Prismatic

by Prismatic Software Inc. HTTP API in Workflow automation

Hosted Local

Prismatic Software Inc. · prismatic.io since 2016 · status page · who's behind it

Prismatic is an embedded integration platform for B2B software companies. Teams build integrations in a low-code designer or in TypeScript, deploy them to customers, and manage them through a GraphQL API, the Prism CLI and MCP servers.

Good for A B2B software company that wants to build integrations once, deploy them per customer and let an in-app agent call them as MCP tools.

Is this your product? Claim this listing or verify it

Assessment. The GraphQL API covers 120 queries and 124 mutations with typed inputs, cursor pagination and Markdown documentation, and tokens follow seven user roles. No price is published, paid use runs under an agreement that is not public, and no API rate limit or idempotency key was found in the reviewed documentation.

Facts

Transport
HTTP, Streamable HTTP, stdio
Endpoint
https://mcp.prismatic.io/mcp
Auth
OAuth
Pricing
Paid · Paid
x402
No
Licence
Proprietary service. The Prism CLI, the Spectral and embedded SDKs, the Prism MCP dev server and the Claude Code skills on GitHub are MIT
Packages
npm @prismatic-io/prism
npm @prismatic-io/prism-mcp
npm @prismatic-io/spectral
npm @prismatic-io/embedded
MCP registry
io.github.prismatic-io/prism-mcp
llms.txt
published
Last release
GitHub stars
29
npm / week
8.4k
Surfaces
GraphQL API at https://app.prismatic.io/api, Prism CLI (@prismatic-io/prism 10.5.0), hosted MCP flow server, local Prism MCP dev server (@prismatic-io/prism-mcp 1.5.0), embedded SDK (@prismatic-io/embedded 4.14.0), Spectral TypeScript SDK (10.34.1)
API
GraphQL, 120 queries and 124 mutations in the schema reference, with a GraphiQL explorer in the docs. No REST API and no OpenAPI file
Credentials
User JWT from an OAuth login. Access tokens last 7 days, refresh tokens are revocable at /auth/revoke, and embedded users get a JWT the customer's backend signs with a key created by an owner or admin
Roles
Owner, admin, integrator, restricted integrator, guest (read-only), customer manager and third-party (per-object permissions)
MCP flow server
Hosted, Streamable HTTP, MCP OAuth or a Bearer token. Global, integration-scoped and instance-scoped endpoints. Tools are the agentic flows the customer has built, plus a default get-me tool
MCP dev server
Local stdio, 19 tools, toolsets integration and component, reads the CLI's saved credentials. No readOnlyHint or destructiveHint annotations in the source
Pagination
Relay cursors, 100 results by default, first, after, sortBy and per-query filters such as name_Icontains
Limits
15 minutes an execution, 1 GB memory by default and up to 10 GB, 6 MB webhook payload, 30 seconds for a synchronous webhook, 500 MB step result. Concurrency depends on the plan, with no published number
Regions
US Commercial (Ohio), US GovCloud, Ireland, London, Canada, Sydney and Cape Town, plus private deployment in the customer's AWS account
Plans
Scale, Enterprise and Custom, all by demo. Volume per-instance pricing. Free trial of 30 days per the Terms of Use
Status
Atlassian Statuspage at www.prismatic-status.io with five components (GraphQL API, Web App, Integration Runner, OAuth 2.0 Refresh, Embedded)
Security
SOC 2 Type 2 per the security policy, AES-256 for stored third-party credentials, TLS 1.2 or later, AWS hosting, Auth0 for user login. Valid security.txt with a PGP key
Open source
The CLI, both SDKs, the MCP dev server and the Claude Code skills are MIT on GitHub. The platform is closed

Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • GraphQL API with 120 documented queries and 124 mutations, field selection, cursor pagination and per-query filters
  • Every docs page has a Markdown twin, indexed by llms.txt at prismatic.io/docs/llms.txt
  • Hosted MCP flow server in seven regions, with OAuth 2.0 and endpoints scoped to one integration or one instance
  • Seven organisation roles, including a read-only guest and a third-party role limited to named integrations, components or customers
  • Dated changelog with ten entries from 20 August to 1 October 2026, and CLI and SDK releases in the same weeks

Weaknesses

  • No prices on the pricing page. All three plans end in a demo request
  • Paid use is governed by a separate agreement that is not published. The public terms cover the website and 30-day trials
  • No API rate limit, Retry-After behaviour or idempotency key found in the reviewed documentation
  • API tokens carry the whole role of the user who created them, and revoking one refresh token revokes all of that user's
  • Mutation failures return HTTP 200 with an errors array of field and message, with no error codes

Before you call it notes for agents

  1. Have a person run prism login once, then store the output of prism me:token --type refresh as PRISM_REFRESH_TOKEN. Access tokens last 7 days
  2. Read the errors array on every mutation. A failed mutation still returns HTTP 200
  3. Pass sortBy with CREATED_AT when paging. Without a sort order pages can repeat or skip records
  4. Use the regional host for the tenant, such as app.eu-west-1.prismatic.io and mcp.eu-west-1.prismatic.io
  5. Create a guest user for a read-only agent, because tokens have no scopes of their own

Who's behind it provenance 89/100

  • Legal entity namedPrismatic Software Inc.20/20
  • Domain ageprismatic.io, registered 2016-07-09 (10 years)15/15
  • Endpoint on the vendor's domainmcp.prismatic.io15/15
  • Terms of servicenot found0/10
  • Privacy policyread, states 7 of the 8 things a reader expects9.3/10
  • Status pagewww.prismatic-status.io10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service none to read

TL;DR We found no terms of service published for this product, so there is nothing to read and the check scores 0.

Privacy policy dated 2024-06-26, states 7 of 8, 1 to know

TL;DR Dated 2024-06-26. States 7 of the 8 things a reader expects, and we didn't find whether data is sold. To know before relying on it, selling or sharing data for advertising.

Says it sells personal data or shares it for advertising
We may share information about your use of our Services with our advertising and analytics partners, who may combine it with other information that you previously provided to them.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2024-06-26
Last Updated: June 26, 2024

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
This Privacy Policy covers the information that we collect about you when you ("Visitor", "Customer", "User") use our website ("Website"), https://prismatic.io, or web application ("Platform"), https://app.prismatic.io, and our related online and offline offerings and software (collectively, the "Services").

The basic statement a privacy policy exists to make.

Says how long data is kept
We will retain your personal or business information in a form that identifies you only for as long as it serves the purpose(s) for which it was originally intended as stated by this Privacy Policy, as allowed or required under applicable law, or subsequently authorized.

Says when data sent to the service is deleted.

Says who else receives the data
Technical information – details of the third-party services you will connect to via the Services, including your credentials for such third-party service provider applications.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
Right to rectify your personal information: if you discover that the information, we hold about you is inaccurate or incomplete, you have the right to have this information rectified (i.e., corrected).

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact
In addition to the above, you may contact us using the details provided at the end of this Policy with any questions about the choices relating to your personal information.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
For example, if the recipient country has not received an Adequacy Decision from the European Commission (such as the United States), we will rely on Standard Contractual Clauses (SCC) that have been approved by the European Commission as the lawful mechanisms for such transfers.

The countries data goes to and the safeguard used.

Prismatic or its service providers may send marketing to email or home addresses that its data partners associate with a website visit or login.
We (or service providers on our behalf) may then send communications and marketing to these email or home addresses.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 4,865 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Terms of Use (last updated 17 March 2023) name Prismatic Software Inc., 5013 S Louise Ave #122, Sioux Falls, SD 57108, and are governed by South Dakota law.

No terms link is recorded. The Terms of Use at https://prismatic.io/legal/terms/ are website terms that also cover trial accounts, and they say non-trial use of the Services is subject to a separate agreement, which is not published.

The Privacy Policy (last updated 26 June 2024) covers the website and the web application at app.prismatic.io.

security.txt at https://prismatic.io/.well-known/security.txt names security@prismatic.io and a PGP key and expires on 16 June 2027.

The API, the regional hosts and the MCP flow server are all on prismatic.io subdomains. The status page is on prismatic-status.io and the trust centre on trust-prismatic.io.

RDAP for prismatic.io gives a registration date of 2016-07-09.

Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-10 00:51 UTC

Right nowUpHTTP 401 · 376 ms · 2 minutes ago
Uptime 24h100.0%94 probes
Uptime 30 days100.0%94 probes
p50 24h300 msget
p95 24h390 msanswers, asks for auth

Probed every five minutes at https://mcp.prismatic.io/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 2 minutes ago
  • github prismatic-io/prism v10.5.0, released 2026-09-30
  • npm @prismatic-io/embedded 4.14.0
  • npm @prismatic-io/prism 10.5.0
  • npm @prismatic-io/prism-mcp 1.5.0
  • npm @prismatic-io/spectral 10.34.1
  • GitHub stars 29
  • npm downloads a week 8.4k

Pages we watch

PageKindLast checkedLast changed
prismatic.io/docs/changelogchangelog6 hours ago · 200no change seen
prismatic.io/legal/privacyprivacy6 hours ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/prismatic.json

Notable

  • The GraphQL API answers at https://app.prismatic.io/api with a Bearer JWT. Refresh tokens are exchanged at /auth/refresh for access tokens valid for 7 days source
  • The hosted MCP flow server turns flows marked as agentic into MCP tools, over Streamable HTTP with MCP OAuth, at mcp.prismatic.io/mcp and six regional hosts source
  • The Prism MCP dev server is a separate local stdio server that wraps the Prism CLI, with 19 tools in two optional toolsets, MIT source
  • Usage is measured in gigabyte-seconds of compute per instance per month against fair use limits set in the contract, and the pricing page says plans are never billed on API calls or executions source
  • An execution runs for at most 15 minutes with 1 GB of memory by default, and a request over the plan's concurrency limit gets a 429 source
  • The status page lists four incidents between 17 August and 30 September 2026, the longest 3 hours 16 minutes of intermittent OAuth token refresh failures in eu-west-1 source
  • The Acceptable Use Policy bars probing, scanning or testing the vulnerability of any system, and access by any means other than the publicly supported interfaces source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 13.4
Graded as a hosted service, on the GraphQL API and the hosted MCP flow server. Atlassian Statuspage at www.prismatic-status.io with five components and 90-day uptime bars (20). Four incidents in the last 90 days, all short or partial. Intermittent OAuth token refresh failures in eu-west-1 for 3 hours 16 minutes on 17 August 2026, raised error rates in us-west-2 for about 70 minutes on 16 September, the web app unavailable in all regions for 21 minutes on 22 September, and workflow editing in the embedded builder down for 33 minutes on 30 September (20). Execution limits are published with numbers (15 minutes, 1 GB, 6 MB webhook payload, 30 seconds synchronous), but concurrency depends on the plan with no number and no API request rate was found (5). A request over the concurrency limit gets a 429, flow concurrency queues requests and failed executions can retry automatically. No Retry-After or backoff guidance for the API was found (7). The pricing page lists standard SLAs on Scale and Enterprise and custom SLAs above, with no SLA text published (5). The API, CLI and MCP flow server are generally available (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 12.2
The contract is a GraphQL schema with 120 queries and 124 mutations in the reference and a GraphiQL explorer. No downloadable schema file or OpenAPI document was found (22). llms.txt and a Markdown twin of every docs page (10). Each operation and field has a one-line description, with no guidance on when to use one over another (11). Arguments are typed, with required markers, enums and input objects (13). The docs carry worked queries in curl, Node.js and Python and document the mutation errors array, with no list of error codes (9). The changelog is public and dated. The API has no version, and deprecated arguments are marked in the schema (10).
Agent ergonomics 13%16.2 10.2
GraphQL field selection lets a caller size each response, and first caps the page. The local MCP dev server has 19 tools in two optional toolsets (22). Relay cursors with a default of 100, sortBy and per-query filters (20). Mutations return an errors array of field and message under HTTP 200, with no codes (10). No idempotency keys were found, and the MCP dev server's tools carry no readOnlyHint or destructiveHint. Customer externalId values must be unique, which stops one kind of duplicate (3). A CLI and two TypeScript SDKs, no API client in a second language (8).
Security & auth 14%17.5 10.3
The API takes a user's JWT from an OAuth login. Access tokens last 7 days and refresh tokens can be revoked, though revoking one revokes all of that user's. Tokens have no scopes and act with the user's role (20). Seven roles include a read-only guest, a restricted integrator who cannot see logs or step results, and a third-party role limited to named objects. No confirmation step before destructive mutations was found (13). Agentic flows return third-party content and no prompt-injection guidance was found (3). Execution logs, step results and log streaming to Datadog, New Relic or Google Cloud. No audit log of API calls was found (8). Valid security.txt with a PGP key, a disclosure address, and SOC 2 Type 2 per the security policy. No bug bounty found, and the trust centre is drawn by script and was not read (15).
Payments & pricing 10%12.5 0.0
No x402, MPP or L402 (0). The pricing page names three plans and gives no price. Each ends in a demo request (0). A free trial exists, 30 days per the Terms of Use, but the signup form is drawn by script and we could not confirm that it needs no card, so the line is scored absent (0). A person signs up and logs in through a browser before any token exists (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.3
The Spectral SDK released v10.34.1 on 6 October 2026 and the changelog's newest entry is 1 October 2026 (30). Ten changelog entries between 20 August and 1 October 2026, and Prism CLI releases on 14, 15 and 30 September (20). A dated changelog with monthly newsletters and a support address. The CLI and MCP repositories each show two open issues (10). Current official CLI, Spectral and embedded SDKs, and the MCP dev server's server.json names io.github.prismatic-io/prism-mcp. We did not confirm the registry entry itself (15). Build, test and release workflows in each repository and dependency updates through October 2026. We did not see the workflow results (8).
Transparency & trusteditorial 40, provenance 89 7%8.8 5.7
Closed platform. The public Terms of Use cover the website and trials and say paid use runs under a separate agreement, which is not published. The CLI, SDKs and MCP dev server are MIT (12). The Privacy Policy covers the web application and names Mixpanel and Auth0, but gives no retention period beyond as long as needed. The Terms say trial data is not kept after a trial, and the changelog gives 14 days of execution retention. No DPA or sub-processor list was found on the pages read (12). Deprecated arguments are marked in the schema and Spectral has upgrade guides for each major version. No deprecation policy with notice periods was found (6). Seven hosting regions and AWS are disclosed. A sub-processor list was not found (10).
Negative events≤15None recorded0
Total59.1 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 17 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Prismatic, or have the agent fetch /fixes/prismatic.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Prismatic

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/prismatic, the October 2026 research run, assessed 9 October 2026. Grade C, 59.1 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Prismatic: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 0 out of 100, up to 12.5 more on the total

Why it scored 0: No x402, MPP or L402 (0). The pricing page names three plans and gives no price. Each ends in a demo request (0). A free trial exists, 30 days per the Terms of Use, but the signup form is drawn by script and we could not confirm that it needs no card, so the line is scored absent (0). A person signs up and logs in through a browser before any token exists (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 59 out of 100, up to 7.2 more on the total

Why it scored 59: The API takes a user's JWT from an OAuth login. Access tokens last 7 days and refresh tokens can be revoked, though revoking one revokes all of that user's. Tokens have no scopes and act with the user's role (20). Seven roles include a read-only guest, a restricted integrator who cannot see logs or step results, and a third-party role limited to named objects. No confirmation step before destructive mutations was found (13). Agentic flows return third-party content and no prompt-injection guidance was found (3). Execution logs, step results and log streaming to Datadog, New Relic or Google Cloud. No audit log of API calls was found (8). Valid security.txt with a PGP key, a disclosure address, and SOC 2 Type 2 per the security policy. No bug bounty found, and the trust centre is drawn by script and was not read (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Reliability, 67 out of 100, up to 6.6 more on the total

Why it scored 67: Graded as a hosted service, on the GraphQL API and the hosted MCP flow server. Atlassian Statuspage at www.prismatic-status.io with five components and 90-day uptime bars (20). Four incidents in the last 90 days, all short or partial. Intermittent OAuth token refresh failures in eu-west-1 for 3 hours 16 minutes on 17 August 2026, raised error rates in us-west-2 for about 70 minutes on 16 September, the web app unavailable in all regions for 21 minutes on 22 September, and workflow editing in the embedded builder down for 33 minutes on 30 September (20). Execution limits are published with numbers (15 minutes, 1 GB, 6 MB webhook payload, 30 seconds synchronous), but concurrency depends on the plan with no number and no API request rate was found (5). A request over the concurrency limit gets a 429, flow concurrency queues requests and failed executions can retry automatically. No `Retry-After` or backoff guidance for the API was found (7). The pricing page lists standard SLAs on Scale and Enterprise and custom SLAs above, with no SLA text published (5). The API, CLI and MCP flow server are generally available (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 4. Agent ergonomics, 63 out of 100, up to 6 more on the total

Why it scored 63: GraphQL field selection lets a caller size each response, and `first` caps the page. The local MCP dev server has 19 tools in two optional toolsets (22). Relay cursors with a default of 100, `sortBy` and per-query filters (20). Mutations return an `errors` array of field and message under HTTP 200, with no codes (10). No idempotency keys were found, and the MCP dev server's tools carry no `readOnlyHint` or `destructiveHint`. Customer `externalId` values must be unique, which stops one kind of duplicate (3). A CLI and two TypeScript SDKs, no API client in a second language (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 5. Schema & documentation, 75 out of 100, up to 4.1 more on the total

Why it scored 75: The contract is a GraphQL schema with 120 queries and 124 mutations in the reference and a GraphiQL explorer. No downloadable schema file or OpenAPI document was found (22). `llms.txt` and a Markdown twin of every docs page (10). Each operation and field has a one-line description, with no guidance on when to use one over another (11). Arguments are typed, with required markers, enums and input objects (13). The docs carry worked queries in curl, Node.js and Python and document the mutation `errors` array, with no list of error codes (9). The changelog is public and dated. The API has no version, and deprecated arguments are marked in the schema (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 65 out of 100, up to 3.1 more on the total

Made of editorial 40, provenance 89.

Why it scored 65: Closed platform. The public Terms of Use cover the website and trials and say paid use runs under a separate agreement, which is not published. The CLI, SDKs and MCP dev server are MIT (12). The Privacy Policy covers the web application and names Mixpanel and Auth0, but gives no retention period beyond as long as needed. The Terms say trial data is not kept after a trial, and the changelog gives 14 days of execution retention. No DPA or sub-processor list was found on the pages read (12). Deprecated arguments are marked in the schema and Spectral has upgrade guides for each major version. No deprecation policy with notice periods was found (6). Seven hosting regions and AWS are disclosed. A sub-processor list was not found (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: not found (0 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)

## 7. Maintenance & community, 83 out of 100, up to 1.5 more on the total

Why it scored 83: The Spectral SDK released v10.34.1 on 6 October 2026 and the changelog's newest entry is 1 October 2026 (30). Ten changelog entries between 20 August and 1 October 2026, and Prism CLI releases on 14, 15 and 30 September (20). A dated changelog with monthly newsletters and a support address. The CLI and MCP repositories each show two open issues (10). Current official CLI, Spectral and embedded SDKs, and the MCP dev server's `server.json` names `io.github.prismatic-io/prism-mcp`. We did not confirm the registry entry itself (15). Build, test and release workflows in each repository and dependency updates through October 2026. We did not see the workflow results (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: whether the free trial needs a card. The signup form at https://prismatic.io/free-trial/ is drawn by script
- unchecked: the trust centre at https://www.trust-prismatic.io, a Vanta page drawn by script, so any sub-processor list, DPA or further certification there is unread
- unchecked: GitHub security advisories for the CLI, SDKs and MCP dev server, and whether CI passes on the default branches
- unchecked: whether `io.github.prismatic-io/prism-mcp` is live in the official MCP registry
- The agreement that governs paid use is not published, so `provenance.terms` is left out
- No API rate limit, SLA text or deprecation policy was found in the reviewed documentation
- Whether a GraphQL schema file can be downloaded without an account
- The lead named the Prism MCP dev server only. Prismatic also runs a hosted MCP flow server, which the listing records

## Weaknesses

- No prices on the pricing page. All three plans end in a demo request
- Paid use is governed by a separate agreement that is not published. The public terms cover the website and 30-day trials
- No API rate limit, `Retry-After` behaviour or idempotency key found in the reviewed documentation
- API tokens carry the whole role of the user who created them, and revoking one refresh token revokes all of that user's
- Mutation failures return HTTP 200 with an `errors` array of field and message, with no error codes

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Have a person run `prism login` once, then store the output of `prism me:token --type refresh` as `PRISM_REFRESH_TOKEN`. Access tokens last 7 days
- Read the `errors` array on every mutation. A failed mutation still returns HTTP 200
- Pass `sortBy` with `CREATED_AT` when paging. Without a sort order pages can repeat or skip records
- Use the regional host for the tenant, such as `app.eu-west-1.prismatic.io` and `mcp.eu-west-1.prismatic.io`
- Create a guest user for a read-only agent, because tokens have no scopes of their own

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: whether the free trial needs a card. The signup form at https://prismatic.io/free-trial/ is drawn by script
  • unchecked: the trust centre at https://www.trust-prismatic.io, a Vanta page drawn by script, so any sub-processor list, DPA or further certification there is unread
  • unchecked: GitHub security advisories for the CLI, SDKs and MCP dev server, and whether CI passes on the default branches
  • unchecked: whether io.github.prismatic-io/prism-mcp is live in the official MCP registry
  • The agreement that governs paid use is not published, so provenance.terms is left out
  • No API rate limit, SLA text or deprecation policy was found in the reviewed documentation
  • Whether a GraphQL schema file can be downloaded without an account
  • The lead named the Prism MCP dev server only. Prismatic also runs a hosted MCP flow server, which the listing records

Sources 28

  1. docs index for agents prismatic.io · seen 2026-10-09
  2. API authentication prismatic.io · seen 2026-10-09
  3. refresh tokens and revocation prismatic.io · seen 2026-10-09
  4. pagination prismatic.io · seen 2026-10-09
  5. queries, mutations and errors prismatic.io · seen 2026-10-09
  6. query reference prismatic.io · seen 2026-10-09
  7. mutation reference prismatic.io · seen 2026-10-09
  8. MCP flow server endpoints prismatic.io · seen 2026-10-09
  9. MCP client setup and OAuth prismatic.io · seen 2026-10-09
  10. Prism MCP dev server docs prismatic.io · seen 2026-10-09
  11. MCP dev server source, tags and server.json github.com · seen 2026-10-09
  12. Prism CLI source and tags github.com · seen 2026-10-09
  13. Spectral SDK tags github.com · seen 2026-10-09
  14. runner environment and limits prismatic.io · seen 2026-10-09
  15. usage limits prismatic.io · seen 2026-10-09
  16. deployment regions prismatic.io · seen 2026-10-09
  17. organisation user roles prismatic.io · seen 2026-10-09
  18. embedded user JWTs prismatic.io · seen 2026-10-09
  19. changelog prismatic.io · seen 2026-10-09
  20. pricing prismatic.io · seen 2026-10-09
  21. Terms of Use prismatic.io · seen 2026-10-09
  22. Acceptable Use Policy prismatic.io · seen 2026-10-09
  23. Privacy Policy prismatic.io · seen 2026-10-09
  24. Security Policy prismatic.io · seen 2026-10-09
  25. security.txt prismatic.io · seen 2026-10-09
  26. status page prismatic-status.io · seen 2026-10-09
  27. status history feed prismatic-status.io · seen 2026-10-09
  28. robots.txt with Content-Signal ai-input=yes prismatic.io · seen 2026-10-09

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid Paid No public prices. The pricing page lists Scale, Enterprise and Custom plans with volume per-instance pricing, each ending in a demo request. A free trial exists, and the Terms of Use set it at 30 days unless stated otherwise at signup. Whether the trial needs a card could not be read because the signup form is drawn by script. Contracts set fair use limits in gigabyte-seconds of compute per instance per month (checked 2026-10-09).

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/prismatic.xml, or this listing's score history at history.json.

Connect

Install

npm install --global @prismatic-io/prism

First request

curl https://app.prismatic.io/api --request POST --header "Authorization: Bearer ${PRISMATIC_API_TOKEN}" --header "Content-Type: application/json" --data '{"query": "query { integrations { nodes { id name }}}"}'

Claude Code

claude mcp add-json prismatic '{"type":"stdio","command":"npx","args":["-y","mcp-remote","https://mcp.prismatic.io/mcp"]}'

MCP client configuration

{
  "mcpServers": {
    "prism": {
      "args": [
        "-y",
        "@prismatic-io/prism-mcp",
        "."
      ],
      "command": "npx",
      "env": {
        "PRISMATIC_URL": "https://app.prismatic.io"
      },
      "type": "stdio"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/prismatic

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Pipedream API + MCP Pipedream (Workday)B65.5automation.workflows automation.apps automation.embedded automation.code automation.webhooks automation.auth agent.toolsno
Workato API + MCP WorkatoC58automation.workflows automation.apps automation.embedded automation.code automation.webhooks automation.auth agent.toolsno
Tray.ai API + MCP Tray.aiC55.5automation.workflows automation.apps automation.embedded automation.code automation.webhooks automation.auth agent.toolsno
Activepieces API + MCP ActivepiecesC57.5automation.workflows automation.apps automation.embedded automation.code automation.webhooks agent.toolsno
Paragon ActionKit + MCP ParagonD47.5automation.embedded automation.workflows automation.apps automation.auth automation.webhooks agent.toolsno
Kestra Kestra TechnologiesB63.6automation.workflows automation.code automation.webhooks automation.apps agent.toolsno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Prismatic on Anchor Terminal, C, 59.1/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/prismatic"><img src="https://www.anchorterminal.com/badges/prismatic.svg" alt="Prismatic on Anchor Terminal" height="20"></a>
    [![Prismatic on Anchor Terminal](https://www.anchorterminal.com/badges/prismatic.svg)](https://www.anchorterminal.com/tools/prismatic)

    It counts on a page on prismatic.io or one of its subdomains, or the README of github.com/prismatic-io/prism.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "prismatic", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.