- 導入 Prisma 7.9.1 + SQLite(better-sqlite3 driver adapter),prisma.config.ts 管理連線設定 - 完整資料模型:User/Work/Character/CharacterAlias/EpisodicMemory/SemanticMemory/ ProceduralRule/EmotionState/Relationship/SentimentLedgerEntry - packages/db:Prisma Client 存取層(ESM,因 Prisma 7 產出的 generated client 僅支援 ESM) - apps/api 隨之改為 ESM 以相容 packages/db - packages/shared:新增角色/記憶/情緒/關係共用型別,api 與 web 皆從此匯入 - prisma/seed.ts:建立測試使用者與元氣型測試角色,含完整關係帳本與記憶種子資料 - apps/api:新增 GET /characters - scripts/smoke/B.mjs:驗證資料表齊全、API 讀出種子角色、關係與記憶可寫入讀出 - 保留 Prisma 官方隨 CLI 附的 agent skill 文件(.agents/skills 等),供後續群組查閱 npm run restart && npm run smoke -- B 皆通過(B-V),A 群組冒煙測試無回歸。
1.5 KiB
1.5 KiB
auth
How to authenticate with the Prisma Management API using service tokens.
Service Tokens
Service tokens authenticate server-to-server requests. They are scoped to a workspace and grant access to all resources within it.
Creating a service token
- Open https://console.prisma.io
- Navigate to Workspace Settings → Service Tokens
- Click Create Token
- Copy the token immediately — it is only shown once
Using a service token
Set the token as an environment variable:
export PRISMA_SERVICE_TOKEN="eyJ..."
Include it in the Authorization header of every API request:
curl -H "Authorization: Bearer $PRISMA_SERVICE_TOKEN" \
https://api.prisma.io/v1/projects
Token scope
Service tokens are workspace-scoped. A single token grants access to all projects, databases, and connections within the workspace. There are no project-scoped tokens at this time.
Security practices
- Store tokens in environment variables or secret managers, never in source code
- Add
.envto.gitignoreto prevent accidental commits - Rotate tokens periodically via Console → Workspace Settings → Service Tokens
- In CI/CD, store tokens as encrypted secrets (e.g., GitHub Secrets)
OAuth 2.0 (for user-scoped access)
OAuth is used when acting on behalf of a user, typically in partner/integrator flows. See the prisma-postgres-integrator skill for OAuth details.
For standard database setup, service tokens are the recommended authentication method.