# Knowledge & memory

> Step-by-step connection and configuration for Neo4j, Neo4j knowledge graph memory, Memgraph, Graphiti, Mem0 and Cognee.

Source: https://triagic.com/docs/integrations/knowledge

Six integrations that let the agent read what your team's knowledge graph or agent
memory already knows about a system, a customer or a past incident. None of these
servers has a database-style read-only role, so this page says for each one where the
read-only boundary actually sits: a server switch, a database grant, or only the
allowlist Triagic applies.

## Neo4j [#neo4j]

`neo4j` · `mcp-neo4j-cypher==0.6.0` via **uvx** · started with `NEO4J_READ_ONLY=true`,
which stops the server registering its write tool at all. Tools: `get_neo4j_schema`,
`read_neo4j_cypher`.

Overview, prompts and the tool list: [/integrations/neo4j](/integrations/neo4j).

1. **Create a read-only user.** In Neo4j Browser or Aura's query console:

   ```cypher
   CREATE USER triagic_reader SET PASSWORD 'choose-a-strong-one' CHANGE NOT REQUIRED;
   GRANT ROLE reader TO triagic_reader;
   ```

   The built-in `reader` role can `MATCH` and nothing else.

2. **Find the connection URI.** Aura: instance → **Connect** → the `neo4j+s://` URI.
   Self-hosted: `bolt://host:7687` or `neo4j://host:7687`, adding `+s` for TLS.

3. **Fill the form.**

   | Field              | Required | What to put                             |
   | ------------------ | -------- | --------------------------------------- |
   | **Connection URI** | yes      | `neo4j+s://xxxxxxxx.databases.neo4j.io` |
   | **Username**       | yes      | `triagic_reader`                        |
   | **Password**       | yes      | The password from step 1                |
   | **Database**       | no       | Blank for the default database          |

4. **Verify.** Health check is `get_neo4j_schema`, which calls `apoc.meta.schema`. Aura
   ships APOC; a self-hosted server needs the APOC core plugin installed.

| If it reports                                 | It usually means                                                                                                   |
| --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| `no procedure with the name apoc.meta.schema` | APOC is not installed on a self-hosted server. Install APOC core and restart.                                      |
| `Neo.ClientError.Security.Unauthorized`       | Wrong username or password.                                                                                        |
| `ServiceUnavailable` / `Couldn't connect`     | The URI is unreachable from the member's machine, or an Aura instance was given `bolt://` instead of `neo4j+s://`. |

## Neo4j knowledge graph memory [#neo4j-knowledge-graph-memory]

`neo4j-memory` · `mcp-neo4j-memory==0.4.5` via **uvx** · reads the entity and
observation graph the `mcp-neo4j-memory` server writes for AI agents. Tools:
`read_graph`, `search_memories`, `find_memories_by_name`. The server's six create, add
and delete tools are hidden by Triagic; it has no read-only switch of its own.

Overview, prompts and the tool list: [/integrations/neo4j-memory](/integrations/neo4j-memory).

1. **Create a read-only user** exactly as for Neo4j above, on the database the memory
   server writes to. This grant is the boundary that holds if anything else is
   misconfigured.

2. **Fill the form.** The same four fields as Neo4j: **Connection URI**, **Username**,
   **Password**, and optional **Database**.

3. **Verify.** Health check is `find_memories_by_name` for a name that does not exist. It
   runs a real query and returns an empty result. This server connects at startup and
   exits if it cannot, so a wrong URI fails immediately with `Failed to connect to Neo4j`.

## Memgraph [#memgraph]

`memgraph` · `mcp-memgraph==0.3.0` via **uvx** · started with `MCP_READ_ONLY=true`,
under which the server refuses any query containing `CREATE`, `MERGE`, `SET`, `DELETE`,
`REMOVE` or `DROP`. Tools: `run_cypher_query`, `search_schema`, `get_node_schema`,
`get_relationship_schema`, `get_enum_schema`, `list_databases`.

Overview, prompts and the tool list: [/integrations/memgraph](/integrations/memgraph).

> **Note:** Read-only here is a keyword check
>
> The server inspects the query text; it does not restrict the database session. Give
> the user only read privileges so the boundary also holds at Memgraph.

1. **Create a read-only user.**

   ```cypher
   CREATE USER triagic_reader IDENTIFIED BY 'choose-a-strong-one';
   GRANT MATCH ON LABELS * TO triagic_reader;
   ```

   Skip this on an instance started without `--auth`; leave the user and password blank.

2. **Fill the form.**

   | Field        | Required | What to put                                |
   | ------------ | -------- | ------------------------------------------ |
   | **Bolt URL** | yes      | `bolt://host:7687`, or `bolt+s://` for TLS |
   | **User**     | no       | `triagic_reader`                           |
   | **Password** | no       | The password from step 1                   |
   | **Database** | no       | Multi-tenant instances only                |

3. **Verify.** Health check runs `RETURN 1 AS ok` through `run_cypher_query`, which
   connects and authenticates. Listing tools alone does not, because the driver connects
   lazily.

| If it reports                                        | It usually means                                                          |
| ---------------------------------------------------- | ------------------------------------------------------------------------- |
| `Write operations are not allowed in read-only mode` | Expected, and deliberate.                                                 |
| `Authentication failure`                             | Wrong user or password, or credentials given to an instance without auth. |
| `Couldn't connect`                                   | Wrong host or port, or `bolt://` against a TLS listener.                  |

## Graphiti [#graphiti]

`graphiti` · a **self-hosted HTTP endpoint**. Nothing runs on members' machines; each
desktop connects to your Graphiti MCP server directly. Tools: `search_nodes`,
`search_memory_facts`, `get_episodes`, `get_entity_edge`, `get_episode_entities`,
`get_status`. The server annotates none of its tools, which is why a custom row for it
shows `connected, 0 tools`; this entry carries the vetted list instead.

Overview, prompts and the tool list: [/integrations/graphiti](/integrations/graphiti).

1. **Run the Graphiti MCP server** from the `mcp_server` directory of the
   `getzep/graphiti` repository, with `docker compose up` or `uv run main.py`. It listens
   on `http://host:8000/mcp/` by default. Keep the trailing slash.

2. **Put it behind a proxy if it leaves your network.** Graphiti has no authentication.
   A reverse proxy that requires `Authorization: Bearer …` is the usual arrangement; the
   token goes in the form's **Bearer token** field.

3. **Fill the form.**

   | Field            | Required | What to put                          |
   | ---------------- | -------- | ------------------------------------ |
   | **Server URL**   | yes      | `http://graphiti.internal:8000/mcp/` |
   | **Bearer token** | no       | Only when a proxy expects one        |

4. **Verify.** Health check is `get_status`, which reports Graphiti's own connection to its
   graph database.

| If it reports                | It usually means                                                                          |
| ---------------------------- | ----------------------------------------------------------------------------------------- |
| `404`                        | Missing `/mcp/` path or its trailing slash.                                               |
| `401` / `403`                | The proxy refused the request; set or correct the bearer token.                           |
| `ECONNREFUSED` / `ENOTFOUND` | The host is reachable from where Graphiti was deployed but not from the member's machine. |

## Mem0 [#mem0]

`mem0` · a **hosted endpoint** at `https://mcp.mem0.ai/mcp`, reached with a Mem0
platform API key as the bearer. Tools: `search_memories`, `get_memories`, `get_memory`,
`list_entities`, `list_events`, `get_event_status`. The add, update and delete tools are
hidden.

Overview, prompts and the tool list: [/integrations/mem0](/integrations/mem0).

1. **Create an API key** at **app.mem0.ai → Settings → API keys**. The key selects the
   workspace; every read is scoped to it.

2. **Fill the form.** One field, **API key**, `m0-…`.

3. **Verify.** Health check is `list_entities`, an authenticated read that fails on a bad
   or revoked key.

| If it reports                 | It usually means                          |
| ----------------------------- | ----------------------------------------- |
| `401 Authentication required` | Not a platform API key, or a revoked one. |

## Cognee [#cognee]

`cognee` · a **self-hosted HTTP endpoint**: a `cognee-mcp` process you run in http mode.
Tools: `recall`, `list_datasets_json`, `list_dataset_data_json`,
`get_client_info_json`. `remember`, `forget`, `cognify_file` and the dataset-creation
tool are hidden.

Overview, prompts and the tool list: [/integrations/cognee](/integrations/cognee).

> **Note:** Why this is not installed on members' machines
>
> The `cognee-mcp` package pulls PyTorch, spaCy and pandas, several gigabytes, so
> Triagic connects to one deployment instead of spawning it per desktop. That process
> holds the Cognee API or Cloud credentials (`COGNEE_SERVICE_URL`, `COGNEE_API_KEY`);
> none of them are entered here.

1. **Run cognee-mcp in http mode**, for example:

   ```bash
   docker run -e TRANSPORT_MODE=http -e COGNEE_SERVICE_URL=https://your-instance.cognee.ai -e COGNEE_API_KEY=ck_... -p 8000:8000 cognee/cognee-mcp:main
   ```

   Or `cognee --transport http` from a local checkout with the same variables set.

2. **Put it behind a proxy if it leaves your network.** `cognee-mcp` has no inbound
   authentication; a reverse proxy expecting `Authorization: Bearer …` is the usual
   arrangement.

3. **Fill the form.**

   | Field            | Required | What to put                           |
   | ---------------- | -------- | ------------------------------------- |
   | **Server URL**   | yes      | `http://cognee-mcp.internal:8000/mcp` |
   | **Bearer token** | no       | Only when a proxy expects one         |

4. **Verify.** Health check is `list_datasets_json`, which round-trips to the Cognee
   backend behind the MCP process.

| If it reports                | It usually means                                                                |
| ---------------------------- | ------------------------------------------------------------------------------- |
| `404`                        | `cognee-mcp` is running in stdio or sse mode, or the URL lacks the `/mcp` path. |
| `ECONNREFUSED` / `ENOTFOUND` | The host is not reachable from the member's machine.                            |

## Not in the catalog, and why [#not-in-the-catalog-and-why]

* **Supermemory**: its hosted MCP server is OAuth-only, with no API-key path. Use a
  custom row once Triagic supports OAuth for MCP servers.
* **Letta**: only a community server exists, and it folds reads and deletes into the
  same tool behind an `op` argument, so no per-tool allowlist can separate them.
