CodeGraph MCP v2.2.1
GitHub Star
v2.2.1 Production · Runtime & Database Verified

The deterministic
code-intelligence engine.

CodeGraph MCP maps repository relationships with runtime telemetry reconciliation and database lineage. AI coding agents resolve call hierarchies, mutating SQL queries, and API routes in < 50ms without token waste.

$ pip install codegraph-engine[mcp]
1from codegraph import reconcile_static_runtime
2
3# Reconcile static AST edges against live recorded traces
4report = reconcile_static_runtime(
5 route="/api/v1/scan-bill",
6 table="bills"
7)
8
9# Verified execution context returned in < 25ms:
10assert report.status == "RECONCILED"
11>>> [scan_bill_handler → BillService.process (RUNTIME_OBSERVED)]
12>>> [BillService.process → bills table (DATAFLOW_VERIFIED)]
1-- Trace all mutating callers writing to SQL tables
2SELECT * FROM find_db_writers('users');
3
4-- Verified Mutating Callers (INSERT / UPDATE / DELETE):
5• AuthService.register_user (app/auth.py:42) INSERT
6• BillingService.charge_card (app/billing.py:91) UPDATE
7• AdminService.delete_user (app/admin.py:114) DELETE
8
9-- Column lineage traced to SQLite foreign keys & models
1{
2 "query": "Trace scan_bill and database writes",
3 "status": "AST_VERIFIED",
4 "freshness": "FRESH (Git HEAD match in 2ms)",
5 "telemetry": "OBSERVED (pytest live traces)",
6 "database_impact": { "writers": 3, "table": "bills" },
7 "context_reduction_pct": 94.2,
8 "latency_ms": 18.4
9}

Runtime evidence

Reconcile static AST with live execution traces for verified context.

→

Database intelligence

Trace SQL/ORM to tables, columns, mutating queries, and data flows.

→

Tree-sitter & AST parsing

Deterministic parsing across Python, JavaScript, and TypeScript.

→

56 MCP tools server

Expose the graph to Claude Code, Cursor, Codex, and Antigravity.

→

Framework-aware routes

FastAPI, Flask, Django, and Express.js route discovery.

→

Impact analysis

Trace callers, callees, and potential impact of code modifications.

→

Next Steps

You've got CodeGraph MCP installed and a graph built. Here's where to go next.

Understand the model

Put it to work

Introduction

CodeGraph MCP is a deterministic, local-first code-intelligence engine for AI coding agents. Instead of letting agents waste context tokens repeatedly running grep, find, and reading hundreds of random files, CodeGraph MCP pre-indexes the structural relationships of a repository.

It parses code locally using Tree-sitter to deterministically extract symbols, definitions, class hierarchies, import chains, and function call relationships. The extracted graph is stored local-first inside a project-level SQLite database with WAL mode and FTS5 full-text search.

Quickstart

Install CodeGraph MCP from PyPI with complete CLI and FastMCP server bindings:

Terminal
pip install "codegraph-engine[mcp]"

Initialize and index your repository:

Terminal
cd /path/to/project
codegraph init .
codegraph index .
codegraph status .

Configuration

Add CodeGraph MCP to Claude Code, Cursor, Windsurf, or Antigravity via your standard MCP config:

claude_desktop_config.json / .cursor/mcp.json
{
  "mcpServers": {
    "codegraph": {
      "command": "codegraph",
      "args": ["serve", "."]
    }
  }
}

How It Works

CodeGraph MCP operates through a deterministic four-phase pipeline:

  • Tree-sitter Parsing: Source files are parsed incrementally into concrete ASTs. Zero LLM hallucinations.
  • Relational Graph Storage: Symbols, calls, imports, and routes are stored in SQLite with foreign-key constraints.
  • Deterministic Resolution: Canonical IDs, qualified names, and route endpoints are resolved with explicit ambiguity states.
  • MCP Tool Serving: FastMCP stdio server serves 56 verified tools with token-bounded context packets.

Runtime Telemetry Reconciliation

Static analysis alone cannot detect runtime dynamic dispatch, monkey-patching, or live test coverage. CodeGraph MCP reconciles static AST graph edges against recorded runtime execution traces.

Runtime Verification Guarantee: Recorded execution traces produce RUNTIME_OBSERVED edges. If a static path is not triggered during tests, it is flagged as NOT_OBSERVED_AT_RUNTIME without claiming it cannot execute.

Database Lineage & Schema Intelligence

CodeGraph MCP indexes relational databases, migrations, and ORMs (SQLAlchemy, Prisma, Django ORM). It connects tables and columns to the exact Python or TypeScript functions that read or write them.

Mutating SQL Writers: Instantly discover which API routes execute INSERT, UPDATE, or DELETE queries before performing breaking database migrations.

Indexing a Project

Run codegraph index . to scan and parse all files in your repository. Incremental indexing utilizes content hashes so subsequent runs finish in milliseconds.

Reading Your Graph in the Browser

Launch the local interactive visualizer with codegraph ui to explore callers, callees, and database relationships directly in your browser.

Framework Routes

CodeGraph MCP automatically traces routes for FastAPI, Flask, Django, and Express.js, connecting HTTP verbs and path templates directly to their handler symbols.

Affected Tests in CI

Use find_related_tests to discover the exact subset of unit and integration tests covering a modified symbol, optimizing continuous integration test run times.

Database Schema & Writers

Query find_db_tables, find_db_columns, and find_db_writers to audit data flow before performing database refactors.

MCP Tools Reference (56 Verified Tools)

Every tool exposed by CodeGraph MCP over Model Context Protocol, categorized into Database, Runtime, Graph, Core, Routes, Git, and Tests.

Database Lineage & Schema Tools (11)

Tools for table inspection, column typing, mutating SQL writers, and schema impact analysis.

find_db_tables DATABASE

Find database tables discovered across ORM models, raw SQL queries, and migrations. Use instead of grep when asking which database tables exist in this repository. Returns canonical IDs (`db.<dialect>.<schema>.<table>`), columns, ORM models, and evidence classes (`FRAMEWORK_VERIFIED`, `STATIC_VERIFIED`, `POSSIBLE`, `UNKNOWN`). Does not connect to live databases or execute SQL.

Resolves: Answering 'Which database tables exist in this repository?'
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Optional Table
dialect string Optional Dialect
schema string Optional Schema
Client Invocation
MCP Client / Agent Call
find_db_tables()
Return Model: DatabaseTableListResult
FieldTypeDescription
statusstringStatus
tablesarrayTables
countintegerCount
Evidence Guarantee Static ORM, SQL, and migration table definitions with canonical IDs and explicit dialect/schema uncertainty.
Epistemic Boundary Does not inspect live production database catalogs or unindexed external schemas.
find_db_columns DATABASE

Find database columns, data types, nullability, primary keys, and foreign keys across tables and ORM models. Use instead of grep when locating where a table column is defined or mapped (`MAPS_TO_COLUMN`, `HAS_PRIMARY_KEY`, `FOREIGN_KEY_TO`). Returns column definitions and source coordinates. Does not inspect live database catalogs.

Resolves: Answering 'What columns exist in bills?' or 'Where is column total_amount defined?'
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Optional Table
column string Optional Column
Client Invocation
MCP Client / Agent Call
find_db_columns(table="bills")
Return Model: DatabaseColumnListResult
FieldTypeDescription
statusstringStatus
columnsarrayColumns
countintegerCount
Evidence Guarantee ORM field-to-column mappings and SQL/migration column definitions with file:line evidence.
Epistemic Boundary Does not prove live database column values or runtime constraint violations.
find_db_models DATABASE

Find ORM models (SQLAlchemy, Flask-SQLAlchemy, Django ORM, SQLModel, Prisma) and their `MAPS_TO_TABLE` mappings. Use when asking which model class maps to a database table or vice versa. Returns model name, table, canonical ID, and `FRAMEWORK_VERIFIED` evidence. Does not import or execute application model modules.

Resolves: Finding which ORM class maps to table 'products' or listing all ORM models in the repository
Parameters Schema
ParameterTypeStatusDefaultDescription
model string Optional Model
table string Optional Table
Client Invocation
MCP Client / Agent Call
find_db_models(table="products")
Return Model: DatabaseModelListResult
FieldTypeDescription
statusstringStatus
modelsstringModels
countintegerCount
Evidence Guarantee Framework-verified ORM model declarations and table mappings.
Epistemic Boundary Does not execute dynamic metaclass table name generators.
find_db_queries DATABASE

Find database queries (`SELECT`, `INSERT`, `UPDATE`, `DELETE`) across ORM calls, query builders, and raw SQL strings. Use when asking which queries touch a table or what SQL a function executes. Returns `READS_TABLE`, `WRITES_TABLE`, `POSSIBLE_TABLE`, or `UNKNOWN_TABLE` with redacted snippets. Never exposes SQL literal secret parameters.

Resolves: Listing all SELECT/INSERT/UPDATE/DELETE operations targeting a table or inside a service function
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Optional Table
symbol string Optional Symbol
operation string Optional Operation
Client Invocation
MCP Client / Agent Call
find_db_queries(table="orders")
Return Model: DatabaseQueryListResult
FieldTypeDescription
statusstringStatus
queriesarrayQueries
countintegerCount
Evidence Guarantee AST- and framework-verified query operations with normalized/redacted SQL snippets and uncertainty preservation.
Epistemic Boundary Does not execute SQL queries or prove query execution plans.
find_db_callers DATABASE

Find all functions, methods, and upstream HTTP routes (`HANDLED_BY`) that read from or write to a database table. Use instead of grep when asking which code or route reaches a table. Returns direct accessors, upstream routes, relationships (`READS_TABLE`, `WRITES_TABLE`), and evidence classes. Does not prove runtime query frequency.

Resolves: Answering 'Which route or service accesses the products table?'
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Required - Table
Client Invocation
MCP Client / Agent Call
find_db_callers(table="products")
Return Model: DatabaseCallersResult
FieldTypeDescription
statusstringStatus
tablestringTable
direct_accessorsstringDirect Accessors
upstream_routesarrayUpstream Routes
countintegerCount
Evidence Guarantee Direct table readers/writers plus transitive upstream callers and HTTP route entrypoints.
Epistemic Boundary Does not prove runtime execution frequency unless paired with get_runtime_trace.
find_db_writers DATABASE

Find all symbols and queries that write (`INSERT`, `UPDATE`, `DELETE`) to a database table or column (`WRITES_TABLE`, `WRITES_COLUMN`). Use when investigating data mutations, state changes, or write blast radius. Returns writer symbols, operations, file:line citations, and redacted snippets. Does not execute database transactions.

Resolves: Answering 'Which service writes to the products table or updates inventory.quantity?'
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Optional Table
column string Optional Column
Client Invocation
MCP Client / Agent Call
find_db_writers(table="products")
Return Model: DatabaseWritersResult
FieldTypeDescription
statusstringStatus
writersarrayWriters
countintegerCount
Evidence Guarantee Verified INSERT/UPDATE/DELETE and ORM mutation call sites with source coordinates.
Epistemic Boundary Does not prove whether a database transaction commits or rolls back at runtime.
find_db_readers DATABASE

Find all symbols and queries that read (`SELECT`, `.query()`, `.objects.filter()`, `.findMany()`) from a database table or column (`READS_TABLE`, `READS_COLUMN`). Use when tracing where table data is consumed across services and views. Returns reader symbols, operations, and evidence classes. Does not prove runtime cache hits.

Resolves: Answering 'What code reads from users or reads column email?'
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Optional Table
column string Optional Column
Client Invocation
MCP Client / Agent Call
find_db_readers(table="users")
Return Model: DatabaseReadersResult
FieldTypeDescription
statusstringStatus
readersarrayReaders
countintegerCount
Evidence Guarantee Verified SELECT and ORM read query sites with file and line spans.
Epistemic Boundary Does not prove whether results are served from an in-memory cache at runtime.
find_db_relationships DATABASE

Find database schema and ORM relationships (`FOREIGN_KEY_TO`, `ORM_RELATION`, `MAPS_TO_TABLE`, `HAS_PRIMARY_KEY`, `HAS_INDEX`, `MIGRATES_TABLE`). Use when inspecting foreign keys, table joins, or model associations. Preserves explicit database relationship types and never collapses them into generic `DEPENDS_ON`.

Resolves: Answering 'What foreign keys or ORM relationships exist for orders?'
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Optional Table
Client Invocation
MCP Client / Agent Call
find_db_relationships(table="orders")
Return Model: DatabaseRelationshipsResult
FieldTypeDescription
statusstringStatus
relationshipsstringRelationships
countintegerCount
Evidence Guarantee Explicit schema and ORM relationship edges with canonical source/target IDs and source coordinates.
Epistemic Boundary Does not prove unindexed database triggers on external servers.
get_db_table DATABASE

Return complete structural details for a database table including columns, primary keys, foreign keys, indexes, constraints, ORM models, readers, writers, migrations, and upstream routes. Use when inspecting a specific table's schema and code usage in one call. Does not query live database servers.

Resolves: Inspecting everything known about a database table (columns, models, readers, writers, routes, migrations)
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Required - Table
Client Invocation
MCP Client / Agent Call
get_db_table(table="products")
Return Model: DatabaseTableDetailResult
FieldTypeDescription
statusstringStatus
tablestringTable
canonical_idstringCanonical Id
dialectstringDialect
schemastringSchema
columnsarrayColumns
primary_keysstringPrimary Keys
foreign_keysstringForeign Keys
indexesstringIndexes
orm_modelsstringOrm Models
readersarrayReaders
writersarrayWriters
migrationsstringMigrations
upstream_routesarrayUpstream Routes
Evidence Guarantee Consolidated static schema, ORM mapping, reader/writer, route, and migration evidence for the table.
Epistemic Boundary Does not return live table row counts or production data rows.
get_db_schema DATABASE

Return a repository-wide database schema summary including all discovered tables, columns, ORM models, foreign keys, and migrations. Use for database architecture overviews or schema audits. Preserves `UNKNOWN` dialect and schema when not statically provable and never guesses database names.

Resolves: Understanding the complete data model, tables, foreign keys, and migration history of a repository
Parameters Schema
ParameterTypeStatusDefaultDescription
dialect string Optional Dialect
schema string Optional Schema
Client Invocation
MCP Client / Agent Call
get_db_schema()
Return Model: DatabaseSchemaOverviewResult
FieldTypeDescription
statusstringStatus
dialectsstringDialects
schemasstringSchemas
tablesarrayTables
orm_modelsstringOrm Models
foreign_keysstringForeign Keys
migrationsstringMigrations
env_variablesstringEnv Variables
Evidence Guarantee Repository-wide database topology with explicit dialect/schema uncertainty and redacted env metadata.
Epistemic Boundary Does not connect to external database servers or read `.env` secret values.
get_db_impact DATABASE

Compute bidirectional Code <-> Database change impact for a table or column, returning affected ORM models, readers, writers, upstream HTTP routes, migrations, and statically linked tests. Use before renaming or altering a database table or column. Does not execute database migrations or tests.

Resolves: Answering 'What breaks if I rename or drop column shop_id on products?'
Parameters Schema
ParameterTypeStatusDefaultDescription
table string Optional Table
column string Optional Column
Client Invocation
MCP Client / Agent Call
get_db_impact(table="products", column="shop_id")
Return Model: DatabaseImpactResult
FieldTypeDescription
statusstringStatus
tablestringTable
columnstringColumn
affected_modelsstringAffected Models
affected_readersarrayAffected Readers
affected_writersarrayAffected Writers
affected_routesarrayAffected Routes
affected_migrationsstringAffected Migrations
affected_testsarrayAffected Tests
Evidence Guarantee Bidirectional impact across ORM models, queries, service callers, HTTP routes, migrations, and tests.
Epistemic Boundary Does not prove runtime migration locking or production table size.

Runtime Telemetry & Reconciliation Tools (6)

Tools for execution trace recording, runtime observation reconciliation, and dynamic call tracing.

trace_path RUNTIME

Compute deterministic multi-hop relationship paths between two symbols (`from_symbol` -> `to_symbol`). Use when tracing how an entrypoint, route, or caller reaches a downstream service or database function. Returns ordered hop edges with relationship types and evidence classes. Does not prove runtime branch conditions along the path.

Resolves: Proving how an HTTP endpoint or CLI command reaches a downstream repository or helper
Parameters Schema
ParameterTypeStatusDefaultDescription
from_symbol string Optional From Symbol
to_symbol string Optional To Symbol
start_symbol string Optional Start Symbol
target_symbol string Optional Target Symbol
source_symbol string Optional Source Symbol
max_depth integer Optional 5 Max Depth
Client Invocation
MCP Client / Agent Call
trace_path(from_symbol="login_endpoint", to_symbol="find_by_email", max_depth=4)
Return Model: PathTraceResult
FieldTypeDescription
statusstringStatus
from_symbolstringFrom Symbol
to_symbolstringTo Symbol
pathstringPath
pathsstringPaths
hopsstringHops
evidence_classstringEvidence Class
confidencestringConfidence
Evidence Guarantee Ordered multi-hop chain where every hop carries file, line, and evidence_class.
Epistemic Boundary Does not prove that a conditional runtime branch is taken for a specific input payload.
trace_call RUNTIME

Traverse callers, callees, or both from a single `symbol` (`canonical_id` supported as alias) up to `depth` with confidence and relationship labels. Use when exploring upstream and/or downstream call trees from one symbol without a known second endpoint. Does not prove runtime branch execution.

Resolves: Tracing 2 hops of upstream callers (`callers=True`) or downstream callees (`callees=True`) from one symbol
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
depth integer Optional 2 Depth
callers boolean Optional True Callers
callees boolean Optional False Callees
both boolean Optional False Both
Client Invocation
MCP Client / Agent Call
trace_call(symbol="verify_password", depth=2, callers=True)
Return Model: DirectionalCallTraceList
FieldTypeDescription
sourcestringSource
targetstringTarget
relationshipstringRelationship
confidencestringConfidence
evidence_classstringEvidence Class
depthintegerDepth
filestringFile
start_lineintegerStart Line
Evidence Guarantee Directional multi-hop call traversal with hop depth and confidence.
Epistemic Boundary Does not prove runtime reachability under specific input conditions.
trace_flow RUNTIME

Trace multi-hop upstream callers and downstream callees around a single symbol (`symbol`; `canonical_id` supported as alias) up to `depth`. Use when exploring bidirectional execution flow around a function or handler without a known second endpoint. Does not prove runtime branch execution; use trace_path when both endpoints are known.

Resolves: Exploring upstream callers and downstream callees around a single symbol in one call
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
depth integer Optional 2 Depth
callers boolean Optional True Callers
callees boolean Optional False Callees
both boolean Optional False Both
Client Invocation
MCP Client / Agent Call
trace_flow(symbol="place_order", depth=2)
Return Model: DirectionalCallTraceList
FieldTypeDescription
sourcestringSource
targetstringTarget
relationshipstringRelationship
confidencestringConfidence
evidence_classstringEvidence Class
depthintegerDepth
filestringFile
start_lineintegerStart Line
Evidence Guarantee Bidirectional multi-hop call traversal with hop depth, confidence, and evidence_class.
Epistemic Boundary Does not prove runtime reachability under specific input conditions.
ingest_runtime_traces RUNTIME

Ingest optional runtime observation traces (OpenTelemetry JSON, structured JSON/JSONL events, or SQL query logs) into CodeGraph's `RUNTIME_OBSERVED` layer. Use when grounding static analysis with recorded runtime traces. Automatically strips headers/cookies/bodies, redacts SQL bind parameters and secrets, and never converts runtime observations into static `AST_VERIFIED` proof.

Resolves: Loading recorded OpenTelemetry spans, JSONL runtime events, or SQL logs before calling get_runtime_trace or reconcile_static_runtime
Parameters Schema
ParameterTypeStatusDefaultDescription
source_path string Optional Source Path
format string Optional auto Format
payload string Optional Payload
max_events integer Optional 5000 Max Events
sample_rate number Optional 1.0 Sample Rate
Client Invocation
MCP Client / Agent Call
ingest_runtime_traces(source_path="traces/scan_bill.json")
Return Model: RuntimeIngestResult
FieldTypeDescription
statusstringStatus
runtime_generationstringRuntime Generation
events_ingestedstringEvents Ingested
edges_recordedarrayEdges Recorded
redacted_fieldsstringRedacted Fields
Evidence Guarantee Sanitized RUNTIME_OBSERVED edges with observation_count, first_seen, last_seen, and runtime_generation.
Epistemic Boundary Never proves static AST_VERIFIED relationships and never launches or instruments the user application.
get_runtime_trace RUNTIME

Retrieve aggregated runtime execution edges (`RUNTIME_OBSERVED`) and reverse maps (`table -> runtime writers/readers`, `route -> runtime tables`) with `observation_count`, `first_seen`, `last_seen`, and `runtime_generation`. Use when asking what actually happened at runtime. Does not treat unobserved paths as impossible.

Resolves: Answering 'What happened at runtime when /api/scan-bill ran?' or 'Which runtime queries wrote to bills?'
Parameters Schema
ParameterTypeStatusDefaultDescription
route string Optional Route
symbol string Optional Symbol
table string Optional Table
Client Invocation
MCP Client / Agent Call
get_runtime_trace(route="/api/scan-bill")
Return Model: RuntimeTraceResult
FieldTypeDescription
statusstringStatus
edgesarrayEdges
observationsstringObservations
reverse_mapsstringReverse Maps
countintegerCount
Evidence Guarantee Aggregated RUNTIME_OBSERVED edges with observation counts, timestamps, and sanitized SQL templates.
Epistemic Boundary Does not prove that unobserved static branches cannot execute under other inputs.
reconcile_static_runtime RUNTIME

Reconcile static repository edges against ingested runtime observations, classifying edges into `CONFIRMED_RUNTIME_PATH`, `STATIC_RUNTIME_CONFLICT`, `NOT_OBSERVED_AT_RUNTIME`, and `RUNTIME_ONLY_OBSERVED`. Use when comparing static code analysis with runtime behavior. Never treats `NOT_OBSERVED_AT_RUNTIME` as proof that a path cannot execute.

Resolves: Answering 'Where do static and runtime paths differ?' or 'Which dynamic calls were observed only at runtime?'
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
route string Optional Route
table string Optional Table
Client Invocation
MCP Client / Agent Call
reconcile_static_runtime(route="/api/scan-bill")
Return Model: StaticRuntimeReconciliationResult
FieldTypeDescription
statusstringStatus
confirmed_runtime_pathsstringConfirmed Runtime Paths
static_runtime_conflictsstringStatic Runtime Conflicts
not_observed_at_runtimebooleanNot Observed At Runtime
runtime_only_observedbooleanRuntime Only Observed
summarystringSummary
Evidence Guarantee Explicit four-bucket reconciliation preserving both static evidence classes and RUNTIME_OBSERVED / RUNTIME_UNOBSERVED states.
Epistemic Boundary Never overwrites static AST_VERIFIED edges and never treats NOT_OBSERVED_AT_RUNTIME as dead-code proof.

Graph Traversal & Call Hierarchy Tools (8)

Directional call hierarchies, caller/callee graphs, and change impact propagation.

get_callers GRAPH

Return statically verified callers of a symbol with confidence and evidence_class. Primary input: `symbol` (also accepts `canonical_id` as a compatibility alias using the exact same resolution path). Use for multi-file call-relationship and upstream impact questions. Does not prove runtime dispatch unless evidence_class indicates framework/dataflow verification.

Resolves: Answering 'What calls function X?' across the repository
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
Client Invocation
MCP Client / Agent Call
get_callers(symbol="verify_password")
Return Model: CallerListResult
FieldTypeDescription
statusstringStatus
canonical_idstringCanonical Id
callersarrayCallers
sourcestringSource
relationshipstringRelationship
evidence_classstringEvidence Class
confidencestringConfidence
filestringFile
start_lineintegerStart Line
Evidence Guarantee Call-site file, line, source caller symbol, and RelationshipEvidenceClass.
Epistemic Boundary Does not prove dead-code reachability at runtime or reflective eval/getattr calls.
get_callees GRAPH

Return symbols called or invoked by the specified symbol with evidence_class classification. Primary input: `symbol` (also accepts `canonical_id` as a compatibility alias using the exact same resolution path). Use to inspect downstream dependencies invoked by a function or handler. Does not resolve dynamic callbacks passed as opaque runtime arguments.

Resolves: Answering 'What does function X call?' without manually reading every imported module
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
Client Invocation
MCP Client / Agent Call
get_callees(symbol="process_checkout")
Return Model: CalleeListResult
FieldTypeDescription
statusstringStatus
canonical_idstringCanonical Id
calleesarrayCallees
targetstringTarget
relationshipstringRelationship
evidence_classstringEvidence Class
confidencestringConfidence
filestringFile
start_lineintegerStart Line
Evidence Guarantee AST/dataflow-verified outgoing calls with exact call-site line numbers.
Epistemic Boundary Does not prove external network calls or dynamically constructed strings.
analyze_impact GRAPH

Compute downstream callers, dependents, affected routes, and related tests if a symbol (`symbol`; `canonical_id` supported as alias) is modified. Use before refactoring or changing a function/class signature. Does not prove runtime failure without inspecting call sites.

Resolves: Evaluating blast radius of a signature or behavior change to a symbol
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
max_depth integer Optional 3 Max Depth
Client Invocation
MCP Client / Agent Call
analyze_impact(symbol="DatabasePool.acquire", max_depth=3)
Return Model: SymbolImpactResult
FieldTypeDescription
symbolstringSymbol
direct_callersarrayDirect Callers
transitive_callersarrayTransitive Callers
dependent_filesarrayDependent Files
affected_routesarrayAffected Routes
related_testsarrayRelated Tests
Evidence Guarantee Multi-hop reverse dependency traversal with hop distances and evidence classes.
Epistemic Boundary Does not prove dynamic string-based reflection consumers.
find_callers GRAPH

Find functions and methods that call the specified symbol (`symbol`; `canonical_id` supported as alias) up to `max_results`. Use instead of grep or search_code when answering 'who calls X?'. Does not prove runtime execution of conditional branches; preserves POSSIBLE and UNKNOWN evidence classes.

Resolves: Answering 'Who calls function X?' with a bounded result list
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
max_results integer Optional 20 Max Results
Client Invocation
MCP Client / Agent Call
find_callers(symbol="place_order", max_results=20)
Return Model: CallerEdgeList
FieldTypeDescription
sourcestringSource
targetstringTarget
relationshipstringRelationship
confidencestringConfidence
evidence_classstringEvidence Class
filestringFile
start_lineintegerStart Line
Evidence Guarantee Graph edges with relationship, confidence, evidence_class, and call-site coordinates.
Epistemic Boundary Does not prove runtime execution or dynamic reflection calls.
find_callees GRAPH

Find functions and methods called by the specified symbol (`symbol`; `canonical_id` supported as alias) up to `max_results`. Use instead of reading multiple files manually when answering 'what does X call?'. Does not resolve opaque runtime callbacks; preserves POSSIBLE and UNKNOWN evidence classes.

Resolves: Answering 'What does function X call?' with a bounded result list
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
max_results integer Optional 20 Max Results
Client Invocation
MCP Client / Agent Call
find_callees(symbol="place_order", max_results=20)
Return Model: CalleeEdgeList
FieldTypeDescription
sourcestringSource
targetstringTarget
relationshipstringRelationship
confidencestringConfidence
evidence_classstringEvidence Class
filestringFile
start_lineintegerStart Line
Evidence Guarantee Outgoing call edges with target, confidence, evidence_class, and line numbers.
Epistemic Boundary Does not prove external service behavior or dynamic eval calls.
get_call_graph GRAPH

Compute the multi-hop call graph rooted at `symbol` (`canonical_id` supported as alias) up to `depth` and `max_results`. Use when exploring the multi-hop call neighborhood around a central service or controller. Does not prove runtime reachability for specific inputs.

Resolves: Mapping 2-hop or 3-hop call neighborhoods around a core function
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
depth integer Optional 2 Depth
max_results integer Optional 100 Max Results
Client Invocation
MCP Client / Agent Call
get_call_graph(symbol="AuthService.authenticate", depth=2, max_results=50)
Return Model: CallGraphEdgeList
FieldTypeDescription
sourcestringSource
targetstringTarget
relationshipstringRelationship
confidencestringConfidence
evidence_classstringEvidence Class
depthintegerDepth
filestringFile
start_lineintegerStart Line
Evidence Guarantee Bounded multi-hop subgraph edges with hop depth and evidence metadata.
Epistemic Boundary Does not prove that every branch in the call graph executes on a single request.
get_dependency_graph GRAPH

Return module-level `IMPORTS` graph edges across the repository or filtered to `file_path`. Use when inspecting raw module-to-module import topology. Does not prove symbol-level call invocation; prefer get_imports or get_dependents for targeted queries.

Resolves: Inspecting module import edges for a specific file or across a small repository
Parameters Schema
ParameterTypeStatusDefaultDescription
file_path any Optional None File Path
Client Invocation
MCP Client / Agent Call
get_dependency_graph(file_path="src/auth/service.py")
Return Model: DependencyGraphEdgeList
FieldTypeDescription
sourcestringSource
targetstringTarget
relationshipstringRelationship
confidencestringConfidence
evidencestringEvidence
Evidence Guarantee AST-extracted module IMPORTS edges with source, target, and confidence.
Epistemic Boundary Does not prove whether imported symbols are called.
get_graph GRAPH

Return up to `limit` (1..500) parser-confirmed definition and import graph edges with evidence metadata. Use for inspecting raw structural `DEFINES` and `IMPORTS` edges in small repositories or diagnostics. Does not replace targeted relationship tools like get_callers or trace_path.

Resolves: Sampling raw structural graph edges during diagnostics
Parameters Schema
ParameterTypeStatusDefaultDescription
limit integer Optional 200 Limit
Client Invocation
MCP Client / Agent Call
get_graph(limit=50)
Return Model: GraphEdgeList
FieldTypeDescription
sourcestringSource
targetstringTarget
relationshipstringRelationship
confidencestringConfidence
evidence_classstringEvidence Class
filestringFile
lineintegerLine
Evidence Guarantee Validated structural edges with source, target, relationship, and confidence.
Epistemic Boundary Does not return task-ranked context or multi-hop traces.

Core Symbol Inspection & Context Tools (23)

Canonical symbol resolution, bounded context packets, file slices, and evidence verification.

resolve_symbol CORE

Resolve a symbol name, qualified name, canonical ID, or route into its canonical repository identity and file/line location. Use as the first step before relationship queries when exact symbol identity is unknown or potentially ambiguous. Primary input: `symbol` (also accepts `canonical_id` or `name` as compatibility aliases). Returns canonical_id, ambiguity_state, and candidate alternatives. Does not prove runtime execution or dynamic monkey-patching.

Resolves: Locating where a class, function, or method is canonically defined
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
name string Optional Name
Client Invocation
MCP Client / Agent Call
resolve_symbol(symbol="AuthService")
Return Model: SymbolResolutionResult
FieldTypeDescription
statusstringStatus
canonical_idstringCanonical Id
qualified_namestringQualified Name
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
ambiguity_statestringAmbiguity State
matchesarrayMatches
alternativesarrayAlternatives
Evidence Guarantee AST-verified symbol definition coordinates and explicit AMBIGUOUS/UNKNOWN states.
Epistemic Boundary Does not prove runtime call edges or dynamic attribute injection.
search_symbols CORE

Search indexed repository symbols by partial name or keyword with ranked relevance. Use when exact symbol spelling is unknown and you need candidate symbol definitions. Returns ranked symbol definitions with file paths and line spans. Does not return module import graphs or call relationships.

Resolves: Finding where a feature or domain concept is defined across the codebase
Parameters Schema
ParameterTypeStatusDefaultDescription
query string Required - Query
top_k integer Optional 20 Top K
Client Invocation
MCP Client / Agent Call
search_symbols(query="verify_password", top_k=10)
Return Model: SymbolSearchResult
FieldTypeDescription
statusstringStatus
querystringQuery
resultsstringResults
canonical_idstringCanonical Id
qualified_namestringQualified Name
kindstringKind
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
Evidence Guarantee AST-extracted symbol declarations with source file and line numbers.
Epistemic Boundary Does not prove who calls or imports the matched symbols.
get_symbol CORE

Return authoritative signature, kind, parent scope, decorators, and bounded source snippet for a symbol. Primary input: `symbol` (also accepts `canonical_id` or `name` as compatibility aliases). Use when you have a symbol name or canonical_id and need its declaration metadata. Does not traverse multi-hop call graphs.

Resolves: Inspecting a symbol's signature, return type, and decorators without reading the entire file
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
name string Optional Name
Client Invocation
MCP Client / Agent Call
get_symbol(symbol="login_endpoint")
Return Model: SymbolDetailResult
FieldTypeDescription
statusstringStatus
canonical_idstringCanonical Id
qualified_namestringQualified Name
kindstringKind
signaturestringSignature
decoratorsstringDecorators
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
snippetstringSnippet
Evidence Guarantee AST-verified symbol signature, decorators, and exact line span.
Epistemic Boundary Does not prove downstream impact or callers outside the symbol body.
get_file CORE

Open and inspect a repository file's structural AST outline or a bounded line range (`path`, `start_line`, `end_line`, `max_lines`). Use after `search_code`, `find_symbol`, or `find_routes` identifies a target file and line span across Python, HTML, Jinja, JS, TS, CSS, YAML, JSON, or Markdown. Blocks path traversal, binary files, and sensitive files; does not prove cross-file callers.

Resolves: Opening a targeted line range (`start_line`, `end_line`) of a Python, HTML, Jinja, JS, CSS, or config file
Parameters Schema
ParameterTypeStatusDefaultDescription
path string Required - Path
start_line any Optional None Start Line
end_line any Optional None End Line
max_lines integer Optional 200 Max Lines
include_content boolean Optional False Include Content
Client Invocation
MCP Client / Agent Call
get_file(path="templates/dashboard.html", start_line=40, end_line=110)
Return Model: FileStructureResult
FieldTypeDescription
statusstringStatus
pathstringPath
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
contentstringContent
truncatedbooleanTruncated
categorystringCategory
file_categorystringFile Category
artifact_typestringArtifact Type
symbolsarraySymbols
importsstringImports
freshnessbooleanFreshness
Evidence Guarantee Bounded on-disk source lines (`start_line`..`end_line`, `truncated`) plus parser-extracted symbols and imports.
Epistemic Boundary Does not prove reverse dependents across the repository.
get_references CORE

Return verified and candidate references to a symbol across the repository with evidence_class labels. Primary input: `symbol` (also accepts `canonical_id` or `name` as compatibility aliases). Use for cross-file reference, registration, dispatch, or DI binding lookup. Does not guarantee dynamic reflection targets when evidence_class is UNKNOWN or POSSIBLE.

Resolves: Finding all usages, registrations, or DI bindings of a symbol across files
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
name string Optional Name
Client Invocation
MCP Client / Agent Call
get_references(symbol="command_registry")
Return Model: ReferenceListResult
FieldTypeDescription
statusstringStatus
canonical_idstringCanonical Id
referencesstringReferences
relationshipstringRelationship
evidence_classstringEvidence Class
confidencestringConfidence
filestringFile
start_lineintegerStart Line
Evidence Guarantee Source-backed reference locations with explicit confidence and evidence_class.
Epistemic Boundary Does not prove runtime execution order or unindexed external consumers.
get_imports CORE

Return parser-extracted module and symbol imports for a file or symbol (`file` or `symbol`; `canonical_id` and `path` supported as aliases). Use for forward dependency and package boundary questions. Does not return reverse importers (use get_dependents for reverse dependencies).

Resolves: Inspecting what modules or workspace packages a file depends on
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol any Optional None Symbol
file any Optional None File
canonical_id any Optional None Canonical Id
path any Optional None Path
Client Invocation
MCP Client / Agent Call
get_imports(file="src/auth/routes.py")
Return Model: ImportsResult
FieldTypeDescription
statusstringStatus
filestringFile
importsstringImports
sourcestringSource
targetstringTarget
relationshipstringRelationship
evidence_classstringEvidence Class
Evidence Guarantee AST-verified import statements and resolved internal module paths.
Epistemic Boundary Does not prove whether an imported symbol is actually invoked at runtime.
get_dependents CORE

Return files, symbols, and packages that import or depend on the target symbol or file (`symbol` or `file`; `canonical_id` and `path` supported as aliases). Use for blast-radius, change-impact, and package boundary analysis. Does not prove runtime failure without checking test and caller evidence.

Resolves: Determining which modules or packages break if a shared symbol or file signature changes
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol any Optional None Symbol
file any Optional None File
canonical_id any Optional None Canonical Id
path any Optional None Path
Client Invocation
MCP Client / Agent Call
get_dependents(file="src/auth/repository.py")
Return Model: DependentsResult
FieldTypeDescription
statusstringStatus
dependentsstringDependents
sourcestringSource
targetstringTarget
relationshipstringRelationship
evidence_classstringEvidence Class
filestringFile
Evidence Guarantee Verified reverse import and call edges pointing to the target.
Epistemic Boundary Does not prove unindexed external repository consumers.
get_architecture CORE

Return structural repository overview including modules, workspace packages (`DEPENDS_ON_PACKAGE`), entrypoints, and layer relationships. Use for high-level architecture, monorepo package boundary, and onboarding questions. Does not replace symbol-level evidence for specific bug fixes.

Resolves: Understanding overall system structure, entrypoints, and monorepo package dependencies
Parameters Schema
ParameterTypeStatusDefaultDescription
No arguments required.
Client Invocation
MCP Client / Agent Call
get_architecture()
Return Model: ArchitectureOverviewResult
FieldTypeDescription
statusstringStatus
modulesstringModules
packagesstringPackages
package_dependenciesstringPackage Dependencies
entrypointsstringEntrypoints
routesarrayRoutes
summarystringSummary
Evidence Guarantee Manifest-backed workspace packages and AST-verified module dependency counts.
Epistemic Boundary Does not infer package boundaries from directory names without manifest evidence.
get_context CORE

Compile a token-bounded, coverage-optimized ContextPacket containing verified symbols, compressed relationships, routes, DI providers, packages, and related tests. Primary input: `query` (natural-language question, symbol, or task description; `task` is also supported as a compatibility alias for string or structured TaskSpec dict). Budget controls: `max_tokens` (default 4000, hard cap 20000), `max_files` (default 15, hard cap 30), `max_lines` (default 500, hard cap 1500). Preserves UNKNOWN, POSSIBLE, and AMBIGUOUS states explicitly. Does not return full raw files; use targeted get_file or read_file only if exact omitted lines are needed afterward.

Resolves: Investigating a bug, route flow, DI chain, or multi-file feature in one bounded call
Parameters Schema
ParameterTypeStatusDefaultDescription
query string Optional Query
task any Optional Task
intent any Optional None Intent
max_tokens integer Optional 4000 Max Tokens
max_files integer Optional 15 Max Files
max_lines integer Optional 500 Max Lines
top_k integer Optional 15 Top K
plan any Optional None Plan
mode string Optional BALANCED Mode
explain boolean Optional False Explain
resource_mode any Optional None Resource Mode
Client Invocation
MCP Client / Agent Call
get_context(query="How does UserRepository get injected into UserController", intent="DEBUG", max_tokens=4000)
Return Model: ContextPacket
FieldTypeDescription
symbolsarraySymbols
relationshipsstringRelationships
routesarrayRoutes
testsarrayTests
packagesstringPackages
unknownsstringUnknowns
conflictsstringConflicts
uncertaintiesstringUncertainties
freshnessbooleanFreshness
selected_tokensintegerSelected Tokens
candidate_tokensintegerCandidate Tokens
selected_filesarraySelected Files
selected_linesintegerSelected Lines
coverage_scorestringCoverage Score
truncatedbooleanTruncated
candidate_token_estimatestringCandidate Token Estimate
selected_token_estimatestringSelected Token Estimate
context_reduction_pctstringContext Reduction Pct
coveragestringCoverage
Evidence Guarantee Bounded source snippets, compressed relationships with supporting_locations, coverage_score, budget metadata (selected_tokens, candidate_tokens, selected_files, selected_lines, truncated), and explicit UNKNOWN/POSSIBLE/AMBIGUOUS preservation.
Epistemic Boundary Does not execute code or fabricate edges for unresolvable dynamic dispatch.
read_file CORE

Read a bounded line range (1..500 lines) of a non-sensitive repository file. Use AFTER CodeGraph tools identify the exact file and line span, or directly for trivial single-file edits. Blocks path traversal and sensitive credential files. Does not compute cross-file relationships.

Resolves: Inspecting exact implementation lines inside a symbol span identified by CodeGraph
Parameters Schema
ParameterTypeStatusDefaultDescription
path string Required - Path
start_line integer Optional 1 Start Line
end_line integer Optional 200 End Line
Client Invocation
MCP Client / Agent Call
read_file(path="src/auth/service.py", start_line=10, end_line=45)
Return Model: FileContentSlice
FieldTypeDescription
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
contentstringContent
Evidence Guarantee Exact on-disk source lines within repository privacy boundaries.
Epistemic Boundary Does not compute cross-file callers, DI bindings, or test links.
search_code CORE

Search literal text, HTML/Jinja template IDs, UI strings, CSS selectors, config keys, or route paths across readable repository files and indexed code chunks. Use instead of grep when searching for exact text, button labels, or template strings. Does not prove semantic call, import, or route relationships; never creates semantic graph edges from text matches.

Resolves: Locating UI button labels, HTML/Jinja template IDs, CSS selectors, error message strings, SQL fragments, or configuration keys
Parameters Schema
ParameterTypeStatusDefaultDescription
query string Required - Query
top_k integer Optional 10 Top K
path_filter any Optional None Path Filter
file_types any Optional None File Types
include_tests boolean Optional True Include Tests
include_configs boolean Optional True Include Configs
max_results integer Optional 20 Max Results
Client Invocation
MCP Client / Agent Call
search_code(query="Add Manual Entry", top_k=10)
Return Model: CodeChunkSearchResult
FieldTypeDescription
pathstringPath
filestringFile
lineintegerLine
start_lineintegerStart Line
end_lineintegerEnd Line
matched_textstringMatched Text
snippetstringSnippet
categorystringCategory
file_categorystringFile Category
match_typestringMatch Type
symbolstringSymbol
scorestringScore
reasonstringReason
Evidence Guarantee Ranked source and text matches with file path, exact line number, matched_text, snippet, match_type, and file_category.
Epistemic Boundary Does not prove module import graphs or caller/callee relationships; never creates semantic edges.
find_symbol CORE

Find function, method, or class definitions by exact short name or qualified name (`symbol`; `name` and `canonical_id` supported as aliases). Use instead of grep when locating where a class, function, or method is defined. Does not return callers, callees, or ambiguity alternatives like resolve_symbol.

Resolves: Quickly listing all definitions matching an exact symbol name
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
name string Optional Name
canonical_id string Optional Canonical Id
Client Invocation
MCP Client / Agent Call
find_symbol(symbol="InventoryService")
Return Model: SymbolLocationList
FieldTypeDescription
symbolstringSymbol
kindstringKind
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
Evidence Guarantee AST-indexed symbol rows matching name or qualified_name.
Epistemic Boundary Does not disambiguate routes or compute call relationships.
find_references CORE

Find textual occurrences and references of a symbol name (`symbol`; `name` and `canonical_id` supported as aliases) across indexed code chunks. Use when locating references or mentions of an identifier across files. Does not prove semantic call edges; use get_references when full relationship classification is required.

Resolves: Finding all code chunks referencing an identifier across the repository
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
name string Optional Name
canonical_id string Optional Canonical Id
Client Invocation
MCP Client / Agent Call
find_references(symbol="parse_bill")
Return Model: ChunkReferenceList
FieldTypeDescription
filestringFile
symbolstringSymbol
start_lineintegerStart Line
end_lineintegerEnd Line
Evidence Guarantee Lexical substring matches inside indexed code chunks.
Epistemic Boundary Does not prove AST-verified call or reference semantics.
compile_task CORE

Normalize a developer question or task (`query`; `task` supported as string or TaskSpec dict alias) into a structured `TaskSpec`, ground targets against the index, detect ambiguities, and build a `RetrievalPlan`. Use before get_context when you want to inspect target resolution and ambiguity candidates prior to context retrieval. Does not retrieve source code snippets.

Resolves: Pre-checking whether task targets are ambiguous before compiling a full ContextPacket
Parameters Schema
ParameterTypeStatusDefaultDescription
query string Optional Query
task any Optional Task
max_tokens integer Optional 20000 Max Tokens
resource_mode string Optional BALANCED Resource Mode
Client Invocation
MCP Client / Agent Call
compile_task(query="Debug AuthService")
Return Model: CompiledTaskPlan
FieldTypeDescription
task_specstringTask Spec
ambiguitystringAmbiguity
ambiguitiesstringAmbiguities
entry_pointsstringEntry Points
retrieval_planstringRetrieval Plan
recommended_next_stepstringRecommended Next Step
Evidence Guarantee Deterministic TaskSpec, ambiguity list, candidate entrypoints, and RetrievalPlan.
Epistemic Boundary Does not return symbol bodies or relationship edges until get_context is called.
plan_retrieval CORE

Construct a deterministic `RetrievalPlan` for a question or task (`query`; `task` supported as alias) without executing graph or source retrieval. Use to inspect planned retrieval steps, token budgets, and query expansions. Does not return code snippets or relationship edges.

Resolves: Inspecting how CodeGraph plans to allocate token budget for a complex query
Parameters Schema
ParameterTypeStatusDefaultDescription
query string Optional Query
task any Optional Task
max_tokens integer Optional 20000 Max Tokens
resource_mode string Optional BALANCED Resource Mode
Client Invocation
MCP Client / Agent Call
plan_retrieval(query="Trace payment processing")
Return Model: RetrievalPlanDict
FieldTypeDescription
intentstringIntent
stepsstringSteps
token_budgetstringToken Budget
expanded_queriesarrayExpanded Queries
ambiguitiesstringAmbiguities
Evidence Guarantee Deterministic step list, token budget allocation, and expanded queries.
Epistemic Boundary Does not execute retrieval or prove symbol relationships.
get_repository_status CORE

Return repository indexing status, generation counter, freshness state (`FRESH` or `STALE`), symbol counts, and modified/deleted file lists. Use to check whether the index is fresh before trusting cached graph facts after disk edits. Does not re-index the repository automatically.

Resolves: Checking if freshness is FRESH or STALE after editing files
Parameters Schema
ParameterTypeStatusDefaultDescription
No arguments required.
Client Invocation
MCP Client / Agent Call
get_repository_status()
Return Model: RepositoryStatusReport
FieldTypeDescription
repositorystringRepository
generationstringGeneration
freshnessbooleanFreshness
freshness_detailbooleanFreshness Detail
files_indexedarrayFiles Indexed
symbols_indexedarraySymbols Indexed
graph_edgesarrayGraph Edges
framework_routesarrayFramework Routes
modified_filesarrayModified Files
deleted_filesarrayDeleted Files
parse_failed_filesarrayParse Failed Files
Evidence Guarantee On-disk mtime/hash comparison against indexed file records.
Epistemic Boundary Does not prove external git remote state.
get_project_structure CORE

Return up to 500 indexed repository-relative source file paths in deterministic sorted order. Use for a flat inventory of indexed files when exploring a small project. Does not return package dependency graphs or entrypoints (prefer get_architecture).

Resolves: Listing indexed file paths in a small repository
Parameters Schema
ParameterTypeStatusDefaultDescription
No arguments required.
Client Invocation
MCP Client / Agent Call
get_project_structure()
Return Model: IndexedFilePathList
FieldTypeDescription
pathstringPath
Evidence Guarantee Sorted list of non-sensitive indexed file paths.
Epistemic Boundary Does not prove package ownership or module relationships.
get_dependencies CORE

List up to 500 raw parser-extracted `(source_path, imported)` rows from the imports table. Use for bulk inspection of raw import statements across the repository. Does not resolve workspace package boundaries; prefer get_imports or get_architecture.

Resolves: Auditing raw import strings across the repository
Parameters Schema
ParameterTypeStatusDefaultDescription
No arguments required.
Client Invocation
MCP Client / Agent Call
get_dependencies()
Return Model: RawImportRowList
FieldTypeDescription
source_pathstringSource Path
importedstringImported
Evidence Guarantee AST-extracted import strings per source file.
Epistemic Boundary Does not prove installed third-party package versions.
get_file_symbols CORE

List extracted symbols (`symbol`, `kind`, `start_line`, `end_line`) in a single repository-relative file. Use for a lightweight symbol table of one file when imports and artifact metadata are not needed. Does not return cross-file relationships; prefer get_file for full file outline.

Resolves: Listing symbol names and line ranges inside a single file
Parameters Schema
ParameterTypeStatusDefaultDescription
path string Required - Path
Client Invocation
MCP Client / Agent Call
get_file_symbols(path="src/auth/service.py")
Return Model: FileSymbolRowList
FieldTypeDescription
symbolstringSymbol
kindstringKind
start_lineintegerStart Line
end_lineintegerEnd Line
Evidence Guarantee AST-extracted symbol names, kinds, and line spans within `path`.
Epistemic Boundary Does not return file imports or callers.
search_memory CORE

Search local SQLite repository memory notes by keyword up to `limit` (1..100). Use only to recall previously stored local session notes. Never overrides current AST or source-file evidence; does not prove current repository state.

Resolves: Looking up user-saved architectural notes in local memory
Parameters Schema
ParameterTypeStatusDefaultDescription
query string Required - Query
limit integer Optional 20 Limit
Client Invocation
MCP Client / Agent Call
search_memory(query="auth", limit=10)
Return Model: MemoryNoteList
FieldTypeDescription
keystringKey
valuestringValue
Evidence Guarantee Local key-value notes stored in the repository memory table.
Epistemic Boundary Never proves current code structure; source code and AST evidence always take precedence.
get_evidence CORE

Return bounded source-derived `Evidence` citations (`file`, `start_line`, `end_line`, `symbol`, `snippet`, `content_hash`) for a non-sensitive file or symbol. Use when constructing hash-verifiable code citations. Blocks sensitive files and does not compute cross-file callers.

Resolves: Fetching verifiable evidence snippets for a symbol inside a known file
Parameters Schema
ParameterTypeStatusDefaultDescription
path string Required - Path
symbol any Optional None Symbol
Client Invocation
MCP Client / Agent Call
get_evidence(path="src/auth/service.py", symbol="AuthService.authenticate")
Return Model: EvidenceCitationList
FieldTypeDescription
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
symbolstringSymbol
snippetstringSnippet
content_hashstringContent Hash
Evidence Guarantee Indexed chunk snippets paired with SHA-256 content hashes and line coordinates.
Epistemic Boundary Does not compute cross-file relationship edges.
verify_evidence CORE

Verify that a cited evidence span (`file_path`, `start_line`, `end_line`) exists on disk, matches `expected_hash`, and is not stale. Use to validate whether previously retrieved evidence is still current after repository edits. Does not re-index modified files.

Resolves: Confirming a cited snippet has not drifted on disk before applying a patch
Parameters Schema
ParameterTypeStatusDefaultDescription
file_path string Required - File Path
start_line integer Required - Start Line
end_line integer Required - End Line
expected_hash any Optional None Expected Hash
symbol any Optional None Symbol
Client Invocation
MCP Client / Agent Call
verify_evidence(file_path="src/auth/service.py", start_line=1, end_line=20)
Return Model: EvidenceVerificationResult
FieldTypeDescription
validstringValid
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
reasonstringReason
current_hashstringCurrent Hash
Evidence Guarantee Cryptographic hash and line-bound check against current on-disk file content.
Epistemic Boundary Does not prove semantic correctness of the code inside the span.
get_resource_status CORE

Return current resource governor state including memory usage, pressure level, concurrency limits, and activity mode. Use for diagnosing server resource pressure or throttling behavior. Does not inspect repository source code or symbols.

Resolves: Checking if the MCP server is under memory pressure or running in CONSERVATIVE mode
Parameters Schema
ParameterTypeStatusDefaultDescription
No arguments required.
Client Invocation
MCP Client / Agent Call
get_resource_status()
Return Model: ResourceGovernorState
FieldTypeDescription
modestringMode
pressurestringPressure
rss_mbstringRss Mb
active_tasksstringActive Tasks
Evidence Guarantee Live process memory and governor concurrency telemetry.
Epistemic Boundary Does not report symbol index freshness (use get_repository_status for index freshness).

Framework Route Discovery Tools (2)

Framework-aware HTTP route mapping for FastAPI, Flask, Django, and Express.

list_routes ROUTES

Return HTTP/RPC framework routes, mounted router prefixes (`MOUNTS`), methods, and handler symbols. Use when locating API endpoints, route handlers, or mounted sub-applications (FastAPI, Flask, Django, Express, NestJS). Does not prove runtime middleware authentication unless traced via get_context or trace_path.

Resolves: Answering 'Which route handles /api/v1/auth/login?'
Parameters Schema
ParameterTypeStatusDefaultDescription
framework any Optional None Framework
method any Optional None Method
path any Optional None Path
Client Invocation
MCP Client / Agent Call
list_routes(method="POST", path="/api/v1/auth/login")
Return Model: RouteListResult
FieldTypeDescription
statusstringStatus
routesarrayRoutes
route_pathstringRoute Path
http_methodstringHttp Method
handler_namestringHandler Name
canonical_idstringCanonical Id
frameworkstringFramework
filestringFile
lineintegerLine
evidence_classstringEvidence Class
Evidence Guarantee Framework-verified route paths, HTTP methods, composed mount prefixes, and handler canonical IDs.
Epistemic Boundary Does not prove external API gateway or reverse-proxy rewrite rules outside the repository.
find_routes ROUTES

Find HTTP/RPC framework routes, mounted router prefixes (`MOUNTS`), methods, and handler symbols across FastAPI, Flask, Django, Express, and NestJS. Use instead of grep when locating API endpoints or route handlers. Does not prove runtime middleware authentication unless traced via trace_path or get_context.

Resolves: Answering 'Where is /api/scan-bill handled?'
Parameters Schema
ParameterTypeStatusDefaultDescription
framework any Optional None Framework
method any Optional None Method
path any Optional None Path
Client Invocation
MCP Client / Agent Call
find_routes(path="/api/scan-bill")
Return Model: RouteListResult
FieldTypeDescription
statusstringStatus
routesarrayRoutes
route_pathstringRoute Path
http_methodstringHttp Method
handler_namestringHandler Name
canonical_idstringCanonical Id
frameworkstringFramework
filestringFile
lineintegerLine
evidence_classstringEvidence Class
Evidence Guarantee Framework-verified route paths, HTTP methods, composed mount prefixes, and handler canonical IDs.
Epistemic Boundary Does not prove external API gateway or reverse-proxy rewrite rules outside the repository.

Git History & Change Impact Tools (4)

Recent file commit history, changed files, and git diff impact analysis.

get_git_impact GIT

Compute deterministic change impact between Git refs (`base`..`head`), including modified symbols, downstream callers, affected packages, and covering tests. Use for PR review, regression analysis, and pre-commit blast-radius checks. Does not execute tests; reports static test-to-symbol coverage edges.

Resolves: Finding affected callers, packages, and tests after recent commits or before a refactor
Parameters Schema
ParameterTypeStatusDefaultDescription
base string Optional HEAD~1 Base
head string Optional HEAD Head
Client Invocation
MCP Client / Agent Call
get_git_impact(base="HEAD~1", head="HEAD")
Return Model: GitImpactResult
FieldTypeDescription
statusstringStatus
basestringBase
headstringHead
changed_filesarrayChanged Files
modified_symbolsarrayModified Symbols
impacted_callersarrayImpacted Callers
affected_packagesstringAffected Packages
related_testsarrayRelated Tests
Evidence Guarantee Git diff line mapping intersected with AST symbol spans and graph dependents.
Epistemic Boundary Does not prove whether tests pass or fail at runtime.
get_recent_changes GIT

Return repository files modified between two Git refs (`since`..`until`) in a read-only sandboxed query. Use when reviewing recent commits or identifying which files changed before running impact analysis. Does not compute downstream symbol callers; use get_git_impact for symbol-level blast radius.

Resolves: Listing files touched in the last N commits during debugging or code review
Parameters Schema
ParameterTypeStatusDefaultDescription
since string Optional HEAD~10 Since
until string Optional HEAD Until
Client Invocation
MCP Client / Agent Call
get_recent_changes(since="HEAD~5", until="HEAD")
Return Model: GitChangedFilesList
FieldTypeDescription
pathstringPath
statusstringStatus
Evidence Guarantee Git diff status and relative file paths between refs.
Epistemic Boundary Does not compute symbol-level callers or covering tests (use get_git_impact).
get_file_history GIT

Return recent Git commits touching a specific repository file (`path`, up to `n` commits). Use when investigating when and why a specific file was recently modified. Does not return full commit diffs or cross-file dependency impact.

Resolves: Checking recent commit history on a buggy file
Parameters Schema
ParameterTypeStatusDefaultDescription
path string Required - Path
n integer Optional 10 N
Client Invocation
MCP Client / Agent Call
get_file_history(path="src/auth/service.py", n=5)
Return Model: FileCommitHistoryList
FieldTypeDescription
commitstringCommit
authorstringAuthor
datestringDate
subjectstringSubject
Evidence Guarantee Commit hashes, authors, timestamps, and commit subjects touching `path`.
Epistemic Boundary Does not prove which specific symbol inside the file caused a regression.
analyze_change_impact GIT

Analyze changed files, modified symbols, downstream callers, and related tests between Git refs `since` and `until`. Use for commit-range impact analysis when `since`/`until` parameter naming is preferred. Does not execute tests at runtime.

Resolves: Analyzing blast radius of commits between `since` and `until`
Parameters Schema
ParameterTypeStatusDefaultDescription
since string Optional HEAD~1 Since
until string Optional HEAD Until
Client Invocation
MCP Client / Agent Call
analyze_change_impact(since="HEAD~2", until="HEAD")
Return Model: ChangeImpactReport
FieldTypeDescription
changed_filesarrayChanged Files
modified_symbolsarrayModified Symbols
callersarrayCallers
related_testsarrayRelated Tests
Evidence Guarantee Git diff mapped to indexed symbols, callers, and related tests.
Epistemic Boundary Does not prove runtime test pass/fail status.

Test Discovery & Coverage Tools (2)

Deterministic symbol-to-test suite mapping.

find_tests TESTS

Find test files and test functions statically linked to a target symbol (`symbol`; `canonical_id` supported as alias) via direct calls, imports, fixtures, or route invocation. Use instead of grep when answering 'what tests cover symbol X?'. Does not execute tests at runtime and never fabricates coverage from lexical similarity alone.

Resolves: Selecting the exact pytest/jest test functions to run after modifying a symbol
Parameters Schema
ParameterTypeStatusDefaultDescription
symbol string Optional Symbol
canonical_id string Optional Canonical Id
max_results integer Optional 10 Max Results
Client Invocation
MCP Client / Agent Call
find_tests(symbol="parse_bill")
Return Model: RelatedTestsResult
FieldTypeDescription
test_symbolstringTest Symbol
filestringFile
start_lineintegerStart Line
end_lineintegerEnd Line
relationshipstringRelationship
evidence_classstringEvidence Class
confidencestringConfidence
reasonstringReason
Evidence Guarantee AST/fixture/route-verified links from test functions to target symbols.
Epistemic Boundary Does not prove runtime line coverage percentage or assertion completeness.

CLI Commands Reference (13 Commands)

CodeGraph MCP provides 13 deterministic terminal commands for repository indexing, health auditing, MCP server hosting, and context extraction.

codegraph init [PATH] CORE LIFECYCLE

Initialize repository indexing and configuration.

Resolves: Creates the persistent SQLite index (.codegraph.sqlite3) and sets up the project graph cache without requiring external DB infrastructure.
Terminal Command
codegraph init .
Flags & Options
FlagDescription
--repository, -r <path>Repository path
--jsonMachine-readable JSON output
Terminal Output
Deterministic Output
Initialized CodeGraph repository at /path/to/repo (indexed 190 files)
codegraph index [PATH] CORE LIFECYCLE

Perform incremental AST & relationship indexing with 16-phase telemetry.

Resolves: Detects modified or deleted files using content hashes and Git commits; only re-indexes what changed in milliseconds.
Terminal Command
codegraph index . --verbose
Flags & Options
FlagDescription
--verbose, -vShow phase-by-phase timings and memory usage
--quiet, -qSuppress progress blocks
--jsonOutput phase metrics as JSON
Terminal Output
Deterministic Output
Phase: Repository Scan [190/190 files, 100%] elapsed: 0.09s
Phase: Final Commit & Checkpoint
scanned=190 indexed=1 unchanged=189 removed=0
codegraph status [PATH] HEALTH & FRESHNESS

Inspect index freshness, file counts, and resource consumption in < 5ms.

Resolves: Eliminates slow full-repo scans before queries by checking git commit HEAD match and working tree status instantly.
Terminal Command
codegraph status .
Flags & Options
FlagDescription
--repository, -r <path>Repository path
Terminal Output
Deterministic Output
{
  "status": "FRESH",
  "files": 190,
  "symbols": 1944,
  "graph_edges": 14293,
  "resource_profile": "BALANCED"
}
codegraph doctor [PATH] HEALTH & FRESHNESS

Verify SQLite schema integrity, foreign keys, FTS search, and orphaned processes.

Resolves: Detects database corruption, schema mismatches, duplicate canonical symbol IDs, and stale background processes.
Terminal Command
codegraph doctor --database
Flags & Options
FlagDescription
--databaseRun deep schema & foreign key checks
--processesAudit active MCP processes and parent PIDs
--jsonOutput diagnostic report as JSON
Terminal Output
Deterministic Output
{
  "status": "OK",
  "database_version": 8,
  "foreign_keys": true,
  "issues": []
}
codegraph run <COMMAND...> RUNTIME TELEMETRY

Zero-friction runtime telemetry interceptor.

Resolves: Bypasses the complexity of setting up OpenTelemetry or Pino streaming. Injects lightweight NODE_OPTIONS or PYTHONSTARTUP hooks to record live HTTP routes, latencies, and uncaught exceptions directly into SQLite.
Terminal Command
codegraph run npm run dev
# or
codegraph run uvicorn main:app --reload
Flags & Options
FlagDescription
--sample-rate <float>Trace sampling rate (0.0 to 1.0, default 1.0)
Terminal Output
Deterministic Output
>> Dev server active on port 8000
[CodeGraph Runtime Interceptor: Captured 14 HTTP spans -> .codegraph/runtime.sqlite3]
codegraph serve [PATH] MCP SERVER

Run the Model Context Protocol (MCP) server over stdio or SSE HTTP.

Resolves: Connects AI coding agents (Claude, Cursor, Antigravity) to the repository intelligence graph via JSON-RPC standard I/O or persistent SSE HTTP.
Terminal Command
codegraph serve . --transport sse --port 8765
Flags & Options
FlagDescription
--profile <name>Tool profile (core | minimal | agent | developer | full)
--transport, -t <stdio|sse>Transport layer (default: stdio)
--host <str>Host for SSE server (default: 127.0.0.1)
--port, -p <int>Port for SSE server (default: 8765)
Terminal Output
Deterministic Output
CodeGraph MCP server running on http://127.0.0.1:8765/sse (56 tools registered)
codegraph stop [PATH] PROCESS LIFECYCLE

Safely terminate active CodeGraph background processes and release SQLite file locks.

Resolves: Prevents "database is locked" crashes by gracefully signalling MCP servers to close connections before unmounting or updating.
Terminal Command
codegraph stop --json
Flags & Options
FlagDescription
--all, -aStop all CodeGraph processes across all repositories
--timeout <sec>Graceful shutdown timeout before SIGKILL
--jsonOutput machine-readable JSON
Terminal Output
Deterministic Output
{
  "status": "ok",
  "stopped_count": 1,
  "stale_cleaned_count": 0
}
codegraph install [PATH] AGENT ONBOARDING

Idempotently detect and configure AI coding agents.

Resolves: Eliminates manual JSON config editing. Detects Claude Code, Cursor, Antigravity, Cline, and Codex; injects mcpServers and safe marker-bounded instructions.
Terminal Command
codegraph install --yes --target auto --location local
Flags & Options
FlagDescription
--target, -t <auto|all|agent>Target specific agents
--location, -l <local|global>Project (.cursor/mcp.json) vs user global (~/.claude.json)
--yes, -yNon-interactive confirmation
--dry-runPreview changes without writing
Terminal Output
Deterministic Output
Configured Claude Code (CLAUDE.md, .mcp.json)
Configured Cursor (.cursor/mcp.json, .cursorrules)
Configured Antigravity (.agents/mcp_config.json, AGENTS.md)
codegraph search <QUERY> CODE EXPLORATION

Search symbols and text chunks with AST-verified evidence.

Resolves: Combines SQLite FTS5 lexical matching with exact symbol grounding; returns exact file lines, content hashes, and match confidence.
Terminal Command
codegraph search "create_order" -r .
Flags & Options
FlagDescription
--repository, -r <path>Repository path
--top_k <int>Number of results to return (default: 10)
--jsonMachine-readable JSON output
Terminal Output
Deterministic Output
Found 1 symbol match:
  src/app/orders.py:42 function create_order(user_id: int, items: list) -> Order
codegraph routes [PATH] FRAMEWORK INTELLIGENCE

Discover HTTP endpoints with composed router mount prefixes.

Resolves: Finds composite router mounts across FastAPI, Flask, Django, and Express. Handles include_router prefixes and nested mounts statically.
Terminal Command
codegraph routes -r . --limit 3
Flags & Options
FlagDescription
--limit <int>Bounded pagination limit (default: 50)
--offset <int>Pagination offset (default: 0)
--jsonOutput routes as JSON
Terminal Output
Deterministic Output
Found 3 route(s):
  [GET]  /api/v1/health -> health_check (src/api.py:14)
  [POST] /api/v1/orders -> create_order (src/orders.py:42)
  [GET]  /api/v1/users/{id} -> get_user (src/users.py:88)
codegraph trace <SYMBOL> GRAPH TRAVERSAL

Trace a symbol definition, callers, and callees with explicit confidence labels.

Resolves: Traverses AST call graphs multi-hops deep, highlighting exact call sites and distinguishing AST_VERIFIED from dynamic UNKNOWN calls.
Terminal Command
codegraph trace OrderService.create_order -d 2
Flags & Options
FlagDescription
-d, --depth <int>Traversal depth (default: 1)
--jsonOutput call hierarchy as JSON
Terminal Output
Deterministic Output
Symbol: OrderService.create_order (src/services/order.py:28)
  ▲ Callers (1):
    - [AST_VERIFIED] api.create_order_endpoint (src/api.py:52)
  ▼ Callees (2):
    - [AST_VERIFIED] UserRepository.get_by_id (src/db/users.py:15)
    - [AST_VERIFIED] OrderRepository.insert (src/db/orders.py:40)
codegraph context <QUERY> CONTEXT OPTIMIZATION

Compile token-budgeted ContextPacket for an AI agent task.

Resolves: Selects the top high-signal symbols and slices needed for a specific task intent (DEBUG, TRACE, REVIEW) fitting strictly within a token budget.
Terminal Command
codegraph context "fix order validation error" --intent DEBUG
Flags & Options
FlagDescription
--intent <str>Task intent (UNDERSTAND | DEBUG | TRACE | REVIEW | IMPACT)
--max-tokens <int>Token limit (default: 8000)
--jsonOutput serialized ContextPacket
Terminal Output
Deterministic Output
ContextPacket compiled (540 tokens, reduction: 78.4%):
  - 4 confirmed symbols, 2 database tables, 1 covering test
codegraph privacy [PATH] SECURITY & COMPLIANCE

Verify repository privacy boundaries and ensure no sensitive data is indexed.

Resolves: Scans SQLite database to guarantee that .env files, RSA private keys, JWTs, and database credentials have been redacted and never saved.
Terminal Command
codegraph privacy .
Flags & Options
FlagDescription
--jsonOutput privacy audit as JSON
Terminal Output
Deterministic Output
Privacy Audit PASSED: 0 sensitive files indexed, 0 exposed secrets found.

Scaling Benchmarks

Empirically measured scaling metrics across codebases from 10,000 to over 1,000,000 lines of code.

Scale Cold Index Time Warm Re-index Query Latency Database Size Memory Footprint
Small (10k LOC)0.42 s0.08 s12 ms2.4 MB< 35 MB
Medium (100k LOC)2.85 s0.31 s24 ms18.2 MB< 85 MB
Large (500k LOC)11.40 s1.15 s42 ms76.5 MB< 180 MB
Monorepo (1M+ LOC)23.10 s2.40 s58 ms152.0 MB< 320 MB
Scaling Benchmark
Throughput scaling across codebase sizes
Performance Comparison
Retrieval latency: SQLite WAL + FTS5 vs Vector DBs
Navigate with mouse or Esc to close CodeGraph MCP Search