MCP server for querying BrainKB, a knowledge base for neuroscience knowledge graphs.
healthy
status
53
tools exposed
1728ms
connect latency
26c63cb595cc
schema fingerprint
Tools (53)
brainkb_login
Authenticate to BrainKB with the user's credentials and cache the JWT for
THIS session only (isolated per caller). The password/token are never echoed.
Uses single sign-on: one login mints a refresh token, cached for THIS session,
which is exchanged on demand for per-service access toke
brainkb_globus_login
Start an OAuth login (Globus / ORCID / GitHub) for THIS session — use this
instead of brainkb_login when the user signs in with Globus rather than a
password. Returns a URL to open in a browser; after signing in, the page shows
a short one-time code — pass it to brainkb_finish_login(code
brainkb_finish_login
Complete an OAuth login started with brainkb_globus_login by exchanging the
one-time code shown in the browser for a session token. The code is single-use
and never echoed back.
brainkb_logout
Forget the cached token for this session.
brainkb_whoami
Report the current caller's auth state (email, authenticated, and when the
cached session expires). When signed in it also returns base_url — the backend
THIS SERVER talks to, which on a hosted deployment is an internal address and
says nothing about the caller's own machine.
brainkb_create_token
Generate a Personal Access Token (PAT) for browser-free auth. Requires you
to be logged in already (brainkb_login or brainkb_globus_login). The token is
shown ONCE and never again — copy it and set it as BRAINKB_TOKEN in your
MCP/skill config; then no login or browser is needed until it
brainkb_list_tokens
List your Personal Access Tokens (metadata only — the secret is never
shown): id, name, prefix, created/last-used/expiry, and whether each is
active/revoked/expired. Use the id with brainkb_revoke_token.
brainkb_revoke_token
Revoke one of your Personal Access Tokens by id (see brainkb_list_tokens).
Takes effect immediately — the next call using that token fails.
brainkb_use_token
Use a Personal Access Token (brainkb_pat_...) for THIS session — an
alternative to setting BRAINKB_TOKEN in the config. Validates the token, then
caches it so subsequent calls authenticate with it. The token is never echoed.
brainkb_list_spaces
List spaces the user can see (their own/member spaces + public ones), each
annotated with THIS caller's permission so you know what they may do:
- your_role: 'owner' | 'editor' | 'viewer' | null (their space membership)
- is_owner: they own the space
- access: 'owner' | 'me
brainkb_create_space
Create a workspace/space. The caller becomes owner.
slug: lowercase/hyphen id, **globally unique** — if it's already taken the call
returns 409 (pick another slug; slugs are never reused/deleted).
visibility: 'private' or 'public';
description: short human description (recommended —
brainkb_set_space_visibility
Set a space 'public' (anyone, even anonymous, can read) or 'private'
(members only). Owner only.
brainkb_add_space_member
Add/update a space member. role: 'owner' | 'editor' | 'viewer'. Owner only.
brainkb_add_space_graph
Register a named graph and bind it to a space, so ingest/read on that graph
are governed by the space's membership and visibility. Owner/editor only.
The named_graph_iri is **globally unique** — one graph belongs to exactly one
space. If it's already registered (to any space) the call re
brainkb_ingest_text
Ingest raw RDF text (Turtle / N-Triples / JSON-LD, auto-detected) into a
named graph. Returns a job_id; ingestion runs in the background — poll with
brainkb_job_status. The graph must be registered (see brainkb_add_space_graph)
and the caller must have write access to its space.
`sh
brainkb_list_uploads
List RDF files YOU have staged with POST /upload but not yet ingested.
Shows each upload_id, its size, sha256 and when it expires. Only your own
uploads are visible.
brainkb_upload_status
State of one of your staged/submitted uploads.
`state` is `staged` (waiting for brainkb_ingest_upload), `submitting` (the server
is streaming it to the ingest API), `submitted` (accepted — `job_id` is set, poll
brainkb_job_status) or `failed` (the staged bytes were KEPT, so retry with
brainkb_discard_upload
Delete one of your staged uploads without ingesting it.
brainkb_ingest_upload
Ingest a file you staged with `POST /upload` into a named graph.
This is the route for a large local file: your HTTP client streams the bytes
straight to this server over HTTPS, then you name the resulting upload_id here. The
server reads its own staged copy and posts it to the ingest A
brainkb_ingest_files
Ingest local RDF files (ttl/nt/nq/rdf/owl/jsonld/json) into a named graph.
Returns a job_id; runs in the background — poll with brainkb_job_status.
brainkb_list_jobs
List the user's ingest jobs (newest first) with status and progress.
brainkb_job_status
Detailed status of one ingest job: status, progress %, current file/stage,
per-file failures, and (when complete) a summary.
brainkb_recover_job
Attempt to recover a stuck/errored ingest job (marks it recoverable/errored).
brainkb_search
Full-text search over the knowledge graphs, access-filtered by space
visibility. Pass `space` to scope to one workspace, omit for a full search.
Anonymous/other users never see private-space data.
brainkb_read_space
Read all RDF (JSON-LD) in a space's graphs. Public spaces are readable by
anyone; private spaces require membership.
brainkb_list_registered_graphs
List registered named graphs visible to the caller (private-space graphs the
caller can't access are hidden).
brainkb_sparql
Run an arbitrary SPARQL query. Requires an Admin/SuperAdmin role (the
sparql_admin capability) — for ordinary questions prefer brainkb_search,
brainkb_read_space, or the provenance/delta tools, which need no admin role.
brainkb_provenance_job
PROV-O provenance bundle (JSON-LD) for one ingest job.
brainkb_provenance_graph
PROV-O ingestion/activity history (JSON-LD) for a named graph.
brainkb_delta
The exact triples a job added (its delta), as JSON-LD.
brainkb_delta_history
A named graph's change history: one entry per ingest delta (job, triple
count, timestamp), newest first.
(Admin only) Show a user's roles, effective capabilities, and delegated
grants. Useful to check why someone can/can't create team spaces, ingest, etc.
brainkb_grant_capability
(Admin only) Delegate a capability to a user — e.g. 'create_team_space' or
'manage_team_space' so a Curator/Lab Member can create/manage team spaces.
Grantable: create_private_space, create_team_space, manage_team_space, ingest,
recover, read_private (NOT the admin-only 'grant'/'sparql_a
brainkb_revoke_capability
(Admin only) Revoke a previously granted capability from a user.
brainkb_list_capabilities
(Admin only) Catalog of all KG capabilities, which are delegatable
('grantable'), which are admin-only, and a description of each. Use this to see
the available permission options before granting to a user or group/role.
brainkb_role_capabilities
(Admin only) List the capabilities granted to a role/group (e.g.
'uk_collaborator', 'Lab Member').
brainkb_grant_role_capability
(Admin only) Grant a capability to a whole role/group so EVERY member gets
it — e.g. give a custom group 'uk_collaborator' the 'ingest' or
'create_private_space' capability. Grantable: create_private_space,
create_team_space, manage_team_space, ingest, recover, read_private (NOT the
brainkb_revoke_role_capability
(Admin only) Revoke a capability from a role/group.
brainkb_list_access_rules
List a space's fine-grained access rules (member/manager of the space).
brainkb_add_access_rule
(Space manager) Restrict a space action to a subject.
action: 'read' | 'write' | 'manage'.
subject_type: 'global_role' (e.g. 'Admin','Lab Member') | 'member' (an email) |
'space_role' ('viewer'|'editor'|'owner', matched as >=).
When rules exist for an action, only matching callers ma
brainkb_remove_access_rule
(Space manager) Delete a fine-grained access rule by its id
(see brainkb_list_access_rules).
brainkb_list_users
(Admin) List users (profiles) — filter by `q` (name/email/orcid) or `role`.
Shows profile_id, email, roles, providers, ban status.
brainkb_available_roles
(Admin) List the available roles/groups (Admin, Lab Member, Curator, …).
brainkb_create_role
(Admin) Create a new role/group — e.g. an 'External' collaborator group —
which can then be assigned with brainkb_assign_role.
brainkb_assign_role
(Admin) Assign a role/group to a user by email (e.g. 'Lab Member', 'External',
or a custom group). The user must already have a profile (created on first
login/registration). NOTE: assigning the 'Admin'/'SuperAdmin' role is
SuperAdmin-only (hierarchy: SuperAdmin > Admin).
brainkb_remove_role
(Admin) Remove a role/group from a user by email.
brainkb_activate_user
(Admin) Activate a user's account (sets the JWT user active) by email.
brainkb_deactivate_user
(Admin) Deactivate a user's account by email.
brainkb_ban_user
(Admin) Ban a user by email (reversible; preserves history). This is how
accounts are removed — there is NO hard delete. Banning an Admin is
SuperAdmin-only; SuperAdmin accounts cannot be banned.
brainkb_unban_user
(Admin) Lift a ban on a user by email.
brainkb_list_permissions
(Admin) List all usermanagement permissions (resource/action pairs used for
page-access and role-permission mapping). These are the addable 'permission'
options; KG action-capabilities are listed by brainkb_list_capabilities.
brainkb_create_permission
(Admin) Create a new usermanagement permission, e.g.
name='dataset.export', resource='dataset', action='export'. Attach it to roles
via the usermanagement role-permissions API.
Endpoint
https://mcp.brainkb.org/mcp Category: Files & Storage · Last checked: 2026-08-15T10:22:56Z
Monitor your own MCP server
Get alerted the moment yours goes down, a tool schema drifts, or an upstream silently breaks.
What this means. This server responded to the MCP handshake and listed its tools without authentication. The schema fingerprint lets us flag if tool signatures silently change (schema drift) between checks.