-federation
  operation: postV1AuthGithub-actionsToken
  path: /v1/auth/github-actions/token
  stability: experimental
  note: Exchanges a GitHub Actions OIDC token for a workspace service token — keyless CI auth.
deprecated_schemes:
- name: apiKeyAuth
  note: Carried only by the nine per-tag specs split from the earlier Accelerate/Pulse/Optimize source
    documents in openapi/_original/. Those products are no longer in the advertised line and this scheme
    does not appear in the provider-published Management API contract. Kept as history, not asserted as
    current.
mtls: false
openid_connect: false
openid_connect_note: No /.well-known/openid-configuration is served on any Prisma host (all 404).
cross_reference:
- scopes/prisma-scopes.yml
- conventions/prisma-conventions.yml
- well-known/prisma-well-known.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/prisma-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.