Prisma Guard is the ultimate companion for Prisma, bridging the gap between database models, runtime safety, and API validation. Traditional database workflows force developers to manually sanitize inputs, coordinate maintenance windows, and duplicate schema validation logic. Prisma Guard solves this with two complementary, zero-config layers: a lightweight Prisma Client query extension that silently strips unmapped fields and enforces operational policies at runtime, and a high-performance CLI code generator that transforms Prisma schemas into decorated, multi-tier Zod validation schemas.
At runtime, Prisma Guard safeguards your database against accidental mutations, schema poisoning, and downtime. It automatically strips unmapped extra fields from writes (create, update, upsert) with zero-overhead memoized whitelists running at an astounding 2.21 microseconds per query (benchmarked over 100,000 iterations). It introduces a declarative Maintenance & Read-Only Mode (maintenance: { enabled, exclude, messages }) with sync/async resolvers (e.g. Redis flags) and model exemptions (e.g. AuditLog, Session), instantly protecting database integrity during migrations. In addition, fine-grained Operation Guards (operations: { create, update, delete, upsert, write }) allow developers to intercept mutations, enforce business rules, or forbid hard deletions on sensitive tables, throwing typed PrismaGuardMaintenanceError (HTTP 503) and PrismaGuardOperationBlockedError (HTTP 403).
The CLI code generator automatically produces dual schema sets for every model by default (skipScalar: false): Public Schemas (respecting omissions, ideal for client-facing API requests) and Scalar Schemas (preserving all database fields intact, ideal for internal service layers and queues). It exports seven strongly-typed variants per model — including Create, Input, Update, Scalar, ScalarInput, ScalarUpdate, and the game-changing CreateRequired (which omits auto-generated IDs and @default timestamps while requiring internal tenant fields). Standard numeric types (Int, Float) feature automatic coercion via z.coerce.number(), decimal fields support precision regex validation with range refinements, and circular relations are safely handled via z.lazy().
Schemas can be customized directly within Prisma files using triple-slash comments: field-level constraints (/// @zod.email(), /// @zod.min().max()), multi-line checks (/// @zod.create.check(...)), opt-in relation inclusions (/// @zod.include), and Virtual Fields (/// @zod.add confirmPassword: z.string()) for API-only properties like password confirmations or terms agreements. Global behaviors are governed by defineConfig() — supporting autoTrim, date/ID omissions (omitDates, omitIds), custom type maps, and centralized, customizable error message dictionaries. Prisma Guard auto-manages .gitignore, runs Prettier formatting, integrates with CI/CD pipelines, and generates native VS Code snippets (npx prisma-guard metadata --vscode) for an effortless local developer experience.