> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Pinecone

> Connect Pinecone to CloudThinker to inspect indexes and namespaces, search records, and approve record updates

Connect your Pinecone project to let CloudThinker agents list indexes, read namespace statistics, and search records. Pinecone authenticates with a **project API key**, and the key's role decides whether agents can write.

## Prerequisites

* A **Pinecone account** with the project you want agents to read.
* The **project owner** role, which is the role Pinecone lets create API keys in a project.
* For searches and writes, indexes created with **integrated embedding**. Pinecone states that the connection supports only these indexes, and not indexes whose vectors come from an external embedding model.

## Setup

<Steps>
  <Step title="Open your project">
    Open the Pinecone console and select the project agents should read.
  </Step>

  <Step title="Create an API key">
    Go to **API keys** and click **Create API key**. Enter an **API key name** such as `cloudthinker`, and select the **Permissions** to grant (see [Required permissions](#required-permissions)). Click **Create key**.
  </Step>

  <Step title="Copy the key">
    Copy the key and store it securely. Pinecone says you cannot see the API key again after you close the dialog.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Go to **Connections → Pinecone**, paste the key into **PINECONE\_API\_KEY**, and click **Connect**. CloudThinker sets up the connection and shows a **Connected** status.
  </Step>
</Steps>

<Note>
  **Connected** means CloudThinker finished setting up the connection. Pinecone checks the key the first time an agent calls it, so a wrong or revoked key can still show **Connected**. Run the verify prompt below to confirm.
</Note>

## Connection details

| Field | Description | Example |
| - | - | - |
| **PINECONE\_API\_KEY** | API key for one Pinecone project | `<your-api-key>` |

A key belongs to one project, so one connection reaches the indexes of that project only.

## Required permissions

| Goal | Role to select | What Pinecone says it grants |
| - | - | - |
| Read only | **Project viewer** (`ProjectViewer`) | Read-only access to all resources and data |
| Also let agents create indexes and upsert records | **Project editor** (`ProjectEditor`) | Read and write access to all resources and data |

<Tip>
  Start with the read-only role. Pinecone notes that the Starter and Builder plans can set permissions to **All** only, so choosing a narrower role needs the Standard or Enterprise plan.
</Tip>

## Agent capabilities

Once connected, agents read your project and ask before they write.

| Capability | Description |
| - | - |
| **Index inventory** | List indexes, read an index's configuration, and see record counts and namespaces |
| **Search** | Search records in one integrated-embedding index by text, or across several indexes with deduplicated, reranked results |
| **Reranking** | Rerank documents you supply, without needing an index |
| **Writes (confirmation required)** | Create an integrated-embedding index and upsert records into a namespace |

Before any write, the agent shows the exact index name, namespace, embedding model, and records, then waits for your explicit confirmation.

### Verify the connection

```text theme={null}
List my Pinecone indexes and report each one's record count and namespaces
```

### Example prompts

```text theme={null}
Which Pinecone indexes use integrated embedding, and how many records does each namespace hold
Search the docs-search index for refund policy and show the five best matches with their scores
Upsert these three FAQ records into the faq namespace of docs-search, after showing me the exact records
```

## Troubleshooting

<Accordion title="Connected, but every request fails with 401">
  Pinecone returns 401 when the API key is missing or invalid. The key may be mistyped, deleted, or from a different project. Create a new key in the right project and update the connection.
</Accordion>

<Accordion title="The agent cannot search or write to one of my indexes">
  Pinecone supports only indexes with integrated embedding through this connection. An index built from vectors you generated with an external embedding model cannot be searched or written here.
</Accordion>

<Accordion title="A write was refused or never ran">
  Writes need a role with write access, such as **Project editor**, and your confirmation in the conversation. Check the key's permissions in the Pinecone console, then confirm the exact index, namespace, and records the agent shows.
</Accordion>

<Accordion title="Requests slow down or return 429">
  Pinecone returns 429 when requests are rate-limited. Wait a moment, then ask again.
</Accordion>

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Read-only role first** — a **Project viewer** key cannot write even if a request tries to.
- **One project per key** — create the key in the single project agents should read, and delete it in Pinecone when you remove the connection.

## Related

<CardGroup cols={2}>
  <Card title="OpenSearch Connection" icon="magnifying-glass-chart" href="/guide/connections/opensearch">
    Indexes, queries, and search relevance
  </Card>

  <Card title="Elasticsearch Connection" icon="https://mintcdn.com/cloudthinker/aLd-ttc-SCW-aFky/images/icons/elasticsearch.svg?fit=max&auto=format&n=aLd-ttc-SCW-aFky&q=85&s=c7389cfcd0bc8d303aeeb68bd19199ca" href="/guide/connections/elasticsearch" width="24" height="24" data-path="images/icons/elasticsearch.svg">
    Log analysis and search performance
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.