At a glance
- Availability: Experimental (how to enable).
- Authentication: Basic auth.
- Connection: HTTP Basic auth with
NEO4J_USERNAMEas the username andNEO4J_PASSWORDas the password. - Provider documentation: Authentication reference.
Credentials
Set these per environment. See Connect an integration.Setup
- Create a Neo4j Aura instance: Sign up at https://console.neo4j.io and create an AuraDB Free instance (no credit card required). Download or copy the generated password: it is shown only once. Self-hosted Neo4j 5.19+ also exposes the Query API.
- Find your host: From the Aura console, copy the instance’s connection URI (neo4j+s://xxxxxxxx.databases.neo4j.io). Store the host part (xxxxxxxx.databases.neo4j.io) as NEO4J_HOST in your .env. Every tool sends its requests to this host.
- Store credentials: Add NEO4J_USERNAME=neo4j and NEO4J_PASSWORD=… to your .env file. The Query API authenticates with HTTP Basic auth using these values.
- Verify access: Run the Run Cypher Query tool with statement ‘RETURN 1 AS ok’ against database ‘neo4j’. A 401 means wrong credentials; a connection error usually means the wrong host.
Provider notes
- The Query API requires Neo4j 5.19+ (all Aura instances qualify); on self-managed instances below 5.25 it is disabled by default and must be enabled in the server configuration. Aura serves it over HTTPS on port 443
- Self-hosted instances must expose HTTPS (port 7473 by default) for these tools, since tool URLs use https://. Include the port in NEO4J_HOST, e.g. my-server:7473
- Always pass Cypher values via the parameters object ($placeholders) rather than string-concatenating them into the statement; this enables plan caching and prevents Cypher injection
- Both tools run implicit (auto-commit) transactions; explicit multi-request transactions are not exposed
- The Query API has no server-side read-only mode: Run Cypher Query is read-only by convention only, and write statements sent through it would execute. Connect with a read-only database user if you need a hard guarantee
Tools
Verify the connection
Call a read tool such asneo4j__run_cypher_query with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.