๐๐โ๏ธ Neo4j Aura Database Manager MCP Server
mcp-name: io.github.neo4j-contrib/mcp-neo4j-aura-manager
๐ Overview
A Model Context Protocol (MCP) server implementation that provides tools for managing Neo4j Aura database instances through the Neo4j Aura API.
This server allows you to create, monitor, and manage Neo4j Aura instances directly through Claude, making it easy to provision and maintain your graph database infrastructure.
๐ Authentication
Authentication with the Neo4j Aura API requires:
You can obtain these credentials from the Neo4j Aura console, see the documentation of the Aura API
Here is the API Specification
๐ฆ Components
The server offers these core tools:
๐ ๏ธ Instance Management
๐ข Tenant/Project Management
-
list_tenants
- List all Neo4j Aura tenants/projects
- No input required
- Returns: List of all tenants with their details
-
get_tenant_details
- Get details for a specific tenant/project
- Input:
tenant_id (string): ID of the tenant/project to retrieve
- Returns: Detailed information about the tenant/project
๐ง Usage with Claude Desktop
๐พ Installation
pip install mcp-neo4j-aura-manager
โ๏ธ Configuration
Add the server to your claude_desktop_config.json:
"mcpServers": {
"neo4j-aura": {
"command": "uvx",
"args": [
"mcp-neo4j-aura-manager@0.4.8",
"--client-id",
"<your-client-id>",
"--client-secret",
"<your-client-secret>"
]
}
}
Alternatively, you can set environment variables:
"mcpServers": {
"neo4j-aura": {
"command": "uvx",
"args": [ "mcp-neo4j-aura-manager@0.4.8" ],
"env": {
"NEO4J_AURA_CLIENT_ID": "<your-client-id>",
"NEO4J_AURA_CLIENT_SECRET": "<your-client-secret>"
}
}
}
๐ณ Using with Docker
"mcpServers": {
"neo4j-aura": {
"command": "docker",
"args": [
"run",
"--rm",
"-e", "NEO4J_AURA_CLIENT_ID=${NEO4J_AURA_CLIENT_ID}",
"-e", "NEO4J_AURA_CLIENT_SECRET=${NEO4J_AURA_CLIENT_SECRET}",
"mcp-neo4j-aura-manager:0.4.8"
]
}
}
๐ท๏ธ Namespacing for Multi-tenant Deployments
The server supports namespacing to prefix tool names for multi-tenant deployments:
"mcpServers": {
"neo4j-aura-app1": {
"command": "uvx",
"args": [
"mcp-neo4j-aura-manager@0.4.8",
"--client-id", "<your-client-id>",
"--client-secret", "<your-client-secret>",
"--namespace", "app1"
]
},
"neo4j-aura-app2": {
"command": "uvx",
"args": [
"mcp-neo4j-aura-manager@0.4.8",
"--client-id", "<your-client-id>",
"--client-secret", "<your-client-secret>",
"--namespace", "app2"
]
}
}
CLI Usage
mcp-neo4j-aura-manager --client-id <id> --client-secret <secret> --namespace myapp
Environment Variables
export NEO4J_AURA_CLIENT_ID=your_client_id
export NEO4J_AURA_CLIENT_SECRET=your_client_secret
export NEO4J_NAMESPACE=myapp
mcp-neo4j-aura-manager
Docker with Namespacing
docker run -e NEO4J_AURA_CLIENT_ID=<id> \
-e NEO4J_AURA_CLIENT_SECRET=<secret> \
-e NEO4J_NAMESPACE=myapp \
mcp-neo4j-aura-manager
๐ HTTP Transport Mode
The server supports HTTP transport for web-based deployments and microservices:
mcp-neo4j-aura-manager --transport http
mcp-neo4j-aura-manager --transport http --host 127.0.0.1 --port 8080 --path /api/mcp/
Environment variables for HTTP configuration:
export NEO4J_TRANSPORT=http
export NEO4J_MCP_SERVER_HOST=127.0.0.1
export NEO4J_MCP_SERVER_PORT=8080
export NEO4J_MCP_SERVER_PATH=/api/mcp/
export NEO4J_MCP_SERVER_ALLOWED_HOSTS="localhost,127.0.0.1"
export NEO4J_MCP_SERVER_ALLOW_ORIGINS="http://localhost:3000"
export NEO4J_NAMESPACE=myapp
mcp-neo4j-aura-manager
๐ Transport Modes
The server supports three transport modes:
- STDIO (default): Standard input/output for local tools and Claude Desktop
- SSE: Server-Sent Events for web-based deployments
- HTTP: Streamable HTTP for modern web deployments and microservices
๐ Security Protection
The server includes comprehensive security protection with secure defaults that protect against common web-based attacks while preserving full MCP functionality when using HTTP transport.
๐ก๏ธ DNS Rebinding Protection
TrustedHost Middleware validates Host headers to prevent DNS rebinding attacks:
Secure by Default:
- Only
localhost and 127.0.0.1 hosts are allowed by default
- Malicious websites cannot trick browsers into accessing your local server
Environment Variable:
export NEO4J_MCP_SERVER_ALLOWED_HOSTS="example.com,www.example.com"
๐ CORS Protection
Cross-Origin Resource Sharing (CORS) protection blocks browser-based requests by default:
Environment Variable:
export NEO4J_MCP_SERVER_ALLOW_ORIGINS="https://example.com,https://example.com"
๐ง Complete Security Configuration
Development Setup:
mcp-neo4j-aura-manager --transport http \
--allowed-hosts "localhost,127.0.0.1" \
--allow-origins "http://localhost:3000"
Production Setup:
mcp-neo4j-aura-manager --transport http \
--allowed-hosts "example.com,www.example.com" \
--allow-origins "https://example.com,https://example.com"
๐จ Security Best Practices
For allow_origins:
- Be specific:
["https://example.com", "https://example.com"]
- Never use
"*" in production with credentials
- Use HTTPS origins in production
For allowed_hosts:
- Include your actual domain:
["example.com", "www.example.com"]
- Include localhost only for development
- Never use
"*" unless you understand the risks
๐ณ Docker Deployment
The Neo4j Aura Manager MCP server can be deployed using Docker for remote deployments. Docker deployment should use HTTP transport for web accessibility. In order to integrate this deployment with applications like Claude Desktop, you will have to use a proxy in your MCP configuration such as mcp-remote.
๐ณ Using with Docker for Claude Desktop
Here we use the Docker Hub hosted Aura Manager MCP server image with stdio transport for use with Claude Desktop.
Config details:
-i: Interactive mode - keeps STDIN open for stdio transport communication
--rm: Automatically remove container when it exits (cleanup)
-p 8000:8000: Port mapping - maps host port 8000 to container port 8000
NEO4J_TRANSPORT=stdio: Uses stdio transport for Claude Desktop compatibility
NEO4J_AURA_CLIENT_ID and NEO4J_AURA_CLIENT_SECRET: Your Aura API credentials
{
"mcpServers": {
"neo4j-aura": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-p",
"8000:8000",
"-e", "NEO4J_AURA_CLIENT_ID=your-client-id",
"-e", "NEO4J_AURA_CLIENT_SECRET=your-client-secret",
"-e", "NEO4J_TRANSPORT=stdio",
"mcp/neo4j-aura-manager:latest"
]
}
}
}
๐ฆ Using Your Built Image
After building locally with docker build -t mcp-neo4j-aura-manager:latest .:
docker build -t mcp-neo4j-aura-manager:<version> .
docker run --rm -p 8000:8000 \
-e NEO4J_AURA_CLIENT_ID="your-client-id" \
-e NEO4J_AURA_CLIENT_SECRET="your-client-secret" \
-e NEO4J_TRANSPORT="http" \
-e NEO4J_MCP_SERVER_HOST="0.0.0.0" \
-e NEO4J_MCP_SERVER_PORT="8000" \
-e NEO4J_MCP_SERVER_PATH="/mcp/" \
mcp-neo4j-aura-manager:<version>
docker run --rm -p 8000:8000 \
-e NEO4J_AURA_CLIENT_ID="your-client-id" \
-e NEO4J_AURA_CLIENT_SECRET="your-client-secret" \
-e NEO4J_TRANSPORT="http" \
-e NEO4J_MCP_SERVER_HOST="0.0.0.0" \
-e NEO4J_MCP_SERVER_PORT="8000" \
-e NEO4J_MCP_SERVER_PATH="/mcp/" \
-e NEO4J_MCP_SERVER_ALLOWED_HOSTS="example.com,www.example.com" \
-e NEO4J_MCP_SERVER_ALLOW_ORIGINS="https://example.com" \
mcp-neo4j-aura-manager:<version>
๐ง Environment Variables
| Variable | Default | Description |
|---|
NEO4J_AURA_CLIENT_ID | (none) | Neo4j Aura API Client ID |
NEO4J_AURA_CLIENT_SECRET | (none) | Neo4j Aura API Client Secret |
NEO4J_NAMESPACE | (empty - no prefix) | Namespace prefix for tool names (e.g., myapp-list_instances) |
NEO4J_TRANSPORT | stdio (local), http (remote) | Transport protocol (stdio, http, or sse) |
NEO4J_MCP_SERVER_HOST | 127.0.0.1 (local) | Host to bind to |
NEO4J_MCP_SERVER_PORT | 8000 | Port for HTTP/SSE transport |
NEO4J_MCP_SERVER_PATH | /mcp/ | Path for accessing MCP server |
NEO4J_MCP_SERVER_ALLOW_ORIGINS | (empty - secure by default) | Comma-separated list of allowed CORS origins |
NEO4J_MCP_SERVER_ALLOWED_HOSTS | localhost,127.0.0.1 | Comma-separated list of allowed hosts (DNS rebinding protection) |
NEO4J_MCP_SERVER_STATELESS | false | Enable stateless mode for HTTP/SSE transports (true/false, has no effect for stdio) |
๐ SSE Transport for Legacy Web Access
When using SSE transport (for legacy web clients), the server exposes an HTTP endpoint:
docker run -d -p 8000:8000 \
-e NEO4J_AURA_CLIENT_ID="your-client-id" \
-e NEO4J_AURA_CLIENT_SECRET="your-client-secret" \
-e NEO4J_TRANSPORT="sse" \
-e NEO4J_MCP_SERVER_HOST="0.0.0.0" \
-e NEO4J_MCP_SERVER_PORT="8000" \
--name neo4j-aura-mcp-server \
mcp-neo4j-aura-manager:latest
curl http://localhost:8000/sse
npx @modelcontextprotocol/inspector http://localhost:8000/sse
๐ Claude Desktop Integration with Docker
For Claude Desktop integration with a Dockerized server using http transport:
{
"mcpServers": {
"neo4j-aura-docker": {
"command": "npx",
"args": ["-y", "mcp-remote@latest", "http://localhost:8000/mcp/"]
}
}
}
Note: First start your Docker container with HTTP transport, then Claude Desktop can connect to it via the HTTP endpoint and proxy server like mcp-remote.
๐ Usage Examples
๐ Give overview over my tenants

๐ Find an instance by name

๐ List instances and find paused instance

โถ๏ธ Resume paused instances

โ Create a new instance

๐ Development
๐ฆ Prerequisites
- Install
uv (Universal Virtualenv):
pip install uv
brew install uv
cargo install uv
- Clone the repository and set up development environment:
git clone https://github.com/yourusername/mcp-neo4j-aura-manager.git
cd mcp-neo4j-aura-manager
uv venv
source .venv/bin/activate
.venv\Scripts\activate
uv pip install -e ".[dev]"
๐ License
This MCP server is licensed under the MIT License. This means you are free to use, modify, and distribute the software, subject to the terms and conditions of the MIT License. For more details, please see the LICENSE file in the project repository.