Grafbase
for LuumenAI

Read federated schemas and audit logs, then change graph config with approval

Connect Grafbase and your agent can read the composed federated schema, individual subgraph SDL, schema checks, audit logs, and API keys without waiting on a console tab. Changes — assigning a team role, enabling an MCP server, retiring an API key, removing a subgraph — are previewed first and go through approval before they run.

The Grafbase toolbox

28 tools: 17 read, 11 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadDelete Grafbase Audit LogDelete a specific Grafbase audit log entry.
  • ReadDelete Schema CheckAttempt to delete a schema check from the Grafbase platform.
  • ReadGet Grafbase Audit LogRetrieve a specific Grafbase audit log entry by searching organization activity.
  • ReadGet Extension by NameRetrieve a Grafbase extension by its name.
  • ReadGet Extension Version By Name And VersionRetrieve details of a specific Grafbase extension version by name and version.
  • ReadGet Federated SchemaRetrieves the composed federated graph schema from Grafbase in SDL format.
  • ReadGet Grafbase InvitationRetrieve details about a specific Grafbase invitation by ID.
  • ReadGet Notifications Inbox MessagesRetrieve notifications inbox messages for the authenticated Grafbase user.
  • ReadGet Grafbase Schema CheckRetrieve details of a specific schema check by its ID.
  • ReadGet Subgraph SchemaRetrieves the GraphQL SDL schema for a specific subgraph by name.
  • ReadList API KeysList all API keys (access tokens) for the authenticated Grafbase user.
  • ReadList Grafbase Audit LogsList audit logs for Grafbase organizations.
  • ReadList ExtensionsList all extensions configured for a Grafbase project.
  • ReadList MCP ServersCheck MCP server configuration status for a Grafbase gateway.
  • ReadList Grafbase Schema ChecksList schema checks for a Grafbase graph.
  • ReadList Grafbase SchemasList all schemas in the Grafbase schema registry.
  • ReadList Grafbase SubgraphsList published subgraphs in your Grafbase federated graphs.
  • WriteAdd Zitadel Redirect URIAdd a redirect URI to Zitadel OAuth configuration in Grafbase. Approval by default
  • WriteAssign Team RoleAssign a role to a team member in Grafbase. Approval by default
  • WriteDelete Grafbase API KeyDelete an existing Grafbase API key (access token) by ID. Approval by default
  • WriteDelete ExtensionDelete a Grafbase extension configuration by its unique ID. Approval by default
  • WriteDelete MCP ServerDelete a Grafbase MCP server configuration by its unique ID. Approval by default
  • WriteDelete Grafbase SubgraphDelete a subgraph from a Grafbase federated graph. Approval by default
  • WriteDelete Grafbase TeamDelete a team from the Grafbase organization. Approval by default
  • WriteDisable MCP ServerDisable the Model Context Protocol (MCP) server for a Grafbase project. Approval by default
  • WriteEnable Grafbase MCP ServerEnable the Model Context Protocol (MCP) server on a Grafbase gateway. Approval by default
  • WriteMark Notifications as ReadMark Grafbase notifications as read. Approval by default
  • WriteRemove Graph OwnerRemove an owner from a Grafbase graph. Approval by default

One prompt, start to finish

What a governed Grafbase run looks like inside Luumen.

Questions

How does LuumenAI connect to Grafbase?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Grafbase on its own?

Read actions answer immediately. Anything that writes — add zitadel redirect uri, assign team role, delete grafbase api key, delete extension, and more — is shown as a plan and requires approval by default, including the 7 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Grafbase — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Grafbase to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.