Field guide · 10 practical articles
Ship Prisma APIs faster. Generate the repetitive parts.
Ten practical guides to shipping Prisma APIs faster with generated CRUD routes, OpenAPI, guarded MCP tools, pagination, hooks, tenant scope, and SSE.
The reading path
From Prisma schema to working API
Start with generated routes, then add callers, guards, hooks, pagination, streaming, and explicitly allowlisted MCP tools for authenticated agents.
- A1 Getting started Build a Prisma CRUD API Without Writing Every Route Generate working CRUD routes and optional MCP tools from a Prisma schema, then add the API rules your product needs.
- A2 Tenant safety 7 Ways a Multi-Tenant Prisma API Can Leak Data Find seven common tenant-isolation mistakes and learn the direct fix for each one.
- A3 Guard shapes Prisma Guard force() Explained: Defaults vs Server Rules Learn when a value is a client option, a default, or a server rule that clients cannot override.
- A4 User types One Prisma Model, Different APIs for Every User Type Give public users, staff, and admins different API contracts without duplicating your model.
- A5 Hooks When Generated Prisma Routes Need Hooks—and When They Don’t Use hooks for rules that shapes cannot express, and keep simple rules in configuration.
- A6 Response fields Control Prisma Responses with select and include Choose which fields and relations an endpoint returns, including nested data.
- A7 Large reads Choose a Prisma Read Route: Pages, POST Queries, or Streaming Pick the right generated read route for normal lists, large filters, and progressive results.
- A8 Writes Safe Prisma Writes: Create, Update, Upsert, and Delete Build REST and MCP write actions that validate input, apply server values, and avoid dangerous bulk changes.
- A9 Error help Fix prisma-guard Errors: A Practical Reference Start with the error message, find the failing step, and apply the matching correction.
- A10 Silent bugs When Prisma Returns 200 but the Result Is Wrong Diagnose successful requests that return the wrong filters, fields, scope, count, or page.
Evidence, not folklore
Every runtime claim has a trail.
Claims trace to the project READMEs, the reproducible guard lab, or the HTTP/PostgreSQL lab. Error text and runtime results are version-pinned.