Server definition
- Hash
- sha256:71562d4dccca694c786d5a64602d4a8cf50367b544300f333cca2c49dc5e318c
- What it is
- What a remote MCP server returned when asked what it offers: 55 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "(Admin) Activate a user's account (sets the JWT user active) by email.",
"inputSchema": {
"properties": {
"email": {
"title": "Email",
"type": "string"
}
},
"required": [
"email"
],
"title": "brainkb_activate_userArguments",
"type": "object"
},
"name": "brainkb_activate_user",
"outputSchema": null
},
{
"description": "(Space manager) Restrict a space action to a subject.\n action: 'read' | 'write' | 'manage'.\n subject_type: 'global_role' (e.g. 'Admin','Lab Member') | 'member' (an email) |\n 'space_role' ('viewer'|'editor'|'owner', matched as >=).\n When rules exist for an action, only matching callers may perform it; the space\n owner and Admin/SuperAdmin always bypass (no lockout). Example: restrict writing\n to Admins -> action='write', subject_type='global_role', subject_value='Admin'.",
"inputSchema": {
"properties": {
"action": {
"title": "Action",
"type": "string"
},
"slug": {
"title": "Slug",
"type": "string"
},
"subject_type": {
"title": "Subject Type",
"type": "string"
},
"subject_value": {
"title": "Subject Value",
"type": "string"
}
},
"required": [
"slug",
"action",
"subject_type",
"subject_value"
],
"title": "brainkb_add_access_ruleArguments",
"type": "object"
},
"name": "brainkb_add_access_rule",
"outputSchema": null
},
{
"description": "Register a named graph and bind it to a space, so ingest/read on that graph\n are governed by the space's membership and visibility. Owner/editor only.\n The named_graph_iri is **globally unique** — one graph belongs to exactly one\n space. If it's already registered (to any space) the call returns 409; graph\n bindings are permanent (no unregister/delete).",
"inputSchema": {
"properties": {
"description": {
"default": "",
"title": "Description",
"type": "string"
},
"named_graph_iri": {
"title": "Named Graph Iri",
"type": "string"
},
"slug": {
"title": "Slug",
"type": "string"
}
},
"required": [
"slug",
"named_graph_iri"
],
"title": "brainkb_add_space_graphArguments",
"type": "object"
},
"name": "brainkb_add_space_graph",
"outputSchema": null
},
{
"description": "Add/update a space member. role: 'owner' | 'editor' | 'viewer'. Owner only.",
"inputSchema": {
"properties": {
"member_email": {
"title": "Member Email",
"type": "string"
},
"role": {
"default": "viewer",
"title": "Role",
"type": "string"
},
"slug": {
"title": "Slug",
"type": "string"
}
},
"required": [
"slug",
"member_email"
],
"title": "brainkb_add_space_memberArguments",
"type": "object"
},
"name": "brainkb_add_space_member",
"outputSchema": null
},
{
"description": "(Admin) Assign a role/group to a user by email (e.g. 'Lab Member', 'External',\n or a custom group). The user must already have a profile (created on first\n login/registration). NOTE: assigning the 'Admin'/'SuperAdmin' role is\n SuperAdmin-only (hierarchy: SuperAdmin > Admin).",
"inputSchema": {
"properties": {
"email": {
"title": "Email",
"type": "string"
},
"role": {
"title": "Role",
"type": "string"
}
},
"required": [
"email",
"role"
],
"title": "brainkb_assign_roleArguments",
"type": "object"
},
"name": "brainkb_assign_role",
"outputSchema": null
},
{
"description": "(Admin) List the available roles/groups (Admin, Lab Member, Curator, …).",
"inputSchema": {
"properties": {},
"title": "brainkb_available_rolesArguments",
"type": "object"
},
"name": "brainkb_available_roles",
"outputSchema": null
},
{
"description": "(Admin) Ban a user by email (reversible; preserves history). This is how\n accounts are removed — there is NO hard delete. Banning an Admin is\n SuperAdmin-only; SuperAdmin accounts cannot be banned.",
"inputSchema": {
"properties": {
"email": {
"title": "Email",
"type": "string"
},
"reason": {
"title": "Reason",
"type": "string"
}
},
"required": [
"email",
"reason"
],
"title": "brainkb_ban_userArguments",
"type": "object"
},
"name": "brainkb_ban_user",
"outputSchema": null
},
{
"description": "(Admin only) Show a user's roles, effective capabilities, and delegated\n grants. Useful to check why someone can/can't create team spaces, ingest, etc.",
"inputSchema": {
"properties": {
"member": {
"title": "Member",
"type": "string"
}
},
"required": [
"member"
],
"title": "brainkb_capabilitiesArguments",
"type": "object"
},
"name": "brainkb_capabilities",
"outputSchema": null
},
{
"description": "(Admin) Create a new usermanagement permission, e.g.\n name='dataset.export', resource='dataset', action='export'. Attach it to roles\n via the usermanagement role-permissions API.",
"inputSchema": {
"properties": {
"action": {
"title": "Action",
"type": "string"
},
"description": {
"default": "",
"title": "Description",
"type": "string"
},
"name": {
"title": "Name",
"type": "string"
},
"resource": {
"title": "Resource",
"type": "string"
}
},
"required": [
"name",
"resource",
"action"
],
"title": "brainkb_create_permissionArguments",
"type": "object"
},
"name": "brainkb_create_permission",
"outputSchema": null
},
{
"description": "(Admin) Create a new role/group — e.g. an 'External' collaborator group —\n which can then be assigned with brainkb_assign_role.",
"inputSchema": {
"properties": {
"category": {
"default": "Content",
"title": "Category",
"type": "string"
},
"description": {
"default": "",
"title": "Description",
"type": "string"
},
"name": {
"title": "Name",
"type": "string"
}
},
"required": [
"name"
],
"title": "brainkb_create_roleArguments",
"type": "object"
},
"name": "brainkb_create_role",
"outputSchema": null
},
{
"description": "Create a workspace/space. The caller becomes owner.\n slug: lowercase/hyphen id, **globally unique** — if it's already taken the call\n returns 409 (pick another slug; slugs are never reused/deleted).\n visibility: 'private' or 'public';\n description: short human description (recommended — surfaces in the registry);\n space_type: 'individual' (a personal space — any write-capable role) or 'team'\n (a shared space — only Admin/SuperAdmin, or a user granted create_team_space).",
"inputSchema": {
"properties": {
"description": {
"default": "",
"title": "Description",
"type": "string"
},
"name": {
"title": "Name",
"type": "string"
},
"slug": {
"title": "Slug",
"type": "string"
},
"space_type": {
"default": "individual",
"title": "Space Type",
"type": "string"
},
"visibility": {
"default": "private",
"title": "Visibility",
"type": "string"
}
},
"required": [
"slug",
"name"
],
"title": "brainkb_create_spaceArguments",
"type": "object"
},
"name": "brainkb_create_space",
"outputSchema": null
},
{
"description": "Generate a Personal Access Token (PAT) for browser-free auth. Requires you\n to be logged in already (brainkb_login or brainkb_globus_login). The token is\n shown ONCE and never again — copy it and set it as BRAINKB_TOKEN in your\n MCP/skill config; then no login or browser is needed until it expires.\n `name`: a label so you can tell tokens apart (e.g. 'laptop'). `days`: lifetime\n (default 90, server-capped). Treat the returned token like a password.",
"inputSchema": {
"properties": {
"days": {
"default": 90,
"title": "Days",
"type": "integer"
},
"name": {
"default": "",
"title": "Name",
"type": "string"
}
},
"title": "brainkb_create_tokenArguments",
"type": "object"
},
"name": "brainkb_create_token",
"outputSchema": null
},
{
"description": "(Admin) Deactivate a user's account by email.",
"inputSchema": {
"properties": {
"email": {
"title": "Email",
"type": "string"
}
},
"required": [
"email"
],
"title": "brainkb_deactivate_userArguments",
"type": "object"
},
"name": "brainkb_deactivate_user",
"outputSchema": null
},
{
"description": "The exact triples a job added (its delta), as JSON-LD.",
"inputSchema": {
"properties": {
"job_id": {
"title": "Job Id",
"type": "string"
}
},
"required": [
"job_id"
],
"title": "brainkb_deltaArguments",
"type": "object"
},
"name": "brainkb_delta",
"outputSchema": null
},
{
"description": "Compare two jobs' deltas: A-only / B-only / shared triple counts + triples.",
"inputSchema": {
"properties": {
"job_id_a": {
"title": "Job Id A",
"type": "string"
},
"job_id_b": {
"title": "Job Id B",
"type": "string"
}
},
"required": [
"job_id_a",
"job_id_b"
],
"title": "brainkb_delta_compareArguments",
"type": "object"
},
"name": "brainkb_delta_compare",
"outputSchema": null
},
{
"description": "A named graph's change history: one entry per ingest delta (job, triple\n count, timestamp), newest first.",
"inputSchema": {
"properties": {
"named_graph_iri": {
"title": "Named Graph Iri",
"type": "string"
}
},
"required": [
"named_graph_iri"
],
"title": "brainkb_delta_historyArguments",
"type": "object"
},
"name": "brainkb_delta_history",
"outputSchema": null
},
{
"description": "Delete one of your staged uploads without ingesting it.",
"inputSchema": {
"properties": {
"upload_id": {
"title": "Upload Id",
"type": "string"
}
},
"required": [
"upload_id"
],
"title": "brainkb_discard_uploadArguments",
"type": "object"
},
"name": "brainkb_discard_upload",
"outputSchema": null
},
{
"description": "Complete an OAuth login started with brainkb_globus_login by exchanging the\n one-time code shown in the browser for a session token. The code is single-use\n and never echoed back.",
"inputSchema": {
"properties": {
"base_url": {
"default": "",
"title": "Base Url",
"type": "string"
},
"code": {
"title": "Code",
"type": "string"
}
},
"required": [
"code"
],
"title": "brainkb_finish_loginArguments",
"type": "object"
},
"name": "brainkb_finish_login",
"outputSchema": {
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "brainkb_finish_loginOutput",
"type": "object"
}
},
{
"description": "Start an OAuth login (Globus / ORCID / GitHub) for THIS session — use this\n instead of brainkb_login when the user signs in with Globus rather than a\n password. Returns a URL to open in a browser; after signing in, the page shows\n a short one-time code — pass it to brainkb_finish_login(code) to complete.\n (The browser step is unavoidable: only the user can consent at the provider.)",
"inputSchema": {
"properties": {
"base_url": {
"default": "",
"title": "Base Url",
"type": "string"
},
"provider": {
"default": "globus",
"title": "Provider",
"type": "string"
}
},
"title": "brainkb_globus_loginArguments",
"type": "object"
},
"name": "brainkb_globus_login",
"outputSchema": {
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "brainkb_globus_loginOutput",
"type": "object"
}
},
{
"description": "(Admin only) Delegate a capability to a user — e.g. 'create_team_space' or\n 'manage_team_space' so a Curator/Lab Member can create/manage team spaces.\n Grantable: create_private_space, create_team_space, manage_team_space, ingest,\n recover, read_private (NOT the admin-only 'grant'/'sparql_admin').",
"inputSchema": {
"properties": {
"capability": {
"title": "Capability",
"type": "string"
},
"member": {
"title": "Member",
"type": "string"
}
},
"required": [
"member",
"capability"
],
"title": "brainkb_grant_capabilityArguments",
"type": "object"
},
"name": "brainkb_grant_capability",
"outputSchema": null
},
{
"description": "(Admin only) Grant a capability to a whole role/group so EVERY member gets\n it — e.g. give a custom group 'uk_collaborator' the 'ingest' or\n 'create_private_space' capability. Grantable: create_private_space,\n create_team_space, manage_team_space, ingest, recover, read_private (NOT the\n admin-only 'grant'/'sparql_admin'). Create the group first with\n brainkb_create_role, then assign it to users with brainkb_assign_role.",
"inputSchema": {
"properties": {
"capability": {
"title": "Capability",
"type": "string"
},
"role": {
"title": "Role",
"type": "string"
}
},
"required": [
"role",
"capability"
],
"title": "brainkb_grant_role_capabilityArguments",
"type": "object"
},
"name": "brainkb_grant_role_capability",
"outputSchema": null
},
{
"description": "Ingest local RDF files (ttl/nt/nq/rdf/owl/jsonld/json) into a named graph.\n Returns a job_id; runs in the background — poll with brainkb_job_status.",
"inputSchema": {
"properties": {
"file_paths": {
"items": {
"type": "string"
},
"title": "File Paths",
"type": "array"
},
"max_concurrency": {
"default": 8,
"title": "Max Concurrency",
"type": "integer"
},
"named_graph_iri": {
"title": "Named Graph Iri",
"type": "string"
}
},
"required": [
"named_graph_iri",
"file_paths"
],
"title": "brainkb_ingest_filesArguments",
"type": "object"
},
"name": "brainkb_ingest_files",
"outputSchema": null
},
{
"description": "Ingest raw RDF text (Turtle / N-Triples / JSON-LD, auto-detected) into a\n named graph. Returns a job_id; ingestion runs in the background — poll with\n brainkb_job_status. The graph must be registered (see brainkb_add_space_graph)\n and the caller must have write access to its space.\n\n `sha256` / `expected_bytes` are an integrity contract, and you should use them\n whenever the RDF came from a file. Ingest is append-only — no delete for\n triples, no unregister for a graph — so RDF that arrives here mangled is\n permanent. Because `data` is a string, it passes through the caller's context,\n where dense Turtle is exactly what gets silently altered: ligatures, Greek\n letters, embedded newlines, escaped quotes. Declare the digest of the bytes you\n MEANT to send (`shasum -a 256 file.ttl`) and this refuses the write on any\n mismatch, turning an unrecoverable corruption into a clean rejection.\n ",
"inputSchema": {
"properties": {
"data": {
"title": "Data",
"type": "string"
},
"expected_bytes": {
"default": 0,
"title": "Expected Bytes",
"type": "integer"
},
"named_graph_iri": {
"title": "Named Graph Iri",
"type": "string"
},
"sha256": {
"default": "",
"title": "Sha256",
"type": "string"
}
},
"required": [
"named_graph_iri",
"data"
],
"title": "brainkb_ingest_textArguments",
"type": "object"
},
"name": "brainkb_ingest_text",
"outputSchema": null
},
{
"description": "Ingest a file you staged with `POST /upload` into a named graph.\n\n This is the route for a large local file: your HTTP client streams the bytes\n straight to this server over HTTPS, then you name the resulting upload_id here. The\n server reads its own staged copy and posts it to the ingest API internally, so\n the RDF never passes through a model's context — nothing to transcribe, no\n context-window ceiling, and no reason to split the document (splitting breaks\n blank-node identity and silently detaches triples, permanently).\n\n Stage a file with any HTTP client — the point is that the LIBRARY reads the file,\n so the bytes never pass through a model:\n\n import requests, hashlib, pathlib\n f = pathlib.Path(\"review.ttl\")\n r = requests.post(\n \"https://mcp.brainkb.org/upload\",\n params={\"filename\": f.name,\n \"sha256\": hashlib.sha256(f.read_bytes()).hexdigest()},\n headers={\"Authorization\": f\"Bearer {TOKEN}\"},\n data=f.open(\"rb\"), # streamed — never loaded into memory\n )\n print(r.json()) # -> {\"upload_id\": \"up_...\", \"state\": \"staged\"}\n\n It returns an upload_id and the sha256 the server computed — compare it with your\n own before ingesting.\n\n Returns a job_id; poll brainkb_job_status, then reconcile brainkb_delta(job_id)\n against the triple count you expected. The staged copy is deleted once the\n ingest API has accepted the bytes.\n ",
"inputSchema": {
"properties": {
"named_graph_iri": {
"title": "Named Graph Iri",
"type": "string"
},
"upload_id": {
"title": "Upload Id",
"type": "string"
}
},
"required": [
"named_graph_iri",
"upload_id"
],
"title": "brainkb_ingest_uploadArguments",
"type": "object"
},
"name": "brainkb_ingest_upload",
"outputSchema": null
},
{
"description": "Detailed status of one ingest job: status, progress %, current file/stage,\n per-file failures, and (when complete) a summary.",
"inputSchema": {
"properties": {
"job_id": {
"title": "Job Id",
"type": "string"
}
},
"required": [
"job_id"
],
"title": "brainkb_job_statusArguments",
"type": "object"
},
"name": "brainkb_job_status",
"outputSchema": null
},
{
"description": "List a space's fine-grained access rules (member/manager of the space).",
"inputSchema": {
"properties": {
"slug": {
"title": "Slug",
"type": "string"
}
},
"required": [
"slug"
],
"title": "brainkb_list_access_rulesArguments",
"type": "object"
},
"name": "brainkb_list_access_rules",
"outputSchema": null
},
{
"description": "(Admin only) Catalog of all KG capabilities, which are delegatable\n ('grantable'), which are admin-only, and a description of each. Use this to see\n the available permission options before granting to a user or group/role.",
"inputSchema": {
"properties": {},
"title": "brainkb_list_capabilitiesArguments",
"type": "object"
},
"name": "brainkb_list_capabilities",
"outputSchema": null
},
{
"description": "List the user's ingest jobs (newest first) with status and progress.",
"inputSchema": {
"properties": {
"limit": {
"default": 50,
"title": "Limit",
"type": "integer"
}
},
"title": "brainkb_list_jobsArguments",
"type": "object"
},
"name": "brainkb_list_jobs",
"outputSchema": null
},
{
"description": "(Admin) List all usermanagement permissions (resource/action pairs used for\n page-access and role-permission mapping). These are the addable 'permission'\n options; KG action-capabilities are listed by brainkb_list_capabilities.",
"inputSchema": {
"properties": {},
"title": "brainkb_list_permissionsArguments",
"type": "object"
},
"name": "brainkb_list_permissions",
"outputSchema": null
},
{
"description": "List registered named graphs visible to the caller (private-space graphs the\n caller can't access are hidden).",
"inputSchema": {
"properties": {},
"title": "brainkb_list_registered_graphsArguments",
"type": "object"
},
"name": "brainkb_list_registered_graphs",
"outputSchema": null
},
{
"description": "List spaces the user can see (their own/member spaces + public ones), each\n annotated with THIS caller's permission so you know what they may do:\n - your_role: 'owner' | 'editor' | 'viewer' | null (their space membership)\n - is_owner: they own the space\n - access: 'owner' | 'member' | 'public' (how it's available to them)\n - can_write: their space role permits ingest (owner/editor) — a real ingest\n also needs the 'ingest' capability + any per-space access rules.\n Use this to tell the user which spaces they can read vs. write vs. only see as\n public.",
"inputSchema": {
"properties": {},
"title": "brainkb_list_spacesArguments",
"type": "object"
},
"name": "brainkb_list_spaces",
"outputSchema": null
},
{
"description": "List your Personal Access Tokens (metadata only — the secret is never\n shown): id, name, prefix, created/last-used/expiry, and whether each is\n active/revoked/expired. Use the id with brainkb_revoke_token.",
"inputSchema": {
"properties": {},
"title": "brainkb_list_tokensArguments",
"type": "object"
},
"name": "brainkb_list_tokens",
"outputSchema": null
},
{
"description": "List RDF files YOU have staged with POST /upload but not yet ingested.\n\n Shows each upload_id, its size, sha256 and when it expires. Only your own\n uploads are visible.",
"inputSchema": {
"properties": {},
"title": "brainkb_list_uploadsArguments",
"type": "object"
},
"name": "brainkb_list_uploads",
"outputSchema": null
},
{
"description": "(Admin) List users (profiles) — filter by `q` (name/email/orcid) or `role`.\n Shows profile_id, email, roles, providers, ban status.",
"inputSchema": {
"properties": {
"limit": {
"default": 50,
"title": "Limit",
"type": "integer"
},
"q": {
"default": "",
"title": "Q",
"type": "string"
},
"role": {
"default": "",
"title": "Role",
"type": "string"
}
},
"title": "brainkb_list_usersArguments",
"type": "object"
},
"name": "brainkb_list_users",
"outputSchema": null
},
{
"description": "Authenticate to BrainKB with the user's credentials and cache the JWT for\n THIS session only (isolated per caller). The password/token are never echoed.\n\n Uses single sign-on: one login mints a refresh token, cached for THIS session,\n which is exchanged on demand for per-service access tokens (query_service,\n usermanagement, …). Falls back to a legacy per-service token if the backend\n has no SSO. On the hosted multi-user remote you can skip this and instead have\n your client send an 'Authorization: Bearer <token>' header (a refresh token\n unlocks all services).",
"inputSchema": {
"properties": {
"base_url": {
"default": "",
"title": "Base Url",
"type": "string"
},
"email": {
"title": "Email",
"type": "string"
},
"password": {
"title": "Password",
"type": "string"
}
},
"required": [
"email",
"password"
],
"title": "brainkb_loginArguments",
"type": "object"
},
"name": "brainkb_login",
"outputSchema": {
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "brainkb_loginOutput",
"type": "object"
}
},
{
"description": "Forget the cached token for this session.",
"inputSchema": {
"properties": {},
"title": "brainkb_logoutArguments",
"type": "object"
},
"name": "brainkb_logout",
"outputSchema": {
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "brainkb_logoutOutput",
"type": "object"
}
},
{
"description": "PROV-O ingestion/activity history (JSON-LD) for a named graph.",
"inputSchema": {
"properties": {
"named_graph_iri": {
"title": "Named Graph Iri",
"type": "string"
}
},
"required": [
"named_graph_iri"
],
"title": "brainkb_provenance_graphArguments",
"type": "object"
},
"name": "brainkb_provenance_graph",
"outputSchema": null
},
{
"description": "PROV-O provenance bundle (JSON-LD) for one ingest job.",
"inputSchema": {
"properties": {
"job_id": {
"title": "Job Id",
"type": "string"
}
},
"required": [
"job_id"
],
"title": "brainkb_provenance_jobArguments",
"type": "object"
},
"name": "brainkb_provenance_job",
"outputSchema": null
},
{
"description": "Find a canned question BrainKB can answer, then run it with brainkb_qa_run.\n\n Prefer these over writing SPARQL: they are vetted against BrainKB's actual\n vocabulary. Discovery is two steps, so you never read every query at once:\n\n 1. brainkb_qa_list() -> the menu: each category's name, a description of\n the questions it covers, and how many queries it has. Pick the category\n whose description matches the user's question.\n 2. brainkb_qa_list(category=\"<name>\") -> that category's queries. Each has\n `question` (what it answers), `notes` (when to use it, where parameter\n values come from, what the results mean), `params` (required ones have\n no default — ask the user rather than guess) and a working `example`.\n\n `search=\"words\"` filters queries by words in their id/question/notes; use it\n alone to search every category when none of the descriptions fits.\n ",
"inputSchema": {
"properties": {
"category": {
"default": "",
"title": "Category",
"type": "string"
},
"search": {
"default": "",
"title": "Search",
"type": "string"
}
},
"title": "brainkb_qa_listArguments",
"type": "object"
},
"name": "brainkb_qa_list",
"outputSchema": null
},
{
"description": "Run a canned question from brainkb_qa_list by id. `params` maps parameter\n names to values; they are validated and escaped, never spliced in raw. Runs\n through the same SPARQL endpoint as brainkb_sparql, so it needs the same\n role.",
"inputSchema": {
"properties": {
"params": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"title": "Params"
},
"query_id": {
"title": "Query Id",
"type": "string"
}
},
"required": [
"query_id"
],
"title": "brainkb_qa_runArguments",
"type": "object"
},
"name": "brainkb_qa_run",
"outputSchema": null
},
{
"description": "Read all RDF (JSON-LD) in a space's graphs. Public spaces are readable by\n anyone; private spaces require membership.",
"inputSchema": {
"properties": {
"slug": {
"title": "Slug",
"type": "string"
}
},
"required": [
"slug"
],
"title": "brainkb_read_spaceArguments",
"type": "object"
},
"name": "brainkb_read_space",
"outputSchema": null
},
{
"description": "Attempt to recover a stuck/errored ingest job (marks it recoverable/errored).",
"inputSchema": {
"properties": {
"job_id": {
"title": "Job Id",
"type": "string"
}
},
"required": [
"job_id"
],
"title": "brainkb_recover_jobArguments",
"type": "object"
},
"name": "brainkb_recover_job",
"outputSchema": null
},
{
"description": "(Space manager) Delete a fine-grained access rule by its id\n (see brainkb_list_access_rules).",
"inputSchema": {
"properties": {
"rule_id": {
"title": "Rule Id",
"type": "integer"
},
"slug": {
"title": "Slug",
"type": "string"
}
},
"required": [
"slug",
"rule_id"
],
"title": "brainkb_remove_access_ruleArguments",
"type": "object"
},
"name": "brainkb_remove_access_rule",
"outputSchema": null
},
{
"description": "(Admin) Remove a role/group from a user by email.",
"inputSchema": {
"properties": {
"email": {
"title": "Email",
"type": "string"
},
"role": {
"title": "Role",
"type": "string"
}
},
"required": [
"email",
"role"
],
"title": "brainkb_remove_roleArguments",
"type": "object"
},
"name": "brainkb_remove_role",
"outputSchema": null
},
{
"description": "(Admin only) Revoke a previously granted capability from a user.",
"inputSchema": {
"properties": {
"capability": {
"title": "Capability",
"type": "string"
},
"member": {
"title": "Member",
"type": "string"
}
},
"required": [
"member",
"capability"
],
"title": "brainkb_revoke_capabilityArguments",
"type": "object"
},
"name": "brainkb_revoke_capability",
"outputSchema": null
},
{
"description": "(Admin only) Revoke a capability from a role/group.",
"inputSchema": {
"properties": {
"capability": {
"title": "Capability",
"type": "string"
},
"role": {
"title": "Role",
"type": "string"
}
},
"required": [
"role",
"capability"
],
"title": "brainkb_revoke_role_capabilityArguments",
"type": "object"
},
"name": "brainkb_revoke_role_capability",
"outputSchema": null
},
{
"description": "Revoke one of your Personal Access Tokens by id (see brainkb_list_tokens).\n Takes effect immediately — the next call using that token fails.",
"inputSchema": {
"properties": {
"token_id": {
"title": "Token Id",
"type": "integer"
}
},
"required": [
"token_id"
],
"title": "brainkb_revoke_tokenArguments",
"type": "object"
},
"name": "brainkb_revoke_token",
"outputSchema": null
},
{
"description": "(Admin only) List the capabilities granted to a role/group (e.g.\n 'uk_collaborator', 'Lab Member').",
"inputSchema": {
"properties": {
"role": {
"title": "Role",
"type": "string"
}
},
"required": [
"role"
],
"title": "brainkb_role_capabilitiesArguments",
"type": "object"
},
"name": "brainkb_role_capabilities",
"outputSchema": null
},
{
"description": "Full-text search over the knowledge graphs, access-filtered by space\n visibility. Pass `space` to scope to one workspace, omit for a full search.\n Anonymous/other users never see private-space data.",
"inputSchema": {
"properties": {
"limit": {
"default": 25,
"title": "Limit",
"type": "integer"
},
"offset": {
"default": 0,
"title": "Offset",
"type": "integer"
},
"q": {
"title": "Q",
"type": "string"
},
"space": {
"default": "",
"title": "Space",
"type": "string"
}
},
"required": [
"q"
],
"title": "brainkb_searchArguments",
"type": "object"
},
"name": "brainkb_search",
"outputSchema": null
},
{
"description": "Set a space 'public' (anyone, even anonymous, can read) or 'private'\n (members only). Owner only.",
"inputSchema": {
"properties": {
"slug": {
"title": "Slug",
"type": "string"
},
"visibility": {
"title": "Visibility",
"type": "string"
}
},
"required": [
"slug",
"visibility"
],
"title": "brainkb_set_space_visibilityArguments",
"type": "object"
},
"name": "brainkb_set_space_visibility",
"outputSchema": null
},
{
"description": "Run an arbitrary SPARQL query. Requires an Admin/SuperAdmin role (the\n sparql_admin capability) — for ordinary questions prefer brainkb_search,\n brainkb_read_space, or the provenance/delta tools, which need no admin role.",
"inputSchema": {
"properties": {
"sparql_query": {
"title": "Sparql Query",
"type": "string"
}
},
"required": [
"sparql_query"
],
"title": "brainkb_sparqlArguments",
"type": "object"
},
"name": "brainkb_sparql",
"outputSchema": null
},
{
"description": "(Admin) Lift a ban on a user by email.",
"inputSchema": {
"properties": {
"email": {
"title": "Email",
"type": "string"
}
},
"required": [
"email"
],
"title": "brainkb_unban_userArguments",
"type": "object"
},
"name": "brainkb_unban_user",
"outputSchema": null
},
{
"description": "State of one of your staged/submitted uploads.\n\n `state` is `staged` (waiting for brainkb_ingest_upload), `submitting` (the server\n is streaming it to the ingest API), `submitted` (accepted — `job_id` is set, poll\n brainkb_job_status) or `failed` (the staged bytes were KEPT, so retry with\n brainkb_ingest_upload rather than re-uploading).",
"inputSchema": {
"properties": {
"upload_id": {
"title": "Upload Id",
"type": "string"
}
},
"required": [
"upload_id"
],
"title": "brainkb_upload_statusArguments",
"type": "object"
},
"name": "brainkb_upload_status",
"outputSchema": null
},
{
"description": "Use a Personal Access Token (brainkb_pat_...) for THIS session — an\n alternative to setting BRAINKB_TOKEN in the config. Validates the token, then\n caches it so subsequent calls authenticate with it. The token is never echoed.",
"inputSchema": {
"properties": {
"base_url": {
"default": "",
"title": "Base Url",
"type": "string"
},
"token": {
"title": "Token",
"type": "string"
}
},
"required": [
"token"
],
"title": "brainkb_use_tokenArguments",
"type": "object"
},
"name": "brainkb_use_token",
"outputSchema": {
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "brainkb_use_tokenOutput",
"type": "object"
}
},
{
"description": "Report the current caller's auth state (email, authenticated, and when the\n cached session expires). When signed in it also returns base_url — the backend\n THIS SERVER talks to, which on a hosted deployment is an internal address and\n says nothing about the caller's own machine.",
"inputSchema": {
"properties": {},
"title": "brainkb_whoamiArguments",
"type": "object"
},
"name": "brainkb_whoami",
"outputSchema": {
"properties": {
"result": {
"additionalProperties": true,
"title": "Result",
"type": "object"
}
},
"required": [
"result"
],
"title": "brainkb_whoamiOutput",
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:71562d4dccca694c786d5a64602d4a8cf50367b544300f333cca2c49dc5e318c | sha256sum