{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "prismatic",
    "name": "Prismatic",
    "vendor": "Prismatic Software Inc.",
    "vendorUrl": "https://prismatic.io",
    "kind": "http-api",
    "category": "workflow-automation",
    "summary": "Prismatic is an embedded integration platform for B2B software companies. Teams build integrations in a low-code designer or in TypeScript, deploy them to customers, and manage them through a GraphQL API, the Prism CLI and MCP servers.",
    "url": "https://www.anchorterminal.com/tools/prismatic",
    "markdownUrl": "https://www.anchorterminal.com/tools/prismatic.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/prismatic.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/prismatic.json",
    "repo": "https://github.com/prismatic-io/prism",
    "license": "Proprietary service. The Prism CLI, the Spectral and embedded SDKs, the Prism MCP dev server and the Claude Code skills on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http",
      "stdio"
    ],
    "remoteUrl": "https://mcp.prismatic.io/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@prismatic-io/prism"
      },
      {
        "registry": "npm",
        "name": "@prismatic-io/prism-mcp"
      },
      {
        "registry": "npm",
        "name": "@prismatic-io/spectral"
      },
      {
        "registry": "npm",
        "name": "@prismatic-io/embedded"
      }
    ],
    "auth": "oauth",
    "authNotes": "Access starts with a person creating an account, by free trial or contract, and logging in through the browser (`prism login`). The API takes that user's JWT as a Bearer token. `prism me:token --type refresh` prints a refresh token for headless use, exchanged at `/auth/refresh` for an access token valid for 7 days. Tokens have no scopes of their own and act with the user's role. The hosted MCP flow server uses MCP OAuth or the same Bearer token, and embedded end users get a JWT signed by the customer's backend.",
    "pricing": "paid",
    "pricingNotes": "No public prices. The pricing page lists Scale, Enterprise and Custom plans with volume per-instance pricing, each ending in a demo request. A free trial exists, and the Terms of Use set it at 30 days unless stated otherwise at signup. Whether the trial needs a card could not be read because the signup form is drawn by script. Contracts set fair use limits in gigabyte-seconds of compute per instance per month (checked 2026-10-09).",
    "priceSummary": "Paid",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the API docs or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 29,
      "npmWeekly": 8416,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://prismatic.io/docs/api/",
    "llmsTxt": "https://prismatic.io/docs/llms.txt",
    "registryName": "io.github.prismatic-io/prism-mcp",
    "capabilities": [
      "automation.workflows",
      "automation.embedded",
      "automation.apps",
      "automation.code",
      "automation.webhooks",
      "automation.auth",
      "agent.tools"
    ],
    "tags": [
      "hosted",
      "enterprise",
      "graphql",
      "mcp",
      "cli",
      "oauth",
      "llms-txt",
      "typescript",
      "sales-led",
      "status-page",
      "soc2",
      "webhooks",
      "closed-source"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 59.1,
      "grade": "C",
      "agentReady": false,
      "rank": 561,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 63,
        "maintenance": 83,
        "payments": 0,
        "reliability": 67,
        "schema": 75,
        "security": 59,
        "transparency": 65
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 67,
          "points": 13.4,
          "reason": "Graded as a hosted service, on the GraphQL API and the hosted MCP flow server. Atlassian Statuspage at www.prismatic-status.io with five components and 90-day uptime bars (20). Four incidents in the last 90 days, all short or partial. Intermittent OAuth token refresh failures in eu-west-1 for 3 hours 16 minutes on 17 August 2026, raised error rates in us-west-2 for about 70 minutes on 16 September, the web app unavailable in all regions for 21 minutes on 22 September, and workflow editing in the embedded builder down for 33 minutes on 30 September (20). Execution limits are published with numbers (15 minutes, 1 GB, 6 MB webhook payload, 30 seconds synchronous), but concurrency depends on the plan with no number and no API request rate was found (5). A request over the concurrency limit gets a 429, flow concurrency queues requests and failed executions can retry automatically. No `Retry-After` or backoff guidance for the API was found (7). The pricing page lists standard SLAs on Scale and Enterprise and custom SLAs above, with no SLA text published (5). The API, CLI and MCP flow server are generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "The contract is a GraphQL schema with 120 queries and 124 mutations in the reference and a GraphiQL explorer. No downloadable schema file or OpenAPI document was found (22). `llms.txt` and a Markdown twin of every docs page (10). Each operation and field has a one-line description, with no guidance on when to use one over another (11). Arguments are typed, with required markers, enums and input objects (13). The docs carry worked queries in curl, Node.js and Python and document the mutation `errors` array, with no list of error codes (9). The changelog is public and dated. The API has no version, and deprecated arguments are marked in the schema (10)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 63,
          "points": 10.24,
          "reason": "GraphQL field selection lets a caller size each response, and `first` caps the page. The local MCP dev server has 19 tools in two optional toolsets (22). Relay cursors with a default of 100, `sortBy` and per-query filters (20). Mutations return an `errors` array of field and message under HTTP 200, with no codes (10). No idempotency keys were found, and the MCP dev server's tools carry no `readOnlyHint` or `destructiveHint`. Customer `externalId` values must be unique, which stops one kind of duplicate (3). A CLI and two TypeScript SDKs, no API client in a second language (8)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 59,
          "points": 10.33,
          "reason": "The API takes a user's JWT from an OAuth login. Access tokens last 7 days and refresh tokens can be revoked, though revoking one revokes all of that user's. Tokens have no scopes and act with the user's role (20). Seven roles include a read-only guest, a restricted integrator who cannot see logs or step results, and a third-party role limited to named objects. No confirmation step before destructive mutations was found (13). Agentic flows return third-party content and no prompt-injection guidance was found (3). Execution logs, step results and log streaming to Datadog, New Relic or Google Cloud. No audit log of API calls was found (8). Valid security.txt with a PGP key, a disclosure address, and SOC 2 Type 2 per the security policy. No bug bounty found, and the trust centre is drawn by script and was not read (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 0,
          "points": 0,
          "reason": "No x402, MPP or L402 (0). The pricing page names three plans and gives no price. Each ends in a demo request (0). A free trial exists, 30 days per the Terms of Use, but the signup form is drawn by script and we could not confirm that it needs no card, so the line is scored absent (0). A person signs up and logs in through a browser before any token exists (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "The Spectral SDK released v10.34.1 on 6 October 2026 and the changelog's newest entry is 1 October 2026 (30). Ten changelog entries between 20 August and 1 October 2026, and Prism CLI releases on 14, 15 and 30 September (20). A dated changelog with monthly newsletters and a support address. The CLI and MCP repositories each show two open issues (10). Current official CLI, Spectral and embedded SDKs, and the MCP dev server's `server.json` names `io.github.prismatic-io/prism-mcp`. We did not confirm the registry entry itself (15). Build, test and release workflows in each repository and dependency updates through October 2026. We did not see the workflow results (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 65,
          "points": 5.69,
          "note": "editorial 40, provenance 89",
          "reason": "Closed platform. The public Terms of Use cover the website and trials and say paid use runs under a separate agreement, which is not published. The CLI, SDKs and MCP dev server are MIT (12). The Privacy Policy covers the web application and names Mixpanel and Auth0, but gives no retention period beyond as long as needed. The Terms say trial data is not kept after a trial, and the changelog gives 14 days of execution retention. No DPA or sub-processor list was found on the pages read (12). Deprecated arguments are marked in the schema and Spectral has upgrade guides for each major version. No deprecation policy with notice periods was found (6). Seven hosting regions and AWS are disclosed. A sub-processor list was not found (10)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "GraphQL field selection lets a caller size each response, and `first` caps the page. The local MCP dev server has 19 tools in two optional toolsets (22). Relay cursors with a default of 100, `sortBy` and per-query filters (20). Mutations return an `errors` array of field and message under HTTP 200, with no codes (10). No idempotency keys were found, and the MCP dev server's tools carry no `readOnlyHint` or `destructiveHint`. Customer `externalId` values must be unique, which stops one kind of duplicate (3). A CLI and two TypeScript SDKs, no API client in a second language (8).",
          "maintenance": "The Spectral SDK released v10.34.1 on 6 October 2026 and the changelog's newest entry is 1 October 2026 (30). Ten changelog entries between 20 August and 1 October 2026, and Prism CLI releases on 14, 15 and 30 September (20). A dated changelog with monthly newsletters and a support address. The CLI and MCP repositories each show two open issues (10). Current official CLI, Spectral and embedded SDKs, and the MCP dev server's `server.json` names `io.github.prismatic-io/prism-mcp`. We did not confirm the registry entry itself (15). Build, test and release workflows in each repository and dependency updates through October 2026. We did not see the workflow results (8).",
          "payments": "No x402, MPP or L402 (0). The pricing page names three plans and gives no price. Each ends in a demo request (0). A free trial exists, 30 days per the Terms of Use, but the signup form is drawn by script and we could not confirm that it needs no card, so the line is scored absent (0). A person signs up and logs in through a browser before any token exists (0).",
          "reliability": "Graded as a hosted service, on the GraphQL API and the hosted MCP flow server. Atlassian Statuspage at www.prismatic-status.io with five components and 90-day uptime bars (20). Four incidents in the last 90 days, all short or partial. Intermittent OAuth token refresh failures in eu-west-1 for 3 hours 16 minutes on 17 August 2026, raised error rates in us-west-2 for about 70 minutes on 16 September, the web app unavailable in all regions for 21 minutes on 22 September, and workflow editing in the embedded builder down for 33 minutes on 30 September (20). Execution limits are published with numbers (15 minutes, 1 GB, 6 MB webhook payload, 30 seconds synchronous), but concurrency depends on the plan with no number and no API request rate was found (5). A request over the concurrency limit gets a 429, flow concurrency queues requests and failed executions can retry automatically. No `Retry-After` or backoff guidance for the API was found (7). The pricing page lists standard SLAs on Scale and Enterprise and custom SLAs above, with no SLA text published (5). The API, CLI and MCP flow server are generally available (10).",
          "schema": "The contract is a GraphQL schema with 120 queries and 124 mutations in the reference and a GraphiQL explorer. No downloadable schema file or OpenAPI document was found (22). `llms.txt` and a Markdown twin of every docs page (10). Each operation and field has a one-line description, with no guidance on when to use one over another (11). Arguments are typed, with required markers, enums and input objects (13). The docs carry worked queries in curl, Node.js and Python and document the mutation `errors` array, with no list of error codes (9). The changelog is public and dated. The API has no version, and deprecated arguments are marked in the schema (10).",
          "security": "The API takes a user's JWT from an OAuth login. Access tokens last 7 days and refresh tokens can be revoked, though revoking one revokes all of that user's. Tokens have no scopes and act with the user's role (20). Seven roles include a read-only guest, a restricted integrator who cannot see logs or step results, and a third-party role limited to named objects. No confirmation step before destructive mutations was found (13). Agentic flows return third-party content and no prompt-injection guidance was found (3). Execution logs, step results and log streaming to Datadog, New Relic or Google Cloud. No audit log of API calls was found (8). Valid security.txt with a PGP key, a disclosure address, and SOC 2 Type 2 per the security policy. No bug bounty found, and the trust centre is drawn by script and was not read (15).",
          "transparency": "Closed platform. The public Terms of Use cover the website and trials and say paid use runs under a separate agreement, which is not published. The CLI, SDKs and MCP dev server are MIT (12). The Privacy Policy covers the web application and names Mixpanel and Auth0, but gives no retention period beyond as long as needed. The Terms say trial data is not kept after a trial, and the changelog gives 14 days of execution retention. No DPA or sub-processor list was found on the pages read (12). Deprecated arguments are marked in the schema and Spectral has upgrade guides for each major version. No deprecation policy with notice periods was found (6). Seven hosting regions and AWS are disclosed. A sub-processor list was not found (10)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://prismatic.io/docs/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API authentication",
            "url": "https://prismatic.io/docs/api/authentication.md",
            "seen": "2026-10-09"
          },
          {
            "what": "refresh tokens and revocation",
            "url": "https://prismatic.io/docs/api/ci-cd-system.md",
            "seen": "2026-10-09"
          },
          {
            "what": "pagination",
            "url": "https://prismatic.io/docs/api/pagination.md",
            "seen": "2026-10-09"
          },
          {
            "what": "queries, mutations and errors",
            "url": "https://prismatic.io/docs/api/queries-and-mutations.md",
            "seen": "2026-10-09"
          },
          {
            "what": "query reference",
            "url": "https://prismatic.io/docs/api/schema/queries.md",
            "seen": "2026-10-09"
          },
          {
            "what": "mutation reference",
            "url": "https://prismatic.io/docs/api/schema/mutations.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP flow server endpoints",
            "url": "https://prismatic.io/docs/ai/mcp-endpoints.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP client setup and OAuth",
            "url": "https://prismatic.io/docs/ai/test-mcp-clients.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Prism MCP dev server docs",
            "url": "https://prismatic.io/docs/dev-tools/prism-mcp.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP dev server source, tags and server.json",
            "url": "https://github.com/prismatic-io/prism-mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "Prism CLI source and tags",
            "url": "https://github.com/prismatic-io/prism",
            "seen": "2026-10-09"
          },
          {
            "what": "Spectral SDK tags",
            "url": "https://github.com/prismatic-io/spectral",
            "seen": "2026-10-09"
          },
          {
            "what": "runner environment and limits",
            "url": "https://prismatic.io/docs/integrations/integration-runner-environment-limits.md",
            "seen": "2026-10-09"
          },
          {
            "what": "usage limits",
            "url": "https://prismatic.io/docs/integrations/usage-limits.md",
            "seen": "2026-10-09"
          },
          {
            "what": "deployment regions",
            "url": "https://prismatic.io/docs/configure-prismatic/deployment-regions.md",
            "seen": "2026-10-09"
          },
          {
            "what": "organisation user roles",
            "url": "https://prismatic.io/docs/configure-prismatic/organization-users.md",
            "seen": "2026-10-09"
          },
          {
            "what": "embedded user JWTs",
            "url": "https://prismatic.io/docs/get-started/embedded-marketplace/authenticate-embedded-users.md",
            "seen": "2026-10-09"
          },
          {
            "what": "changelog",
            "url": "https://prismatic.io/docs/changelog/",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://prismatic.io/pricing/",
            "seen": "2026-10-09"
          },
          {
            "what": "Terms of Use",
            "url": "https://prismatic.io/legal/terms/",
            "seen": "2026-10-09"
          },
          {
            "what": "Acceptable Use Policy",
            "url": "https://prismatic.io/legal/acceptable-use/",
            "seen": "2026-10-09"
          },
          {
            "what": "Privacy Policy",
            "url": "https://prismatic.io/legal/privacy/",
            "seen": "2026-10-09"
          },
          {
            "what": "Security Policy",
            "url": "https://prismatic.io/legal/security/",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://prismatic.io/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://www.prismatic-status.io/",
            "seen": "2026-10-09"
          },
          {
            "what": "status history feed",
            "url": "https://www.prismatic-status.io/history.rss",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt with Content-Signal ai-input=yes",
            "url": "https://prismatic.io/robots.txt",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: whether the free trial needs a card. The signup form at https://prismatic.io/free-trial/ is drawn by script",
          "unchecked: the trust centre at https://www.trust-prismatic.io, a Vanta page drawn by script, so any sub-processor list, DPA or further certification there is unread",
          "unchecked: GitHub security advisories for the CLI, SDKs and MCP dev server, and whether CI passes on the default branches",
          "unchecked: whether `io.github.prismatic-io/prism-mcp` is live in the official MCP registry",
          "The agreement that governs paid use is not published, so `provenance.terms` is left out",
          "No API rate limit, SLA text or deprecation policy was found in the reviewed documentation",
          "Whether a GraphQL schema file can be downloaded without an account",
          "The lead named the Prism MCP dev server only. Prismatic also runs a hosted MCP flow server, which the listing records"
        ]
      },
      "negative": 0,
      "verdict": "The GraphQL API covers 120 queries and 124 mutations with typed inputs, cursor pagination and Markdown documentation, and tokens follow seven user roles. No price is published, paid use runs under an agreement that is not public, and no API rate limit or idempotency key was found in the reviewed documentation.",
      "bestFor": "A B2B software company that wants to build integrations once, deploy them per customer and let an in-app agent call them as MCP tools.",
      "strengths": [
        "GraphQL API with 120 documented queries and 124 mutations, field selection, cursor pagination and per-query filters",
        "Every docs page has a Markdown twin, indexed by `llms.txt` at prismatic.io/docs/llms.txt",
        "Hosted MCP flow server in seven regions, with OAuth 2.0 and endpoints scoped to one integration or one instance",
        "Seven organisation roles, including a read-only guest and a third-party role limited to named integrations, components or customers",
        "Dated changelog with ten entries from 20 August to 1 October 2026, and CLI and SDK releases in the same weeks"
      ],
      "weaknesses": [
        "No prices on the pricing page. All three plans end in a demo request",
        "Paid use is governed by a separate agreement that is not published. The public terms cover the website and 30-day trials",
        "No API rate limit, `Retry-After` behaviour or idempotency key found in the reviewed documentation",
        "API tokens carry the whole role of the user who created them, and revoking one refresh token revokes all of that user's",
        "Mutation failures return HTTP 200 with an `errors` array of field and message, with no error codes"
      ],
      "agentNotes": [
        "Have a person run `prism login` once, then store the output of `prism me:token --type refresh` as `PRISM_REFRESH_TOKEN`. Access tokens last 7 days",
        "Read the `errors` array on every mutation. A failed mutation still returns HTTP 200",
        "Pass `sortBy` with `CREATED_AT` when paging. Without a sort order pages can repeat or skip records",
        "Use the regional host for the tenant, such as `app.eu-west-1.prismatic.io` and `mcp.eu-west-1.prismatic.io`",
        "Create a guest user for a read-only agent, because tokens have no scopes of their own"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 59.1
        }
      ],
      "editorialScores": {
        "ergonomics": 63,
        "maintenance": 83,
        "payments": 0,
        "reliability": 67,
        "schema": 75,
        "security": 59,
        "transparency": 40
      },
      "provenanceScore": 89
    },
    "connect": {
      "install": "npm install --global @prismatic-io/prism",
      "http": "curl https://app.prismatic.io/api --request POST --header \"Authorization: Bearer ${PRISMATIC_API_TOKEN}\" --header \"Content-Type: application/json\" --data '{\"query\": \"query { integrations { nodes { id name }}}\"}'",
      "claudeCode": "claude mcp add-json prismatic '{\"type\":\"stdio\",\"command\":\"npx\",\"args\":[\"-y\",\"mcp-remote\",\"https://mcp.prismatic.io/mcp\"]}'",
      "config": {
        "mcpServers": {
          "prism": {
            "args": [
              "-y",
              "@prismatic-io/prism-mcp",
              "."
            ],
            "command": "npx",
            "env": {
              "PRISMATIC_URL": "https://app.prismatic.io"
            },
            "type": "stdio"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/automation.workflows",
      "tool": "https://letme.dev/prismatic"
    },
    "notable": [
      "The GraphQL API answers at https://app.prismatic.io/api with a Bearer JWT. Refresh tokens are exchanged at `/auth/refresh` for access tokens valid for 7 days (https://prismatic.io/docs/api/authentication.md)",
      "The hosted MCP flow server turns flows marked as agentic into MCP tools, over Streamable HTTP with MCP OAuth, at `mcp.prismatic.io/mcp` and six regional hosts (https://prismatic.io/docs/ai/mcp-endpoints.md)",
      "The Prism MCP dev server is a separate local stdio server that wraps the Prism CLI, with 19 tools in two optional toolsets, MIT (https://github.com/prismatic-io/prism-mcp)",
      "Usage is measured in gigabyte-seconds of compute per instance per month against fair use limits set in the contract, and the pricing page says plans are never billed on API calls or executions (https://prismatic.io/docs/integrations/usage-limits.md)",
      "An execution runs for at most 15 minutes with 1 GB of memory by default, and a request over the plan's concurrency limit gets a 429 (https://prismatic.io/docs/integrations/integration-runner-environment-limits.md)",
      "The status page lists four incidents between 17 August and 30 September 2026, the longest 3 hours 16 minutes of intermittent OAuth token refresh failures in eu-west-1 (https://www.prismatic-status.io/history)",
      "The Acceptable Use Policy bars probing, scanning or testing the vulnerability of any system, and access by any means other than the publicly supported interfaces (https://prismatic.io/legal/acceptable-use/)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces",
        "value": "GraphQL API at https://app.prismatic.io/api, Prism CLI (`@prismatic-io/prism` 10.5.0), hosted MCP flow server, local Prism MCP dev server (`@prismatic-io/prism-mcp` 1.5.0), embedded SDK (`@prismatic-io/embedded` 4.14.0), Spectral TypeScript SDK (10.34.1)"
      },
      {
        "label": "API",
        "value": "GraphQL, 120 queries and 124 mutations in the schema reference, with a GraphiQL explorer in the docs. No REST API and no OpenAPI file"
      },
      {
        "label": "Credentials",
        "value": "User JWT from an OAuth login. Access tokens last 7 days, refresh tokens are revocable at `/auth/revoke`, and embedded users get a JWT the customer's backend signs with a key created by an owner or admin"
      },
      {
        "label": "Roles",
        "value": "Owner, admin, integrator, restricted integrator, guest (read-only), customer manager and third-party (per-object permissions)"
      },
      {
        "label": "MCP flow server",
        "value": "Hosted, Streamable HTTP, MCP OAuth or a Bearer token. Global, integration-scoped and instance-scoped endpoints. Tools are the agentic flows the customer has built, plus a default `get-me` tool"
      },
      {
        "label": "MCP dev server",
        "value": "Local stdio, 19 tools, toolsets `integration` and `component`, reads the CLI's saved credentials. No `readOnlyHint` or `destructiveHint` annotations in the source"
      },
      {
        "label": "Pagination",
        "value": "Relay cursors, 100 results by default, `first`, `after`, `sortBy` and per-query filters such as `name_Icontains`"
      },
      {
        "label": "Limits",
        "value": "15 minutes an execution, 1 GB memory by default and up to 10 GB, 6 MB webhook payload, 30 seconds for a synchronous webhook, 500 MB step result. Concurrency depends on the plan, with no published number"
      },
      {
        "label": "Regions",
        "value": "US Commercial (Ohio), US GovCloud, Ireland, London, Canada, Sydney and Cape Town, plus private deployment in the customer's AWS account"
      },
      {
        "label": "Plans",
        "value": "Scale, Enterprise and Custom, all by demo. Volume per-instance pricing. Free trial of 30 days per the Terms of Use"
      },
      {
        "label": "Status",
        "value": "Atlassian Statuspage at www.prismatic-status.io with five components (GraphQL API, Web App, Integration Runner, OAuth 2.0 Refresh, Embedded)"
      },
      {
        "label": "Security",
        "value": "SOC 2 Type 2 per the security policy, AES-256 for stored third-party credentials, TLS 1.2 or later, AWS hosting, Auth0 for user login. Valid security.txt with a PGP key"
      },
      {
        "label": "Open source",
        "value": "The CLI, both SDKs, the MCP dev server and the Claude Code skills are MIT on GitHub. The platform is closed"
      }
    ],
    "provenance": {
      "legalEntity": "Prismatic Software Inc.",
      "domain": "prismatic.io",
      "domainRegistered": "2016-07-09",
      "endpointOnVendorDomain": true,
      "terms": "",
      "privacy": "https://prismatic.io/legal/privacy/",
      "statusPage": "https://www.prismatic-status.io",
      "changelog": "https://prismatic.io/docs/changelog/",
      "securityTxt": "valid",
      "checked": "2026-10-09",
      "notes": [
        "The Terms of Use (last updated 17 March 2023) name Prismatic Software Inc., 5013 S Louise Ave #122, Sioux Falls, SD 57108, and are governed by South Dakota law.",
        "No terms link is recorded. The Terms of Use at https://prismatic.io/legal/terms/ are website terms that also cover trial accounts, and they say non-trial use of the Services is subject to a separate agreement, which is not published.",
        "The Privacy Policy (last updated 26 June 2024) covers the website and the web application at app.prismatic.io.",
        "security.txt at https://prismatic.io/.well-known/security.txt names security@prismatic.io and a PGP key and expires on 16 June 2027.",
        "The API, the regional hosts and the MCP flow server are all on prismatic.io subdomains. The status page is on prismatic-status.io and the trust centre on trust-prismatic.io.",
        "RDAP for prismatic.io gives a registration date of 2016-07-09."
      ],
      "score": 89,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Prismatic Software Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "prismatic.io, registered 2016-07-09 (10 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.prismatic.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "www.prismatic-status.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "",
          "state": "none-found",
          "points": 0,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://prismatic.io/legal/privacy/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2024-06-26",
          "words": 4865,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: June 26, 2024",
              "says": "Last updated 2024-06-26"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy covers the information that we collect about you when you (\"Visitor\", \"Customer\", \"User\") use our website (\"Website\"), https://prismatic.io, or web application (\"Platform\"), https://app.prismatic.io, and our related online and offline offerings and software (collectively, the \"Services\")."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will retain your personal or business information in a form that identifies you only for as long as it serves the purpose(s) for which it was originally intended as stated by this Privacy Policy, as allowed or required under applicable law, or subsequently authorized."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Technical information – details of the third-party services you will connect to via the Services, including your credentials for such third-party service provider applications."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Right to rectify your personal information: if you discover that the information, we hold about you is inaccurate or incomplete, you have the right to have this information rectified (i.e., corrected)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "In addition to the above, you may contact us using the details provided at the end of this Policy with any questions about the choices relating to your personal information."
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "For example, if the recipient country has not received an Adequacy Decision from the European Commission (such as the United States), we will rely on Standard Contractual Clauses (SCC) that have been approved by the European Commission as the lawful mechanisms for such transfers.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We may share information about your use of our Services with our advertising and analytics partners, who may combine it with other information that you previously provided to them."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Prismatic or its service providers may send marketing to email or home addresses that its data partners associate with a website visit or login.",
              "quote": "We (or service providers on our behalf) may then send communications and marketing to these email or home addresses."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/prismatic.json",
    "live": {
      "slug": "prismatic",
      "probe": {
        "target": "https://mcp.prismatic.io/mcp",
        "method": "get",
        "lastAt": "2026-10-10T02:55:06.837417349Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 296,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 298,
        "p95ms24h": 389,
        "samples24h": 115,
        "samples30d": 115,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 30,
            "ok": 30
          }
        ]
      },
      "vendorStatus": {
        "page": "https://www.prismatic-status.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-10T02:50:43.967273294Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "prismatic-io/prism",
          "version": "v10.5.0",
          "released": "2026-09-30",
          "seenAt": "2026-10-09T17:14:48.08709817Z"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/embedded",
          "version": "4.14.0",
          "seenAt": "2026-10-09T17:14:46.07500175Z"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/prism",
          "version": "10.5.0",
          "seenAt": "2026-10-09T17:14:41.869797583Z"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/prism-mcp",
          "version": "1.5.0",
          "seenAt": "2026-10-09T17:14:42.93328997Z"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/spectral",
          "version": "10.34.1",
          "seenAt": "2026-10-09T17:14:44.108249111Z"
        }
      ],
      "githubStars": 29,
      "npmWeekly": 8416,
      "pages": [
        {
          "url": "https://prismatic.io/docs/changelog/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:43:50.569023777Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "8f4fb9151364"
        },
        {
          "url": "https://prismatic.io/legal/privacy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:43:53.22345549Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "6521c9b1a5d9"
        }
      ],
      "updatedAt": "2026-10-10T02:55:06.837417349Z"
    }
  }
}
