Prerequisites
- A Pinecone account with the project you want agents to read.
- The project owner role, which is the role Pinecone lets create API keys in a project.
- For searches and writes, indexes created with integrated embedding. Pinecone states that the connection supports only these indexes, and not indexes whose vectors come from an external embedding model.
Setup
1
Open your project
Open the Pinecone console and select the project agents should read.
2
Create an API key
Go to API keys and click Create API key. Enter an API key name such as
cloudthinker, and select the Permissions to grant (see Required permissions). Click Create key.3
Copy the key
Copy the key and store it securely. Pinecone says you cannot see the API key again after you close the dialog.
4
Add the connection in CloudThinker
Go to Connections → Pinecone, paste the key into PINECONE_API_KEY, and click Connect. CloudThinker sets up the connection and shows a Connected status.
Connected means CloudThinker finished setting up the connection. Pinecone checks the key the first time an agent calls it, so a wrong or revoked key can still show Connected. Run the verify prompt below to confirm.
Connection details
A key belongs to one project, so one connection reaches the indexes of that project only.
Required permissions
Agent capabilities
Once connected, agents read your project and ask before they write.
Before any write, the agent shows the exact index name, namespace, embedding model, and records, then waits for your explicit confirmation.
Verify the connection
Example prompts
Troubleshooting
Connected, but every request fails with 401
Connected, but every request fails with 401
Pinecone returns 401 when the API key is missing or invalid. The key may be mistyped, deleted, or from a different project. Create a new key in the right project and update the connection.
The agent cannot search or write to one of my indexes
The agent cannot search or write to one of my indexes
Pinecone supports only indexes with integrated embedding through this connection. An index built from vectors you generated with an external embedding model cannot be searched or written here.
A write was refused or never ran
A write was refused or never ran
Writes need a role with write access, such as Project editor, and your confirmation in the conversation. Check the key’s permissions in the Pinecone console, then confirm the exact index, namespace, and records the agent shows.
Requests slow down or return 429
Requests slow down or return 429
Pinecone returns 429 when requests are rate-limited. Wait a moment, then ask again.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Read-only role first — a Project viewer key cannot write even if a request tries to.
- One project per key — create the key in the single project agents should read, and delete it in Pinecone when you remove the connection.
Related
OpenSearch Connection
Indexes, queries, and search relevance
Elasticsearch Connection
Log analysis and search performance