Files
Kokorone/.agents/skills/prisma-postgres/references/management-api-sdk.md
Jeffery f44200f543 feat: 完成 B 群組 — 資料層與核心領域模型
- 導入 Prisma 7.9.1 + SQLite(better-sqlite3 driver adapter),prisma.config.ts 管理連線設定
- 完整資料模型:User/Work/Character/CharacterAlias/EpisodicMemory/SemanticMemory/
  ProceduralRule/EmotionState/Relationship/SentimentLedgerEntry
- packages/db:Prisma Client 存取層(ESM,因 Prisma 7 產出的 generated client 僅支援 ESM)
- apps/api 隨之改為 ESM 以相容 packages/db
- packages/shared:新增角色/記憶/情緒/關係共用型別,api 與 web 皆從此匯入
- prisma/seed.ts:建立測試使用者與元氣型測試角色,含完整關係帳本與記憶種子資料
- apps/api:新增 GET /characters
- scripts/smoke/B.mjs:驗證資料表齊全、API 讀出種子角色、關係與記憶可寫入讀出
- 保留 Prisma 官方隨 CLI 附的 agent skill 文件(.agents/skills 等),供後續群組查閱

npm run restart && npm run smoke -- B 皆通過(B-V),A 群組冒煙測試無回歸。
2026-08-13 09:43:15 +08:00

2.3 KiB

management-api-sdk

Use @prisma/management-api-sdk for typed API integration with optional OAuth and token refresh.

The Platform API evolves independently from Prisma ORM. Inspect the installed package's generated api.d.ts for exact paths and request/response shapes.

Priority

HIGH

Why It Matters

The SDK provides typed endpoint methods and removes boilerplate around auth and refresh handling, which reduces errors in production provisioning flows.

Install

npm install @prisma/management-api-sdk

Simple client (existing token)

import { createManagementApiClient } from '@prisma/management-api-sdk'

const client = createManagementApiClient({ token: process.env.PRISMA_SERVICE_TOKEN! })
const { data: workspaces } = await client.GET('/v1/workspaces')

Check the generated client result before using data; typed clients surface HTTP failures separately. Never log a full response from connection/key creation because it may contain one-time credentials.

Workspace service tokens

The typed client exposes routes to list, create, and revoke workspace service tokens:

  • GET /v1/workspaces/{workspaceId}/service-tokens
  • POST /v1/workspaces/{workspaceId}/service-tokens
  • DELETE /v1/workspaces/{workspaceId}/service-tokens/{serviceTokenId}

Creation accepts a display name. The response's data.value is the complete token and is returned exactly once; transfer it directly to the intended secret store without logging the response. Later list calls return metadata and valueHint, not the token value. Treat revocation as destructive and resolve both ids explicitly.

Full SDK (OAuth + refresh)

import { createManagementApiSdk, type TokenStorage } from '@prisma/management-api-sdk'

const tokenStorage: TokenStorage = {
  async getTokens() { return null },
  async setTokens(tokens) {},
  async clearTokens() {},
}

const api = createManagementApiSdk({
  clientId: process.env.PRISMA_CLIENT_ID!,
  redirectUri: 'https://your-app.com/auth/callback',
  tokenStorage,
})

OAuth SDK flow

  1. Call getLoginUrl() and persist state + verifier.
  2. Redirect user to login URL.
  3. Handle callback with handleCallback().
  4. Use api.client for typed endpoint calls.
  5. Call logout() when needed.

References