Montycat MCP - Shared Memory for AI Agents MCP Server
io.github.MontyGovernance/montycat-mcp
Persistent, searchable shared memory for AI agents with semantic recall and live updates.
What is the Montycat MCP - Shared Memory for AI Agents MCP server?
Montycat MCP is a self-hosted MCP server that provides persistent, searchable memory for AI agents. Multiple MCP clients (Claude, Cursor, Codex) read and write to the same memory store, enabling context and decisions to persist across sessions. It supports vector search, keyword search, and hybrid recall, all running locally on your machine.
Montycat MCP gives AI agents a shared memory system that survives between conversations. Store decisions, preferences, and project context once, and every agent you use can access it. The server runs locally with semantic search (find memories by meaning), keyword search (exact identifiers), and hybrid modes. Organize memories into scopes (private, team, shared) and watch for changes in real time.
How to install Montycat MCP - Shared Memory for AI Agents
Copy-paste configuration for popular MCP clients.
MONTYCAT_URIsecretOptional Montycat engine URI: montycat://user:password@host:port/store
MONTYCAT_TLSSet to true when connecting to a TLS-enabled remote Montycat engine
MONTYCAT_TLS_CERTIFICATE_PATHOptional PEM certificate path for exact TLS certificate pinning
MONTYCAT_TLS_VERIFYSet to true to verify TLS with the platform trust store
MONTYCAT_TLS_CERTIFICATE_FINGERPRINTOptional SHA-256 TLS certificate fingerprint
Tools & capabilities
Tools this server exposes to the agent.
montycat_remember— Store a single memory entrymontycat_remember_bulk— Store multiple memory entries at oncemontycat_update— Update an existing memory entrymontycat_forget— Delete a memory entrymontycat_semantic_search— Search memories by meaning using vector searchmontycat_recall— Retrieve memories by keyword, metadata, or exact keymontycat_list_memories— List all memories in a scope or keyspacemontycat_list_enforced_schemas— Inspect field names and data types for structured writesmontycat_await_memory_change— Wait for another agent to write a memory without pollingmontycat_list_keyspaces— List available memory namespacesmontycat_create_keyspace— Create a new memory namespacemontycat_remove_keyspace— Delete a memory namespace
Use cases
- Persist project decisions and context across multiple Claude/Cursor sessions so agents pick up where you left off
- Share team knowledge (design choices, database decisions, API patterns) across multiple AI agents working on the same codebase
- Search for past decisions by meaning (e.g., 'why did we choose PostgreSQL?') even if you don't remember exact wording
- Coordinate between multiple AI agents by having one agent write a memory and another wait for and react to that change
- Organize memories into private, team, and shared scopes for different collaboration contexts
Montycat MCP - Shared Memory for AI Agents MCP server FAQ
Montycat MCP is a self-hosted memory server for AI agents. It stores persistent, searchable memories that survive between chat sessions and are accessible to all your MCP clients (Claude, Cursor, Codex). Memories are recalled by meaning (vector search), keywords (BM25), or both.
Yes. Montycat MCP is open-source (MIT license) and self-hosted on your machine. There is no cloud service or subscription required.
Download the montycat-mcp.mcpb file from the latest GitHub release and drag it into Claude Desktop. No Python installation needed.
Point your client's stdio config at `uvx montycat-mcp` (requires Python 3.10+). For Cursor, use your MCP settings to add a new server with that command.
The local Montycat engine starts automatically with a default setup. If you point it to a remote engine, you provide a connection string with username and password (montycat://user:password@host:port/store).
Yes. Every MCP client connected to the same Montycat engine reads and writes to the same memory store. Use scopes (private, team, shared) to control visibility and organize memories by context.
README (reference)
Source of truth, from the repository.
Montycat MCP - Shared Memory for AI Agents
A self-hosted MCP server that gives AI agents persistent, searchable memory. Claude, Codex, Cursor, and any Model Context Protocol client write to one memory and read each other's.
<!-- mcp-name: io.github.MontyGovernance/montycat-mcp -->- Memory that survives the chat. Decisions, preferences, and project context carry into the next session.
- One memory, many agents. Every MCP client you use works from the same facts.
- Recall by meaning, keyword, or both. Vector search finds a memory when the wording differs, BM25 nails exact identifiers, and hybrid mode fuses the two. Exact-key and metadata lookup too.
- Yours. Server, engine, and embeddings run on your machine. No hosted memory service, no cloud embedding API.
Install
Claude Desktop — download
montycat-mcp.mcpb
and drag it into Claude Desktop. No Python needed. That link always serves the
current release; every release
also carries a version-named copy and a .sha256 to check it against.
Claude Code — install uv, then:
/plugin marketplace add MontyGovernance/montycat-mcp
/plugin install montycat-mcp@montygovernance
/mcp confirms the montycat server is connected.
Codex, Cursor, other MCP clients — point your client's stdio config at
uvx montycat-mcp (Python 3.10+). For Codex:
codex mcp add montycat -- uvx montycat-mcp
The engine
Memory lives in a Montycat Semantic engine. Montycat MCP starts a local one for you, so most people can stop reading here.
Point it at an engine you already run:
export MONTYCAT_URI="montycat://memory-agent:password@localhost:21210/memories"
export MONTYCAT_TLS=true # remote engines only
Or start one yourself with Docker:
docker run -d --name montycat -p 21210:21210 -p 21211:21211 \
-e MONTYCAT_SUPEROWNER=admin -e MONTYCAT_PASSWORD=change-me \
-v montycat_data:/var/lib/.montycat \
montygovernance/montycat:semantic
On Apple Silicon use the arm64-semantic tag instead — semantic is the amd64
image, and it crashes under emulation. Port 21211 carries live memory watches.
Use it
Talk to your agent normally; it picks the tool.
Remember that the team chose PostgreSQL for the billing service.
What did we decide about the billing database?
Save this to the shared
engineeringscope.
scope decides where a memory lives — alice for private, engineering for a
team, shared for common. It is a namespace, not a security boundary: for real
isolation, give each MCP server its own least-privilege Montycat credential.
Tools
| Need | Tools |
|---|---|
| Store | montycat_remember, montycat_remember_bulk, montycat_update, montycat_forget |
| Recall | montycat_semantic_search, montycat_recall, montycat_list_memories |
| Inspect schemas | montycat_list_enforced_schemas — check field names and data types before structured writes or filtered retrieval |
| Collaborate | montycat_await_memory_change — wait for another agent's write, no polling |
| Namespaces | montycat_list_keyspaces, montycat_create_keyspace, montycat_remove_keyspace |
| Admin | semantic index, snapshot, and policy tools — see the plugin guide |
Destructive tools are declared as such, so your client's confirmation prompts apply.
Configuration
| Variable | Purpose |
|---|---|
MONTYCAT_URI | Connection string: montycat://user:password@host:port/store |
MONTYCAT_TLS | true for a remote TLS engine |
MONTYCAT_TLS_VERIFY | Optional: true to verify with the platform trust store |
MONTYCAT_TLS_CERTIFICATE_PATH | Optional PEM certificate path for exact certificate pinning |
MONTYCAT_TLS_CERTIFICATE_FINGERPRINT | Optional SHA-256 certificate fingerprint as an alternative pin |
All three verification settings are optional. With only MONTYCAT_TLS=true,
MCP retains the historical encrypted-but-unverified behavior; with TLS unset or
false, existing plaintext configurations are unchanged.
| MONTYCAT_DEFAULT_KEYSPACE | Memory namespace; memory by default |
| MONTYCAT_SCOPE | Default scope when a call omits one |
| MONTYCAT_AUTO_PROVISION | Create a permitted scope on first use; true by default |
| MONTYCAT_AUTOSTART | off to require an already-running engine |
Compose setup and the full variable list: compose.yaml and the plugin guide.
More
Changelog · Privacy · Issues · Docs · Docker Hub
Existing MemoCat installs keep working: memocat-mcp, MEMOCAT_*, and
memocat:// are still supported. New setups should use the Montycat names.
MIT
Related MCP servers
One shared, persistent memory across AI agents and systems, with semantic recall and live updates.
View repository →
Mora AI
Codex guesses your brand voice. Mora AI gives it the real one: your catalogue and performance.

Submit and manage ZATCA-compliant Saudi e-invoices through Saudi VAT Pro.

io.github.Morous-Dev/engram-cc
Universal AI coding assistant memory — session handoff, SLM compression, and semantic retrieval.

Conducted MCP
Stateless advisor + validator for Conducted Development: kickoff, artifact validation, rule checks.
Travel eSIM catalog: search plans, check availability, and get exact quotes with checkout links.
