It learns your data first
One call returns the labels, relationship types, property types and connecting patterns, with counts. The agent writes Cypher for the graph you have, not one it imagines.
The Galactus DB MCP server connects AI assistants and agents to your graph through the Model Context Protocol. They read the schema, run Cypher and look things up in the documentation, signed in as a database user you choose. Their roles decide what they can do.
0.1 early access · ianknowles/galactus-db-mcp on Docker Hub
read-cypher
{
"query": "MATCH (p:Person)-[:ACTED_IN]->
(m:Movie {title: $title})
RETURN p.name AS actor",
"params": {"title": "The Matrix"}
}Keanu Reeves, Carrie-Anne Moss, …Answers are better when an agent can follow the links: from a document to the people it mentions, from a customer to what they bought, from an alert to the systems behind it.
One call returns the labels, relationship types, property types and connecting patterns, with counts. The agent writes Cypher for the graph you have, not one it imagines.
The documentation is built into the server. Agents search it for a function or procedure and read what Galactus DB supports before writing a query.
Vector search finds a starting point and Cypher follows the graph from there, so retrieval returns the surrounding context and its sources, not isolated text.
Each person or agent sees only the tools their database privileges can use. The read and write tools use the same names as Neo4j's MCP server, so existing prompts keep working.
get-schemaEvery user who can read
Labels and relationship types with counts, property types, the patterns that connect them, and every index and constraint, in one call.
read-cypherEvery user who can read
Runs Cypher in a read transaction, so the database refuses any write, whatever the query says.
explain-cypherEvery user who can read
Shows the plan for a query without running it, so an agent can check that it uses an index.
write-cypherUsers who can write
Runs one statement in its own transaction. Hidden from read-only users and on read-only servers.
list-docs, search-docs, read-docEveryone
The Galactus DB documentation, built in. Agents check what is supported before relying on Neo4j habits.
list-databasesEvery signed-in user
The databases you can use, your home database, and whether you can read, write or change each schema.
list-queries, terminate-queryEvery signed-in user
See running queries and stop one. Users see their own; administrators see everyone's.
admin-cypherAdministrators, when enabled
Users, roles, privileges and databases. Off unless the server is started with admin tools enabled.
The MCP server has no database identity of its own. Every call signs in as the person or agent using it, and Galactus DB checks their roles on every statement. Hiding a tool tidies the list; it is never the protection.
Run one shared server over HTTP next to your database, or let a desktop client start its own over stdio. Both use the same image.
docker run -d --name galactus-db-mcp \
--network <your-gdb-network> \
-e GDB_URI=bolt://gdb:7687 \
-p 127.0.0.1:7688:7688 \
ianknowles/galactus-db-mcphttp://127.0.0.1:7688/mcpclaude mcp add --transport http \
galactus-db http://127.0.0.1:7688/mcp \
--header "Authorization: Basic \
$(printf 'agent:password' | base64)"Their Galactus DB user"galactus-db": {
"command": "docker",
"args": ["run", "-i", "--rm",
"-e", "GDB_MCP_TRANSPORT=stdio",
"-e", "GDB_URI", "-e", "GDB_USER",
"-e", "GDB_PASSWORD",
"ianknowles/galactus-db-mcp"]
}GDB_URI, GDB_USER, GDB_PASSWORDThe Model Context Protocol is an open standard that lets AI applications use external tools and data. An MCP server describes its tools; the AI client decides when to call them. Any client that supports MCP over stdio or streamable HTTP can use Galactus DB.
No. The MCP server needs no licence of its own and works with the free Developer edition. Your database edition's limits still apply.
Only as far as its database user allows. Create a user for each agent with the least privilege it needs: with the reader role it sees only the read, documentation and operations tools, and the database refuses its writes. Start the server with --read-only to remove writing for everyone.
Text stored in your graph can contain instructions an agent might follow. Least-privilege users are the defence; no tool list can prevent that.
Over HTTP, every request carries the caller's Galactus DB credentials and the server keeps no session. The endpoint has no TLS of its own: keep it on 127.0.0.1 or a private network, or put it behind a TLS reverse proxy. The connection from the MCP server to the database is plain Bolt in this release, so run them side by side.
Version 0.1 offers tools only, without MCP resources or prompts. It signs in with a username and password, not OAuth or API tokens, and opens a new database connection for each call. Planned next: TLS to the database and on the endpoint, a limit on failed sign-ins, and tools for vector search, graph algorithms and index advice.
Start Galactus DB with the free Developer edition, then connect the MCP server.