AI READY

Give your AI agents a graph.

The Galactus DB MCP server connects AI assistants and agents to your graph through the Model Context Protocol. They read the schema, run Cypher and look things up in the documentation, signed in as a database user you choose. Their roles decide what they can do.

0.1 early access · ianknowles/galactus-db-mcp on Docker Hub

An agent asks your graphMCP
read-cypher
{
  "query": "MATCH (p:Person)-[:ACTED_IN]->
            (m:Movie {title: $title})
            RETURN p.name AS actor",
  "params": {"title": "The Matrix"}
}
RESULTKeanu Reeves, Carrie-Anne Moss, …
Set up the MCP server
11Tools for schema, Cypher, docs and operations
1 MBDocker image, Linux AMD64 and ARM64
Your rolesChecked by the database on every call

Graphs give AI the context.

Answers are better when an agent can follow the links: from a document to the people it mentions, from a customer to what they bought, from an alert to the systems behind it.

It learns your data first

One call returns the labels, relationship types, property types and connecting patterns, with counts. The agent writes Cypher for the graph you have, not one it imagines.

It checks before it guesses

The documentation is built into the server. Agents search it for a function or procedure and read what Galactus DB supports before writing a query.

It follows the relationships

Vector search finds a starting point and Cypher follows the graph from there, so retrieval returns the surrounding context and its sources, not isolated text.

The tools.

Each person or agent sees only the tools their database privileges can use. The read and write tools use the same names as Neo4j's MCP server, so existing prompts keep working.

get-schema

Every user who can read

Labels and relationship types with counts, property types, the patterns that connect them, and every index and constraint, in one call.

read-cypher

Every user who can read

Runs Cypher in a read transaction, so the database refuses any write, whatever the query says.

explain-cypher

Every user who can read

Shows the plan for a query without running it, so an agent can check that it uses an index.

write-cypher

Users who can write

Runs one statement in its own transaction. Hidden from read-only users and on read-only servers.

list-docs, search-docs, read-doc

Everyone

The Galactus DB documentation, built in. Agents check what is supported before relying on Neo4j habits.

list-databases

Every signed-in user

The databases you can use, your home database, and whether you can read, write or change each schema.

list-queries, terminate-query

Every signed-in user

See running queries and stop one. Users see their own; administrators see everyone's.

admin-cypher

Administrators, when enabled

Users, roles, privileges and databases. Off unless the server is started with admin tools enabled.

Security comes from the database.

The MCP server has no database identity of its own. Every call signs in as the person or agent using it, and Galactus DB checks their roles on every statement. Hiding a tool tidies the list; it is never the protection.

  • Read tools run in a read transaction, so the engine refuses writes
  • Give an agent the reader role and it can only read
  • A time limit on every statement, with rollback when it passes
  • Row and size limits keep results within a context window
  • Browser origins refused unless you allow them
  • An audit line for every call, without query text or passwords
Users, roles and privileges
YOUR AI AGENTAny MCP client
↓ MCP over stdio or HTTP · the agent's own login
GALACTUS DB MCPSchema · Cypher · docs · operations
↓ Bolt · as that user
GALACTUS DBRoles checked on every statement

Connect an agent.

Run one shared server over HTTP next to your database, or let a desktop client start its own over stdio. Both use the same image.

Shared HTTP serverDOCKER
docker run -d --name galactus-db-mcp \
  --network <your-gdb-network> \
  -e GDB_URI=bolt://gdb:7687 \
  -p 127.0.0.1:7688:7688 \
  ianknowles/galactus-db-mcp
ENDPOINThttp://127.0.0.1:7688/mcp
Each person signs inCLAUDE CODE
claude mcp add --transport http \
  galactus-db http://127.0.0.1:7688/mcp \
  --header "Authorization: Basic \
  $(printf 'agent:password' | base64)"
AUTHTheir Galactus DB user
Desktop client, stdioJSON
"galactus-db": {
  "command": "docker",
  "args": ["run", "-i", "--rm",
    "-e", "GDB_MCP_TRANSPORT=stdio",
    "-e", "GDB_URI", "-e", "GDB_USER",
    "-e", "GDB_PASSWORD",
    "ianknowles/galactus-db-mcp"]
}
ENVGDB_URI, GDB_USER, GDB_PASSWORD

Details

What is MCP?

The Model Context Protocol is an open standard that lets AI applications use external tools and data. An MCP server describes its tools; the AI client decides when to call them. Any client that supports MCP over stdio or streamable HTTP can use Galactus DB.

Do I need a licence for it?

No. The MCP server needs no licence of its own and works with the free Developer edition. Your database edition's limits still apply.

Can an agent damage my data?

Only as far as its database user allows. Create a user for each agent with the least privilege it needs: with the reader role it sees only the read, documentation and operations tools, and the database refuses its writes. Start the server with --read-only to remove writing for everyone.

Text stored in your graph can contain instructions an agent might follow. Least-privilege users are the defence; no tool list can prevent that.

How are passwords and connections protected?

Over HTTP, every request carries the caller's Galactus DB credentials and the server keeps no session. The endpoint has no TLS of its own: keep it on 127.0.0.1 or a private network, or put it behind a TLS reverse proxy. The connection from the MCP server to the database is plain Bolt in this release, so run them side by side.

What is not included yet?

Version 0.1 offers tools only, without MCP resources or prompts. It signs in with a username and password, not OAuth or API tokens, and opens a new database connection for each call. Planned next: TLS to the database and on the endpoint, a limit on failed sign-ins, and tools for vector search, graph algorithms and index advice.

Put your graph to work for AI.

Start Galactus DB with the free Developer edition, then connect the MCP server.