OrchestrAI Live

Integration · Database

PlanetScale + OrchestrAI

Catalog exported 2026-09-02 · PlanetScale website

See your PlanetScale databases from chat and confirm the connection works. Read-only inventory for now.

OrchestrAI exposes 3 PlanetScale operations: 3 are low-risk (read-only or low-impact).

3operations
3low risk
0create or modify
0destructive
0step-level approval

What teams use it for

The PlanetScale connection is an inventory view: it confirms the service token is valid and lists the databases and the resources under them that the token can see, which is enough for a platform team to answer which PlanetScale databases exist across environments during an audit or cost review. It also lets OrchestrAI cross-reference a database name that shows up in an application's configuration on another platform. Coverage is read-only for now. Creating branches, opening deploy requests, running queries, and changing plans are not available, so all schema and lifecycle work remains in the PlanetScale app or pscale CLI.

Every PlanetScale operation, with its risk level

PlanetScale operations available through OrchestrAI
Operation What it does Risk Step-level approval
List Managed Platform Deployments List deployments, machines, or runtime resources for providers that expose deployment inventory Low risk No
List Managed Platform Projects List projects, apps, sites, databases, or clusters for supported PaaS and managed database providers Low risk No
Validate Managed Platform Connection Validate configured credentials for a supported PaaS or managed database provider Low risk No

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

What you connect

A PlanetScale credential (stored as vercel, fly, railway, netlify, render, neon, supabase, planetscale, upstash, aiven, cockroachdb_cloud). Connected-service tokens are envelope-encrypted with a per-record key wrapped by a cloud KMS.

Prompts that work

  • List all the databases in our PlanetScale organization
  • Check whether the PlanetScale token we added last week still works
  • Show me what runtime resources are listed under the orders database on PlanetScale

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI create a PlanetScale branch or deploy request?
No, The three PlanetScale operations are list projects, list deployments, and validate connection, all rated low risk. Branching and deploy requests are not covered.
What can OrchestrAI actually change in PlanetScale?
Nothing at present. Every PlanetScale operation is read-only, which makes it safe to connect with a token scoped to read access.
How does OrchestrAI authenticate to PlanetScale?
You add a PlanetScale credential once in the connections screen. It is envelope-encrypted with a per-record key wrapped by a cloud KMS and is only decrypted inside the run that needs it.

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.