Agent skill

Neo4j Snowflake Graph Analytics Skill

by neo4j-contrib in neo4j-contrib/neo4j-skills

Run Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN, Node2Vec, FastRP, GraphSAGE) directly inside Snowflake without moving data.

MITAuto-check: notesDatabases

Install Neo4j Snowflake Graph Analytics Skill

skills CLI
$ npx skills add neo4j-contrib/neo4j-skills --skill neo4j-snowflake-graph-analytics-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install neo4j-contrib/neo4j-skills neo4j-snowflake-graph-analytics-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/neo4j-contrib/neo4j-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/neo4j-snowflake-graph-analytics-skill .claude/skills/neo4j-snowflake-graph-analytics-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
neo4j-snowflake-graph-analytics-skill
GitHub stars
114
Token cost
~7k tokens
SKILL.md length
2,262 words
Files
3 (incl. references)
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Run Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN, Node2Vec, FastRP, GraphSAGE) directly inside Snowflake without moving data.

  • Works in 4 steps: Explore the Source Data → Prepare Projection Views (the important… → Project → Compute → Write → …
  • Running graph algorithms against Snowflake tables via the Neo4j Snowflake Native App (GDS Snowflake
  • SKILL.md covers When to Use, When NOT to Use, The End-to-End Flow and Step 1 — Explore the Source Data, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Neo4j Snowflake Graph Analytics Skill is an agent skill from neo4j-contrib/neo4j-skills. Run Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN, Node2Vec, FastRP, GraphSAGE) directly inside Snowflake without moving data. Use when running graph algorithms against Snowflake tables via the Neo4j Snowflake Native App ("GDS Snowflake", "graph algorithms in Snowflake", "Neo4j Graph Analytics"). Covers the explore → prepare projection views → project-compute-write flow, the strict view/column type rules the graph engine requires, exact SQL CALL syntax, and privilege setup in both modes…

Its SKILL.md is about 7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/algorithms.md`).

It sits in Databases, covering Data warehousing. It works with Snowflake, Neo4j and SQL. The repository describes itself as: Neo4j Skills for Coding and other Agents including Cypher. The licence is MIT.

When your agent uses it

  • Running graph algorithms against Snowflake tables via the Neo4j Snowflake Native App (GDS Snowflake
  • Graph algorithms in Snowflake
  • Neo4j Graph Analytics)

Example prompts

  • “GDS Snowflake”
  • “graph algorithms in Snowflake”
  • “Neo4j Graph Analytics”
  • “/neo4j-snowflake-graph-analytics-skill”

Requirements

  • Pre-approved tools (allowed-tools): Bash, WebFetch

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Explore the Source Data
  2. Prepare Projection Views (the important part)
  3. Project → Compute → Write
  4. Inspect & Look Up Names

What it can do on your machine

Read from SKILL.md and the folder at commit bb30e1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • neo4j.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Neo4j Snowflake Graph Analytics Skill loads about 7k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 228 tokens; SKILL.md has 2,262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~228
When it runs · the whole SKILL.md, loaded when a task matches
~7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from neo4j-contrib/neo4j-skills at commit bb30e1f, republished under its MIT licence (© neo4j-contrib). 2,262 words, ~6,952 tokens.

Download SKILL.mdSave it as .claude/skills/neo4j-snowflake-graph-analytics-skill/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
neo4j-snowflake-graph-analytics-skill
description
Run Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN, Node2Vec, FastRP, GraphSAGE) directly inside Snowflake without moving data. Use when running graph algorithms against Snowflake tables via the Neo4j Snowflake Native App ("GDS Snowflake", "graph algorithms in Snowflake", "Neo4j Graph Analytics"). Covers the explore → prepare projection views → project-compute-write flow, the strict view/column type rules the graph engine requires, exact SQL CALL syntax, and privilege setup in both modes — app-identity grants and execute-as-user / per-user PAT auth (programmatic access token, set_enable_custom_credentials, register_user_role, caller grants). Does NOT cover Cypher or Neo4j DBMS queries — use neo4j-cypher-skill. Does NOT cover Aura Graph Analytics — use neo4j-aura-graph-analytics-skill. Does NOT cover self-managed GDS — use neo4j-gds-skill.
allowed-tools
Bash, WebFetch
version
1.2.1

Snowflake Native App — graph algorithm power inside Snowflake. Data stays in Snowflake; project into a graph, run algorithms via SQL CALL, results written back to Snowflake tables.

Docs: https://neo4j.com/docs/snowflake-graph-analytics/current/


When to Use

  • Running graph algorithms / GDS in Snowflake
  • Data already lives in Snowflake tables
  • On-demand / pipeline workloads — ephemeral sessions, pay per session-minute
  • Full isolation from the live database during analytics

When NOT to Use

  • Aura Pro with embedded GDS plugin → neo4j-gds-skill
  • Aura Graph Analytics → neo4j-aura-graph-analytics-skill
  • Self-managed Neo4j with embedded GDS plugin → neo4j-gds-skill
  • Writing Cypher queries → neo4j-cypher-skill

The End-to-End Flow

This is the flow that works. Don't jump straight to a CALL — most failures come from skipping the data-preparation step.

  1. Explore the source data — inspect table DDLs to learn columns and types.
  2. Prepare projection views — create node/relationship views that expose the required key columns and cast every property to a supported type (see the strict rules below). This is the step that matters most.
  3. Project → Compute → Write — run the algorithm with a single CALL, assembling the project, compute, and write config.
  4. Inspect & look up names — join numeric results back to the source table to get human-readable labels.

Step 1 — Explore the Source Data

Look at the table definitions before designing the graph:

sql
SELECT GET_DDL('TABLE', 'MY_DATABASE.MY_SCHEMA.MY_TABLE');
-- or inspect columns/types:
SELECT COLUMN_NAME, DATA_TYPE
FROM MY_DATABASE.INFORMATION_SCHEMA.COLUMNS
WHERE TABLE_SCHEMA = 'MY_SCHEMA' AND TABLE_NAME = 'MY_TABLE';

Decide which tables are nodes and which represent relationships (edges) between them.


Step 2 — Prepare Projection Views (the important part)

The graph engine is strict about column names and types. Snowflake views inherit the source column type by default, so you MUST add explicit CASTs — never SELECT col without one for a property column.

Create views that reshape your tables into the node/relationship format:

sql
CREATE OR REPLACE VIEW MY_DATABASE.MY_SCHEMA.MY_NODES_VW AS
SELECT ... FROM MY_DATABASE.MY_SCHEMA.MY_TABLE;
Node views
  • Key column: expose the primary key as NODEID. It must be BIGINT or STRING. Always alias and cast explicitly: SOURCE_COL::BIGINT AS NODEID or SOURCE_COL::STRING AS NODEID.
  • Allowed node property types (exactly): BIGINT, DOUBLE, ARRAY, VECTOR(FLOAT, n). Anything else must be cast to one of these or dropped.
  • Composite keys: concatenate parts with '++'.
  • Naming: <table>_NODES_VW.
Source-type → view-type casting rules

Apply these when projecting columns from your tables (keep the original column name unless renaming):

Source typeAction
Whole-number numerics (INT, INTEGER, BIGINT, SMALLINT, TINYINT, BYTEINT, NUMBER(p,0))CAST(col AS BIGINT) AS col
Fractional numerics (FLOAT, DOUBLE, REAL, DECIMAL(p,s>0), NUMBER(p,s>0))CAST(col AS DOUBLE) AS col
ARRAY of numberskeep as ARRAY (except GraphSAGE — see below). Not allowed on relationship views.
VECTOR(FLOAT, n)keep as-is. Not allowed on relationship views.
BOOLEANdrop by default. Opt-in only: IFF(col, 1, 0)::BIGINT AS col
DATE, TIME, TIMESTAMP*drop by default. Opt-in only: DATE_PART('EPOCH_SECOND', col)::BIGINT AS col (tell the user the unit)
VARCHAR, CHAR, TEXT, STRINGdrop — can't be a graph property. To read results by name, join output back to the source table on the key (see Step 4)
VARIANT, OBJECT, GEOGRAPHY, GEOMETRY, BINARYdrop — not supported as graph properties

Lowest-common-denominator policy: by default include only safe columns (numeric → BIGINT/DOUBLE, ARRAY, VECTOR). Booleans and time-like columns require explicit opt-in. When you drop columns, briefly tell the user which and why, so they can ask for them back.

Relationship views
  • Key columns: expose SOURCENODEID and TARGETNODEID, cast with the same rules as NODEID (SOURCE_COL::BIGINT AS SOURCENODEID, etc.). Every value must match an existing NODEID in a node view.
  • Allowed relationship property types (narrower): BIGINT, DOUBLE, INT only. No ARRAY, no VECTOR. (The docs describe relationship properties as FLOAT; the engine accepts these whole/fractional numeric casts and treats them as weights — keep them numeric.)
  • Naming: <table>_RELATIONSHIPS_VW.

Example node + relationship views:

sql
CREATE OR REPLACE VIEW MY_DATABASE.MY_SCHEMA.USER_NODES_VW AS
SELECT user_id::BIGINT AS NODEID,
       CAST(age AS BIGINT)        AS age,
       CAST(balance AS DOUBLE)    AS balance
FROM MY_DATABASE.MY_SCHEMA.USERS;

CREATE OR REPLACE VIEW MY_DATABASE.MY_SCHEMA.TRANSFERS_RELATIONSHIPS_VW AS
SELECT from_user::BIGINT AS SOURCENODEID,
       to_user::BIGINT   AS TARGETNODEID,
       CAST(amount AS DOUBLE) AS amount
FROM MY_DATABASE.MY_SCHEMA.TRANSFERS;

The required logical column names are nodeId / sourceNodeId / targetNodeId — Snowflake folds unquoted identifiers to uppercase, so NODEID etc. match. Casting explicitly is what matters.


Step 3 — Project → Compute → Write

Every run is a single CALL whose first argument is the compute pool and second is a JSON config with three parts. Note JSON uses single quotes in Snowflake SQL.

App name: Neo4j_Graph_Analytics is only the default installation name. If the app was installed under a different name, replace it everywhere — in the procedure call (<APP>.graph.<algo>), the preview.* / admin.* calls, the USE DATABASE <APP> statement, and the privilege grants below. Check with SHOW APPLICATIONS;.

sql
USE ROLE MY_CONSUMER_ROLE;

CALL Neo4j_Graph_Analytics.graph.wcc('CPU_X64_XS', {
    'defaultTablePrefix': 'MY_DATABASE.MY_SCHEMA',
    'project': {
        'nodeTables': ['USER_NODES_VW'],
        'relationshipTables': {
            'TRANSFERS_RELATIONSHIPS_VW': {
                'sourceTable': 'USER_NODES_VW',
                'targetTable': 'USER_NODES_VW',
                'orientation': 'NATURAL'
            }
        }
    },
    'compute': { 'consecutiveIds': true },
    'write': [{
        'nodeLabel': 'USER_NODES_VW',
        'outputTable': 'result_wcc_user_communities'
    }]
});

SELECT * FROM MY_DATABASE.MY_SCHEMA.result_wcc_user_communities;
Config parts
  • defaultTablePrefix — set to the database + schema where your views and output tables live (DB.SCHEMA); lets you reference them by short name.
  • project — nodeTables (array; each maps to a label) and relationshipTables (map; each key maps to a type, with sourceTable/targetTable/orientation).
  • compute — algorithm parameters. Omit any parameter whose value would be null.
  • write — a list of write targets. nodeLabel (or sourceLabel/targetLabel) is the table/view name of the nodes being written. For relationship results use relationshipType.
Orientation

Set orientation per relationship table in relationshipTables:

  • NATURAL (default) — directed, source → target (as stored in the table).
  • UNDIRECTED — treated as bidirectional (each relationship is included in both directions).
  • REVERSE — direction flipped, target → source.

Choose based on the algorithm:

  • UNDIRECTED — community detection that treats edges symmetrically: WCC, Louvain, Leiden, Label Propagation. Triangle Count requires UNDIRECTED.
  • NATURAL — directed-flow and ranking: PageRank, Article Rank, Dijkstra and the other pathfinding algorithms, Max Flow. Node Similarity expects a bipartite graph (two disjoint node sets) projected NATURAL; use REVERSE to compare the other node set instead.
  • KNN ignores relationships entirely — similarity comes from node properties, so orientation has no effect on it (and K-Means likewise uses only node properties).
Compute pools (first CALL argument)
PoolUse
CPU_X64_XSDefault — dev / small graphs
CPU_X64_S/M/LProgressively larger
HIGHMEM_X64_S/M/LLarge graphs, lower CPU need
GPU_NV_XS, GPU_NV_S, GPU_GCP_NV_L4_1_24GGraphSAGE / GPU work (availability varies by region)

Prefer CPU_X64_XS unless the user asks otherwise or GraphSAGE makes a GPU pool appropriate. See Estimating Jobs.

Result table naming

Name output tables result_<algotag>_<short_description>, underscores only, no spaces/special chars (e.g. result_louvain_customer_segments). When writing multiple node labels, use a distinct table per label.


Step 4 — Inspect & Look Up Names

What the algorithm produces depends on its type — check the algorithm's write config:

  • Node-property results (centrality, community detection, k-means, embeddings, FastPath) — a table keyed by NODEID.
  • Relationship results (Node Similarity, KNN, Dijkstra & other pathfinding, Max Flow) — a table keyed by SOURCENODEID / TARGETNODEID. BFS and other heterogeneous writes also add SOURCELABEL / TARGETLABEL, with the node IDs stored as strings.
  • A model (GraphSAGE training) — no output table; it writes to the model catalog. Use the model later for prediction, which then produces a node-property table.

VARCHAR labels were dropped during projection, so join the result back to the source table on the key column(s) to get readable names. For node-property results, join on NODEID:

sql
SELECT u.name, u.country, r.score
FROM MY_DATABASE.MY_SCHEMA.result_page_rank_influence r
JOIN MY_DATABASE.MY_SCHEMA.USERS u
  ON r.NODEID = u.user_id
ORDER BY r.score DESC
LIMIT 10;

For relationship results, join the source table twice — once on SOURCENODEID and once on TARGETNODEID.


Available Algorithms

Procedure = Neo4j_Graph_Analytics.graph.<name>. Names below are exact.

For complete algorithm compute/write parameter reference, see references/algorithms.md.

Community Detection
AlgorithmProcedureUse case
Weakly Connected ComponentswccFind disconnected subgraphs
LouvainlouvainCommunity detection (modularity)
LeidenleidenCommunity detection, more stable than Louvain
Label Propagationlabel_propagationFast community detection by label spreading
K-MeanskmeansCluster nodes by node properties
Triangle Counttriangle_countLocal clustering / dense subgraphs
Centrality
AlgorithmProcedureUse case
PageRankpage_rankRank nodes by influence
Article Rankarticle_rankPageRank variant, discounts high-degree neighbours
BetweennessbetweennessFind bridge nodes
DegreedegreeCount direct connections
Pathfinding
AlgorithmProcedureUse case
Dijkstra Source-TargetdijkstraShortest path(s) from source to target(s) or pairs
Dijkstra Single-Sourcedijkstra_single_sourceShortest paths from one node to all others
Delta-Stepping SSSPdelta_steppingParallel single-source shortest paths
Breadth First SearchbfsBFS traversal from a source
Yen's K-Shortest PathsyensTop-K shortest loopless paths
Max Flowmax_flowMaximum flow with capacities
Min-Cost Max Flowmax_flow_min_costMax flow minimising total cost
FastPathfastpathFast approximate shortest paths
Similarity
AlgorithmProcedureUse case
Node Similaritynode_similaritySimilar nodes by shared neighbours
Filtered Node Similaritynode_similarity_filteredNode similarity with source/target filters
KNNknnK most similar nodes
Filtered KNNknn_filteredKNN with source/target filters
Node Embeddings
AlgorithmProcedureUse case
FastRPfast_rpFast node embeddings
Node2Vecnode2vecRandom-walk node embeddings
HashGNNhashgnnGNN-inspired embeddings without training
GraphSAGE (Graph ML)
AlgorithmProcedureUse case
Node Classification — traings_nc_trainTrain supervised node-label model
Node Classification — predictgs_nc_predictPredict labels with a trained model
Unsupervised embeddings — traings_unsup_trainTrain unsupervised embedding model
Unsupervised embeddings — predictgs_unsup_predictInfer embeddings with a trained model
Model catalog (GraphSAGE)

show_models, model_exists, drop_model.


Algorithm-Specific Notes

Show full SKILL.md (916 more words)Show less
GraphSAGE
  • Projected node tables used by GraphSAGE must not contain ARRAY property columns — use VECTOR(FLOAT, n) for multi-valued numeric features. (ARRAY is fine for non-GraphSAGE algorithms.)
  • Feature columns must be non-NULL and finite — filter, impute, or exclude nullable feature columns in the view. For gs_nc_train, the targetProperty is a label (not a feature) and may be NULL.
  • Before running, list the node properties GraphSAGE will use per node table: all non-NODEID columns; for gs_nc_train exclude the targetProperty.
  • Training (gs_nc_train, gs_unsup_train) can be slow and may use a GPU pool (GPU_NV_S). Show the exact CALL and get explicit confirmation before running training.
Dijkstra Source-Target (dijkstra)

Provide one of:

  • single pair: sourceNode + sourceNodeTable, targetNode + targetNodeTable;
  • one source, many targets: sourceNode + sourceNodeTable, targetNodes (list) + targetNodesTable;
  • many pairs: sourceTargetNodePairsTable (table with SOURCENODEID/TARGETNODEID columns) + sourceNodeTable + targetNodeTable.
General
  • Never use NODEID itself as an algorithm property.
  • Omit any config parameter whose value is null.

Installation

  1. Install Neo4j Graph Analytics from the Snowflake Marketplace (default app name Neo4j_Graph_Analytics).
  2. Enable Event sharing when prompted.
  3. Data Products → Apps → Neo4j Graph Analytics → Privileges → Grant: grant CREATE COMPUTE POOL and CREATE WAREHOUSE, then click Activate.

Privilege Setup

Two parts. Part A (consumer roles) is always required. Part B is a choice of exactly one data-access mode — don't mix them.

ModeJob runs asGrant styleUse when
App identity (OAuth) — defaultthe applicationdirect grants + a database role granted to the appDefault. Simplest, one set of grants covers every user.
Execute-as-user — previewthe calling user, under a registered roleGRANT CALLER / GRANT INHERITED CALLER to the appYou need per-user attribution in QUERY_HISTORY and per-user authorization on jobs.

Execute-as-user is a granularity upgrade, not a security upgrade, and it adds real operational surface (a PAT, a SECRET, and caller grants per user, plus token rotation). Default to app identity; only set up execute-as-user when the user explicitly asks for per-user identity or per-user authorization.

Part A — Consumer roles (both modes)
sql
USE ROLE ACCOUNTADMIN;

-- Consumer role for app users
CREATE ROLE IF NOT EXISTS MY_CONSUMER_ROLE;
GRANT APPLICATION ROLE Neo4j_Graph_Analytics.app_user TO ROLE MY_CONSUMER_ROLE;
SET MY_USER = (SELECT CURRENT_USER());
GRANT ROLE MY_CONSUMER_ROLE TO USER IDENTIFIER($MY_USER);

-- Optional: admin role, needed for the app_admin procedures (compute pools, execute-as-user flag)
CREATE ROLE IF NOT EXISTS MY_ADMIN_ROLE;
GRANT APPLICATION ROLE Neo4j_Graph_Analytics.app_admin TO ROLE MY_ADMIN_ROLE;
GRANT ROLE MY_ADMIN_ROLE TO USER IDENTIFIER($MY_USER);

-- Let the consumer role read output tables
GRANT USAGE ON DATABASE MY_DATABASE TO ROLE MY_CONSUMER_ROLE;
GRANT USAGE ON SCHEMA MY_DATABASE.MY_SCHEMA TO ROLE MY_CONSUMER_ROLE;
GRANT SELECT ON FUTURE TABLES IN SCHEMA MY_DATABASE.MY_SCHEMA TO ROLE MY_CONSUMER_ROLE;

ACCOUNTADMIN does not implicitly hold the application roles. The preview.* and admin.* procedures require a role that was granted Neo4j_Graph_Analytics.app_admin; algorithm procedures and preview.register_user_role require app_user.

Part B, option 1 — App-identity grants (default, run once per database/schema)
sql
USE ROLE ACCOUNTADMIN;

-- Database role granting the app access to your data
USE DATABASE MY_DATABASE;
CREATE DATABASE ROLE IF NOT EXISTS MY_DB_ROLE;
GRANT USAGE ON DATABASE MY_DATABASE TO DATABASE ROLE MY_DB_ROLE;
GRANT USAGE ON SCHEMA MY_DATABASE.MY_SCHEMA TO DATABASE ROLE MY_DB_ROLE;
GRANT SELECT ON ALL TABLES  IN SCHEMA MY_DATABASE.MY_SCHEMA TO DATABASE ROLE MY_DB_ROLE;
GRANT SELECT ON ALL VIEWS   IN SCHEMA MY_DATABASE.MY_SCHEMA TO DATABASE ROLE MY_DB_ROLE;
-- FUTURE grants let the app read tables/views it creates (needed for chaining)
GRANT SELECT ON FUTURE TABLES IN SCHEMA MY_DATABASE.MY_SCHEMA TO DATABASE ROLE MY_DB_ROLE;
GRANT SELECT ON FUTURE VIEWS  IN SCHEMA MY_DATABASE.MY_SCHEMA TO DATABASE ROLE MY_DB_ROLE;
GRANT CREATE TABLE ON SCHEMA MY_DATABASE.MY_SCHEMA TO DATABASE ROLE MY_DB_ROLE;
GRANT DATABASE ROLE MY_DB_ROLE TO APPLICATION Neo4j_Graph_Analytics;

USE ROLE MY_CONSUMER_ROLE;   -- run algorithms as the consumer role

Replace MY_DATABASE, MY_SCHEMA, MY_CONSUMER_ROLE, MY_DB_ROLE with your names throughout.

Part B, option 2 — Execute-as-user (preview)

Jobs authenticate as the calling user with a Programmatic Access Token (PAT), under a role that user holds, bounded by caller grants. Procedures live in <APP>.preview.* and may change before GA.

Onboarding can't be scripted end-to-end: ADD PROGRAMMATIC ACCESS TOKEN reveals the token secret once. Run Part 1, collect the token from the user, then run Part 2.

sql
-- PART 1 — enable execute-as-user and mint the token
USE ROLE ACCOUNTADMIN;

-- Prerequisite: PATs require a network policy by default, else jobs fail with
-- "Fail : Network policy is required". This waives it; a user who already has a
-- network policy keeps it enforced. Authentication policies are schema-level objects.
USE SCHEMA MY_DATABASE.MY_SCHEMA;
CREATE AUTHENTICATION POLICY IF NOT EXISTS pat_no_network_required
    PAT_POLICY = (NETWORK_POLICY_EVALUATION = ENFORCED_NOT_REQUIRED);
ALTER USER <user_name> SET AUTHENTICATION POLICY pat_no_network_required;

-- Step 1: enable on the install — once per account, not per user. Needs app_admin,
-- which ACCOUNTADMIN does not hold implicitly.
USE ROLE MY_ADMIN_ROLE;
CALL Neo4j_Graph_Analytics.preview.set_enable_custom_credentials(TRUE);

-- Step 2a: mint a PAT bound to the role. ROLE_RESTRICTION is load-bearing — it pins
-- the PAT to this role whatever the app's registry says, and must match Step 2d.
USE ROLE ACCOUNTADMIN;
ALTER USER <user_name> ADD PROGRAMMATIC ACCESS TOKEN app_pat
    DAYS_TO_EXPIRY = 365
    ROLE_RESTRICTION = 'MY_CONSUMER_ROLE';

STOP. Copy the token_secret column from that last result set now — Snowflake will not show it again — and paste it into SECRET_STRING below.

sql
-- PART 2, steps 2b + 2c — store the token, let the app read it. These are direct
-- grants, not caller grants: the app reads the secret as itself at job-start time.
USE ROLE ACCOUNTADMIN;
CREATE OR REPLACE SECRET MY_DATABASE.MY_SCHEMA.pat_secret_<user_name>
    TYPE = GENERIC_STRING                    -- GENERIC_STRING only; PASSWORD won't work
    SECRET_STRING = '<paste_token_secret_here>';
GRANT USAGE ON DATABASE MY_DATABASE TO APPLICATION Neo4j_Graph_Analytics;
GRANT USAGE ON SCHEMA MY_DATABASE.MY_SCHEMA TO APPLICATION Neo4j_Graph_Analytics;
GRANT READ ON SECRET MY_DATABASE.MY_SCHEMA.pat_secret_<user_name>
    TO APPLICATION Neo4j_Graph_Analytics;
sql
-- Step 2d: register the user. Run in a session opened AS <user_name> so
-- CURRENT_USER() resolves to them, under a role holding app_user.
USE ROLE MY_CONSUMER_ROLE;
CALL Neo4j_Graph_Analytics.preview.register_user_role(
    'MY_CONSUMER_ROLE',                              -- = ROLE_RESTRICTION on the PAT
    'MY_DATABASE.MY_SCHEMA.pat_secret_<user_name>'   -- FQN of the SECRET
);
sql
-- Step 2e: caller grants for the data the jobs read and write. Repeat per schema —
-- this is the only widening mechanism, and there is no FUTURE equivalent, so re-run
-- it after creating views or tables a later job needs to read.
USE ROLE ACCOUNTADMIN;
GRANT CALLER USAGE ON DATABASE MY_DATABASE TO APPLICATION Neo4j_Graph_Analytics;
GRANT CALLER USAGE ON SCHEMA MY_DATABASE.MY_SCHEMA TO APPLICATION Neo4j_Graph_Analytics;
GRANT CALLER CREATE TABLE ON SCHEMA MY_DATABASE.MY_SCHEMA TO APPLICATION Neo4j_Graph_Analytics;
GRANT INHERITED CALLER INSERT ON ALL TABLES IN SCHEMA MY_DATABASE.MY_SCHEMA TO APPLICATION Neo4j_Graph_Analytics;
GRANT INHERITED CALLER SELECT ON ALL TABLES IN SCHEMA MY_DATABASE.MY_SCHEMA TO APPLICATION Neo4j_Graph_Analytics;
GRANT INHERITED CALLER SELECT ON ALL VIEWS  IN SCHEMA MY_DATABASE.MY_SCHEMA TO APPLICATION Neo4j_Graph_Analytics;

To check what an admin registered for a user:

sql
CALL Neo4j_Graph_Analytics.preview.get_user_role_registration('<user_name>');

Rotating and rolling back:

sql
-- Rotate: mint a new PAT, re-point the secret (its grants survive), drop the old PAT.
-- The registry needs no update — the SECRET name didn't change, only its value.
CREATE OR REPLACE SECRET MY_DATABASE.MY_SCHEMA.pat_secret_<user_name>
    TYPE = GENERIC_STRING SECRET_STRING = '<new_token_secret>';
ALTER USER <user_name> REMOVE PROGRAMMATIC ACCESS TOKEN <old_pat_name>;

-- Disable account-wide: app identity returns for everyone, registrations sit unused.
CALL Neo4j_Graph_Analytics.preview.set_enable_custom_credentials(FALSE);

-- Revoke a single user, leaving registry and SECRET intact:
REVOKE READ ON SECRET MY_DATABASE.MY_SCHEMA.pat_secret_<user_name>
    FROM APPLICATION Neo4j_Graph_Analytics;

-- ...or invalidate the credential outright:
ALTER USER <user_name> REMOVE PROGRAMMATIC ACCESS TOKEN app_pat;

Common Patterns

Chaining algorithms

Because results write to tables (and the FUTURE TABLES grant lets the app read what it creates), feed one algorithm's output into the next:

sql
-- 1. Embeddings
CALL Neo4j_Graph_Analytics.graph.fast_rp('CPU_X64_XS', { ... });
-- 2. KNN over the embedding output table (projected as a node view)
CALL Neo4j_Graph_Analytics.graph.knn('CPU_X64_XS', { ... });

In execute-as-user mode there are no FUTURE caller grants — re-run the Step 2e caller grants after creating the projection views over an intermediate result table, so the next algorithm can read them.

Convert categorical data to numeric

The graph engine can't use VARCHAR as a property. Map categories to numbers in the view (e.g. CASE / a lookup join). To read results by their original label, join the output table back to the source table on the key.


Troubleshooting

ProblemSolution
Insufficient privilegesApp needs SELECT on your tables/views and CREATE TABLE on the schema (see Privilege Setup)
no role registered for <user>Execute-as-user is enabled but this user isn't onboarded — run preview.register_user_role as that user (Part B option 2, Step 2d)
Network policy is requiredThe PAT user has no authentication policy allowing PATs without a network policy — attach one with PAT_POLICY = (NETWORK_POLICY_EVALUATION = ENFORCED_NOT_REQUIRED)
does not exist or not authorized in execute-as-user modeMissing caller grants on the data schema, or objects created after the ON ALL ... grants — re-run Step 2e
Insufficient privileges to operate on table on write in execute-as-user modeThe write schema is missing CALLER CREATE TABLE / INHERITED CALLER INSERT ON ALL TABLES — re-run Step 2e
USE ROLE not allowed / Current session is restrictedExpected under a role-restricted PAT — everything must be reachable from the registered primary role
Job errors at authentication in execute-as-user modePAT's ROLE_RESTRICTION doesn't match the registered role, or the SECRET isn't TYPE = GENERIC_STRING
Column nodeId not foundView is missing/mis-cast the key — expose NODEID (and SOURCENODEID/TARGETNODEID) with explicit casts
Type / projection error on a propertyA property column wasn't cast to a supported type — apply the casting rules; relationship props must be BIGINT/DOUBLE/INT
GraphSAGE fails on featuresRemove ARRAY feature columns (use VECTOR), and ensure features are non-NULL/finite
Compute pool not availablePool may still be starting; wait a minute and retry
Algorithm returns no resultsCheck node/relationship views aren't empty and that every SOURCENODEID/TARGETNODEID matches a NODEID

Full guide: https://neo4j.com/docs/snowflake-graph-analytics/current/troubleshooting/


Further Reading


Checklist

  • App installed; consumer role created; one data-access mode set up (app identity or execute-as-user)
  • If execute-as-user: install flag on, PAT minted with matching ROLE_RESTRICTION, SECRET readable by the app, user registered, caller grants issued
  • Views expose NODEID / SOURCENODEID / TARGETNODEID, every property explicitly cast
  • orientation matches the algorithm
  • Single CALL ran without error; output table populated
  • Results joined back to source table for readable labels

© neo4j-contrib, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in neo4j-snowflake-graph-analytics-skill of neo4j-contrib/neo4j-skills.

  • SKILL.md
  • README.md
  • references/algorithms.md

Open the folder on GitHubat commit bb30e1f

Compare with similar skills

Neo4j Snowflake Graph Analytics Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Neo4j Snowflake Graph Analytics Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Neo4j Snowflake Graph Analytics Skill this skillneo4j-contrib/neo4j-skills114—~7kAutomated safety check: NotesMIT
Expensive Snowflake Query FinderAltimateAI/data-engineering-skills128—~662Automated safety check: PassMIT
SQL Queriesw95/awesome-claude-corporate-skills2443 repos~2.8kAutomated safety check: PassMIT
Optimizing Query By IdAltimateAI/data-engineering-skills128—~919Automated safety check: PassMIT
Snowflake Semanticviewgithub/awesome-copilot40k1 repos~1.1kAutomated safety check: PassMIT
Snowflake Developmentsickn33/agentic-awesome-skills47k2 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Expensive Snowflake Query Finder

    AltimateAI/data-engineering-skills

    Ranks the costliest, slowest or heaviest-scanning Snowflake queries from query history and suggests how to optimize them.

    128 GitHub stars~662 tokensUpdated 3 days ago
    DatabasesAuto-check passed
  • SQL Queries

    w95/awesome-claude-corporate-skills

    Write correct, performant SQL across all major data warehouse dialects (Snowflake, BigQuery, Databricks, PostgreSQL, etc.).

    244 GitHub starsUsed in 3 repos~2.8k tokens
    DatabasesAuto-check passed
  • Optimizing Query By Id

    AltimateAI/data-engineering-skills

    Optimizes Snowflake query performance using query ID from history.

    128 GitHub stars~919 tokensUpdated 3 days ago
    DatabasesAuto-check passed
  • Snowflake Semanticview

    github/awesome-copilot

    Official

    Create, alter, and validate Snowflake semantic views using Snowflake CLI (snow).

    40k GitHub starsUsed in 1 repo~1.1k tokens
    DatabasesAuto-check passed
  • Snowflake Development

    sickn33/agentic-awesome-skills

    Comprehensive Snowflake development assistant covering SQL best practices, data pipeline design (Dynamic Tables, Streams, Tasks, Snowpipe), Cortex AI functions, Cortex Agents, Snowpark Python, dbt…

    47k GitHub starsUsed in 2 repos~2.1k tokens
    DatabasesAuto-check passed
  • Warehouse SQL

    HybridAIOne/hybridclaw

    Review and run read-only natural-language SQL against a customer data warehouse with cached schema introspection and explicit write grants.

    159 GitHub stars~1.8k tokensUpdated yesterday
    DatabasesAuto-check passed

More from neo4j-contrib/neo4j-skills

All 28 skills in this repo
  • Neo4j Aura Agent Skill

    neo4j-contrib/neo4j-skills

    Manages Neo4j Aura Agents via the v2beta1 REST API — create, list, get, update, delete, and invoke Aura agents backed by an AuraDB instance.

    114 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check: notes
  • Neo4j Cypher Skill

    neo4j-contrib/neo4j-skills

    Generates, optimizes, and validates Cypher 25 queries for Neo4j 2025.x and 2026.x.

    114 GitHub starsUsed in 1 repo~6.1k tokens
    Auto-check passed
  • Neo4j Aura Graph Analytics Skill

    neo4j-contrib/neo4j-skills

    Serverless Aura Graph Analytics (AGA) GDS Sessions — covers GdsSessions, AuraGraphDataScience, AuraAPICredentials, DbmsConnectionInfo, SessionMemory, getorcreate, remote graph projection with…

    114 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Neo4j Getting Started Skill

    neo4j-contrib/neo4j-skills

    Orchestrates zero-to-running-app in 8 stages — prerequisites → context → provision → model → load → explore → query → build.

    114 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check: warnings
  • Neo4j Aura Provisioning Skill

    neo4j-contrib/neo4j-skills

    Provisions and manages Neo4j Aura instances via CLI (aura-cli v1.7+) or REST API.

    114 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Neo4j Driver Dotnet Skill

    neo4j-contrib/neo4j-skills

    Neo4j .NET Driver v6 — IDriver lifecycle, DI registration (singleton), ExecutableQuery fluent API, ExecuteReadAsync/ExecuteWriteAsync managed transactions, IResultCursor (FetchAsync/ ToListAsync)…

    114 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Neo4j Snowflake Graph Analytics Skill

What does Neo4j Snowflake Graph Analytics Skill do?

Run Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN, Node2Vec, FastRP, GraphSAGE) directly inside Snowflake without moving data. Neo4j Snowflake Graph Analytics Skill is an agent skill from neo4j-contrib/neo4j-skills. Run Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN, Node2Vec, FastRP, GraphSAGE) directly inside Snowflake without moving data.

When should I use Neo4j Snowflake Graph Analytics Skill?

Neo4j Snowflake Graph Analytics Skill fits situations like: running graph algorithms against Snowflake tables via the Neo4j Snowflake Native App (GDS Snowflake; graph algorithms in Snowflake; neo4j Graph Analytics).

How do I install Neo4j Snowflake Graph Analytics Skill in Claude Code?

Run `npx skills add neo4j-contrib/neo4j-skills --skill neo4j-snowflake-graph-analytics-skill -a claude-code`. Or copy the skill folder (neo4j-snowflake-graph-analytics-skill in neo4j-contrib/neo4j-skills) into .claude/skills/neo4j-snowflake-graph-analytics-skill in your project. Claude Code loads it when a task matches its description.

How do I install Neo4j Snowflake Graph Analytics Skill in Codex?

Run `npx skills add neo4j-contrib/neo4j-skills --skill neo4j-snowflake-graph-analytics-skill -a codex`. Or copy the skill folder (neo4j-snowflake-graph-analytics-skill in neo4j-contrib/neo4j-skills) into .agents/skills/neo4j-snowflake-graph-analytics-skill in your project. Codex loads it when a task matches its description.

Can I use Neo4j Snowflake Graph Analytics Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add neo4j-contrib/neo4j-skills --skill neo4j-snowflake-graph-analytics-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/neo4j-snowflake-graph-analytics-skill, .gemini/skills/neo4j-snowflake-graph-analytics-skill, .github/skills/neo4j-snowflake-graph-analytics-skill and .opencode/skills/neo4j-snowflake-graph-analytics-skill in your project.

What does Neo4j Snowflake Graph Analytics Skill need to run?

SKILL.md names no scripts, command-line tools or credentials: Neo4j Snowflake Graph Analytics Skill is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, WebFetch.

Does Neo4j Snowflake Graph Analytics Skill access the network?

SKILL.md names 2 domains. As links in the text: neo4j.com and github.com. This is read from the text; nothing was executed.

Is Neo4j Snowflake Graph Analytics Skill safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Neo4j Snowflake Graph Analytics Skill use?

Neo4j Snowflake Graph Analytics Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Neo4j Snowflake Graph Analytics Skill use?

About 7k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.3k tokens, read only when the agent opens those files.

What are the alternatives to Neo4j Snowflake Graph Analytics Skill?

Skills that share tags, products or a category with Neo4j Snowflake Graph Analytics Skill: Expensive Snowflake Query Finder (AltimateAI/data-engineering-skills, 128 stars), SQL Queries (w95/awesome-claude-corporate-skills, 244 stars), Optimizing Query By Id (AltimateAI/data-engineering-skills, 128 stars) and Snowflake Semanticview (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Neo4j Snowflake Graph Analytics Skill?

neo4j-contrib (a GitHub organization) maintains it in neo4j-contrib/neo4j-skills, which has 114 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 9, 2026.

Source: neo4j-contrib/neo4j-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.