Skip to content
Official MCP RegistryListed

org.brainkb/brainkb

MCP server for querying BrainKB, a knowledge base for neuroscience knowledge graphs.

First seen 2 Oct 2026. Evidence as of 2 Oct 2026.

55
Tools
From an anonymous probe
1
Source listings
Each with its own history
0
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
brainkb_activate_user(Admin) Activate a user's account (sets the JWT user active) by email.Not declared
brainkb_add_access_rule(Space manager) Restrict a space action to a subject. action: 'read' | 'write' | 'manage'. subject_type: 'global_role' (e.g. 'Admin','Lab Member') | 'member' (an email) | 'space_role' ('viewer'|'editor'|'owner', matched as >=). When rules exist for an action, only matching callers may perform it; the space owner and Admin/SuperAdmin always bypass (no lockout). Example: restrict writing to Admins -> action='write', subject_type='global_role', subject_value='Admin'.Not declared
brainkb_add_space_graphRegister a named graph and bind it to a space, so ingest/read on that graph are governed by the space's membership and visibility. Owner/editor only. The named_graph_iri is **globally unique** — one graph belongs to exactly one space. If it's already registered (to any space) the call returns 409; graph bindings are permanent (no unregister/delete).Not declared
brainkb_add_space_memberAdd/update a space member. role: 'owner' | 'editor' | 'viewer'. Owner only.Not declared
brainkb_assign_role(Admin) Assign a role/group to a user by email (e.g. 'Lab Member', 'External', or a custom group). The user must already have a profile (created on first login/registration). NOTE: assigning the 'Admin'/'SuperAdmin' role is SuperAdmin-only (hierarchy: SuperAdmin > Admin).Not declared
brainkb_available_roles(Admin) List the available roles/groups (Admin, Lab Member, Curator, …).Not declared
brainkb_ban_user(Admin) Ban a user by email (reversible; preserves history). This is how accounts are removed — there is NO hard delete. Banning an Admin is SuperAdmin-only; SuperAdmin accounts cannot be banned.Not declared
brainkb_capabilities(Admin only) Show a user's roles, effective capabilities, and delegated grants. Useful to check why someone can/can't create team spaces, ingest, etc.Not declared
brainkb_create_permission(Admin) Create a new usermanagement permission, e.g. name='dataset.export', resource='dataset', action='export'. Attach it to roles via the usermanagement role-permissions API.Not declared
brainkb_create_role(Admin) Create a new role/group — e.g. an 'External' collaborator group — which can then be assigned with brainkb_assign_role.Not declared
brainkb_create_spaceCreate a workspace/space. The caller becomes owner. slug: lowercase/hyphen id, **globally unique** — if it's already taken the call returns 409 (pick another slug; slugs are never reused/deleted). visibility: 'private' or 'public'; description: short human description (recommended — surfaces in the registry); space_type: 'individual' (a personal space — any write-capable role) or 'team' (a shared space — only Admin/SuperAdmin, or a user granted create_team_space).Not declared
brainkb_create_tokenGenerate a Personal Access Token (PAT) for browser-free auth. Requires you to be logged in already (brainkb_login or brainkb_globus_login). The token is shown ONCE and never again — copy it and set it as BRAINKB_TOKEN in your MCP/skill config; then no login or browser is needed until it expires. `name`: a label so you can tell tokens apart (e.g. 'laptop'). `days`: lifetime (default 90, server-capped). Treat the returned token like a password.Not declared
brainkb_deactivate_user(Admin) Deactivate a user's account by email.Not declared
brainkb_deltaThe exact triples a job added (its delta), as JSON-LD.Not declared
brainkb_delta_compareCompare two jobs' deltas: A-only / B-only / shared triple counts + triples.Not declared
brainkb_delta_historyA named graph's change history: one entry per ingest delta (job, triple count, timestamp), newest first.Not declared
brainkb_discard_uploadDelete one of your staged uploads without ingesting it.Not declared
brainkb_finish_loginComplete an OAuth login started with brainkb_globus_login by exchanging the one-time code shown in the browser for a session token. The code is single-use and never echoed back.Not declared
brainkb_globus_loginStart an OAuth login (Globus / ORCID / GitHub) for THIS session — use this instead of brainkb_login when the user signs in with Globus rather than a password. Returns a URL to open in a browser; after signing in, the page shows a short one-time code — pass it to brainkb_finish_login(code) to complete. (The browser step is unavoidable: only the user can consent at the provider.)Not declared
brainkb_grant_capability(Admin only) Delegate a capability to a user — e.g. 'create_team_space' or 'manage_team_space' so a Curator/Lab Member can create/manage team spaces. Grantable: create_private_space, create_team_space, manage_team_space, ingest, recover, read_private (NOT the admin-only 'grant'/'sparql_admin').Not declared
brainkb_grant_role_capability(Admin only) Grant a capability to a whole role/group so EVERY member gets it — e.g. give a custom group 'uk_collaborator' the 'ingest' or 'create_private_space' capability. Grantable: create_private_space, create_team_space, manage_team_space, ingest, recover, read_private (NOT the admin-only 'grant'/'sparql_admin'). Create the group first with brainkb_create_role, then assign it to users with brainkb_assign_role.Not declared
brainkb_ingest_filesIngest local RDF files (ttl/nt/nq/rdf/owl/jsonld/json) into a named graph. Returns a job_id; runs in the background — poll with brainkb_job_status.Not declared
brainkb_ingest_textIngest raw RDF text (Turtle / N-Triples / JSON-LD, auto-detected) into a named graph. Returns a job_id; ingestion runs in the background — poll with brainkb_job_status. The graph must be registered (see brainkb_add_space_graph) and the caller must have write access to its space. `sha256` / `expected_bytes` are an integrity contract, and you should use them whenever the RDF came from a file. Ingest is append-only — no delete for triples, no unregister for a graph — so RDF that arrives here mangled is permanent. Because `data` is a string, it passes through the caller's context, where dense Turtle is exactly what gets silently altered: ligatures, Greek letters, embedded newlines, escaped quotes. Declare the digest of the bytes you MEANT to send (`shasum -a 256 file.ttl`) and this refuses the write on any mismatch, turning an unrecoverable corruption into a clean rejection. Not declared
brainkb_ingest_uploadIngest a file you staged with `POST /upload` into a named graph. This is the route for a large local file: your HTTP client streams the bytes straight to this server over HTTPS, then you name the resulting upload_id here. The server reads its own staged copy and posts it to the ingest API internally, so the RDF never passes through a model's context — nothing to transcribe, no context-window ceiling, and no reason to split the document (splitting breaks blank-node identity and silently detaches triples, permanently). Stage a file with any HTTP client — the point is that the LIBRARY reads the file, so the bytes never pass through a model: import requests, hashlib, pathlib f = pathlib.Path("review.ttl") r = requests.post( "https://mcp.brainkb.org/upload", params={"filename": f.name, "sha256": hashlib.sha256(f.read_bytes()).hexdigest()}, headers={"Authorization": f"Bearer {TOKEN}"}, data=f.open("rb"), # streamed — never loaded into memory ) print(r.json()) # -> {"upload_id": "up_...", "state": "staged"} It returns an upload_id and the sha256 the server computed — compare it with your own before ingesting. Returns a job_id; poll brainkb_job_status, then reconcile brainkb_delta(job_id) against the triple count you expected. The staged copy is deleted once the ingest API has accepted the bytes. Not declared
brainkb_job_statusDetailed status of one ingest job: status, progress %, current file/stage, per-file failures, and (when complete) a summary.Not declared
brainkb_list_access_rulesList a space's fine-grained access rules (member/manager of the space).Not declared
brainkb_list_capabilities(Admin only) Catalog of all KG capabilities, which are delegatable ('grantable'), which are admin-only, and a description of each. Use this to see the available permission options before granting to a user or group/role.Not declared
brainkb_list_jobsList the user's ingest jobs (newest first) with status and progress.Not declared
brainkb_list_permissions(Admin) List all usermanagement permissions (resource/action pairs used for page-access and role-permission mapping). These are the addable 'permission' options; KG action-capabilities are listed by brainkb_list_capabilities.Not declared
brainkb_list_registered_graphsList registered named graphs visible to the caller (private-space graphs the caller can't access are hidden).Not declared
brainkb_list_spacesList spaces the user can see (their own/member spaces + public ones), each annotated with THIS caller's permission so you know what they may do: - your_role: 'owner' | 'editor' | 'viewer' | null (their space membership) - is_owner: they own the space - access: 'owner' | 'member' | 'public' (how it's available to them) - can_write: their space role permits ingest (owner/editor) — a real ingest also needs the 'ingest' capability + any per-space access rules. Use this to tell the user which spaces they can read vs. write vs. only see as public.Not declared
brainkb_list_tokensList your Personal Access Tokens (metadata only — the secret is never shown): id, name, prefix, created/last-used/expiry, and whether each is active/revoked/expired. Use the id with brainkb_revoke_token.Not declared
brainkb_list_uploadsList RDF files YOU have staged with POST /upload but not yet ingested. Shows each upload_id, its size, sha256 and when it expires. Only your own uploads are visible.Not declared
brainkb_list_users(Admin) List users (profiles) — filter by `q` (name/email/orcid) or `role`. Shows profile_id, email, roles, providers, ban status.Not declared
brainkb_loginAuthenticate to BrainKB with the user's credentials and cache the JWT for THIS session only (isolated per caller). The password/token are never echoed. Uses single sign-on: one login mints a refresh token, cached for THIS session, which is exchanged on demand for per-service access tokens (query_service, usermanagement, …). Falls back to a legacy per-service token if the backend has no SSO. On the hosted multi-user remote you can skip this and instead have your client send an 'Authorization: Bearer <token>' header (a refresh token unlocks all services).Not declared
brainkb_logoutForget the cached token for this session.Not declared
brainkb_provenance_graphPROV-O ingestion/activity history (JSON-LD) for a named graph.Not declared
brainkb_provenance_jobPROV-O provenance bundle (JSON-LD) for one ingest job.Not declared
brainkb_qa_listFind a canned question BrainKB can answer, then run it with brainkb_qa_run. Prefer these over writing SPARQL: they are vetted against BrainKB's actual vocabulary. Discovery is two steps, so you never read every query at once: 1. brainkb_qa_list() -> the menu: each category's name, a description of the questions it covers, and how many queries it has. Pick the category whose description matches the user's question. 2. brainkb_qa_list(category="<name>") -> that category's queries. Each has `question` (what it answers), `notes` (when to use it, where parameter values come from, what the results mean), `params` (required ones have no default — ask the user rather than guess) and a working `example`. `search="words"` filters queries by words in their id/question/notes; use it alone to search every category when none of the descriptions fits. Not declared
brainkb_qa_runRun a canned question from brainkb_qa_list by id. `params` maps parameter names to values; they are validated and escaped, never spliced in raw. Runs through the same SPARQL endpoint as brainkb_sparql, so it needs the same role.Not declared
brainkb_read_spaceRead all RDF (JSON-LD) in a space's graphs. Public spaces are readable by anyone; private spaces require membership.Not declared
brainkb_recover_jobAttempt to recover a stuck/errored ingest job (marks it recoverable/errored).Not declared
brainkb_remove_access_rule(Space manager) Delete a fine-grained access rule by its id (see brainkb_list_access_rules).Not declared
brainkb_remove_role(Admin) Remove a role/group from a user by email.Not declared
brainkb_revoke_capability(Admin only) Revoke a previously granted capability from a user.Not declared
brainkb_revoke_role_capability(Admin only) Revoke a capability from a role/group.Not declared
brainkb_revoke_tokenRevoke one of your Personal Access Tokens by id (see brainkb_list_tokens). Takes effect immediately — the next call using that token fails.Not declared
brainkb_role_capabilities(Admin only) List the capabilities granted to a role/group (e.g. 'uk_collaborator', 'Lab Member').Not declared
brainkb_searchFull-text search over the knowledge graphs, access-filtered by space visibility. Pass `space` to scope to one workspace, omit for a full search. Anonymous/other users never see private-space data.Not declared
brainkb_set_space_visibilitySet a space 'public' (anyone, even anonymous, can read) or 'private' (members only). Owner only.Not declared
brainkb_sparqlRun an arbitrary SPARQL query. Requires an Admin/SuperAdmin role (the sparql_admin capability) — for ordinary questions prefer brainkb_search, brainkb_read_space, or the provenance/delta tools, which need no admin role.Not declared
brainkb_unban_user(Admin) Lift a ban on a user by email.Not declared
brainkb_upload_statusState of one of your staged/submitted uploads. `state` is `staged` (waiting for brainkb_ingest_upload), `submitting` (the server is streaming it to the ingest API), `submitted` (accepted — `job_id` is set, poll brainkb_job_status) or `failed` (the staged bytes were KEPT, so retry with brainkb_ingest_upload rather than re-uploading).Not declared
brainkb_use_tokenUse a Personal Access Token (brainkb_pat_...) for THIS session — an alternative to setting BRAINKB_TOKEN in the config. Validates the token, then caches it so subsequent calls authenticate with it. The token is never echoed.Not declared
brainkb_whoamiReport the current caller's auth state (email, authenticated, and when the cached session expires). When signed in it also returns base_url — the backend THIS SERVER talks to, which on a hosted deployment is an internal address and says nothing about the caller's own machine.Not declared

Change history

No changes since the first observation. The first snapshot is the baseline.

Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registryorg.brainkb/brainkb2 Oct 20262 Oct 20261