Serveur MCP

brainkb

org.brainkb/brainkb

Ce que fait ce MCP

Manages and queries neuroscience knowledge graphs, including RDF ingestion, named graphs, jobs, spaces, memberships, roles, and access controls.

brainkb_activate_user
(Admin) Activate a user's account (sets the JWT user active) by email.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_activate_userArguments', 'required': ['email'], 'properties': {'email': {'type': 'string', 'title': 'Email'}}}
brainkb_add_access_rule
(Space manager) Restrict a space action to a subject. action: 'read' | 'write' | 'manage'. subject_type: 'global_role' (e.g. 'Admin','Lab Member') | 'member' (an email) | 'space_role' ('viewer'|'editor'|'owner', matched as >=). When rules exist for an action, only matching callers may perform it; the space owner and Admin/SuperAdmin always bypass (no lockout). Example: restrict writing to Admins -> action='write', subject_type='global_role', subject_value='Admin'.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_add_access_ruleArguments', 'required': ['slug', 'action', 'subject_type', 'subject_value'], 'properties': {'slug': {'type': 'string', 'title': 'Slug'}, 'action': {'type': 'string', 'title': 'Action'}, 'subject_type': {'type': 'string', 'title': 'Subject Type'}, 'subject_value': {'type': 'string', 'title': 'Subject Value'}}}
brainkb_add_space_graph
Register a named graph and bind it to a space, so ingest/read on that graph are governed by the space's membership and visibility. Owner/editor only. The named_graph_iri is **globally unique** — one graph belongs to exactly one space. If it's already registered (to any space) the call returns 409; graph bindings are permanent (no unregister/delete).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_add_space_graphArguments', 'required': ['slug', 'named_graph_iri'], 'properties': {'slug': {'type': 'string', 'title': 'Slug'}, 'description': {'type': 'string', 'title': 'Description', 'default': ''}, 'named_graph_iri': {'type': 'string', 'title': 'Named Graph Iri'}}}
brainkb_add_space_member
Add/update a space member. role: 'owner' | 'editor' | 'viewer'. Owner only.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_add_space_memberArguments', 'required': ['slug', 'member_email'], 'properties': {'role': {'type': 'string', 'title': 'Role', 'default': 'viewer'}, 'slug': {'type': 'string', 'title': 'Slug'}, 'member_email': {'type': 'string', 'title': 'Member Email'}}}
brainkb_assign_role
(Admin) Assign a role/group to a user by email (e.g. 'Lab Member', 'External', or a custom group). The user must already have a profile (created on first login/registration). NOTE: assigning the 'Admin'/'SuperAdmin' role is SuperAdmin-only (hierarchy: SuperAdmin > Admin).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_assign_roleArguments', 'required': ['email', 'role'], 'properties': {'role': {'type': 'string', 'title': 'Role'}, 'email': {'type': 'string', 'title': 'Email'}}}
brainkb_available_roles
(Admin) List the available roles/groups (Admin, Lab Member, Curator, …).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_available_rolesArguments', 'properties': {}}
brainkb_ban_user
(Admin) Ban a user by email (reversible; preserves history). This is how accounts are removed — there is NO hard delete. Banning an Admin is SuperAdmin-only; SuperAdmin accounts cannot be banned.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_ban_userArguments', 'required': ['email', 'reason'], 'properties': {'email': {'type': 'string', 'title': 'Email'}, 'reason': {'type': 'string', 'title': 'Reason'}}}
brainkb_capabilities
(Admin only) Show a user's roles, effective capabilities, and delegated grants. Useful to check why someone can/can't create team spaces, ingest, etc.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_capabilitiesArguments', 'required': ['member'], 'properties': {'member': {'type': 'string', 'title': 'Member'}}}
brainkb_create_permission
(Admin) Create a new usermanagement permission, e.g. name='dataset.export', resource='dataset', action='export'. Attach it to roles via the usermanagement role-permissions API.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_create_permissionArguments', 'required': ['name', 'resource', 'action'], 'properties': {'name': {'type': 'string', 'title': 'Name'}, 'action': {'type': 'string', 'title': 'Action'}, 'resource': {'type': 'string', 'title': 'Resource'}, 'description': {'type': 'string', 'title': 'Description', 'default': ''}}}
brainkb_create_role
(Admin) Create a new role/group — e.g. an 'External' collaborator group — which can then be assigned with brainkb_assign_role.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_create_roleArguments', 'required': ['name'], 'properties': {'name': {'type': 'string', 'title': 'Name'}, 'category': {'type': 'string', 'title': 'Category', 'default': 'Content'}, 'description': {'type': 'string', 'title': 'Description', 'default': ''}}}
brainkb_create_space
Create a workspace/space. The caller becomes owner. slug: lowercase/hyphen id, **globally unique** — if it's already taken the call returns 409 (pick another slug; slugs are never reused/deleted). visibility: 'private' or 'public'; description: short human description (recommended — surfaces in the registry); space_type: 'individual' (a personal space — any write-capable role) or 'team' (a shared space — only Admin/SuperAdmin, or a user granted create_team_space).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_create_spaceArguments', 'required': ['slug', 'name'], 'properties': {'name': {'type': 'string', 'title': 'Name'}, 'slug': {'type': 'string', 'title': 'Slug'}, 'space_type': {'type': 'string', 'title': 'Space Type', 'default': 'individual'}, 'visibility': {'type': 'string', 'title': 'Visibility', 'default': 'private'}, 'description': {'type': 'string', 'title': 'Description', 'default': ''}}}
brainkb_create_token
Generate a Personal Access Token (PAT) for browser-free auth. Requires you to be logged in already (brainkb_login or brainkb_globus_login). The token is shown ONCE and never again — copy it and set it as BRAINKB_TOKEN in your MCP/skill config; then no login or browser is needed until it expires. `name`: a label so you can tell tokens apart (e.g. 'laptop'). `days`: lifetime (default 90, server-capped). Treat the returned token like a password.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_create_tokenArguments', 'properties': {'days': {'type': 'integer', 'title': 'Days', 'default': 90}, 'name': {'type': 'string', 'title': 'Name', 'default': ''}}}
brainkb_deactivate_user
(Admin) Deactivate a user's account by email.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_deactivate_userArguments', 'required': ['email'], 'properties': {'email': {'type': 'string', 'title': 'Email'}}}
brainkb_delta
The exact triples a job added (its delta), as JSON-LD.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_deltaArguments', 'required': ['job_id'], 'properties': {'job_id': {'type': 'string', 'title': 'Job Id'}}}
brainkb_delta_compare
Compare two jobs' deltas: A-only / B-only / shared triple counts + triples.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_delta_compareArguments', 'required': ['job_id_a', 'job_id_b'], 'properties': {'job_id_a': {'type': 'string', 'title': 'Job Id A'}, 'job_id_b': {'type': 'string', 'title': 'Job Id B'}}}
brainkb_delta_history
A named graph's change history: one entry per ingest delta (job, triple count, timestamp), newest first.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_delta_historyArguments', 'required': ['named_graph_iri'], 'properties': {'named_graph_iri': {'type': 'string', 'title': 'Named Graph Iri'}}}
brainkb_discard_upload
Delete one of your staged uploads without ingesting it.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_discard_uploadArguments', 'required': ['upload_id'], 'properties': {'upload_id': {'type': 'string', 'title': 'Upload Id'}}}
brainkb_finish_login
Complete an OAuth login started with brainkb_globus_login by exchanging the one-time code shown in the browser for a session token. The code is single-use and never echoed back.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_finish_loginArguments', 'required': ['code'], 'properties': {'code': {'type': 'string', 'title': 'Code'}, 'base_url': {'type': 'string', 'title': 'Base Url', 'default': ''}}}
Schéma de sortie
{'type': 'object', 'title': 'brainkb_finish_loginOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
brainkb_globus_login
Start an OAuth login (Globus / ORCID / GitHub) for THIS session — use this instead of brainkb_login when the user signs in with Globus rather than a password. Returns a URL to open in a browser; after signing in, the page shows a short one-time code — pass it to brainkb_finish_login(code) to complete. (The browser step is unavoidable: only the user can consent at the provider.)
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_globus_loginArguments', 'properties': {'base_url': {'type': 'string', 'title': 'Base Url', 'default': ''}, 'provider': {'type': 'string', 'title': 'Provider', 'default': 'globus'}}}
Schéma de sortie
{'type': 'object', 'title': 'brainkb_globus_loginOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
brainkb_grant_capability
(Admin only) Delegate a capability to a user — e.g. 'create_team_space' or 'manage_team_space' so a Curator/Lab Member can create/manage team spaces. Grantable: create_private_space, create_team_space, manage_team_space, ingest, recover, read_private (NOT the admin-only 'grant'/'sparql_admin').
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_grant_capabilityArguments', 'required': ['member', 'capability'], 'properties': {'member': {'type': 'string', 'title': 'Member'}, 'capability': {'type': 'string', 'title': 'Capability'}}}
brainkb_grant_role_capability
(Admin only) Grant a capability to a whole role/group so EVERY member gets it — e.g. give a custom group 'uk_collaborator' the 'ingest' or 'create_private_space' capability. Grantable: create_private_space, create_team_space, manage_team_space, ingest, recover, read_private (NOT the admin-only 'grant'/'sparql_admin'). Create the group first with brainkb_create_role, then assign it to users with brainkb_assign_role.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_grant_role_capabilityArguments', 'required': ['role', 'capability'], 'properties': {'role': {'type': 'string', 'title': 'Role'}, 'capability': {'type': 'string', 'title': 'Capability'}}}
brainkb_ingest_files
Ingest local RDF files (ttl/nt/nq/rdf/owl/jsonld/json) into a named graph. Returns a job_id; runs in the background — poll with brainkb_job_status.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_ingest_filesArguments', 'required': ['named_graph_iri', 'file_paths'], 'properties': {'file_paths': {'type': 'array', 'items': {'type': 'string'}, 'title': 'File Paths'}, 'max_concurrency': {'type': 'integer', 'title': 'Max Concurrency', 'default': 8}, 'named_graph_iri': {'type': 'string', 'title': 'Named Graph Iri'}}}
brainkb_ingest_text
Ingest raw RDF text (Turtle / N-Triples / JSON-LD, auto-detected) into a named graph. Returns a job_id; ingestion runs in the background — poll with brainkb_job_status. The graph must be registered (see brainkb_add_space_graph) and the caller must have write access to its space. `sha256` / `expected_bytes` are an integrity contract, and you should use them whenever the RDF came from a file. Ingest is append-only — no delete for triples, no unregister for a graph — so RDF that arrives here mangled is permanent. Because `data` is a string, it passes through the caller's context, where dense Turtle is exactly what gets silently altered: ligatures, Greek letters, embedded newlines, escaped quotes. Declare the digest of the bytes you MEANT to send (`shasum -a 256 file.ttl`) and this refuses the write on any mismatch, turning an unrecoverable corruption into a clean rejection.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_ingest_textArguments', 'required': ['named_graph_iri', 'data'], 'properties': {'data': {'type': 'string', 'title': 'Data'}, 'sha256': {'type': 'string', 'title': 'Sha256', 'default': ''}, 'expected_bytes': {'type': 'integer', 'title': 'Expected Bytes', 'default': 0}, 'named_graph_iri': {'type': 'string', 'title': 'Named Graph Iri'}}}
brainkb_ingest_upload
Ingest a file you staged with `POST /upload` into a named graph. This is the route for a large local file: your HTTP client streams the bytes straight to this server over HTTPS, then you name the resulting upload_id here. The server reads its own staged copy and posts it to the ingest API internally, so the RDF never passes through a model's context — nothing to transcribe, no context-window ceiling, and no reason to split the document (splitting breaks blank-node identity and silently detaches triples, permanently). Stage a file with any HTTP client — the point is that the LIBRARY reads the file, so the bytes never pass through a model: import requests, hashlib, pathlib f = pathlib.Path("review.ttl") r = requests.post( "https://mcp.brainkb.org/upload", params={"filename": f.name, "sha256": hashlib.sha256(f.read_bytes()).hexdigest()}, headers={"Authorization": f"Bearer {TOKEN}"}, data=f.open("rb"), # streamed — never loaded into memory ) print(r.json()) # -> {"upload_id": "up_...", "state": "staged"} It returns an upload_id and the sha256 the server computed — compare it with your own before ingesting. Returns a job_id; poll brainkb_job_status, then reconcile brainkb_delta(job_id) against the triple count you expected. The staged copy is deleted once the ingest API has accepted the bytes.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_ingest_uploadArguments', 'required': ['named_graph_iri', 'upload_id'], 'properties': {'upload_id': {'type': 'string', 'title': 'Upload Id'}, 'named_graph_iri': {'type': 'string', 'title': 'Named Graph Iri'}}}
brainkb_job_status
Detailed status of one ingest job: status, progress %, current file/stage, per-file failures, and (when complete) a summary.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_job_statusArguments', 'required': ['job_id'], 'properties': {'job_id': {'type': 'string', 'title': 'Job Id'}}}
brainkb_list_access_rules
List a space's fine-grained access rules (member/manager of the space).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_access_rulesArguments', 'required': ['slug'], 'properties': {'slug': {'type': 'string', 'title': 'Slug'}}}
brainkb_list_capabilities
(Admin only) Catalog of all KG capabilities, which are delegatable ('grantable'), which are admin-only, and a description of each. Use this to see the available permission options before granting to a user or group/role.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_capabilitiesArguments', 'properties': {}}
brainkb_list_jobs
List the user's ingest jobs (newest first) with status and progress.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_jobsArguments', 'properties': {'limit': {'type': 'integer', 'title': 'Limit', 'default': 50}}}
brainkb_list_permissions
(Admin) List all usermanagement permissions (resource/action pairs used for page-access and role-permission mapping). These are the addable 'permission' options; KG action-capabilities are listed by brainkb_list_capabilities.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_permissionsArguments', 'properties': {}}
brainkb_list_registered_graphs
List registered named graphs visible to the caller (private-space graphs the caller can't access are hidden).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_registered_graphsArguments', 'properties': {}}
brainkb_list_spaces
List spaces the user can see (their own/member spaces + public ones), each annotated with THIS caller's permission so you know what they may do: - your_role: 'owner' | 'editor' | 'viewer' | null (their space membership) - is_owner: they own the space - access: 'owner' | 'member' | 'public' (how it's available to them) - can_write: their space role permits ingest (owner/editor) — a real ingest also needs the 'ingest' capability + any per-space access rules. Use this to tell the user which spaces they can read vs. write vs. only see as public.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_spacesArguments', 'properties': {}}
brainkb_list_tokens
List your Personal Access Tokens (metadata only — the secret is never shown): id, name, prefix, created/last-used/expiry, and whether each is active/revoked/expired. Use the id with brainkb_revoke_token.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_tokensArguments', 'properties': {}}
brainkb_list_uploads
List RDF files YOU have staged with POST /upload but not yet ingested. Shows each upload_id, its size, sha256 and when it expires. Only your own uploads are visible.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_uploadsArguments', 'properties': {}}
brainkb_list_users
(Admin) List users (profiles) — filter by `q` (name/email/orcid) or `role`. Shows profile_id, email, roles, providers, ban status.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_list_usersArguments', 'properties': {'q': {'type': 'string', 'title': 'Q', 'default': ''}, 'role': {'type': 'string', 'title': 'Role', 'default': ''}, 'limit': {'type': 'integer', 'title': 'Limit', 'default': 50}}}
brainkb_login
Authenticate to BrainKB with the user's credentials and cache the JWT for THIS session only (isolated per caller). The password/token are never echoed. Uses single sign-on: one login mints a refresh token, cached for THIS session, which is exchanged on demand for per-service access tokens (query_service, usermanagement, …). Falls back to a legacy per-service token if the backend has no SSO. On the hosted multi-user remote you can skip this and instead have your client send an 'Authorization: Bearer <token>' header (a refresh token unlocks all services).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_loginArguments', 'required': ['email', 'password'], 'properties': {'email': {'type': 'string', 'title': 'Email'}, 'base_url': {'type': 'string', 'title': 'Base Url', 'default': ''}, 'password': {'type': 'string', 'title': 'Password'}}}
Schéma de sortie
{'type': 'object', 'title': 'brainkb_loginOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
brainkb_logout
Forget the cached token for this session.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_logoutArguments', 'properties': {}}
Schéma de sortie
{'type': 'object', 'title': 'brainkb_logoutOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
brainkb_provenance_graph
PROV-O ingestion/activity history (JSON-LD) for a named graph.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_provenance_graphArguments', 'required': ['named_graph_iri'], 'properties': {'named_graph_iri': {'type': 'string', 'title': 'Named Graph Iri'}}}
brainkb_provenance_job
PROV-O provenance bundle (JSON-LD) for one ingest job.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_provenance_jobArguments', 'required': ['job_id'], 'properties': {'job_id': {'type': 'string', 'title': 'Job Id'}}}
brainkb_qa_list
Find a canned question BrainKB can answer, then run it with brainkb_qa_run. Prefer these over writing SPARQL: they are vetted against BrainKB's actual vocabulary. Discovery is two steps, so you never read every query at once: 1. brainkb_qa_list() -> the menu: each category's name, a description of the questions it covers, and how many queries it has. Pick the category whose description matches the user's question. 2. brainkb_qa_list(category="<name>") -> that category's queries. Each has `question` (what it answers), `notes` (when to use it, where parameter values come from, what the results mean), `params` (required ones have no default — ask the user rather than guess) and a working `example`. `search="words"` filters queries by words in their id/question/notes; use it alone to search every category when none of the descriptions fits.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_qa_listArguments', 'properties': {'search': {'type': 'string', 'title': 'Search', 'default': ''}, 'category': {'type': 'string', 'title': 'Category', 'default': ''}}}
brainkb_qa_run
Run a canned question from brainkb_qa_list by id. `params` maps parameter names to values; they are validated and escaped, never spliced in raw. Runs through the same SPARQL endpoint as brainkb_sparql, so it needs the same role.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_qa_runArguments', 'required': ['query_id'], 'properties': {'params': {'anyOf': [{'type': 'object', 'additionalProperties': True}, {'type': 'null'}], 'title': 'Params', 'default': None}, 'query_id': {'type': 'string', 'title': 'Query Id'}}}
brainkb_read_space
Read all RDF (JSON-LD) in a space's graphs. Public spaces are readable by anyone; private spaces require membership.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_read_spaceArguments', 'required': ['slug'], 'properties': {'slug': {'type': 'string', 'title': 'Slug'}}}
brainkb_recover_job
Attempt to recover a stuck/errored ingest job (marks it recoverable/errored).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_recover_jobArguments', 'required': ['job_id'], 'properties': {'job_id': {'type': 'string', 'title': 'Job Id'}}}
brainkb_remove_access_rule
(Space manager) Delete a fine-grained access rule by its id (see brainkb_list_access_rules).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_remove_access_ruleArguments', 'required': ['slug', 'rule_id'], 'properties': {'slug': {'type': 'string', 'title': 'Slug'}, 'rule_id': {'type': 'integer', 'title': 'Rule Id'}}}
brainkb_remove_role
(Admin) Remove a role/group from a user by email.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_remove_roleArguments', 'required': ['email', 'role'], 'properties': {'role': {'type': 'string', 'title': 'Role'}, 'email': {'type': 'string', 'title': 'Email'}}}
brainkb_revoke_capability
(Admin only) Revoke a previously granted capability from a user.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_revoke_capabilityArguments', 'required': ['member', 'capability'], 'properties': {'member': {'type': 'string', 'title': 'Member'}, 'capability': {'type': 'string', 'title': 'Capability'}}}
brainkb_revoke_role_capability
(Admin only) Revoke a capability from a role/group.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_revoke_role_capabilityArguments', 'required': ['role', 'capability'], 'properties': {'role': {'type': 'string', 'title': 'Role'}, 'capability': {'type': 'string', 'title': 'Capability'}}}
brainkb_revoke_token
Revoke one of your Personal Access Tokens by id (see brainkb_list_tokens). Takes effect immediately — the next call using that token fails.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_revoke_tokenArguments', 'required': ['token_id'], 'properties': {'token_id': {'type': 'integer', 'title': 'Token Id'}}}
brainkb_role_capabilities
(Admin only) List the capabilities granted to a role/group (e.g. 'uk_collaborator', 'Lab Member').
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_role_capabilitiesArguments', 'required': ['role'], 'properties': {'role': {'type': 'string', 'title': 'Role'}}}
brainkb_search
Full-text search over the knowledge graphs, access-filtered by space visibility. Pass `space` to scope to one workspace, omit for a full search. Anonymous/other users never see private-space data.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_searchArguments', 'required': ['q'], 'properties': {'q': {'type': 'string', 'title': 'Q'}, 'limit': {'type': 'integer', 'title': 'Limit', 'default': 25}, 'space': {'type': 'string', 'title': 'Space', 'default': ''}, 'offset': {'type': 'integer', 'title': 'Offset', 'default': 0}}}
brainkb_set_space_visibility
Set a space 'public' (anyone, even anonymous, can read) or 'private' (members only). Owner only.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_set_space_visibilityArguments', 'required': ['slug', 'visibility'], 'properties': {'slug': {'type': 'string', 'title': 'Slug'}, 'visibility': {'type': 'string', 'title': 'Visibility'}}}
brainkb_sparql
Run an arbitrary SPARQL query. Requires an Admin/SuperAdmin role (the sparql_admin capability) — for ordinary questions prefer brainkb_search, brainkb_read_space, or the provenance/delta tools, which need no admin role.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_sparqlArguments', 'required': ['sparql_query'], 'properties': {'sparql_query': {'type': 'string', 'title': 'Sparql Query'}}}
brainkb_unban_user
(Admin) Lift a ban on a user by email.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_unban_userArguments', 'required': ['email'], 'properties': {'email': {'type': 'string', 'title': 'Email'}}}
brainkb_upload_status
State of one of your staged/submitted uploads. `state` is `staged` (waiting for brainkb_ingest_upload), `submitting` (the server is streaming it to the ingest API), `submitted` (accepted — `job_id` is set, poll brainkb_job_status) or `failed` (the staged bytes were KEPT, so retry with brainkb_ingest_upload rather than re-uploading).
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_upload_statusArguments', 'required': ['upload_id'], 'properties': {'upload_id': {'type': 'string', 'title': 'Upload Id'}}}
brainkb_use_token
Use a Personal Access Token (brainkb_pat_...) for THIS session — an alternative to setting BRAINKB_TOKEN in the config. Validates the token, then caches it so subsequent calls authenticate with it. The token is never echoed.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_use_tokenArguments', 'required': ['token'], 'properties': {'token': {'type': 'string', 'title': 'Token'}, 'base_url': {'type': 'string', 'title': 'Base Url', 'default': ''}}}
Schéma de sortie
{'type': 'object', 'title': 'brainkb_use_tokenOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
brainkb_whoami
Report the current caller's auth state (email, authenticated, and when the cached session expires). When signed in it also returns base_url — the backend THIS SERVER talks to, which on a hosted deployment is an internal address and says nothing about the caller's own machine.
Schéma d’entrée
{'type': 'object', 'title': 'brainkb_whoamiArguments', 'properties': {}}
Schéma de sortie
{'type': 'object', 'title': 'brainkb_whoamiOutput', 'required': ['result'], 'properties': {'result': {'type': 'object', 'title': 'Result', 'additionalProperties': True}}}
Ajouté
brainkb_qa_run
1 October 2026 02:51
Ajouté
brainkb_qa_list
1 October 2026 02:51
Ajouté
brainkb_create_permission
17 September 2026 12:54
Ajouté
brainkb_list_permissions
17 September 2026 12:54
Ajouté
brainkb_unban_user
17 September 2026 12:54
Ajouté
brainkb_ban_user
17 September 2026 12:54
Ajouté
brainkb_deactivate_user
17 September 2026 12:54
Ajouté
brainkb_activate_user
17 September 2026 12:54
Ajouté
brainkb_remove_role
17 September 2026 12:54
Ajouté
brainkb_assign_role
17 September 2026 12:54
Ajouté
brainkb_create_role
17 September 2026 12:54
Ajouté
brainkb_available_roles
17 September 2026 12:54
Ajouté
brainkb_list_users
17 September 2026 12:54
Ajouté
brainkb_remove_access_rule
17 September 2026 12:54
Ajouté
brainkb_add_access_rule
17 September 2026 12:54
Ajouté
brainkb_list_access_rules
17 September 2026 12:54
Ajouté
brainkb_revoke_role_capability
17 September 2026 12:54
Ajouté
brainkb_grant_role_capability
17 September 2026 12:54
Ajouté
brainkb_role_capabilities
17 September 2026 12:54
Ajouté
brainkb_list_capabilities
17 September 2026 12:54
Ajouté
brainkb_revoke_capability
17 September 2026 12:54
Ajouté
brainkb_grant_capability
17 September 2026 12:54
Ajouté
brainkb_capabilities
17 September 2026 12:54
Ajouté
brainkb_delta_compare
17 September 2026 12:54
Ajouté
brainkb_delta_history
17 September 2026 12:54
Ajouté
brainkb_delta
17 September 2026 12:54
Ajouté
brainkb_provenance_graph
17 September 2026 12:54
Ajouté
brainkb_provenance_job
17 September 2026 12:54
Ajouté
brainkb_sparql
17 September 2026 12:54
Ajouté
brainkb_list_registered_graphs
17 September 2026 12:54