Chapter 12 · APOC, Procedures, Functions, Triggers-Like Workflows, and Extending Cypher
APOC Core: Procedures vs Functions, Installation/Availability, Configuration, and Security Boundaries
Install and verify APOC Core deliberately, separate supported Core from community Extended, and constrain extension privileges before using any convenience procedure.
Learning outcomes
AtlasMart has reached the point where developers want helpers for data cleanup, path expansion and JSON exchange. The risk is to treat “APOC” as one magic capability. In reality a function, a procedure, a server plugin, a filesystem permission and an outbound HTTP permission have different execution and security boundaries.
Distinguish Cypher functions from procedures by row-flow and side-effect semantics.
Install and verify the APOC Core release compatible with Neo4j 2026.07.1.
Separate APOC Core support from APOC Extended/community-managed components.
Explain procedure allowlisting/unrestricted execution and Community vs Enterprise privilege boundaries.
Keep file, HTTP and trigger-like capabilities disabled until a documented AtlasMart requirement justifies them.
The mandatory lab continues Neo4j Community
2026.07.1, database neo4j, explicit
CYPHER 25 for version-sensitive examples,
container atlasmart-neo4j, authentication
enabled, loopback HTTP/Bolt endpoints, and the AtlasMart
identifiers/model built in Chapters 01–11. Neo4j
5.26.30 remains the LTS comparison line. This
chapter adds APOC Core 2026.07.1 as an optional
extension; APOC Extended is never required.
This generation environment does not run the Neo4j container, so no plugin load, procedure list, filesystem read/write, HTTP request, trigger execution or custom-JAR output is invented. The lab tells you exactly what to inspect. Community Edition lacks Enterprise RBAC/load privileges, so the free path emphasizes configuration minimization, loopback-only access, file/network denial by default, and application-level authorization boundaries.
1. Function, procedure and plugin are three different concepts
| Concept | How Cypher uses it | Typical behavior | Design implication |
|---|---|---|---|
| Function |
Inside an expression, e.g.
RETURN apoc.version()
|
Returns a value per row/expression | Composes naturally with projection/filtering; should not be treated as an external workflow engine |
| Procedure | CALL ... YIELD ... |
Can emit zero/many rows and may perform broader work depending on the procedure | Scope, privileges, side effects and result cardinality need explicit review |
| Plugin/JAR | Loaded into the Neo4j server JVM | Provides procedures/functions/extensions | Couples deployment and upgrade lifecycle to server compatibility |
APOC Core is implemented as a server-side Java extension. Installing it changes the server process, not merely the client query text. That is why version matching, restart behavior and security configuration belong in the same lesson as syntax.
2. Current support and compatibility contract
| Component | 2026.07 status | AtlasMart policy |
|---|---|---|
| Neo4j DBMS | 2026.07.1 current line |
Pinned mandatory server baseline |
| APOC Core |
2026.07.1; year/month must match Neo4j line
|
Optional, officially supported library |
| APOC Extended | Separate community-maintained project; not officially supported by Neo4j | Do not make course labs depend on it |
| Cypher 25 | APOC changes after 2025.06 target Cypher 25 |
Use CYPHER 25 and avoid deprecated APOC
conveniences when native Cypher exists
|
Patch numbers do not have to match in the general compatibility
rule, but this lab pins both server and Core to
2026.07.1 so the evidence is unambiguous.
3. Recreate the disposable container with APOC Core while preserving named data volumes
If your existing atlasmart-neo4j container was
created without APOC, stop and recreate the container rather
than editing a running server ad hoc. The Docker
NEO4J_PLUGINS helper is documented as a development
convenience, not a production deployment recommendation.
docker stop atlasmart-neo4jdocker rm atlasmart-neo4jdocker run -d ` --name atlasmart-neo4j ` -p 127.0.0.1:7474:7474 ` -p 127.0.0.1:7687:7687 ` -v atlasmart-neo4j-data:/data ` -v atlasmart-neo4j-logs:/logs ` -e NEO4J_AUTH=neo4j/atlasmart-course-2026 ` -e 'NEO4J_PLUGINS=["apoc"]' ` neo4j:2026.07.1
For production, download the matching APOC Core JAR, verify
provenance/checksum according to your supply-chain process,
mount it into /plugins, and test the exact
server/plugin pair before rollout. Do not rely on runtime
plugin download as a production control plane.
CYPHER 25RETURN apoc.version() AS apocVersion;SHOW PROCEDURES YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;SHOW FUNCTIONS YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;
4. Load only what the workload needs
| Control | Default/current meaning | Safer AtlasMart starting point |
|---|---|---|
dbms.security.procedures.allowlist |
* loads procedures/functions |
If you operate a hardened server, narrow to required names after testing |
dbms.security.procedures.unrestricted |
Empty by default | Keep empty unless a documented procedure truly needs unrestricted internals |
| Enterprise execute/load privileges | Fine-grained RBAC, execute/boosted/load controls | Not available in Community; do not pretend Community can reproduce RBAC evidence |
| File import/export | Disabled in APOC by default | Leave disabled in Lessons 1–2 |
| Outbound HTTP | Available to URL-capable procedures subject to platform/security controls | Use only controlled endpoints; block internal/private metadata ranges in Community |
“Unrestricted” is not a synonym for “installed.” It lets designated extensions bypass normal sandbox restrictions and is therefore a much stronger security decision. Likewise, boosted procedure execution in Enterprise can bypass ordinary user privileges; it should never be granted broadly to convenience procedure families.
5. Deliberately wrong: apoc.* unrestricted because
“APOC is trusted”
Trusting the publisher does not mean every procedure should run with elevated server powers. Some APOC procedures can execute dynamically supplied Cypher or access URLs/files. A broad unrestricted/boosted grant converts a small application requirement into a large attack surface. The repair is to identify the exact operation, prefer native Cypher where equivalent, load only the necessary extension set, and grant the minimum execution/filesystem/network capability.
CYPHER 25CALL apoc.help('path') YIELD name, type, textRETURN name, type, textORDER BY name;SHOW PROCEDURES YIELD name, mode, adminWHERE name STARTS WITH 'apoc.'RETURN name, mode, adminORDER BY name;
6. Reproducible AtlasMart baseline
CYPHER 25MERGE (c:Customer {customerId:'C-1001'})SET c.name='Mina Rahimi'MERGE (p1:Product {productId:'P-1001'})SET p1.name='Trail Camera', p1.category='Cameras', p1.price=129.90MERGE (p2:Product {productId:'P-2001'})SET p2.name='Smart Shelf Sensor', p2.category='Store IoT', p2.price=79.50MERGE (o:Order {orderId:'O-5001'})SET o.status='PAID', o.orderedAt=datetime('2026-09-08T16:30:00Z')MERGE (c)-[:PLACED]->(o)MERGE (o)-[:CONTAINS {quantity:1}]->(p1)MERGE (o)-[:CONTAINS {quantity:2}]->(p2);
CYPHER 25RETURN apoc.version() AS apocVersion;SHOW PROCEDURES YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;SHOW FUNCTIONS YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;
Expected evidence: apoc.version() should report the
installed Core version and the filtered
SHOW commands should reveal the
functions/procedures actually available. Do not infer Extended,
file access or unrestricted execution from the presence of one
APOC function.
7. Production judgment
| Decision surface | Questions before adopting APOC |
|---|---|
| Correctness | Does APOC change transactional scope, row cardinality or ordering semantics? |
| Performance | Does the server-side helper reduce round trips, or merely hide expensive traversal/materialization? |
| Security | Does it need dynamic Cypher, file access, outbound URLs, unrestricted execution or admin-only procedures? |
| Operations | Is the exact server/APOC pair tested through upgrade, backup/restore and rollback? |
| Portability | Will the same procedure exist on Aura/another tier, or should the logic live in Cypher/application code? |
| Observability | Can failures, retries, procedure latency and external dependencies be traced without opaque server-side logic? |
Check your understanding
- Why is APOC version matching operational rather than cosmetic?
- Does installing APOC automatically permit filesystem import/export?
- Is APOC Extended supported under the same contract as Core?
- What does unrestricted procedure configuration change?
- What is the default decision when native Cypher already expresses the requirement clearly?
Review the answers
1. APOC relies on Neo4j internal APIs, so incompatible server/plugin lines can fail at load or runtime.
2. No. APOC file import/export is disabled by default and controlled separately.
3. No. Core is officially supported by Neo4j; Extended is community-maintained.
4. It grants selected procedures/functions full access beyond ordinary sandbox restrictions and expands risk.
5. Prefer native Cypher unless APOC provides a measured, justified capability that outweighs added coupling.
Summary and next step
APOC is an extension mechanism with a deployment and privilege boundary. Lesson 2 compares native Cypher with Core utilities for maps, collections, text cleanup and bounded path expansion.
Authoritative references
- Current Neo4j versions — Release/LTS snapshot used for this chapter.
- APOC Core 2026.07 documentation — Current officially supported APOC Core manual.
- APOC installation and compatibility — Matching Neo4j/APOC year-month lines, deployment and restart requirements.
- APOC introduction: Core vs Extended — Support boundary between officially supported Core and community-maintained Extended.
- APOC security guidelines — Allowlist/unrestricted execution, file/network and SSRF guidance.
- APOC configuration — apoc.conf location, file/HTTP/trigger-related settings and defaults.
- APOC procedures and functions — Current procedure/function catalog and Cypher 25 status.
- Neo4j Java Reference: extending Neo4j — Custom procedures, functions and server extension boundaries.