LATTICE · graph database

Connect to your workspace

Everything you need to point an app, a dashboard, or an AI agent like Claude at your private Lattice graph — in a few minutes.

lattice> connect --app --mcp --team

Your workspace lives at https://<your-workspace>.lattice-db.se — an isolated graph database that's yours alone. People use the web console; apps and AI agents connect with an access token over HTTPS. This guide covers both.

Throughout, replace <your-workspace> with your actual subdomain and <token> with a token you create in step 2.

Step 1

Sign in to the console

Open https://<your-workspace>.lattice-db.se in a browser and sign in with your username and password. If your organization uses single sign-on, click “Sign in with SSO” instead.

Once you're in, you get a query editor, an interactive graph view, and an ontology browser. If you're an admin, you'll also see a Settings tab — that's where tokens, users, and SSO live.

Step 2

Create an access token

Apps and agents authenticate with a bearer token, never your password. Each token carries a role that decides what it can do.

  1. In the console, go to Settings → Tokens.
  2. Give it a name (e.g. my-app or claude) and pick a role.
  3. Click Create, then copy it immediately — a token is shown only once and can't be retrieved later.
RoleCan doUse it for
readonlyRead data only.Dashboards, analytics, read-only agents.
readwriteRead and write data (not schema).Your application's normal traffic.
adminEverything — read, write, and change the schema/ontology; manage tokens & users.Migrations, setup, letting Claude build your ontology.

Least privilege. Give each app the lowest role it needs — a readonly token physically cannot write. Create separate tokens per app so you can revoke one without affecting the others.

Step 3

Connect your app (HTTP API)

Send queries to the JSON endpoint with your token in the Authorization header. Every query goes to one place:

POST https://<your-workspace>.lattice-db.se/query

cURL

bash
curl -s https://<your-workspace>.lattice-db.se/query \
  -H "Authorization: Bearer <token>" \
  -H "Content-Type: application/json" \
  -d '{"query":"MATCH (n:Person) RETURN n.name LIMIT 10"}'

JavaScript

javascript
const res = await fetch("https://<your-workspace>.lattice-db.se/query", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    query: "MATCH (p:Person)-[:KNOWS]->(f) WHERE p.name = $name RETURN f.name",
    params: { name: "Ada" },
  }),
});
const { columns, rows } = await res.json();

Python

python
import requests

r = requests.post(
    "https://<your-workspace>.lattice-db.se/query",
    headers={"Authorization": "Bearer <token>"},
    json={"query": "MATCH (n) RETURN count(n) AS n"},
)
print(r.json())  # {"columns": ["n"], "rows": [[42]]}
  • Pass values as parameters ($name) via the params object — never string-concatenate into the query.
  • The response is { "columns": [...], "rows": [[...]] }. A returned node or relationship carries its label/type and properties.
  • Queries use openCypherMATCH, CREATE, MERGE, aggregation, variable-length paths, and more.
Step 4

Connect Claude (MCP)

The Model Context Protocol lets an AI agent like Claude talk to your graph directly — run queries, read the schema, and (with a write-capable token) build your ontology for you. Your workspace speaks MCP at /mcp.

The Settings → Tokens panel gives you a ready-to-paste MCP snippet when you create a token — the quickest way to get the exact config for your workspace.

Claude Code (CLI)

bash
claude mcp add --transport http lattice \
  https://<your-workspace>.lattice-db.se/mcp \
  --header "Authorization: Bearer <token>"

Claude Desktop

Open Settings → Developer → Edit Config and add your workspace under mcpServers:

json
{
  "mcpServers": {
    "lattice": {
      "type": "streamable-http",
      "url": "https://<your-workspace>.lattice-db.se/mcp",
      "headers": { "Authorization": "Bearer <token>" }
    }
  }
}

Restart Claude Desktop fully (quit from the tray/menu bar, not just the window). The lattice tools then appear under the tools/connector icon.

What Claude can do

  • query — run openCypher and get the results back.
  • explain — see a query's plan without running it.
  • lattice://schema — read the tables, relationships, and indexes.
  • With an admin or readwrite token, Claude can create your ontology — node & relationship tables, hierarchies, and constraints. A readonly token lets it explore but never change anything.

Try it: with an admin token connected, ask — “Read the lattice://schema resource, then design and create an ontology for my domain: node tables, relationships, and constraints. Build it incrementally and read the schema back after each step.”

Step 5

Invite your team

Give teammates their own console login (admins only):

  1. Go to Settings → Users.
  2. Add a name, a password, and a role (readonly / readwrite / admin).
  3. Share the credentials with your teammate — they sign in at your workspace URL.

Prefer central control? Wire up SSO (next) and your team logs in with your identity provider instead of individual passwords.

Step 6

Single sign-on (SSO)

Under Settings → Single sign-on, connect your OIDC identity provider (Authentik, Okta, Entra, Google Workspace, …) so your team signs in with it — and map IdP groups to Lattice roles.

  • Enter your provider's issuer, client id, and client secret, set a redirect URL of https://<your-workspace>.lattice-db.se/auth/sso/callback, and save. Lattice validates the provider before enabling it.
  • A “Sign in with SSO” button then appears on your login page.

If the SSO card shows “Managed by your organization,” your provider is configured centrally and can't be changed here — just use the SSO button to sign in.

Good to know

Handling tokens safely

  • Shown once. Copy a token when you create it and store it in your app's secret manager or .env — never in source control.
  • Revoke anytime. Delete a token in Settings → Tokens and it stops working immediately; issue a fresh one to rotate.
  • One token per app/agent, each at the lowest role it needs, so a leak is contained and revocation is surgical.
  • Isolated by design. Your workspace is a private database — your tokens only work against your graph, and no one else's tokens work against it.