Chapter 12 · APOC, Procedures, Functions, Triggers-Like Workflows, and Extending Cypher

APOC Core: Procedures vs Functions, Installation/Availability, Configuration, and Security Boundaries

Install and verify APOC Core deliberately, separate supported Core from community Extended, and constrain extension privileges before using any convenience procedure.

Advanced140–180 minutesAPOC compatibility + security labNeo4j 2026.07.1 Community · Cypher 25APOC Core 2026.07.1 optionalLast reviewed: September 2026

Learning outcomes

AtlasMart has reached the point where developers want helpers for data cleanup, path expansion and JSON exchange. The risk is to treat “APOC” as one magic capability. In reality a function, a procedure, a server plugin, a filesystem permission and an outbound HTTP permission have different execution and security boundaries.

01

Distinguish Cypher functions from procedures by row-flow and side-effect semantics.

02

Install and verify the APOC Core release compatible with Neo4j 2026.07.1.

03

Separate APOC Core support from APOC Extended/community-managed components.

04

Explain procedure allowlisting/unrestricted execution and Community vs Enterprise privilege boundaries.

05

Keep file, HTTP and trigger-like capabilities disabled until a documented AtlasMart requirement justifies them.

Chapter 12 baseline · reviewed 9 September 2026

The mandatory lab continues Neo4j Community 2026.07.1, database neo4j, explicit CYPHER 25 for version-sensitive examples, container atlasmart-neo4j, authentication enabled, loopback HTTP/Bolt endpoints, and the AtlasMart identifiers/model built in Chapters 01–11. Neo4j 5.26.30 remains the LTS comparison line. This chapter adds APOC Core 2026.07.1 as an optional extension; APOC Extended is never required.

Evidence and privilege note

This generation environment does not run the Neo4j container, so no plugin load, procedure list, filesystem read/write, HTTP request, trigger execution or custom-JAR output is invented. The lab tells you exactly what to inspect. Community Edition lacks Enterprise RBAC/load privileges, so the free path emphasizes configuration minimization, loopback-only access, file/network denial by default, and application-level authorization boundaries.

1. Function, procedure and plugin are three different concepts

Concept How Cypher uses it Typical behavior Design implication
Function Inside an expression, e.g. RETURN apoc.version() Returns a value per row/expression Composes naturally with projection/filtering; should not be treated as an external workflow engine
Procedure CALL ... YIELD ... Can emit zero/many rows and may perform broader work depending on the procedure Scope, privileges, side effects and result cardinality need explicit review
Plugin/JAR Loaded into the Neo4j server JVM Provides procedures/functions/extensions Couples deployment and upgrade lifecycle to server compatibility

APOC Core is implemented as a server-side Java extension. Installing it changes the server process, not merely the client query text. That is why version matching, restart behavior and security configuration belong in the same lesson as syntax.

2. Current support and compatibility contract

Component 2026.07 status AtlasMart policy
Neo4j DBMS 2026.07.1 current line Pinned mandatory server baseline
APOC Core 2026.07.1; year/month must match Neo4j line Optional, officially supported library
APOC Extended Separate community-maintained project; not officially supported by Neo4j Do not make course labs depend on it
Cypher 25 APOC changes after 2025.06 target Cypher 25 Use CYPHER 25 and avoid deprecated APOC conveniences when native Cypher exists

Patch numbers do not have to match in the general compatibility rule, but this lab pins both server and Core to 2026.07.1 so the evidence is unambiguous.

3. Recreate the disposable container with APOC Core while preserving named data volumes

If your existing atlasmart-neo4j container was created without APOC, stop and recreate the container rather than editing a running server ad hoc. The Docker NEO4J_PLUGINS helper is documented as a development convenience, not a production deployment recommendation.

PowerShell · development-only container recreation
docker stop atlasmart-neo4jdocker rm atlasmart-neo4jdocker run -d `  --name atlasmart-neo4j `  -p 127.0.0.1:7474:7474 `  -p 127.0.0.1:7687:7687 `  -v atlasmart-neo4j-data:/data `  -v atlasmart-neo4j-logs:/logs `  -e NEO4J_AUTH=neo4j/atlasmart-course-2026 `  -e 'NEO4J_PLUGINS=["apoc"]' `  neo4j:2026.07.1
Production difference

For production, download the matching APOC Core JAR, verify provenance/checksum according to your supply-chain process, mount it into /plugins, and test the exact server/plugin pair before rollout. Do not rely on runtime plugin download as a production control plane.

Cypher · prove what actually loaded
CYPHER 25RETURN apoc.version() AS apocVersion;SHOW PROCEDURES YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;SHOW FUNCTIONS YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;

4. Load only what the workload needs

Control Default/current meaning Safer AtlasMart starting point
dbms.security.procedures.allowlist * loads procedures/functions If you operate a hardened server, narrow to required names after testing
dbms.security.procedures.unrestricted Empty by default Keep empty unless a documented procedure truly needs unrestricted internals
Enterprise execute/load privileges Fine-grained RBAC, execute/boosted/load controls Not available in Community; do not pretend Community can reproduce RBAC evidence
File import/export Disabled in APOC by default Leave disabled in Lessons 1–2
Outbound HTTP Available to URL-capable procedures subject to platform/security controls Use only controlled endpoints; block internal/private metadata ranges in Community

“Unrestricted” is not a synonym for “installed.” It lets designated extensions bypass normal sandbox restrictions and is therefore a much stronger security decision. Likewise, boosted procedure execution in Enterprise can bypass ordinary user privileges; it should never be granted broadly to convenience procedure families.

5. Deliberately wrong: apoc.* unrestricted because “APOC is trusted”

Trusting the publisher does not mean every procedure should run with elevated server powers. Some APOC procedures can execute dynamically supplied Cypher or access URLs/files. A broad unrestricted/boosted grant converts a small application requirement into a large attack surface. The repair is to identify the exact operation, prefer native Cypher where equivalent, load only the necessary extension set, and grant the minimum execution/filesystem/network capability.

Cypher · inspect before enabling
CYPHER 25CALL apoc.help('path') YIELD name, type, textRETURN name, type, textORDER BY name;SHOW PROCEDURES YIELD name, mode, adminWHERE name STARTS WITH 'apoc.'RETURN name, mode, adminORDER BY name;

6. Reproducible AtlasMart baseline

Cypher · deterministic fixture
CYPHER 25MERGE (c:Customer {customerId:'C-1001'})SET c.name='Mina Rahimi'MERGE (p1:Product {productId:'P-1001'})SET p1.name='Trail Camera', p1.category='Cameras', p1.price=129.90MERGE (p2:Product {productId:'P-2001'})SET p2.name='Smart Shelf Sensor', p2.category='Store IoT', p2.price=79.50MERGE (o:Order {orderId:'O-5001'})SET o.status='PAID', o.orderedAt=datetime('2026-09-08T16:30:00Z')MERGE (c)-[:PLACED]->(o)MERGE (o)-[:CONTAINS {quantity:1}]->(p1)MERGE (o)-[:CONTAINS {quantity:2}]->(p2);
Cypher · availability evidence
CYPHER 25RETURN apoc.version() AS apocVersion;SHOW PROCEDURES YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;SHOW FUNCTIONS YIELD name, descriptionWHERE name STARTS WITH 'apoc.'RETURN name, descriptionORDER BY nameLIMIT 20;

Expected evidence: apoc.version() should report the installed Core version and the filtered SHOW commands should reveal the functions/procedures actually available. Do not infer Extended, file access or unrestricted execution from the presence of one APOC function.

7. Production judgment

Decision surface Questions before adopting APOC
Correctness Does APOC change transactional scope, row cardinality or ordering semantics?
Performance Does the server-side helper reduce round trips, or merely hide expensive traversal/materialization?
Security Does it need dynamic Cypher, file access, outbound URLs, unrestricted execution or admin-only procedures?
Operations Is the exact server/APOC pair tested through upgrade, backup/restore and rollback?
Portability Will the same procedure exist on Aura/another tier, or should the logic live in Cypher/application code?
Observability Can failures, retries, procedure latency and external dependencies be traced without opaque server-side logic?

Check your understanding

  1. Why is APOC version matching operational rather than cosmetic?
  2. Does installing APOC automatically permit filesystem import/export?
  3. Is APOC Extended supported under the same contract as Core?
  4. What does unrestricted procedure configuration change?
  5. What is the default decision when native Cypher already expresses the requirement clearly?
Review the answers

1. APOC relies on Neo4j internal APIs, so incompatible server/plugin lines can fail at load or runtime.

2. No. APOC file import/export is disabled by default and controlled separately.

3. No. Core is officially supported by Neo4j; Extended is community-maintained.

4. It grants selected procedures/functions full access beyond ordinary sandbox restrictions and expands risk.

5. Prefer native Cypher unless APOC provides a measured, justified capability that outweighs added coupling.

Summary and next step

APOC is an extension mechanism with a deployment and privilege boundary. Lesson 2 compares native Cypher with Core utilities for maps, collections, text cleanup and bounded path expansion.

Authoritative references

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.