{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/pipedream.json",
        "name": "Pipedream API + MCP",
        "score": 65.5,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.embedded",
          "automation.code",
          "automation.webhooks",
          "automation.auth",
          "agent.tools"
        ],
        "slug": "pipedream"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/workato.json",
        "name": "Workato API + MCP",
        "score": 58,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.embedded",
          "automation.code",
          "automation.webhooks",
          "automation.auth",
          "agent.tools"
        ],
        "slug": "workato"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/tray.json",
        "name": "Tray.ai API + MCP",
        "score": 55.5,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.embedded",
          "automation.code",
          "automation.webhooks",
          "automation.auth",
          "agent.tools"
        ],
        "slug": "tray"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/activepieces.json",
        "name": "Activepieces API + MCP",
        "score": 57.5,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.embedded",
          "automation.code",
          "automation.webhooks",
          "agent.tools"
        ],
        "slug": "activepieces"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/paragon.json",
        "name": "Paragon ActionKit + MCP",
        "score": 47.5,
        "shared": [
          "automation.embedded",
          "automation.workflows",
          "automation.apps",
          "automation.auth",
          "automation.webhooks",
          "agent.tools"
        ],
        "slug": "paragon"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/kestra.json",
        "name": "Kestra",
        "score": 63.6,
        "shared": [
          "automation.workflows",
          "automation.code",
          "automation.webhooks",
          "automation.apps",
          "agent.tools"
        ],
        "slug": "kestra"
      }
    ],
    "tool": {
      "slug": "prismatic",
      "name": "Prismatic",
      "vendor": "Prismatic Software Inc.",
      "vendorUrl": "https://prismatic.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Prismatic is an embedded integration platform for B2B software companies. Teams build integrations in a low-code designer or in TypeScript, deploy them to customers, and manage them through a GraphQL API, the Prism CLI and MCP servers.",
      "url": "https://www.anchorterminal.com/tools/prismatic",
      "markdownUrl": "https://www.anchorterminal.com/tools/prismatic.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/prismatic.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/prismatic.json",
      "repo": "https://github.com/prismatic-io/prism",
      "license": "Proprietary service. The Prism CLI, the Spectral and embedded SDKs, the Prism MCP dev server and the Claude Code skills on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.prismatic.io/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@prismatic-io/prism"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/prism-mcp"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/spectral"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/embedded"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a person creating an account, by free trial or contract, and logging in through the browser (`prism login`). The API takes that user's JWT as a Bearer token. `prism me:token --type refresh` prints a refresh token for headless use, exchanged at `/auth/refresh` for an access token valid for 7 days. Tokens have no scopes of their own and act with the user's role. The hosted MCP flow server uses MCP OAuth or the same Bearer token, and embedded end users get a JWT signed by the customer's backend.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page lists Scale, Enterprise and Custom plans with volume per-instance pricing, each ending in a demo request. A free trial exists, and the Terms of Use set it at 30 days unless stated otherwise at signup. Whether the trial needs a card could not be read because the signup form is drawn by script. Contracts set fair use limits in gigabyte-seconds of compute per instance per month (checked 2026-10-09).",
      "priceSummary": "Paid",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the API docs or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29,
        "npmWeekly": 8416,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://prismatic.io/docs/api/",
      "llmsTxt": "https://prismatic.io/docs/llms.txt",
      "registryName": "io.github.prismatic-io/prism-mcp",
      "capabilities": [
        "automation.workflows",
        "automation.embedded",
        "automation.apps",
        "automation.code",
        "automation.webhooks",
        "automation.auth",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "graphql",
        "mcp",
        "cli",
        "oauth",
        "llms-txt",
        "typescript",
        "sales-led",
        "status-page",
        "soc2",
        "webhooks",
        "closed-source"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.1,
        "grade": "C",
        "agentReady": false,
        "rank": 561,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 83,
          "payments": 0,
          "reliability": 67,
          "schema": 75,
          "security": 59,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 67,
            "points": 13.4,
            "reason": "Graded as a hosted service, on the GraphQL API and the hosted MCP flow server. Atlassian Statuspage at www.prismatic-status.io with five components and 90-day uptime bars (20). Four incidents in the last 90 days, all short or partial. Intermittent OAuth token refresh failures in eu-west-1 for 3 hours 16 minutes on 17 August 2026, raised error rates in us-west-2 for about 70 minutes on 16 September, the web app unavailable in all regions for 21 minutes on 22 September, and workflow editing in the embedded builder down for 33 minutes on 30 September (20). Execution limits are published with numbers (15 minutes, 1 GB, 6 MB webhook payload, 30 seconds synchronous), but concurrency depends on the plan with no number and no API request rate was found (5). A request over the concurrency limit gets a 429, flow concurrency queues requests and failed executions can retry automatically. No `Retry-After` or backoff guidance for the API was found (7). The pricing page lists standard SLAs on Scale and Enterprise and custom SLAs above, with no SLA text published (5). The API, CLI and MCP flow server are generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 75,
            "points": 12.19,
            "reason": "The contract is a GraphQL schema with 120 queries and 124 mutations in the reference and a GraphiQL explorer. No downloadable schema file or OpenAPI document was found (22). `llms.txt` and a Markdown twin of every docs page (10). Each operation and field has a one-line description, with no guidance on when to use one over another (11). Arguments are typed, with required markers, enums and input objects (13). The docs carry worked queries in curl, Node.js and Python and document the mutation `errors` array, with no list of error codes (9). The changelog is public and dated. The API has no version, and deprecated arguments are marked in the schema (10)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 63,
            "points": 10.24,
            "reason": "GraphQL field selection lets a caller size each response, and `first` caps the page. The local MCP dev server has 19 tools in two optional toolsets (22). Relay cursors with a default of 100, `sortBy` and per-query filters (20). Mutations return an `errors` array of field and message under HTTP 200, with no codes (10). No idempotency keys were found, and the MCP dev server's tools carry no `readOnlyHint` or `destructiveHint`. Customer `externalId` values must be unique, which stops one kind of duplicate (3). A CLI and two TypeScript SDKs, no API client in a second language (8)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 59,
            "points": 10.33,
            "reason": "The API takes a user's JWT from an OAuth login. Access tokens last 7 days and refresh tokens can be revoked, though revoking one revokes all of that user's. Tokens have no scopes and act with the user's role (20). Seven roles include a read-only guest, a restricted integrator who cannot see logs or step results, and a third-party role limited to named objects. No confirmation step before destructive mutations was found (13). Agentic flows return third-party content and no prompt-injection guidance was found (3). Execution logs, step results and log streaming to Datadog, New Relic or Google Cloud. No audit log of API calls was found (8). Valid security.txt with a PGP key, a disclosure address, and SOC 2 Type 2 per the security policy. No bug bounty found, and the trust centre is drawn by script and was not read (15)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 0,
            "points": 0,
            "reason": "No x402, MPP or L402 (0). The pricing page names three plans and gives no price. Each ends in a demo request (0). A free trial exists, 30 days per the Terms of Use, but the signup form is drawn by script and we could not confirm that it needs no card, so the line is scored absent (0). A person signs up and logs in through a browser before any token exists (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 83,
            "points": 7.26,
            "reason": "The Spectral SDK released v10.34.1 on 6 October 2026 and the changelog's newest entry is 1 October 2026 (30). Ten changelog entries between 20 August and 1 October 2026, and Prism CLI releases on 14, 15 and 30 September (20). A dated changelog with monthly newsletters and a support address. The CLI and MCP repositories each show two open issues (10). Current official CLI, Spectral and embedded SDKs, and the MCP dev server's `server.json` names `io.github.prismatic-io/prism-mcp`. We did not confirm the registry entry itself (15). Build, test and release workflows in each repository and dependency updates through October 2026. We did not see the workflow results (8)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 65,
            "points": 5.69,
            "note": "editorial 40, provenance 89",
            "reason": "Closed platform. The public Terms of Use cover the website and trials and say paid use runs under a separate agreement, which is not published. The CLI, SDKs and MCP dev server are MIT (12). The Privacy Policy covers the web application and names Mixpanel and Auth0, but gives no retention period beyond as long as needed. The Terms say trial data is not kept after a trial, and the changelog gives 14 days of execution retention. No DPA or sub-processor list was found on the pages read (12). Deprecated arguments are marked in the schema and Spectral has upgrade guides for each major version. No deprecation policy with notice periods was found (6). Seven hosting regions and AWS are disclosed. A sub-processor list was not found (10)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "GraphQL field selection lets a caller size each response, and `first` caps the page. The local MCP dev server has 19 tools in two optional toolsets (22). Relay cursors with a default of 100, `sortBy` and per-query filters (20). Mutations return an `errors` array of field and message under HTTP 200, with no codes (10). No idempotency keys were found, and the MCP dev server's tools carry no `readOnlyHint` or `destructiveHint`. Customer `externalId` values must be unique, which stops one kind of duplicate (3). A CLI and two TypeScript SDKs, no API client in a second language (8).",
            "maintenance": "The Spectral SDK released v10.34.1 on 6 October 2026 and the changelog's newest entry is 1 October 2026 (30). Ten changelog entries between 20 August and 1 October 2026, and Prism CLI releases on 14, 15 and 30 September (20). A dated changelog with monthly newsletters and a support address. The CLI and MCP repositories each show two open issues (10). Current official CLI, Spectral and embedded SDKs, and the MCP dev server's `server.json` names `io.github.prismatic-io/prism-mcp`. We did not confirm the registry entry itself (15). Build, test and release workflows in each repository and dependency updates through October 2026. We did not see the workflow results (8).",
            "payments": "No x402, MPP or L402 (0). The pricing page names three plans and gives no price. Each ends in a demo request (0). A free trial exists, 30 days per the Terms of Use, but the signup form is drawn by script and we could not confirm that it needs no card, so the line is scored absent (0). A person signs up and logs in through a browser before any token exists (0).",
            "reliability": "Graded as a hosted service, on the GraphQL API and the hosted MCP flow server. Atlassian Statuspage at www.prismatic-status.io with five components and 90-day uptime bars (20). Four incidents in the last 90 days, all short or partial. Intermittent OAuth token refresh failures in eu-west-1 for 3 hours 16 minutes on 17 August 2026, raised error rates in us-west-2 for about 70 minutes on 16 September, the web app unavailable in all regions for 21 minutes on 22 September, and workflow editing in the embedded builder down for 33 minutes on 30 September (20). Execution limits are published with numbers (15 minutes, 1 GB, 6 MB webhook payload, 30 seconds synchronous), but concurrency depends on the plan with no number and no API request rate was found (5). A request over the concurrency limit gets a 429, flow concurrency queues requests and failed executions can retry automatically. No `Retry-After` or backoff guidance for the API was found (7). The pricing page lists standard SLAs on Scale and Enterprise and custom SLAs above, with no SLA text published (5). The API, CLI and MCP flow server are generally available (10).",
            "schema": "The contract is a GraphQL schema with 120 queries and 124 mutations in the reference and a GraphiQL explorer. No downloadable schema file or OpenAPI document was found (22). `llms.txt` and a Markdown twin of every docs page (10). Each operation and field has a one-line description, with no guidance on when to use one over another (11). Arguments are typed, with required markers, enums and input objects (13). The docs carry worked queries in curl, Node.js and Python and document the mutation `errors` array, with no list of error codes (9). The changelog is public and dated. The API has no version, and deprecated arguments are marked in the schema (10).",
            "security": "The API takes a user's JWT from an OAuth login. Access tokens last 7 days and refresh tokens can be revoked, though revoking one revokes all of that user's. Tokens have no scopes and act with the user's role (20). Seven roles include a read-only guest, a restricted integrator who cannot see logs or step results, and a third-party role limited to named objects. No confirmation step before destructive mutations was found (13). Agentic flows return third-party content and no prompt-injection guidance was found (3). Execution logs, step results and log streaming to Datadog, New Relic or Google Cloud. No audit log of API calls was found (8). Valid security.txt with a PGP key, a disclosure address, and SOC 2 Type 2 per the security policy. No bug bounty found, and the trust centre is drawn by script and was not read (15).",
            "transparency": "Closed platform. The public Terms of Use cover the website and trials and say paid use runs under a separate agreement, which is not published. The CLI, SDKs and MCP dev server are MIT (12). The Privacy Policy covers the web application and names Mixpanel and Auth0, but gives no retention period beyond as long as needed. The Terms say trial data is not kept after a trial, and the changelog gives 14 days of execution retention. No DPA or sub-processor list was found on the pages read (12). Deprecated arguments are marked in the schema and Spectral has upgrade guides for each major version. No deprecation policy with notice periods was found (6). Seven hosting regions and AWS are disclosed. A sub-processor list was not found (10)."
          },
          "sources": [
            {
              "what": "docs index for agents",
              "url": "https://prismatic.io/docs/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "API authentication",
              "url": "https://prismatic.io/docs/api/authentication.md",
              "seen": "2026-10-09"
            },
            {
              "what": "refresh tokens and revocation",
              "url": "https://prismatic.io/docs/api/ci-cd-system.md",
              "seen": "2026-10-09"
            },
            {
              "what": "pagination",
              "url": "https://prismatic.io/docs/api/pagination.md",
              "seen": "2026-10-09"
            },
            {
              "what": "queries, mutations and errors",
              "url": "https://prismatic.io/docs/api/queries-and-mutations.md",
              "seen": "2026-10-09"
            },
            {
              "what": "query reference",
              "url": "https://prismatic.io/docs/api/schema/queries.md",
              "seen": "2026-10-09"
            },
            {
              "what": "mutation reference",
              "url": "https://prismatic.io/docs/api/schema/mutations.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP flow server endpoints",
              "url": "https://prismatic.io/docs/ai/mcp-endpoints.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP client setup and OAuth",
              "url": "https://prismatic.io/docs/ai/test-mcp-clients.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Prism MCP dev server docs",
              "url": "https://prismatic.io/docs/dev-tools/prism-mcp.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP dev server source, tags and server.json",
              "url": "https://github.com/prismatic-io/prism-mcp",
              "seen": "2026-10-09"
            },
            {
              "what": "Prism CLI source and tags",
              "url": "https://github.com/prismatic-io/prism",
              "seen": "2026-10-09"
            },
            {
              "what": "Spectral SDK tags",
              "url": "https://github.com/prismatic-io/spectral",
              "seen": "2026-10-09"
            },
            {
              "what": "runner environment and limits",
              "url": "https://prismatic.io/docs/integrations/integration-runner-environment-limits.md",
              "seen": "2026-10-09"
            },
            {
              "what": "usage limits",
              "url": "https://prismatic.io/docs/integrations/usage-limits.md",
              "seen": "2026-10-09"
            },
            {
              "what": "deployment regions",
              "url": "https://prismatic.io/docs/configure-prismatic/deployment-regions.md",
              "seen": "2026-10-09"
            },
            {
              "what": "organisation user roles",
              "url": "https://prismatic.io/docs/configure-prismatic/organization-users.md",
              "seen": "2026-10-09"
            },
            {
              "what": "embedded user JWTs",
              "url": "https://prismatic.io/docs/get-started/embedded-marketplace/authenticate-embedded-users.md",
              "seen": "2026-10-09"
            },
            {
              "what": "changelog",
              "url": "https://prismatic.io/docs/changelog/",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing",
              "url": "https://prismatic.io/pricing/",
              "seen": "2026-10-09"
            },
            {
              "what": "Terms of Use",
              "url": "https://prismatic.io/legal/terms/",
              "seen": "2026-10-09"
            },
            {
              "what": "Acceptable Use Policy",
              "url": "https://prismatic.io/legal/acceptable-use/",
              "seen": "2026-10-09"
            },
            {
              "what": "Privacy Policy",
              "url": "https://prismatic.io/legal/privacy/",
              "seen": "2026-10-09"
            },
            {
              "what": "Security Policy",
              "url": "https://prismatic.io/legal/security/",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt",
              "url": "https://prismatic.io/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "status page",
              "url": "https://www.prismatic-status.io/",
              "seen": "2026-10-09"
            },
            {
              "what": "status history feed",
              "url": "https://www.prismatic-status.io/history.rss",
              "seen": "2026-10-09"
            },
            {
              "what": "robots.txt with Content-Signal ai-input=yes",
              "url": "https://prismatic.io/robots.txt",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: whether the free trial needs a card. The signup form at https://prismatic.io/free-trial/ is drawn by script",
            "unchecked: the trust centre at https://www.trust-prismatic.io, a Vanta page drawn by script, so any sub-processor list, DPA or further certification there is unread",
            "unchecked: GitHub security advisories for the CLI, SDKs and MCP dev server, and whether CI passes on the default branches",
            "unchecked: whether `io.github.prismatic-io/prism-mcp` is live in the official MCP registry",
            "The agreement that governs paid use is not published, so `provenance.terms` is left out",
            "No API rate limit, SLA text or deprecation policy was found in the reviewed documentation",
            "Whether a GraphQL schema file can be downloaded without an account",
            "The lead named the Prism MCP dev server only. Prismatic also runs a hosted MCP flow server, which the listing records"
          ]
        },
        "negative": 0,
        "verdict": "The GraphQL API covers 120 queries and 124 mutations with typed inputs, cursor pagination and Markdown documentation, and tokens follow seven user roles. No price is published, paid use runs under an agreement that is not public, and no API rate limit or idempotency key was found in the reviewed documentation.",
        "bestFor": "A B2B software company that wants to build integrations once, deploy them per customer and let an in-app agent call them as MCP tools.",
        "strengths": [
          "GraphQL API with 120 documented queries and 124 mutations, field selection, cursor pagination and per-query filters",
          "Every docs page has a Markdown twin, indexed by `llms.txt` at prismatic.io/docs/llms.txt",
          "Hosted MCP flow server in seven regions, with OAuth 2.0 and endpoints scoped to one integration or one instance",
          "Seven organisation roles, including a read-only guest and a third-party role limited to named integrations, components or customers",
          "Dated changelog with ten entries from 20 August to 1 October 2026, and CLI and SDK releases in the same weeks"
        ],
        "weaknesses": [
          "No prices on the pricing page. All three plans end in a demo request",
          "Paid use is governed by a separate agreement that is not published. The public terms cover the website and 30-day trials",
          "No API rate limit, `Retry-After` behaviour or idempotency key found in the reviewed documentation",
          "API tokens carry the whole role of the user who created them, and revoking one refresh token revokes all of that user's",
          "Mutation failures return HTTP 200 with an `errors` array of field and message, with no error codes"
        ],
        "agentNotes": [
          "Have a person run `prism login` once, then store the output of `prism me:token --type refresh` as `PRISM_REFRESH_TOKEN`. Access tokens last 7 days",
          "Read the `errors` array on every mutation. A failed mutation still returns HTTP 200",
          "Pass `sortBy` with `CREATED_AT` when paging. Without a sort order pages can repeat or skip records",
          "Use the regional host for the tenant, such as `app.eu-west-1.prismatic.io` and `mcp.eu-west-1.prismatic.io`",
          "Create a guest user for a read-only agent, because tokens have no scopes of their own"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.1
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 83,
          "payments": 0,
          "reliability": 67,
          "schema": 75,
          "security": 59,
          "transparency": 40
        },
        "provenanceScore": 89
      },
      "connect": {
        "install": "npm install --global @prismatic-io/prism",
        "http": "curl https://app.prismatic.io/api --request POST --header \"Authorization: Bearer ${PRISMATIC_API_TOKEN}\" --header \"Content-Type: application/json\" --data '{\"query\": \"query { integrations { nodes { id name }}}\"}'",
        "claudeCode": "claude mcp add-json prismatic '{\"type\":\"stdio\",\"command\":\"npx\",\"args\":[\"-y\",\"mcp-remote\",\"https://mcp.prismatic.io/mcp\"]}'",
        "config": {
          "mcpServers": {
            "prism": {
              "args": [
                "-y",
                "@prismatic-io/prism-mcp",
                "."
              ],
              "command": "npx",
              "env": {
                "PRISMATIC_URL": "https://app.prismatic.io"
              },
              "type": "stdio"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/prismatic"
      },
      "notable": [
        "The GraphQL API answers at https://app.prismatic.io/api with a Bearer JWT. Refresh tokens are exchanged at `/auth/refresh` for access tokens valid for 7 days (https://prismatic.io/docs/api/authentication.md)",
        "The hosted MCP flow server turns flows marked as agentic into MCP tools, over Streamable HTTP with MCP OAuth, at `mcp.prismatic.io/mcp` and six regional hosts (https://prismatic.io/docs/ai/mcp-endpoints.md)",
        "The Prism MCP dev server is a separate local stdio server that wraps the Prism CLI, with 19 tools in two optional toolsets, MIT (https://github.com/prismatic-io/prism-mcp)",
        "Usage is measured in gigabyte-seconds of compute per instance per month against fair use limits set in the contract, and the pricing page says plans are never billed on API calls or executions (https://prismatic.io/docs/integrations/usage-limits.md)",
        "An execution runs for at most 15 minutes with 1 GB of memory by default, and a request over the plan's concurrency limit gets a 429 (https://prismatic.io/docs/integrations/integration-runner-environment-limits.md)",
        "The status page lists four incidents between 17 August and 30 September 2026, the longest 3 hours 16 minutes of intermittent OAuth token refresh failures in eu-west-1 (https://www.prismatic-status.io/history)",
        "The Acceptable Use Policy bars probing, scanning or testing the vulnerability of any system, and access by any means other than the publicly supported interfaces (https://prismatic.io/legal/acceptable-use/)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surfaces",
          "value": "GraphQL API at https://app.prismatic.io/api, Prism CLI (`@prismatic-io/prism` 10.5.0), hosted MCP flow server, local Prism MCP dev server (`@prismatic-io/prism-mcp` 1.5.0), embedded SDK (`@prismatic-io/embedded` 4.14.0), Spectral TypeScript SDK (10.34.1)"
        },
        {
          "label": "API",
          "value": "GraphQL, 120 queries and 124 mutations in the schema reference, with a GraphiQL explorer in the docs. No REST API and no OpenAPI file"
        },
        {
          "label": "Credentials",
          "value": "User JWT from an OAuth login. Access tokens last 7 days, refresh tokens are revocable at `/auth/revoke`, and embedded users get a JWT the customer's backend signs with a key created by an owner or admin"
        },
        {
          "label": "Roles",
          "value": "Owner, admin, integrator, restricted integrator, guest (read-only), customer manager and third-party (per-object permissions)"
        },
        {
          "label": "MCP flow server",
          "value": "Hosted, Streamable HTTP, MCP OAuth or a Bearer token. Global, integration-scoped and instance-scoped endpoints. Tools are the agentic flows the customer has built, plus a default `get-me` tool"
        },
        {
          "label": "MCP dev server",
          "value": "Local stdio, 19 tools, toolsets `integration` and `component`, reads the CLI's saved credentials. No `readOnlyHint` or `destructiveHint` annotations in the source"
        },
        {
          "label": "Pagination",
          "value": "Relay cursors, 100 results by default, `first`, `after`, `sortBy` and per-query filters such as `name_Icontains`"
        },
        {
          "label": "Limits",
          "value": "15 minutes an execution, 1 GB memory by default and up to 10 GB, 6 MB webhook payload, 30 seconds for a synchronous webhook, 500 MB step result. Concurrency depends on the plan, with no published number"
        },
        {
          "label": "Regions",
          "value": "US Commercial (Ohio), US GovCloud, Ireland, London, Canada, Sydney and Cape Town, plus private deployment in the customer's AWS account"
        },
        {
          "label": "Plans",
          "value": "Scale, Enterprise and Custom, all by demo. Volume per-instance pricing. Free trial of 30 days per the Terms of Use"
        },
        {
          "label": "Status",
          "value": "Atlassian Statuspage at www.prismatic-status.io with five components (GraphQL API, Web App, Integration Runner, OAuth 2.0 Refresh, Embedded)"
        },
        {
          "label": "Security",
          "value": "SOC 2 Type 2 per the security policy, AES-256 for stored third-party credentials, TLS 1.2 or later, AWS hosting, Auth0 for user login. Valid security.txt with a PGP key"
        },
        {
          "label": "Open source",
          "value": "The CLI, both SDKs, the MCP dev server and the Claude Code skills are MIT on GitHub. The platform is closed"
        }
      ],
      "provenance": {
        "legalEntity": "Prismatic Software Inc.",
        "domain": "prismatic.io",
        "domainRegistered": "2016-07-09",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://prismatic.io/legal/privacy/",
        "statusPage": "https://www.prismatic-status.io",
        "changelog": "https://prismatic.io/docs/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Use (last updated 17 March 2023) name Prismatic Software Inc., 5013 S Louise Ave #122, Sioux Falls, SD 57108, and are governed by South Dakota law.",
          "No terms link is recorded. The Terms of Use at https://prismatic.io/legal/terms/ are website terms that also cover trial accounts, and they say non-trial use of the Services is subject to a separate agreement, which is not published.",
          "The Privacy Policy (last updated 26 June 2024) covers the website and the web application at app.prismatic.io.",
          "security.txt at https://prismatic.io/.well-known/security.txt names security@prismatic.io and a PGP key and expires on 16 June 2027.",
          "The API, the regional hosts and the MCP flow server are all on prismatic.io subdomains. The status page is on prismatic-status.io and the trust centre on trust-prismatic.io.",
          "RDAP for prismatic.io gives a registration date of 2016-07-09."
        ],
        "score": 89,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Prismatic Software Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "prismatic.io, registered 2016-07-09 (10 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "mcp.prismatic.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "www.prismatic-status.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "",
            "state": "none-found",
            "points": 0,
            "max": 10
          },
          {
            "kind": "privacy",
            "url": "https://prismatic.io/legal/privacy/",
            "state": "read",
            "readAt": "2026-10-09",
            "statedDate": "2024-06-26",
            "words": 4865,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: June 26, 2024",
                "says": "Last updated 2024-06-26"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy covers the information that we collect about you when you (\"Visitor\", \"Customer\", \"User\") use our website (\"Website\"), https://prismatic.io, or web application (\"Platform\"), https://app.prismatic.io, and our related online and offline offerings and software (collectively, the \"Services\")."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We will retain your personal or business information in a form that identifies you only for as long as it serves the purpose(s) for which it was originally intended as stated by this Privacy Policy, as allowed or required under applicable law, or subsequently authorized."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Technical information – details of the third-party services you will connect to via the Services, including your credentials for such third-party service provider applications."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Right to rectify your personal information: if you discover that the information, we hold about you is inaccurate or incomplete, you have the right to have this information rectified (i.e., corrected)."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "In addition to the above, you may contact us using the details provided at the end of this Policy with any questions about the choices relating to your personal information."
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "For example, if the recipient country has not received an Adequacy Decision from the European Commission (such as the United States), we will rely on Standard Contractual Clauses (SCC) that have been approved by the European Commission as the lawful mechanisms for such transfers.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We may share information about your use of our Services with our advertising and analytics partners, who may combine it with other information that you previously provided to them."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Prismatic or its service providers may send marketing to email or home addresses that its data partners associate with a website visit or login.",
                "quote": "We (or service providers on our behalf) may then send communications and marketing to these email or home addresses."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/prismatic.json",
      "live": {
        "slug": "prismatic",
        "probe": {
          "target": "https://mcp.prismatic.io/mcp",
          "method": "get",
          "lastAt": "2026-10-10T02:07:21.289248186Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 301,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 300,
          "p95ms24h": 389,
          "samples24h": 107,
          "samples30d": 107,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.prismatic-status.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:06:24.908783132Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "prismatic-io/prism",
            "version": "v10.5.0",
            "released": "2026-09-30",
            "seenAt": "2026-10-09T17:14:48.08709817Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/embedded",
            "version": "4.14.0",
            "seenAt": "2026-10-09T17:14:46.07500175Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/prism",
            "version": "10.5.0",
            "seenAt": "2026-10-09T17:14:41.869797583Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/prism-mcp",
            "version": "1.5.0",
            "seenAt": "2026-10-09T17:14:42.93328997Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/spectral",
            "version": "10.34.1",
            "seenAt": "2026-10-09T17:14:44.108249111Z"
          }
        ],
        "githubStars": 29,
        "npmWeekly": 8416,
        "pages": [
          {
            "url": "https://prismatic.io/docs/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:50.569023777Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8f4fb9151364"
          },
          {
            "url": "https://prismatic.io/legal/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:53.22345549Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6521c9b1a5d9"
          }
        ],
        "updatedAt": "2026-10-10T02:07:21.289248186Z"
      }
    },
    "verify": {
      "accepts": "a page on prismatic.io or one of its subdomains, or the README of github.com/prismatic-io/prism",
      "badgeUrl": "https://www.anchorterminal.com/badges/prismatic.svg",
      "body": {
        "slug": "prismatic",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/prismatic",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/prismatic\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/prismatic.svg\" alt=\"Prismatic on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Prismatic on Anchor Terminal](https://www.anchorterminal.com/badges/prismatic.svg)](https://www.anchorterminal.com/tools/prismatic)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/prismatic\"\u003ePrismatic on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/prismatic",
    "json": "https://www.anchorterminal.com/tools/prismatic.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/prismatic.md",
    "slim": "https://www.anchorterminal.com/tools/prismatic.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 59.1/100 · rank #561 of 950 · #6 in Workflow automation · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe GraphQL API covers 120 queries and 124 mutations with typed inputs, cursor pagination and Markdown documentation, and tokens follow seven user roles. No price is published, paid use runs under an agreement that is not public, and no API rate limit or idempotency key was found in the reviewed documentation.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Prismatic Software Inc. (https://prismatic.io) |\n| Kind | HTTP API |\n| Category | Workflow automation (https://www.anchorterminal.com/categories/workflow-automation) |\n| Transport | HTTP, Streamable HTTP, stdio |\n| Endpoint | `https://mcp.prismatic.io/mcp` |\n| Auth | OAuth · Access starts with a person creating an account, by free trial or contract, and logging in through the browser (`prism login`). The API takes that user's JWT as a Bearer token. `prism me:token --type refresh` prints a refresh token for headless use, exchanged at `/auth/refresh` for an access token valid for 7 days. Tokens have no scopes of their own and act with the user's role. The hosted MCP flow server uses MCP OAuth or the same Bearer token, and embedded end users get a JWT signed by the customer's backend. |\n| Pricing | Paid (Paid) · No public prices. The pricing page lists Scale, Enterprise and Custom plans with volume per-instance pricing, each ending in a demo request. A free trial exists, and the Terms of Use set it at 30 days unless stated otherwise at signup. Whether the trial needs a card could not be read because the signup form is drawn by script. Contracts set fair use limits in gigabyte-seconds of compute per instance per month (checked 2026-10-09). |\n| x402 | No · No x402, MPP or L402 in the docs index, the API docs or the pricing page (checked 2026-10-09). |\n| Licence | Proprietary service. The Prism CLI, the Spectral and embedded SDKs, the Prism MCP dev server and the Claude Code skills on GitHub are MIT |\n| Packages | npm: `@prismatic-io/prism`; npm: `@prismatic-io/prism-mcp`; npm: `@prismatic-io/spectral`; npm: `@prismatic-io/embedded` |\n| MCP registry name | `io.github.prismatic-io/prism-mcp` |\n| Source | https://github.com/prismatic-io/prism |\n| Docs | https://prismatic.io/docs/api/ |\n| llms.txt | https://prismatic.io/docs/llms.txt |\n| Last release | 2026-10-06 |\n| GitHub stars | 29 (as of 2026-10-09) |\n| npm downloads / week | 8,416 |\n| Surfaces | GraphQL API at https://app.prismatic.io/api, Prism CLI (`@prismatic-io/prism` 10.5.0), hosted MCP flow server, local Prism MCP dev server (`@prismatic-io/prism-mcp` 1.5.0), embedded SDK (`@prismatic-io/embedded` 4.14.0), Spectral TypeScript SDK (10.34.1) |\n| API | GraphQL, 120 queries and 124 mutations in the schema reference, with a GraphiQL explorer in the docs. No REST API and no OpenAPI file |\n| Credentials | User JWT from an OAuth login. Access tokens last 7 days, refresh tokens are revocable at `/auth/revoke`, and embedded users get a JWT the customer's backend signs with a key created by an owner or admin |\n| Roles | Owner, admin, integrator, restricted integrator, guest (read-only), customer manager and third-party (per-object permissions) |\n| MCP flow server | Hosted, Streamable HTTP, MCP OAuth or a Bearer token. Global, integration-scoped and instance-scoped endpoints. Tools are the agentic flows the customer has built, plus a default `get-me` tool |\n| MCP dev server | Local stdio, 19 tools, toolsets `integration` and `component`, reads the CLI's saved credentials. No `readOnlyHint` or `destructiveHint` annotations in the source |\n| Pagination | Relay cursors, 100 results by default, `first`, `after`, `sortBy` and per-query filters such as `name_Icontains` |\n| Limits | 15 minutes an execution, 1 GB memory by default and up to 10 GB, 6 MB webhook payload, 30 seconds for a synchronous webhook, 500 MB step result. Concurrency depends on the plan, with no published number |\n| Regions | US Commercial (Ohio), US GovCloud, Ireland, London, Canada, Sydney and Cape Town, plus private deployment in the customer's AWS account |\n| Plans | Scale, Enterprise and Custom, all by demo. Volume per-instance pricing. Free trial of 30 days per the Terms of Use |\n| Status | Atlassian Statuspage at www.prismatic-status.io with five components (GraphQL API, Web App, Integration Runner, OAuth 2.0 Refresh, Embedded) |\n| Security | SOC 2 Type 2 per the security policy, AES-256 for stored third-party credentials, TLS 1.2 or later, AWS hosting, Auth0 for user login. Valid security.txt with a PGP key |\n| Open source | The CLI, both SDKs, the MCP dev server and the Claude Code skills are MIT on GitHub. The platform is closed |\n| Capabilities | automation.workflows, automation.embedded, automation.apps, automation.code, automation.webhooks, automation.auth, agent.tools |\n| Tags | hosted, enterprise, graphql, mcp, cli, oauth, llms-txt, typescript, sales-led, status-page, soc2, webhooks, closed-source |\n| JSON | https://www.anchorterminal.com/api/v1/tools/prismatic.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 67 | 13.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 75 | 12.2 |\n| Agent ergonomics | 13% | 16.2 | 63 | 10.2 |\n| Security \u0026 auth | 14% | 17.5 | 59 | 10.3 |\n| Payments \u0026 pricing | 10% | 12.5 | 0 | 0.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 83 | 7.3 |\n| Transparency \u0026 trust (editorial 40, provenance 89) | 7% | 8.8 | 65 | 5.7 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **59.1 → C** |\n\n### Why each score\n\n- Reliability 67: Graded as a hosted service, on the GraphQL API and the hosted MCP flow server. Atlassian Statuspage at www.prismatic-status.io with five components and 90-day uptime bars (20). Four incidents in the last 90 days, all short or partial. Intermittent OAuth token refresh failures in eu-west-1 for 3 hours 16 minutes on 17 August 2026, raised error rates in us-west-2 for about 70 minutes on 16 September, the web app unavailable in all regions for 21 minutes on 22 September, and workflow editing in the embedded builder down for 33 minutes on 30 September (20). Execution limits are published with numbers (15 minutes, 1 GB, 6 MB webhook payload, 30 seconds synchronous), but concurrency depends on the plan with no number and no API request rate was found (5). A request over the concurrency limit gets a 429, flow concurrency queues requests and failed executions can retry automatically. No `Retry-After` or backoff guidance for the API was found (7). The pricing page lists standard SLAs on Scale and Enterprise and custom SLAs above, with no SLA text published (5). The API, CLI and MCP flow server are generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 75: The contract is a GraphQL schema with 120 queries and 124 mutations in the reference and a GraphiQL explorer. No downloadable schema file or OpenAPI document was found (22). `llms.txt` and a Markdown twin of every docs page (10). Each operation and field has a one-line description, with no guidance on when to use one over another (11). Arguments are typed, with required markers, enums and input objects (13). The docs carry worked queries in curl, Node.js and Python and document the mutation `errors` array, with no list of error codes (9). The changelog is public and dated. The API has no version, and deprecated arguments are marked in the schema (10).\n- Agent ergonomics 63: GraphQL field selection lets a caller size each response, and `first` caps the page. The local MCP dev server has 19 tools in two optional toolsets (22). Relay cursors with a default of 100, `sortBy` and per-query filters (20). Mutations return an `errors` array of field and message under HTTP 200, with no codes (10). No idempotency keys were found, and the MCP dev server's tools carry no `readOnlyHint` or `destructiveHint`. Customer `externalId` values must be unique, which stops one kind of duplicate (3). A CLI and two TypeScript SDKs, no API client in a second language (8).\n- Security \u0026 auth 59: The API takes a user's JWT from an OAuth login. Access tokens last 7 days and refresh tokens can be revoked, though revoking one revokes all of that user's. Tokens have no scopes and act with the user's role (20). Seven roles include a read-only guest, a restricted integrator who cannot see logs or step results, and a third-party role limited to named objects. No confirmation step before destructive mutations was found (13). Agentic flows return third-party content and no prompt-injection guidance was found (3). Execution logs, step results and log streaming to Datadog, New Relic or Google Cloud. No audit log of API calls was found (8). Valid security.txt with a PGP key, a disclosure address, and SOC 2 Type 2 per the security policy. No bug bounty found, and the trust centre is drawn by script and was not read (15).\n- Payments \u0026 pricing 0: No x402, MPP or L402 (0). The pricing page names three plans and gives no price. Each ends in a demo request (0). A free trial exists, 30 days per the Terms of Use, but the signup form is drawn by script and we could not confirm that it needs no card, so the line is scored absent (0). A person signs up and logs in through a browser before any token exists (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 83: The Spectral SDK released v10.34.1 on 6 October 2026 and the changelog's newest entry is 1 October 2026 (30). Ten changelog entries between 20 August and 1 October 2026, and Prism CLI releases on 14, 15 and 30 September (20). A dated changelog with monthly newsletters and a support address. The CLI and MCP repositories each show two open issues (10). Current official CLI, Spectral and embedded SDKs, and the MCP dev server's `server.json` names `io.github.prismatic-io/prism-mcp`. We did not confirm the registry entry itself (15). Build, test and release workflows in each repository and dependency updates through October 2026. We did not see the workflow results (8).\n- Transparency \u0026 trust 65: Closed platform. The public Terms of Use cover the website and trials and say paid use runs under a separate agreement, which is not published. The CLI, SDKs and MCP dev server are MIT (12). The Privacy Policy covers the web application and names Mixpanel and Auth0, but gives no retention period beyond as long as needed. The Terms say trial data is not kept after a trial, and the changelog gives 14 days of execution retention. No DPA or sub-processor list was found on the pages read (12). Deprecated arguments are marked in the schema and Spectral has upgrade guides for each major version. No deprecation policy with notice periods was found (6). Seven hosting regions and AWS are disclosed. A sub-processor list was not found (10).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/prismatic.md (JSON https://www.anchorterminal.com/fixes/prismatic.json)\n\n### What we couldn't check\n\n- unchecked: whether the free trial needs a card. The signup form at https://prismatic.io/free-trial/ is drawn by script\n- unchecked: the trust centre at https://www.trust-prismatic.io, a Vanta page drawn by script, so any sub-processor list, DPA or further certification there is unread\n- unchecked: GitHub security advisories for the CLI, SDKs and MCP dev server, and whether CI passes on the default branches\n- unchecked: whether `io.github.prismatic-io/prism-mcp` is live in the official MCP registry\n- The agreement that governs paid use is not published, so `provenance.terms` is left out\n- No API rate limit, SLA text or deprecation policy was found in the reviewed documentation\n- Whether a GraphQL schema file can be downloaded without an account\n- The lead named the Prism MCP dev server only. Prismatic also runs a hosted MCP flow server, which the listing records\n\n### Sources\n\n- docs index for agents: \u003chttps://prismatic.io/docs/llms.txt\u003e (seen 2026-10-09)\n- API authentication: \u003chttps://prismatic.io/docs/api/authentication.md\u003e (seen 2026-10-09)\n- refresh tokens and revocation: \u003chttps://prismatic.io/docs/api/ci-cd-system.md\u003e (seen 2026-10-09)\n- pagination: \u003chttps://prismatic.io/docs/api/pagination.md\u003e (seen 2026-10-09)\n- queries, mutations and errors: \u003chttps://prismatic.io/docs/api/queries-and-mutations.md\u003e (seen 2026-10-09)\n- query reference: \u003chttps://prismatic.io/docs/api/schema/queries.md\u003e (seen 2026-10-09)\n- mutation reference: \u003chttps://prismatic.io/docs/api/schema/mutations.md\u003e (seen 2026-10-09)\n- MCP flow server endpoints: \u003chttps://prismatic.io/docs/ai/mcp-endpoints.md\u003e (seen 2026-10-09)\n- MCP client setup and OAuth: \u003chttps://prismatic.io/docs/ai/test-mcp-clients.md\u003e (seen 2026-10-09)\n- Prism MCP dev server docs: \u003chttps://prismatic.io/docs/dev-tools/prism-mcp.md\u003e (seen 2026-10-09)\n- MCP dev server source, tags and server.json: \u003chttps://github.com/prismatic-io/prism-mcp\u003e (seen 2026-10-09)\n- Prism CLI source and tags: \u003chttps://github.com/prismatic-io/prism\u003e (seen 2026-10-09)\n- Spectral SDK tags: \u003chttps://github.com/prismatic-io/spectral\u003e (seen 2026-10-09)\n- runner environment and limits: \u003chttps://prismatic.io/docs/integrations/integration-runner-environment-limits.md\u003e (seen 2026-10-09)\n- usage limits: \u003chttps://prismatic.io/docs/integrations/usage-limits.md\u003e (seen 2026-10-09)\n- deployment regions: \u003chttps://prismatic.io/docs/configure-prismatic/deployment-regions.md\u003e (seen 2026-10-09)\n- organisation user roles: \u003chttps://prismatic.io/docs/configure-prismatic/organization-users.md\u003e (seen 2026-10-09)\n- embedded user JWTs: \u003chttps://prismatic.io/docs/get-started/embedded-marketplace/authenticate-embedded-users.md\u003e (seen 2026-10-09)\n- changelog: \u003chttps://prismatic.io/docs/changelog/\u003e (seen 2026-10-09)\n- pricing: \u003chttps://prismatic.io/pricing/\u003e (seen 2026-10-09)\n- Terms of Use: \u003chttps://prismatic.io/legal/terms/\u003e (seen 2026-10-09)\n- Acceptable Use Policy: \u003chttps://prismatic.io/legal/acceptable-use/\u003e (seen 2026-10-09)\n- Privacy Policy: \u003chttps://prismatic.io/legal/privacy/\u003e (seen 2026-10-09)\n- Security Policy: \u003chttps://prismatic.io/legal/security/\u003e (seen 2026-10-09)\n- security.txt: \u003chttps://prismatic.io/.well-known/security.txt\u003e (seen 2026-10-09)\n- status page: \u003chttps://www.prismatic-status.io/\u003e (seen 2026-10-09)\n- status history feed: \u003chttps://www.prismatic-status.io/history.rss\u003e (seen 2026-10-09)\n- robots.txt with Content-Signal ai-input=yes: \u003chttps://prismatic.io/robots.txt\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 89/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Prismatic Software Inc. | 20/20 |\n| Domain age | prismatic.io, registered 2016-07-09 (10 years) | 15/15 |\n| Endpoint on the vendor's domain | mcp.prismatic.io | 15/15 |\n| Terms of service | not found | 0/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | www.prismatic-status.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe Terms of Use (last updated 17 March 2023) name Prismatic Software Inc., 5013 S Louise Ave #122, Sioux Falls, SD 57108, and are governed by South Dakota law.\n\nNo terms link is recorded. The Terms of Use at https://prismatic.io/legal/terms/ are website terms that also cover trial accounts, and they say non-trial use of the Services is subject to a separate agreement, which is not published.\n\nThe Privacy Policy (last updated 26 June 2024) covers the website and the web application at app.prismatic.io.\n\nsecurity.txt at https://prismatic.io/.well-known/security.txt names security@prismatic.io and a PGP key and expires on 16 June 2027.\n\nThe API, the regional hosts and the MCP flow server are all on prismatic.io subdomains. The status page is on prismatic-status.io and the trust centre on trust-prismatic.io.\n\nRDAP for prismatic.io gives a registration date of 2016-07-09.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0.\n\n\n**Privacy policy** (https://prismatic.io/legal/privacy/), read 2026-10-09, dated 2024-06-26, states 7 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"We may share information about your use of our Services with our advertising and analytics partners, who may combine it with other information that you previously provided to them.\"\n- Gives the date it was last updated. Last updated 2024-06-26.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Prismatic or its service providers may send marketing to email or home addresses that its data partners associate with a website visit or login. \"We (or service providers on our behalf) may then send communications and marketing to these email or home addresses.\"\n\n## Live (updated 2026-10-10 02:07 UTC)\n\n- Right now: up, HTTP 401, 301 ms, checked 2026-10-10 02:07 UTC (get on `https://mcp.prismatic.io/mcp`, asks for auth)\n- Uptime 24h 100.0% (107 probes) · 30 days 100.0% (107 probes) · p50 300 ms · p95 389 ms\n- Vendor status page: none, All Systems Operational\n- github `prismatic-io/prism` v10.5.0, released 2026-09-30\n- npm `@prismatic-io/embedded` 4.14.0\n- npm `@prismatic-io/prism` 10.5.0\n- npm `@prismatic-io/prism-mcp` 1.5.0\n- npm `@prismatic-io/spectral` 10.34.1\n- Watching changelog \u003chttps://prismatic.io/docs/changelog/\u003e\n- Watching privacy \u003chttps://prismatic.io/legal/privacy/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/prismatic.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- GraphQL API with 120 documented queries and 124 mutations, field selection, cursor pagination and per-query filters\n- Every docs page has a Markdown twin, indexed by `llms.txt` at prismatic.io/docs/llms.txt\n- Hosted MCP flow server in seven regions, with OAuth 2.0 and endpoints scoped to one integration or one instance\n- Seven organisation roles, including a read-only guest and a third-party role limited to named integrations, components or customers\n- Dated changelog with ten entries from 20 August to 1 October 2026, and CLI and SDK releases in the same weeks\n\n## Weaknesses\n\n- No prices on the pricing page. All three plans end in a demo request\n- Paid use is governed by a separate agreement that is not published. The public terms cover the website and 30-day trials\n- No API rate limit, `Retry-After` behaviour or idempotency key found in the reviewed documentation\n- API tokens carry the whole role of the user who created them, and revoking one refresh token revokes all of that user's\n- Mutation failures return HTTP 200 with an `errors` array of field and message, with no error codes\n\n## Before you call it (notes for agents)\n\n1. Have a person run `prism login` once, then store the output of `prism me:token --type refresh` as `PRISM_REFRESH_TOKEN`. Access tokens last 7 days\n2. Read the `errors` array on every mutation. A failed mutation still returns HTTP 200\n3. Pass `sortBy` with `CREATED_AT` when paging. Without a sort order pages can repeat or skip records\n4. Use the regional host for the tenant, such as `app.eu-west-1.prismatic.io` and `mcp.eu-west-1.prismatic.io`\n5. Create a guest user for a read-only agent, because tokens have no scopes of their own\n\n## Connect\n\nInstall:\n\n```bash\nnpm install --global @prismatic-io/prism\n```\n\nFirst request:\n\n```bash\ncurl https://app.prismatic.io/api --request POST --header \"Authorization: Bearer ${PRISMATIC_API_TOKEN}\" --header \"Content-Type: application/json\" --data '{\"query\": \"query { integrations { nodes { id name }}}\"}'\n```\n\nClaude Code:\n\n```bash\nclaude mcp add-json prismatic '{\"type\":\"stdio\",\"command\":\"npx\",\"args\":[\"-y\",\"mcp-remote\",\"https://mcp.prismatic.io/mcp\"]}'\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"prism\": {\n      \"args\": [\n        \"-y\",\n        \"@prismatic-io/prism-mcp\",\n        \".\"\n      ],\n      \"command\": \"npx\",\n      \"env\": {\n        \"PRISMATIC_URL\": \"https://app.prismatic.io\"\n      },\n      \"type\": \"stdio\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/prismatic. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Pipedream API + MCP | B | 65.5 | 315 | automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, automation.auth, agent.tools | no | https://www.anchorterminal.com/tools/pipedream.md |\n| Workato API + MCP | C | 58 | 590 | automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, automation.auth, agent.tools | no | https://www.anchorterminal.com/tools/workato.md |\n| Tray.ai API + MCP | C | 55.5 | 655 | automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, automation.auth, agent.tools | no | https://www.anchorterminal.com/tools/tray.md |\n| Activepieces API + MCP | C | 57.5 | 605 | automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/activepieces.md |\n| Paragon ActionKit + MCP | D | 47.5 | 833 | automation.embedded, automation.workflows, automation.apps, automation.auth, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/paragon.md |\n| Kestra | B | 63.6 | 387 | automation.workflows, automation.code, automation.webhooks, automation.apps, agent.tools | no | https://www.anchorterminal.com/tools/kestra.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The GraphQL API answers at https://app.prismatic.io/api with a Bearer JWT. Refresh tokens are exchanged at `/auth/refresh` for access tokens valid for 7 days (source: \u003chttps://prismatic.io/docs/api/authentication.md\u003e)\n- The hosted MCP flow server turns flows marked as agentic into MCP tools, over Streamable HTTP with MCP OAuth, at `mcp.prismatic.io/mcp` and six regional hosts (source: \u003chttps://prismatic.io/docs/ai/mcp-endpoints.md\u003e)\n- The Prism MCP dev server is a separate local stdio server that wraps the Prism CLI, with 19 tools in two optional toolsets, MIT (source: \u003chttps://github.com/prismatic-io/prism-mcp\u003e)\n- Usage is measured in gigabyte-seconds of compute per instance per month against fair use limits set in the contract, and the pricing page says plans are never billed on API calls or executions (source: \u003chttps://prismatic.io/docs/integrations/usage-limits.md\u003e)\n- An execution runs for at most 15 minutes with 1 GB of memory by default, and a request over the plan's concurrency limit gets a 429 (source: \u003chttps://prismatic.io/docs/integrations/integration-runner-environment-limits.md\u003e)\n- The status page lists four incidents between 17 August and 30 September 2026, the longest 3 hours 16 minutes of intermittent OAuth token refresh failures in eu-west-1 (source: \u003chttps://www.prismatic-status.io/history\u003e)\n- The Acceptable Use Policy bars probing, scanning or testing the vulnerability of any system, and access by any means other than the publicly supported interfaces (source: \u003chttps://prismatic.io/legal/acceptable-use/\u003e)\n\n- #9 of 17 in Best workflow automation platforms with APIs for AI agents: https://www.anchorterminal.com/best/workflow-automation/index.md\n- All 108 workflows comparisons: https://www.anchorterminal.com/compare/workflow-automation/index.md\n\n## Compare\n\n- [Activepieces API + MCP vs Prismatic](https://www.anchorterminal.com/compare/activepieces-vs-prismatic.md): C 57.5 vs C 59.1\n- [Gumloop vs Prismatic](https://www.anchorterminal.com/compare/gumloop-vs-prismatic.md): C 61.6 vs C 59.1\n- [Kestra vs Prismatic](https://www.anchorterminal.com/compare/kestra-vs-prismatic.md): B 63.6 vs C 59.1\n- [Make API + MCP vs Prismatic](https://www.anchorterminal.com/compare/make-vs-prismatic.md): C 58.7 vs C 59.1\n- [n8n API + MCP vs Prismatic](https://www.anchorterminal.com/compare/n8n-vs-prismatic.md): D 53.1 vs C 59.1\n- [Node-RED vs Prismatic](https://www.anchorterminal.com/compare/node-red-vs-prismatic.md): C 61 vs C 59.1\n- [Pipedream API + MCP vs Prismatic](https://www.anchorterminal.com/compare/pipedream-vs-prismatic.md): B 65.5 vs C 59.1\n- [Microsoft Power Automate vs Prismatic](https://www.anchorterminal.com/compare/power-automate-vs-prismatic.md): B 62 vs C 59.1\n- [Prismatic vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/prismatic-vs-tray.md): C 59.1 vs C 55.5\n- [Prismatic vs Windmill API + MCP](https://www.anchorterminal.com/compare/prismatic-vs-windmill.md): C 59.1 vs C 55.9\n- [Prismatic vs Workato API + MCP](https://www.anchorterminal.com/compare/prismatic-vs-workato.md): C 59.1 vs C 58\n- [Paragon ActionKit + MCP vs Prismatic](https://www.anchorterminal.com/compare/paragon-vs-prismatic.md): D 47.5 vs C 59.1\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on prismatic.io or one of its subdomains, or the README of github.com/prismatic-io/prism. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"prismatic\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/prismatic\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/prismatic.svg\" alt=\"Prismatic on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Prismatic on Anchor Terminal](https://www.anchorterminal.com/badges/prismatic.svg)](https://www.anchorterminal.com/tools/prismatic)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/prismatic\"\u003ePrismatic on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Prismatic is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/prismatic-dark.png\n- Light: https://www.anchorterminal.com/assets/share/prismatic-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Workflow automation",
        "url": "https://www.anchorterminal.com/categories/workflow-automation"
      },
      {
        "name": "Prismatic",
        "url": ""
      }
    ],
    "description": "Prismatic is an embedded integration platform for B2B software companies. Teams build integrations in a low-code designer or in TypeScript, deploy them to customers, and manage them through a GraphQL API, the Prism CLI and MCP servers.",
    "facts": [
      "rank #561 of 950",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Prismatic",
    "image": "https://www.anchorterminal.com/assets/og/tools-prismatic.png",
    "path": "/tools/prismatic",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Prismatic review (2026): pricing, alternatives and grade C",
    "toc": null,
    "updated": "2026-10-10",
    "url": "https://www.anchorterminal.com/tools/prismatic"
  },
  "tokens": {
    "markdown": 7300,
    "slim": 1880
  },
  "version": 1
}
