AI-operated backends

Run your project through an AI assistant: model data, change records and build workflows over MCP and the CLI, with permissions and scoped API keys as the guardrail.

Last updated

An AI assistant can do most of what you do in the Anythink dashboard. It can create entities and fields, read and write records, build workflows and read their job history. It does this through the same CLI and REST API you'd use yourself, so it's bound by the same permissions. That's what makes it practical to hand real work to an assistant: the assistant is as capable as the identity you give it, and no more.

This page is about running a project that way. It shows the two ways to work with an assistant, how to give it exactly the access a job needs, and a worked example that builds a feature, then switches to a read-only key to check the result. Each step shows the Anythink dashboard, the CLI and an AI assistant (MCP).

If you haven't used Anythink before, read Core concepts first.

Who it's for and what you'll build#

This is for a developer or small team who'd rather describe a change than click through it: set up a data model from a brief, seed test data, build an automation, answer "what happened to this job?", or audit who can do what. You stay in charge. You decide what the assistant can touch and you read what it plans to run.

You want to Use Guide
Ask questions and make quick changes while you're in the dashboard The AI chat panel Chat with your backend data using AI
Work on your code and your backend together, from your editor The MCP server in Claude Code, Claude Desktop or Cursor Connect Claude to your backend with MCP
Limit what an assistant can read or change A scoped API key, or a role with narrow permissions API keys
Reuse a proven prompt Seven worked prompts, with the commands they run AI assistant recipes for your backend

How an assistant works on your project#

There are two entry points, and both act as you.

  • The AI chat is the AI panel in the Anythink dashboard. You type, the model calls tools, and the panel streams the answer. It needs nothing installed. It can run a set of CLI commands: entities, fields, data, workflows, users and roles (list and get), secrets, files, fetch and docs. Only Claude models call tools, so only Claude can look at or change your data.
  • The MCP server, anythink-mcp, runs on your machine and your assistant launches it. Its cli tool runs your installed anythink command, so the assistant can run any CLI command you could, including integrations, menus, payments and migrations.

Neither has permissions of its own. A tool call succeeds only if the signed-in user, or the API key you connected with, could make the same request with the CLI or REST API. Anything else returns 403. Row-level security applies too. How AI chat and MCP work has the full picture.

Note: The AI chat can act, not just answer. A tool call runs as soon as the model makes it, and the panel doesn't stop to ask first. Treat it like giving someone your keyboard: ask it to explain a change before it makes one, and sign in with a narrower role when the chat is for people who shouldn't delete things.

Step 1: Connect an assistant to a project#

Install the CLI and the MCP server, then register the server with your client. Homebrew installs both.

In the Anythink dashboard

You don't need to install anything to use the AI chat. Select the bot icon (Open AI panel) in the header. To pick the model and whether Anythink or your own provider key pays for it, go to Settings, then AI Settings.

For MCP, the dashboard's part is credentials. Open My Account, select the API Keys tab and create a key for the assistant, as step 2 shows.

With the CLI

bash
brew install anythink-cloud/tap/anythink
claude mcp add anythink anythink-mcp
anythink login
anythink accounts use <account-id>
anythink projects use <project-name>

anythink login signs you in from your terminal, so your password never passes through the conversation with the model. projects use makes one project the active profile, and the MCP server uses it. For Cursor, Claude Desktop and other clients, and for the npm and .NET installs, see Connect Claude to your backend with MCP.

With an AI assistant (MCP)

text
Show me which Anythink project you're connected to, then list every entity in it and the fields on each.

The assistant reads the active profile, then runs entities list and entities get through the cli tool. If it can't see a project, sign in from your terminal as above and ask again.

Step 2: Give it only the access the job needs#

The strongest guardrail is the identity the assistant uses. Create an API key that holds only the permissions the task needs, and save it as its own CLI profile. A key can only hold permissions its creator holds, and its value is shown once.

Permission names follow entity:action: orders:read, orders:create, orders:update, orders:delete. Platform features have their own, such as anythink_workflows:read. Permissions reference lists them all.

In the Anythink dashboard

  1. Open My Account and select the API Keys tab.
  2. Enter a Name that says what the key is for, for example assistant-readonly.
  3. Choose Expires in (days). Pick the shortest you can live with.
  4. Under Permissions, select only :read permissions for the entities the assistant should see. Platform permissions are under Anythink Permissions.
  5. Select Create API Key and copy the key into your secret store. It's shown once.

With the CLI

bash
anythink api-keys create assistant-readonly \
  --permissions orders:read,customers:read,anythink_workflows:read \
  --expires-in 30 \
  --save-as assistant-readonly \
  --yes

With --save-as, the CLI stores the key in a new profile and never prints it. Use the profile for one command with anythink --profile assistant-readonly <command>, or pin an MCP client to it with --profile in the server's arguments, as Connect Claude to your backend with MCP shows. To sign in with a key you already have, run anythink login --org-id <org-id> --api-key <api-key> in a terminal.

With an AI assistant (MCP)

Create the key yourself, in the dashboard or your terminal. Keys the assistant creates pass through the chat, and the dashboard's AI chat can't create them at all. Once the profile exists, tell the assistant to use it:

text
Use the assistant-readonly profile. Summarise this week's orders by status.

For people rather than assistants, the same idea applies to roles. Role permissions are granted in the Anythink dashboard under Roles, so a teammate who uses the AI chat gets only what their role allows.

Step 3: Let it build, and review each write#

When you do want the assistant to change things, give it a clear brief and make it show its work first. This prompt builds a small feature, ending in a workflow, in a test project.

In the Anythink dashboard

  1. Open the AI panel and send:
text
Show me the commands first, then wait. Then create an entity called feedback with a required text field message and an integer field rating. Add a workflow that runs when a feedback record is created with a rating of 2 or less.
  1. The panel doesn't wait for approval. If you want to approve a change before it's made, ask for a plan first, read it, then tell the model to go ahead.

With the CLI

This is what the assistant runs. You can run the same commands yourself, or paste them to review:

bash
anythink entities create feedback
anythink fields add feedback message --type text --required
anythink fields add feedback rating --type integer
anythink workflows create low-rating-feedback \
  --trigger Event --event EntityCreated --entity feedback \
  --filter '{"field":"rating","op":"lte","value":2}' \
  --enabled

With an AI assistant (MCP)

text
Show me the commands you'll run before you run them. Then create an entity called feedback with a required text field message and an integer field rating, and a workflow that runs when a feedback record is created with a rating of 2 or less.

Most MCP clients show each cli call and ask before running it. Read create, update and delete commands before you approve them. A delete can't be undone.

A few habits keep this safe:

  • Ask for a plan first. Add "show me the commands before you run them" to anything that changes data, and "read the records first" to anything that fixes them.
  • Use a test project for new ideas. Try it where you can throw the result away, then repeat it where it matters.
  • Check the numbers. The model does the counting and the arithmetic, so check any figure that feeds billing or reporting.

Step 4: Check the result with a read-only key#

Switch to the read-only profile from step 2 to confirm what the assistant did, and to confirm it can't go further. Reads work. Writes return 403.

In the Anythink dashboard

Open Workflows, select the new workflow and open View Job History. Open feedback in the data view to see the records. To act as a narrower identity in the dashboard, sign in as a user whose role only holds :read permissions.

With the CLI

bash
anythink --profile assistant-readonly workflows get <workflow_id>
anythink --profile assistant-readonly workflows jobs <workflow_id>
anythink --profile assistant-readonly data list orders
anythink --profile assistant-readonly data create orders --data '{"status":"paid"}'

The first three read and succeed. The last is refused with API error (403), because the key has no orders:create. Nothing is written.

With an AI assistant (MCP)

text
Use the assistant-readonly profile. Show me the recent jobs for the low-rating-feedback workflow and tell me why any failed. Don't change anything.

The assistant runs workflows get and workflows jobs through the cli tool. If it tries a write, the project refuses it, whatever the prompt says.

When a job is finished with, revoke its key. Find the key's id with anythink api-keys list, then run anythink api-keys revoke <id> --yes.

Step 5: Keep it auditable#

Ask the assistant to report on access itself, read only:

text
Audit access to this project. Read only, change nothing. Which roles can delete entities or read secrets? Which users hold those roles? Which API keys are still valid?

It runs roles list, roles permissions list, users list and api-keys list, all of which only read. api-keys list shows each key's name, how many permissions it holds, its expiry and its status, and never the key. Make any change the audit suggests in the Anythink dashboard under Roles, or with a command you've read, and run the audit again. AI assistant recipes for your backend has this recipe with sample output, and six others.

What you get, and the limits#

What you get

  • An assistant that can model data, change records, build and debug workflows and audit access, from your editor or from the Anythink dashboard.
  • One permission model. The assistant has no powers of its own, so a scoped key or a narrow role limits it as it limits any other caller.
  • Credentials you control. You sign in and create keys in your terminal or the dashboard, so passwords and key values stay out of the conversation.
  • The same commands everywhere. Anything the assistant runs is a CLI command you can read, rerun and keep in a script.

Limits to plan around

  • The AI chat doesn't ask first. A tool call runs as soon as the model makes it, up to 10 tool rounds per message. Narrow permissions are the guardrail, not the panel.
  • Only Claude calls tools. OpenAI, Grok and Gemini models chat without access to your data.
  • The dashboard chat runs a subset of commands. Integrations, menus, payments, migrations and search run only through a local MCP server.
  • MCP runs on your machine. The server is local, over stdio. There's no hosted MCP endpoint to add as a remote connector.
  • An assistant can delete. With the permission, it can delete entities, records and workflows, and a delete can't be undone. Review writes, and use :read keys for look-only work.
  • A key can't exceed its creator. A permission you don't hold is dropped when you create the key. Check the key's permission count afterwards.
  • Workflows run as a trusted service. An assistant that can edit workflows can build one that reads any data in the project. Hold anythink_workflows:create, :update, :delete and :trigger back from anything you wouldn't trust with that. See How workflows work.
  • AI tokens are metered. Anythink AI mode draws on your plan's allowance and stops when it runs out. Bring Your Own Key doesn't use it. See Limits and quotas.

Next steps#