Knowledge & memory
Step-by-step connection and configuration for Neo4j, Neo4j knowledge graph memory, Memgraph, Graphiti, Mem0 and Cognee.
Six integrations that let the agent read what your team's knowledge graph or agent memory already knows about a system, a customer or a past incident. None of these servers has a database-style read-only role, so this page says for each one where the read-only boundary actually sits: a server switch, a database grant, or only the allowlist Triagic applies.
Neo4j
neo4j · mcp-neo4j-cypher==0.6.0 via uvx · started with NEO4J_READ_ONLY=true,
which stops the server registering its write tool at all. Tools: get_neo4j_schema,
read_neo4j_cypher.
Overview, prompts and the tool list: /integrations/neo4j.
Create a read-only user. In Neo4j Browser or Aura's query console:
CREATE USER triagic_reader SET PASSWORD 'choose-a-strong-one' CHANGE NOT REQUIRED;
GRANT ROLE reader TO triagic_reader;The built-in reader role can MATCH and nothing else.
Find the connection URI. Aura: instance → Connect → the neo4j+s:// URI.
Self-hosted: bolt://host:7687 or neo4j://host:7687, adding +s for TLS.
Fill the form.
| Field | Required | What to put |
|---|---|---|
| Connection URI | yes | neo4j+s://xxxxxxxx.databases.neo4j.io |
| Username | yes | triagic_reader |
| Password | yes | The password from step 1 |
| Database | no | Blank for the default database |
Verify. Health check is get_neo4j_schema, which calls apoc.meta.schema. Aura
ships APOC; a self-hosted server needs the APOC core plugin installed.
| If it reports | It usually means |
|---|---|
no procedure with the name apoc.meta.schema | APOC is not installed on a self-hosted server. Install APOC core and restart. |
Neo.ClientError.Security.Unauthorized | Wrong username or password. |
ServiceUnavailable / Couldn't connect | The URI is unreachable from the member's machine, or an Aura instance was given bolt:// instead of neo4j+s://. |
Neo4j knowledge graph memory
neo4j-memory · mcp-neo4j-memory==0.4.5 via uvx · reads the entity and
observation graph the mcp-neo4j-memory server writes for AI agents. Tools:
read_graph, search_memories, find_memories_by_name. The server's six create, add
and delete tools are hidden by Triagic; it has no read-only switch of its own.
Overview, prompts and the tool list: /integrations/neo4j-memory.
Create a read-only user exactly as for Neo4j above, on the database the memory server writes to. This grant is the boundary that holds if anything else is misconfigured.
Fill the form. The same four fields as Neo4j: Connection URI, Username, Password, and optional Database.
Verify. Health check is find_memories_by_name for a name that does not exist. It
runs a real query and returns an empty result. This server connects at startup and
exits if it cannot, so a wrong URI fails immediately with Failed to connect to Neo4j.
Memgraph
memgraph · mcp-memgraph==0.3.0 via uvx · started with MCP_READ_ONLY=true,
under which the server refuses any query containing CREATE, MERGE, SET, DELETE,
REMOVE or DROP. Tools: run_cypher_query, search_schema, get_node_schema,
get_relationship_schema, get_enum_schema, list_databases.
Overview, prompts and the tool list: /integrations/memgraph.
Read-only here is a keyword check
The server inspects the query text; it does not restrict the database session. Give the user only read privileges so the boundary also holds at Memgraph.
Create a read-only user.
CREATE USER triagic_reader IDENTIFIED BY 'choose-a-strong-one';
GRANT MATCH ON LABELS * TO triagic_reader;Skip this on an instance started without --auth; leave the user and password blank.
Fill the form.
| Field | Required | What to put |
|---|---|---|
| Bolt URL | yes | bolt://host:7687, or bolt+s:// for TLS |
| User | no | triagic_reader |
| Password | no | The password from step 1 |
| Database | no | Multi-tenant instances only |
Verify. Health check runs RETURN 1 AS ok through run_cypher_query, which
connects and authenticates. Listing tools alone does not, because the driver connects
lazily.
| If it reports | It usually means |
|---|---|
Write operations are not allowed in read-only mode | Expected, and deliberate. |
Authentication failure | Wrong user or password, or credentials given to an instance without auth. |
Couldn't connect | Wrong host or port, or bolt:// against a TLS listener. |
Graphiti
graphiti · a self-hosted HTTP endpoint. Nothing runs on members' machines; each
desktop connects to your Graphiti MCP server directly. Tools: search_nodes,
search_memory_facts, get_episodes, get_entity_edge, get_episode_entities,
get_status. The server annotates none of its tools, which is why a custom row for it
shows connected, 0 tools; this entry carries the vetted list instead.
Overview, prompts and the tool list: /integrations/graphiti.
Run the Graphiti MCP server from the mcp_server directory of the
getzep/graphiti repository, with docker compose up or uv run main.py. It listens
on http://host:8000/mcp/ by default. Keep the trailing slash.
Put it behind a proxy if it leaves your network. Graphiti has no authentication.
A reverse proxy that requires Authorization: Bearer … is the usual arrangement; the
token goes in the form's Bearer token field.
Fill the form.
| Field | Required | What to put |
|---|---|---|
| Server URL | yes | http://graphiti.internal:8000/mcp/ |
| Bearer token | no | Only when a proxy expects one |
Verify. Health check is get_status, which reports Graphiti's own connection to its
graph database.
| If it reports | It usually means |
|---|---|
404 | Missing /mcp/ path or its trailing slash. |
401 / 403 | The proxy refused the request; set or correct the bearer token. |
ECONNREFUSED / ENOTFOUND | The host is reachable from where Graphiti was deployed but not from the member's machine. |
Mem0
mem0 · a hosted endpoint at https://mcp.mem0.ai/mcp, reached with a Mem0
platform API key as the bearer. Tools: search_memories, get_memories, get_memory,
list_entities, list_events, get_event_status. The add, update and delete tools are
hidden.
Overview, prompts and the tool list: /integrations/mem0.
Create an API key at app.mem0.ai → Settings → API keys. The key selects the workspace; every read is scoped to it.
Fill the form. One field, API key, m0-….
Verify. Health check is list_entities, an authenticated read that fails on a bad
or revoked key.
| If it reports | It usually means |
|---|---|
401 Authentication required | Not a platform API key, or a revoked one. |
Cognee
cognee · a self-hosted HTTP endpoint: a cognee-mcp process you run in http mode.
Tools: recall, list_datasets_json, list_dataset_data_json,
get_client_info_json. remember, forget, cognify_file and the dataset-creation
tool are hidden.
Overview, prompts and the tool list: /integrations/cognee.
Why this is not installed on members' machines
The cognee-mcp package pulls PyTorch, spaCy and pandas, several gigabytes, so
Triagic connects to one deployment instead of spawning it per desktop. That process
holds the Cognee API or Cloud credentials (COGNEE_SERVICE_URL, COGNEE_API_KEY);
none of them are entered here.
Run cognee-mcp in http mode, for example:
docker run -e TRANSPORT_MODE=http -e COGNEE_SERVICE_URL=https://your-instance.cognee.ai -e COGNEE_API_KEY=ck_... -p 8000:8000 cognee/cognee-mcp:mainOr cognee --transport http from a local checkout with the same variables set.
Put it behind a proxy if it leaves your network. cognee-mcp has no inbound
authentication; a reverse proxy expecting Authorization: Bearer … is the usual
arrangement.
Fill the form.
| Field | Required | What to put |
|---|---|---|
| Server URL | yes | http://cognee-mcp.internal:8000/mcp |
| Bearer token | no | Only when a proxy expects one |
Verify. Health check is list_datasets_json, which round-trips to the Cognee
backend behind the MCP process.
| If it reports | It usually means |
|---|---|
404 | cognee-mcp is running in stdio or sse mode, or the URL lacks the /mcp path. |
ECONNREFUSED / ENOTFOUND | The host is not reachable from the member's machine. |
Not in the catalog, and why
- Supermemory: its hosted MCP server is OAuth-only, with no API-key path. Use a custom row once Triagic supports OAuth for MCP servers.
- Letta: only a community server exists, and it folds reads and deletes into the
same tool behind an
opargument, so no per-tool allowlist can separate them.
Business systems
Step-by-step connection and configuration for Atlassian, Stripe, Slack, Notion, Zendesk, ServiceNow, Linear, Intercom, HubSpot, Salesforce, Freshdesk, and PostHog, which the picker files here.
Custom MCP server
Connecting a data source the catalog does not cover (a local command over stdio, or a remote HTTP endpoint) and what the catalog gives you that this does not.