Integration · Database
Aiven + OrchestrAI
Catalog exported 2026-09-02 · Aiven website
See your Aiven projects and services from chat and check that the connection works, read-only for now.
OrchestrAI exposes 3 Aiven operations: 3 are low-risk (read-only or low-impact).
What teams use it for
Teams that run Aiven alongside AWS or GCP use OrchestrAI to list Aiven projects and service inventory in the same conversation where they operate the rest of their stack. You can also validate that the stored Aiven token is accepted before relying on it in a longer run. Every Aiven operation is low risk and read-only. There is no operation to create, resize, or delete an Aiven service yet, so provisioning stays in the Aiven console.
Every Aiven operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
List Managed Platform Deployments |
List deployments, machines, or runtime resources for providers that expose deployment inventory | Low risk | No |
List Managed Platform Projects |
List projects, apps, sites, databases, or clusters for supported PaaS and managed database providers | Low risk | No |
Validate Managed Platform Connection |
Validate configured credentials for a supported PaaS or managed database provider | Low risk | No |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
What you connect
A Aiven credential (stored as vercel, fly, railway, netlify, render, neon, supabase, planetscale, upstash, aiven, cockroachdb_cloud).
Connected-service tokens are envelope-encrypted with a per-record key wrapped by a cloud KMS.
Prompts that work
- List every project in my Aiven account
- What services are deployed in the Aiven project analytics-prod?
- Check whether the Aiven API token is still valid
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Can OrchestrAI create a Kafka or Postgres service on Aiven?
- Not yet. Aiven coverage is limited to listing projects, listing deployed services, and validating the connection. Provisioning still happens in the Aiven console or CLI.
- Does OrchestrAI need write access to Aiven?
- No. All three Aiven operations are read-only, so a token scoped to read access is enough.
- How does OrchestrAI authenticate to Aiven?
- You add a Aiven credential once in the connections screen. It is envelope-encrypted with a per-record key wrapped by a cloud KMS and is only decrypted inside the run that needs it.
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.