Prerequisites
- A Neon account with access to the projects you want CloudThinker to inspect.
- Permission to authorize CloudThinker through Neon’s OAuth flow.
- A CloudThinker workspace where Neon is not already connected.
CloudThinker supports one Neon connection per workspace. To switch accounts, remove the existing Neon connection and reconnect.
Setup
Authorize CloudThinker
Sign in to the Neon account that owns or can access the projects you want CloudThinker to use, then approve access.
There are no environment fields to fill out for the Neon connection.
Required Permissions
CloudThinker inherits the Neon access granted during OAuth.- Read operations include listing projects, inspecting schemas, reviewing metadata, and analyzing slow queries.
- Write operations such as SQL execution, branch changes, migrations, Neon Auth changes, and Data API provisioning require matching Neon access and explicit approval in CloudThinker.
Agent Capabilities
Once connected, agents can:- Discover Neon projects, shared projects, organizations, computes, and tables.
- Inspect schemas and table metadata.
- Review slow queries and suggest optimizations.
- Run SQL or transactions only after explicit user approval.
- Manage branches, migrations, query tuning, Neon Auth, and Neon Data API provisioning only after explicit user approval.
Example Prompt
Troubleshooting
OAuth flow does not complete
OAuth flow does not complete
You may be signed in to the wrong Neon account, or your browser session may not be signed in to Neon. Sign in to the intended Neon account and retry the CloudThinker Neon connection flow.
CloudThinker says Neon is already connected
CloudThinker says Neon is already connected
Only one OAuth Neon connection is allowed per workspace. Use the existing Neon connection or remove it before reconnecting.
Agent cannot find expected Neon projects
Agent cannot find expected Neon projects
The OAuth flow may have been completed with a Neon account that lacks access to those projects. Reconnect using the Neon account that owns or has access to the projects.
Security Best Practices
- Least-privilege account - Authorize with only the Neon project access CloudThinker needs
- Approval for writes - Keep SQL, branches, migrations, Auth, and Data API changes approval-gated
- Read before writing - Start with project and schema inspection prompts
- Reconnect carefully - Remove the existing workspace connection before switching Neon accounts
Related
MCP Connection
Connect custom tools and services with MCP
Tony Agent
Database analysis and optimization