auth-security
Best practices for implementing JWT, API Keys, OAuth 2.1, and RBAC in a NitroStack application.
Decision and migration guide for Prisma ORM MongoDB projects on v6, which have no upgrade path to v7. Use when a MongoDB project asks about upgrading Prisma, when "upgrade to prisma 7" comes up in a project with provider = "mongodb", or when evaluating a move to Prisma Next.
$ npx -y skills add nitrocloudofficial/nitrostack --skill prisma-mongodb-upgrade --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/prisma-mongodb-upgradeContext preview
The summary Claude sees to decide when to auto-load this skill.
Decision and migration guide for Prisma ORM MongoDB projects on v6, which have no upgrade path to v7. Use when a MongoDB project asks about upgrading Prisma, when "upgrade to prisma 7" comes up in a project with provider = "mongodb", or when evaluating a move to Prisma Next.
name: prisma-mongodb-upgrade description: Decision and migration guide for Prisma ORM MongoDB projects on v6, which have no upgrade path to v7. Use when a MongoDB project asks about upgrading Prisma, when "upgrade to prisma 7" comes up in a project with provider = "mongodb", or when evaluating a move to Prisma Next. Triggers on "upgrade prisma mongodb", "prisma 7 mongodb", "mongodb prisma migration", "prisma next mongodb". license: MIT metadata: author: prisma version: "0.1.0"
MongoDB projects are the one Prisma cohort with no road into Prisma 7: **v6 is the terminal classic-ORM major for MongoDB, and v7 never ships a MongoDB connector**. The successor path is [Prisma Next](https://github.com/prisma/prisma-next), where MongoDB support is in Early Access with GA planned after Postgres. This skill frames the real decision — migrate to Prisma Next (the encouraged path), or stay on v6 where a hard blocker applies — and carries the migration mechanics.
**Never do either of these:**
there. The `prisma-upgrade-v7` guide does not apply to MongoDB projects.
database engine is a separate, much larger decision that is not yours to make implicitly.
| Version | MongoDB status | |---------|----------------| | Prisma ORM v6 | Fully supported (`mongodb` provider); latest 6.x is the current stable path; maintenance line | | Prisma ORM v7 | **No MongoDB connector — not an option, ever** | | Prisma Next | MongoDB support in **Early Access**, actively developed, GA planned after Postgres — the successor path for MongoDB projects |
**Migrating to Prisma Next is the encouraged path.** MongoDB support in Prisma Next is Early Access: functional and moving quickly, with GA planned after Postgres — and the Prisma team wants MongoDB users to migrate early and share feedback. The migration mechanics are detailed in the references.
**Staying on the latest v6 remains a legitimate choice where a hard blocker applies** — stated plainly: the Next Mongo façade does not wrap transactions yet (the underlying driver is available directly; this is expected to change soon), and pre-1.0 minors can carry breaking changes with published upgrade recipes.
| Signal | Direction | |--------|-----------| | No blockers below apply | Migrate to Next; run the `verify-cutover-checklist` and share feedback with the Prisma team | | Greenfield / prototype / internal tool | Migrate to Next | | Codebase uses multi-document transactions (`$transaction`) — check with grep, do not ask | Plan raw-driver session equivalents first (see `client-api-mapping`), or stay on v6 until the façade wrapper lands | | Team cannot absorb pre-1.0 breaking upgrades between minors | Stay on v6 until GA | | Risk-averse but interested | Run a staged Next round-trip on a copy (see `verify-cutover-checklist`), then migrate |
Note: the transactions gap is expected to close soon — this section will be updated when façade transactions merge in Prisma Next.
workflow, no SQL driver adapters (see `prisma-database-setup` for the v6 MongoDB shape).
| Reference | What it covers | |-----------|----------------| | `references/decision-stay-or-migrate.md` | The full decision framing, blocker checks, and stay-hygiene detail | | `references/schema-contract-mapping.md` | v6 schema (`mongodb` provider, `@db.ObjectId`, composite types) → Next contract concepts | | `references/client-api-mapping.md` | v6 client calls → Next equivalents, incl. raw escape hatches and transactions — names map, parity does not | | `references/migrations-mapping.md` | v6 `db push`-only story → Next's plan/migrate/verify/sign flow | | `references/verify-cutover-checklist.md` | No-data-moves verification: same DB, index parity, staged round-trip before cutover |
Behavioral claims about Prisma Next in this skill were verified against [prisma/prisma-next](https://github.com/prisma/prisma-next) at commit `a2791c5dd59d579b4b3052942ae7f8fe5e2ee852` (pre-1.0, ~v0.14/0.15 line). Prisma Next moves quickly in Early Access: **before acting on any Next-side claim, verify it against the version actually installed** (check the project's `@prisma-next/*` versions and the prisma-next skills installed with it). Next's Mongo target requires MongoDB 8.0+ and expects `mongodb@^7` as a user-supplied peer dependency.
This skill is the **discovery bridge**, not a replacement for Prisma Next's own documentation. After a project switches to Prisma Next, run Prisma Next's `init`/skill installation and follow its own skills (quickstart, contract, queries, migrations, runtime) for day-to-day work — do not keep working from this skill's summaries.
The full-stack TypeScript framework to build, test, and deploy production-ready MCP servers and AI-native apps.
Repo: nitrocloudofficial/nitrostack
Best practices for implementing JWT, API Keys, OAuth 2.1, and RBAC in a NitroStack application.
Best practices and guidelines for bootstrapping, defining modules, using dependency injection, managing server lifecycles, and handling events in the…
Best practices for implementing and applying Guards, Interceptors, Middleware, Pipes, and Exception Filters in the NitroStack SDK.
Guidelines and patterns for defining Tools, Resources, and Prompts in a NitroStack application with schema validation via Zod, including caching,…
Best practices for linking tools to interactive frontend widgets using @Widget and @nitrostack/widgets SDK (including state sync, tool calling, display modes,…
Prisma ORM CLI commands reference covering init, generate, migrate, db, dev, studio, validate, format, debug, and mcp. Use for ORM/database CLI workflows, not…