Prysm
// Module — Scripts

Write a script. Ship the API before lunch.

A JavaScript and TypeScript IDE inside PrysmOS — lint, format, and an outline of every function — running on a serverless runtime that starts with zero access. Publish any script as a public HTTP endpoint behind API keys, with OpenAPI docs that write themselves.

JS · TS
lint, format & outline
Serverless
sandboxed runtime
One click
to a public endpoint
API keys
auth done for you
// How it works

From editor to production endpoint in four moves

No repo, no deploy pipeline, no YAML. In PrysmOS the script is the service.

01

Write it in the IDE

JavaScript or TypeScript with lint, format, and a function outline. Autocomplete knows the whole prysm.* surface, so you rarely leave the editor.

02

It runs serverless

Every execution lands in a fresh sandboxed runtime with zero host access by default. You grant capabilities explicitly — nothing sneaks in.

03

Publish as an endpoint

One click and it's a public HTTP endpoint. Route on subpath and method inside one script — many routes, one file.

04

Keys, docs, done

Issue API keys, flip on per-endpoint controls, and hand consumers the auto-generated OpenAPI docs. Ship the API before lunch.

// Feature grid

A scripting surface that ships

Editor, runtime, gateway, and docs — the boring parts of running code in production, already done.

A real JS/TS IDE

Lint, format, and a symbol outline built in, with type-aware autocomplete for the whole prysm.* SDK and inline run output.

Serverless, sandboxed runtime

No servers to provision and no host access to abuse — each run is isolated, and capabilities are granted explicitly, scoped, and logged.

Public HTTP endpoints

Publish a script to a public URL and route on subpath and method — one script can host a whole API surface.

Per-endpoint controls

Allowed methods, CORS, IP allow/deny lists, rate limits, response caching with ETag, idempotency keys, and JSON-Schema request validation — configured per endpoint, not per prayer.

API-key authentication

Endpoints authenticate with API keys — scope them, expire them, revoke them. Least privilege is the default, not the aspiration.

OpenAPI docs, auto-written

Publish a script and the docs page writes itself — routes, request shape, response examples, auth requirements. Your consumers never wait on you.

A vetted npm allowlist

Import from a reviewed set of npm packages — the libraries you actually need, without opening the sandbox to the whole registry.

The prysm.* SDK

Spreadsheets, files, graphs, contracts, store, cache, http, notify, runs — the whole platform, callable from inside your script.

Honest budgets

Clear time and memory limits keep endpoints fast; long work goes to the background job queue instead of blocking a request.

// The prysm.* manifest

The whole platform, one namespace away

Everything a script can touch is capability-gated: each run starts with nothing, and each grant is explicit, scoped, and logged. Namespaced KV with TTLs, allowlisted http egress, and a vetted npm package allowlist included.

import { prysm } from "@prysm/sdk";15 namespaces · capability-gated
prysm.spreadsheetsThe grid, programmatically
list()read()search()create()write()update()delete()
prysm.contractsSchema & freshness rules
list()get()create()update()delete()
prysm.filesFiles in the workspace
list()get()create()update()delete()
prysm.graphsCharts & dashboards
list()get()create()update()delete()
prysm.connectionsExternal data sources
list()get()create()update()delete()
prysm.documentationDocs next to the data
list()get()create()update()delete()
prysm.storeNamespaced KV, with TTLs
get()set()incr()decr()compareAndSet()getMany()setMany()
prysm.httpAllowlisted egress — private IPs blocked
get()post()put()patch()delete()
prysm.cacheRun-scoped memoization
get()set()del()wrap()
prysm.secretsInjected, never logged
get()
prysm.utilThe toolbox
hash()hmac()uuid()slugify()csv()base64()sleep()retry()parallel()chunk()
prysm.notifyReach a human
send()
prysm.logStructured logs with redaction
debug()info()warn()error()
prysm.runsExecution history
list()get()replay()
prysm.scriptsCompose scripts
call()
every call is audited · secrets are redacted from logs · http egress is allowlist-only
// Running it

The ops surface is already there

Scheduling, queueing, versioning, testing, observing — the parts that turn a script into infrastructure.

Environments

Dev → staging → prod, with promotion approvals on the way up — so nothing reaches customers unreviewed.

Schedules

Cron, interval, and one-shot schedules with real timezones — plus a next-run preview in plain English.

Inbound webhooks

Give any service a URL that runs your script — the integration work that used to eat a sprint.

Background job queue

Long work goes to the queue with automatic retries, not into a second system you have to run.

Outbound hook deliveries

Fire events out with a delivery log you can actually read — see every attempt, not just the failures.

Multi-step workflows

Chain scripts into runs where each step's output feeds the next — orchestration without the orchestrator.

Version snapshots & diffs

Every publish is snapshotted. Diff any two versions side by side, restore in one click.

Test suites & benchmarks

Snapshot tests and benchmarks run before promotion — catch the regression before your users do.

Logs, metrics & replay

Every execution is searchable with metrics attached — replay any run to see exactly what happened.

Alert rules

Backtest an alert against run history before it ever pages you — signal, not noise.

Caching & idempotency

Response caching plus idempotency keys make client retries safe by construction.

Organization

Folders, tags, favorites, templates, and shared snippets — so the twentieth script is as tidy as the first.

// See it work

Twenty lines in. A URL out.

A publishable script in PrysmOS: route on input.subpath, touch the grid through the SDK, cache the answer, return JSON. The OpenAPI docs write themselves.

status.ts — published · public
// routes: GET /uptime · GET /health
export default async function run(input) {
const { subpath, method } = input;
 
if (method !== "GET") return { status: 405 };
 
// → GET /api/run/acme/status/uptime
if (subpath === "/uptime") {
const rows = await prysm.spreadsheets.read("ops-ledger", "checks!A2:D");
const up = rows.filter(r => r[3] === "ok").length;
const body = { uptime: up / rows.length, total: rows.length };
await prysm.cache.set("status:uptime", body, { ttl: 30 });
return { status: 200, body };
}
 
return { status: 404, body: { error: "unknown route" } };
}
runtime · v8 isolate · 64MBdeployed to prod · v14
Endpoint live
public
GET https://api.prysmhq.co/run/acme/status/uptime
status
200 OK
latency
41ms
key
read-only
Auto-generated docs
GET /uptime → 200 { uptime, total }
GET /health → 200 { ok: true }
auth: Bearer pk_live_… · cached 30s · rate 60/min
  • Per-endpoint methods, CORS, IP rules & rate limits
  • ETag response caching + idempotency keys for safe retries
  • JSON-Schema request validation, OpenAPI docs generated
  • Logs, metrics & replay on every execution
// In the wild

Small scripts, real infrastructure

Integrations

Webhook receiver

Stripe fires, your script catches it, validates the signature with prysm.util.hmac, writes a row to the grid, and pings the ops channel — all inside one isolate.

Reporting

Scheduled rollup

Every night at 02:00: SQL across three sources, dedupe, aggregate, write the summary sheet, drop the chart on the dashboard. Cron preview shows the next ten runs before you commit.

Platform

Public status API

A published endpoint that reads the ops ledger and returns uptime as JSON — cached for 30s, rate-limited by key, documented automatically. Your status page, minus the status page vendor.

// Questions

Fine print, answered

Nothing, until you grant it. Every run starts on the serverless runtime in a sandbox with zero host access — you grant capabilities explicitly: prysm.* namespaces, namespaced KV storage with TTLs, allowlisted http egress, and imports from a vetted npm package allowlist.

// One workspace

The glue code deserves better glue.

Ship the API before lunch: sandboxed by default, published in one click, documented automatically. Free to start — your first endpoint is twenty lines away.