Standards coverage
of the openCypher TCK scenarios pass: 3,862 of 3,863, none skipped. The single failure is the limit of 12 labels per node, a storage choice.
queries compared with Neo4j 5.26: the verdicts match, except 3 administration statements (CREATE/DROP DATABASE, SHOW ROLES, SHOW SERVERS: refused by Community, accepted here as in Enterprise) and 2 PROFILE queries (tooling gap).
Not measured: result equality over that corpus, identical error messages, fine plan semantics, APOC functions. Not supported: LDAP/SAML, Bolt 5.5 and later.
REST API generation
gDown can publish named Cypher queries as REST APIs. For each database, a query (a favorite) is analysed: gDown proposes the HTTP method, deduces the parameter and result types, and generates an OpenAPI 3.1 contract served under /api/<database>/<contract>/, with a Swagger UI to try it.
- Security: the API is a resource server. It checks the bearer token (JWT) from the OpenID Connect provider you declare (issuer, audience, signature, expiry), then the roles and scopes each operation requires.
- Least privilege: each operation runs with a database role chosen when the contract is written, not with the caller's own rights.
- Limits: body size (413), request rate (429 with Retry-After), maximum rows, and NDJSON streaming for large results.
- Writes: per operation, choose between accepted (202, no body), done (counts of created, updated and deleted) or query (the results of another favorite).
- Replicated: providers, favorites and contracts live in the database, so they are replicated, backed up and dropped with it.
- On Gluonify: Higgs, the orchestrator, can expose these contracts on your own domain, behind a Charm token and rate limits; nothing else of gDown is reachable from outside.