Grafbase MCP server for AI agents and assistants

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with Grafbase MCP or direct API to query data, update resources, manage API schemas, and trigger mutations through natural language.

Grafbase logoGrafbase
Api Key

Grafbase is a platform for building and scaling GraphQL APIs with edge caching and unified data access. It's designed to help you deliver fast, secure, and seamless APIs—all in one place.

28 Tools

Try Grafbase now

Type what you want done — sign in and watch it run live in the Tool Router playground.

TOOL ROUTER PLAYGROUND
Grafbase
Try asking
TOOLS

Supported Tools

Every Grafbase action and event your agent gets out of the box.

Add Zitadel Redirect URI

Add a redirect URI to Zitadel OAuth configuration in Grafbase.

Assign Team Role

Tool to assign a role to a team member in Grafbase.

Delete Grafbase API Key

Delete an existing Grafbase API key (access token) by ID.

Delete Grafbase Audit Log

Tool to delete a specific Grafbase audit log entry.

Delete Extension

Tool to delete a Grafbase extension configuration by its unique ID.

Delete MCP Server

Tool to delete a Grafbase MCP server configuration by its unique ID.

Delete Grafbase Subgraph

Tool to delete a subgraph from a Grafbase federated graph.

Delete Schema Check

Attempt to delete a schema check from the Grafbase platform.

Delete Grafbase Team

Tool to delete a team from the Grafbase organization.

Disable MCP Server

Disable the Model Context Protocol (MCP) server for a Grafbase project.

Enable Grafbase MCP Server

Enable the Model Context Protocol (MCP) server on a Grafbase gateway.

Get Grafbase Audit Log

Tool to retrieve a specific Grafbase audit log entry by searching organization activity.

Get Extension by Name

Tool to retrieve a Grafbase extension by its name.

Get Extension Version By Name And Version

Tool to retrieve details of a specific Grafbase extension version by name and version.

Get Federated Schema

Retrieves the composed federated graph schema from Grafbase in SDL format.

Get Grafbase Invitation

Tool to retrieve details about a specific Grafbase invitation by ID.

Get Notifications Inbox Messages

Tool to retrieve notifications inbox messages for the authenticated Grafbase user.

Get Grafbase Schema Check

Retrieve details of a specific schema check by its ID.

Get Subgraph Schema

Retrieves the GraphQL SDL schema for a specific subgraph by name.

List API Keys

List all API keys (access tokens) for the authenticated Grafbase user.

List Grafbase Audit Logs

Tool to list audit logs for Grafbase organizations.

List Extensions

Tool to list all extensions configured for a Grafbase project.

List MCP Servers

Check MCP server configuration status for a Grafbase gateway.

List Grafbase Schema Checks

List schema checks for a Grafbase graph.

List Grafbase Schemas

Tool to list all schemas in the Grafbase schema registry.

List Grafbase Subgraphs

Tool to list published subgraphs in your Grafbase federated graphs.

Mark Notifications as Read

Tool to mark Grafbase notifications as read.

Remove Graph Owner

Tool to remove an owner from a Grafbase graph.

SETUP GUIDE

Connect Grafbase MCP Tool with your Agent

1

Install Composio

typescript
npm install @composio/core ai @ai-sdk/mcp @ai-sdk/openai
Install the Composio SDK and your agent framework
2

Create a session with MCP enabled

typescript
import { Composio } from "@composio/core";

const composio = new Composio();
const { mcp } = await composio.create("your-user-id", {
  toolkits: ["grafbase"],
  mcp: true,
});
Create a session scoped to Grafbase and read its MCP URL and headers
3

Connect your agent to the MCP server

typescript
import { createMCPClient } from "@ai-sdk/mcp";
import { openai } from "@ai-sdk/openai";
import { generateText, stepCountIs } from "ai";

const client = await createMCPClient({
  transport: { type: "http", url: mcp.url, headers: mcp.headers },
});

const { text } = await generateText({
  model: openai("gpt-5.6-sol"),
  tools: await client.tools(),
  prompt: "Fetch federated schema for production environment",
  stopWhen: stepCountIs(10),
});

console.log(text);
await client.close();
Pass the session's MCP URL and headers to your agent and run a Grafbase request
SETUP GUIDE

Connect Grafbase API Tool with your Agent

1

Install Composio

typescript
npm install @composio/core @composio/openai openai
Install the Composio SDK, the OpenAI provider, and the OpenAI SDK
2

Create a Composio session

typescript
import OpenAI from "openai";
import { Composio } from "@composio/core";
import { OpenAIResponsesProvider } from "@composio/openai";

const composio = new Composio({ provider: new OpenAIResponsesProvider() });
const client = new OpenAI();

const session = await composio.create("your-user-id", { toolkits: ["grafbase"] });
const tools = await session.tools();
Initialize Composio with the OpenAI Responses provider and create a session scoped to Grafbase
3

Run Grafbase tools with your agent

typescript
let response = await client.responses.create({
  model: "gpt-5.6-sol",
  tools,
  input: [{ role: "user", content: "Fetch federated schema for production environment" }],
});

while (response.output.some((o) => o.type === "function_call")) {
  const outputs = await composio.provider.handleToolCalls(session, response.output);
  response = await client.responses.create({
    model: "gpt-5.6-sol",
    tools,
    previous_response_id: response.id,
    input: outputs,
  });
}

console.log(response.output_text);
Send a request, execute the Grafbase tool calls through the session, and print the final answer

Why Use Composio?

AI Native Grafbase Integration

  • Supports both Grafbase MCP and direct API based integrations
  • Structured, LLM-friendly schemas for reliable tool execution
  • Rich coverage for reading, writing, and querying your Grafbase data

Managed Auth

  • Built-in API key management with secure storage
  • Central place to manage, scope, and revoke Grafbase access
  • Per user and per environment credentials instead of hard-coded keys

Agent Optimized Design

  • Tools are tuned using real error and success rates to improve reliability over time
  • Comprehensive execution logs so you always know what ran, when, and on whose behalf

Enterprise Grade Security

  • Fine-grained RBAC so you control which agents and users can access Grafbase
  • Scoped, least privilege access to Grafbase resources
  • Full audit trail of agent actions to support review and compliance

Rolling this out across your team?

Give your team centralized access control across every framework with Composio’s MCP Gateway.

EXPLORE MCP GATEWAY
FAQ

Frequently asked questions

Yes, Grafbase requires you to configure your own API key credentials. Once set up, Composio handles secure credential storage and API request handling for you.

Yes! Composio's Tool Router enables agents to use multiple toolkits. Learn more.

Yes. Composio is SOC 2 Type II compliant and is built to keep your Grafbase connection and credentials secure. OAuth tokens and API keys are encrypted, and sensitive customer data is protected at rest and in transit.

Composio also undergoes independent security testing and continuously monitors its systems for security threats. You can review the latest reports and policies in the Composio Trust Center.

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

Create the key in your Grafbase account settings, then paste it once on Composio's connection page. Composio stores it encrypted and uses it only for the Grafbase actions your agent runs. Nobody else in your workspace can read it, and you can revoke it inside Grafbase at any time.

When you connect a Grafbase account through Composio, every action runs under that account, so anything the agent creates, sends, or changes shows up in Grafbase as done by you. Keep an approval step in your prompt for actions with side effects, such as sending or deleting, and have the agent draft first.

Whatever the credentials you connect allow inside Grafbase. If Grafbase lets you scope a key to specific permissions, create a scoped one so the agent can only do what you intend. You can revoke the key inside Grafbase at any time.

Yes. Composio supports multiple connected accounts for the same app, and that works in Claude, ChatGPT, or any other assistant you connect through Composio. Give each Grafbase connection a name such as work or personal, and the assistant uses the one you mention in the request. Each account keeps its own credentials and nothing is merged.

The connection stops working the moment Grafbase rejects the old key. Create a new key in Grafbase and reconnect the account from the Composio dashboard or by asking your agent to reconnect Grafbase. Nothing else changes.

Composio's free Hobby plan includes 100,000 tool calls per month with no credit card, which covers most personal Grafbase use. Paid plans add higher limits and team features. Your Grafbase plan and its API limits still apply as usual.

Built-in connectors usually give one AI access to a limited set of apps. Many people use Composio because it lets their AI connect to more apps than it normally supports, or connect to multiple accounts for the same app (e.g. connect Claude to multiple Grafbase accounts).

With Composio, you connect Grafbase once and then use it across different AI assistants without setting it up separately in each one. Connect your apps to Composio once, then connect Composio to whichever AI you use, whether that's Claude, ChatGPT, Hermes, or your own custom assistant.

Start with Grafbase.It takes 30 seconds.

Managed auth, hosted MCP servers, and every Grafbase tool your agent needs.Free to start.

Start building