PluginBench
MCP Server
Active
Apache-2.0

io.github.n24q02m/mnemo-mcp MCP Server

io.github.n24q02m/mnemo-mcp

Persistent AI memory with hybrid search, knowledge graphs, and encrypted sync—open, free, unlimited.

What is the io.github.n24q02m/mnemo-mcp MCP server?

Mnemo MCP Server is a persistent memory system for AI agents that combines full-text and vector search via Reciprocal Rank Fusion, temporal knowledge graphs with entity resolution, and multi-machine sync with AES-256-GCM encryption. It captures typed memories (conversation, fact, preference, skill, task, decision), auto-archives by importance and recency, and supports LLM-driven compression and consolidation.

Mnemo gives AI agents long-term memory across conversations and machines. It uses hybrid retrieval (FTS5 + embeddings), importance scoring, temporal decay, and knowledge graphs to surface the most relevant memories. Features include zero-config local setup (SQLite + Fastretrieval), optional cloud reranking, multi-provider LLM dispatch, encrypted passport sync to Google Drive or S3, and plugin hooks for proactive memory capture.

How to install io.github.n24q02m/mnemo-mcp

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • API_KEYS
    secret

    Provider API keys (format: PROVIDER_API_KEY:key,...). Select models per task with EMBEDDING_MODELS / RERANK_MODELS / LLM_MODELS (CSV provider/model, order = litellm fallback); provider is inferred from the model prefix. Empty embedding/rerank chains select Fastretrieval local ONNX/GGUF models; configured cloud chains never silently fall back to local.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mnemo-mcp": {
      "command": "uvx",
      "args": [
        "mnemo-mcp"
      ],
      "env": {
        "API_KEYS": "<YOUR_API_KEYS>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • add_memory — Add a new memory to the store
  • search_memory — Search memories using hybrid retrieval (FTS + vector search with RRF and reranking)
  • list_memories — List all memories with optional filtering
  • update_memory — Update an existing memory
  • delete_memory — Delete a memory
  • export_memories — Export memories to JSONL format
  • import_memories — Import memories from JSONL format
  • memory_stats — Get statistics about stored memories
  • restore_memory — Restore an archived memory
  • archived_memories — List archived memories
  • consolidate_memories — LLM-driven consolidation of related memories
  • entity_search — Search the temporal knowledge graph by entity
  • entity_graph — Retrieve entity relationships and graph structure
  • history — Query memory history with time-travel via as_of parameter
  • config — Manage server configuration, sync setup, and passport import/export
  • help — Access documentation for memory and config tools

Use cases

  • Store and retrieve conversation context, facts, and preferences across multiple AI sessions without losing information
  • Build a knowledge graph of entities and relationships mentioned in conversations for smarter context retrieval
  • Sync memories across devices and machines using encrypted passport bundles with Google Drive or S3 backends
  • Compress older memories via LLM summarization to reduce token usage while retaining key facts
  • Automatically archive less-important memories and restore them when relevant, keeping active memory lean

io.github.n24q02m/mnemo-mcp MCP server FAQ

What is Mnemo MCP?

Mnemo is a persistent memory system for AI agents that combines hybrid search (full-text + vector), temporal knowledge graphs, importance scoring, and multi-machine sync. It runs locally on SQLite with zero external dependencies by default.

Is Mnemo free?

Yes. Mnemo is open-source (Apache-2.0) and free. Local embeddings and reranking use Fastretrieval's built-in Qwen3 model. Optional cloud providers (Jina, Gemini, OpenAI, Cohere) are pay-as-you-go.

How do I install Mnemo in Claude Code?

Run `/plugin marketplace add n24q02m/claude-plugins` then `/plugin install mnemo-mcp@n24q02m-plugins`. For Cursor/Windsurf, add the stdio config to `mcp.json`: `{"mnemo": {"command": "uvx", "args": ["mnemo-mcp"]}}`.

Does Mnemo require authentication?

No authentication is required to run locally. Multi-machine sync via Google Drive or S3 uses optional OAuth (bundled public client for Drive) or cloud credentials you provide.

What embedding and reranking models does Mnemo use by default?

Mnemo uses Fastretrieval's local Qwen3 ONNX embedding and reranking models—no API keys needed. You can optionally configure Jina, Gemini, OpenAI, or Cohere via `LLM_MODELS` and `RERANK_MODELS` environment variables.

Can I sync memories across machines?

Yes. Mnemo supports encrypted passport sync via Google Drive (bundled OAuth) or S3-compatible backends (R2, B2, MinIO). Sync uses AES-256-GCM encryption and Argon2id key derivation with delta-sync and last-write-wins conflict resolution.

README (reference)

Source of truth, from the repository.

Mnemo MCP Server

Renamed (2026-09-13): repo is now mnemo — CLI-first (mnemo command). PyPI package stays mnemo-mcp; MCP server remains a secondary surface.

mcp-name: io.github.n24q02m/mnemo-mcp

Persistent AI memory with hybrid search and embedded sync. Open, free, unlimited.

<!-- Badge Row 1: Status -->

Mode CI codecov PyPI License: Apache-2.0 SafeSkill 91/100

<!-- Badge Row 2: Tech -->

Python SQLite MCP semantic-release Renovate

<!-- BEGIN: AUTO-GENERATED-CROSS-PROMO --> <details> <summary><strong>Sister projects from n24q02m</strong> (click to expand)</summary>
ProjectTaglineTag
agent-chat-pluginPeer AI agents chat in a shared folder — no human relay, no orchestrator, wor...Tooling
better-code-review-graphKnowledge graph for token-efficient code reviews -- semantic search and call-...MCP
better-drive2-way Google Drive sync with .driveignore filter — rclone engine, Windows trayTooling
better-email-mcpIMAP/SMTP email for AI agents -- read, send, organize folders, and manage att...MCP
better-godot-mcpComposite MCP server for Godot Engine -- 17 composite tools for AI-assisted g...MCP
better-notion-mcpMarkdown-first Notion for AI agents -- pages, databases, blocks, and comments...MCP
better-semantic-releaseDrop-in python-semantic-release fork with built-in release-safety guards (orp...Tooling
better-telegram-mcpTelegram for AI agents -- messages, chats, media, and contacts across both bo...MCP
better-workspace-mcpGoogle Workspace MCP server (Docs/Drive/Calendar/Gmail/Sheets/Slides/Tasks/Ch...MCP
claude-pluginsClaude Code plugin marketplace for the n24q02m MCP servers -- install web sea...Marketplace
imagine-mcpImage and video understanding + generation for AI agents -- across Gemini, Op...MCP
jules-task-archiverChrome Extension for bulk operations on Jules tasks via batchexecute API -- a...Tooling
mcp-coreShared foundation for building MCP servers -- Streamable HTTP transport, OAut...MCP
mnemo-mcpPersistent AI memory with hybrid search and embedded sync. Open, free, unlimi...MCP
fastretrievalMulti-model retrieval runtime for ONNX/GGUF embeddings and rerankingLibrary
skretSecrets without the server.CLI
tacetA self-distilling neuro-symbolic cascade that amortises LLM cost across knowl...Tooling
web-coreShared web infrastructure package for search, scraping, HTTP security, and st...Library
wet-mcpOpen-source MCP server for AI agents: web search, content extraction, and lib...MCP
</details> <!-- END: AUTO-GENERATED-CROSS-PROMO -->

Table of contents

<a href="https://glama.ai/mcp/servers/n24q02m/mnemo-mcp"> <img width="380" height="200" src="https://glama.ai/mcp/servers/n24q02m/mnemo-mcp/badge" alt="Mnemo MCP server" /> </a>

Roadmap (current = Phase 3 / v2.x)

PhaseVersionStatusHighlights
Phase 1v1.xShippedTyped memory(action="capture") (6 context_types + dedup) -- RRF (k=60) hybrid fusion + cross-encoder rerank + temporal decay -- importance x recency archive policy + restore -- Alembic migrations -- multi-provider LLM dispatch -- plugin trinity (recall-context + memory-commit skills, SessionStart + opt-in PostToolUse hooks)
Phase 2v1.x+1ShippedLLM-driven compression of older memories + Passport sync (encrypted import/export bundle for cross-machine bootstrap) -- AES-256-GCM + Argon2id, S3 / R2 / B2 / MinIO + GDrive backends, delta-sync with LWW per row
Phase 3v2.0.0Shipped (BREAKING)Temporal knowledge graph -- bitemporal valid_from / valid_to columns -- entity resolution via embedding KNN -- entity_search / entity_graph / history actions -- KG-aware passport bundle sections -- KG_AUTO_ENABLED opt-in auto-extract on capture

Features

  • Hybrid retrieval -- FTS5 + vector search (sqlite-vec locally, Vectorize on Cloudflare), fused via Reciprocal Rank Fusion (k=60), then re-ranked by a configurable rerank chain (RERANK_MODELS, order = litellm fallback; empty -> Fastretrieval's local Qwen3 reranker) with temporal decay and importance boost
  • Typed capture -- memory(action="capture") with 6 context_types (conversation/fact/preference/skill/task/decision), embedding-based dedup, and a configurable LLM chain (LLM_MODELS, order = litellm fallback)
  • Knowledge graph -- Automatic entity extraction and relation tracking; top results boosted by graph proximity
  • Importance scoring + archive policy -- LLM-scored 0.0-1.0 importance; soft-archive when recency_factor * (1 - importance) > 1.0; restore action available
  • Auto-archive trigger -- Background sweep every Nth capture (default 100) -- no cron required
  • STM-to-LTM consolidation -- LLM summarization of related memories in a category
  • Duplicate detection -- Warns before adding semantically similar memories
  • Zero config -- Fastretrieval's built-in local registry resolves Qwen3 ONNX embedding + reranking, no API keys needed. Optional cloud providers (Jina AI, Gemini, OpenAI, Cohere)
  • Multi-machine sync -- JSONL-based merge sync via Google Drive (bundled Desktop OAuth public client)
  • Plugin trinity -- Ships /recall-context + /memory-commit skills and SessionStart + opt-in PostToolUse hooks (see docs/ARCHITECTURE.md)
  • Proactive memory -- Tool descriptions and skills guide AI to save preferences, decisions, facts at the right moment
  • LLM compression -- Per-turn compression via the multi-provider dispatcher targets ~3x token reduction at >=0.9 fact retention; graceful skip when no provider configured (see docs/compression.md)
  • Encrypted passport sync -- AES-256-GCM bundles + Argon2id KDF, S3 (R2 / B2 / MinIO) and Google Drive backends, delta-sync with last-write-wins per row (see docs/passport.md). Bootstrap via the passport-bootstrap skill.
  • Temporal knowledge graph -- Bitemporal columns (valid_from / valid_to / superseded_by) on every memory + entity-resolution dedup (embedding KNN at default 0.85 cosine threshold) + audit trail (memory_audit table with prev/new state hashes) + new actions (entity_search / entity_graph / history) + opt-in KG_AUTO_ENABLED auto-extract on capture. BREAKING for clients that called memory.get expecting historical-inclusive results: pass as_of for time-travel; default now filters to current-state (valid_to IS NULL).

Quick install

# Method 1 (default): plugin install via Claude Code
/plugin marketplace add n24q02m/claude-plugins
/plugin install mnemo-mcp@n24q02m-plugins

# Method 2 (CLI): direct uvx invocation
claude mcp add mnemo -- uvx mnemo-mcp

# Method 3 (remote): point a client at an HTTP deployment
claude mcp add --transport http mnemo https://<your-host>/mcp

Install matrix (stdio unless noted; see the Setup page for full steps):

ClientInstall
Claude Code (plugin)/plugin marketplace add n24q02m/claude-plugins then /plugin install mnemo-mcp@n24q02m-plugins
Claude Code (stdio)claude mcp add mnemo -- uvx mnemo-mcp
Codexregister stdio command uvx mnemo-mcp under mcp_servers in ~/.codex/config.toml
Gemini CLIadd the mcpServers JSON below to ~/.gemini/settings.json
Cursor / Windsurfadd the mcpServers JSON below via the client's MCP settings (mcp.json)
Any client (HTTP self-host)point the client at https://<your-host>/mcp (Streamable HTTP, OAuth-gated)

Example stdio config (zero-config local defaults):

{
  "mcpServers": {
    "mnemo": {
      "command": "uvx",
      "args": ["mnemo-mcp"]
    }
  }
}

Comparison vs. peers

Featuremnemo-mcpMem0LettaOpenMemory
Hybrid retrieval (FTS + vec)yes (FTS5 + RRF; sqlite-vec local / Vectorize on Cloudflare)yespartialyes
Cross-encoder rerank chainyes (Fastretrieval Qwen3 local + Jina + Cohere)partial (Cohere only)nono
Temporal decay scoringyes (exp half-life)nonono
Importance boost in rankyes (LLM 0.0-1.0)nonono
Soft-archive + restore policyyes (importance x recency)nonono
Self-hostable (single SQLite file)yes (zero ext deps)partial (cloud-first)yes (Postgres)yes (Postgres + Qdrant)
Multi-provider LLM dispatchyes (LLM_MODELS chain, any litellm provider)partialyespartial
Plugin trinity (skills + hooks)yes (recall-context + memory-commit)n/an/an/a
Multi-machine syncyes (GDrive bundled OAuth)yes (cloud)n/an/a
E2E-encrypted passport syncyes (AES-256-GCM + Argon2id, S3 + GDrive)nonono
LLM compression on captureyes (multi-provider, ~3x at >=0.90 retention)nonono
Backend-pluggable sync architectureyes (S3 / R2 / B2 / MinIO + GDrive)nonono
Bitemporal valid_from / valid_to queriesyes (as_of time-travel)nopartial (events only)no
Entity resolution via embedding KNNyes (cosine threshold tunable)nonono
Audit trail with state hashesyes (memory_audit table)nonono

Status

2026-05-02 -- Architecture stabilization update

Past months saw significant churn around credential handling and the daemon-bridge auto-spawn pattern. This caused multi-process races, browser tab spam, and inconsistent setup UX across plugins. The architecture is now stable: 2 clean modes (stdio + HTTP), no daemon-bridge layer, no auto-spawn from stdio.

Apologies for the instability period. If you encountered issues with prior versions, please update to the latest release and follow the current setup docs -- most prior workarounds are no longer needed.

Related plugins from the same author:

All plugins share the same architecture -- install once, learn pattern transfers.

Documentation

Full docs at mcp.n24q02m.com/servers/mnemo-mcp/setup/:

  • Setup -- install methods for Claude Code, Codex, Gemini CLI, Cursor, Windsurf, mcp.json
  • Modes overview -- stdio / local-relay / remote-relay / remote-oauth
  • Multi-user setup -- per-JWT-sub credential model

Install with AI agent -- paste this to your AI coding agent:

Install MCP server mnemo-mcp following the steps at https://raw.githubusercontent.com/n24q02m/claude-plugins/main/plugins/mnemo-mcp/setup-with-agent.md

Smithery

mnemo-mcp is packaged for Smithery -- install or run it straight from the registry. It starts over stdio via uvx mnemo-mcp with no configuration required to launch; credentials are configured at runtime through the server's own config flow (see Documentation). The published start command lives in smithery.yaml.

Tools

15 MCP tools, 17 memory actions. The memory surface is exposed both as 11 specialized single-purpose tools and a deprecated legacy memory dispatcher (same actions), plus config, help, and config__open_relay:

ToolActionsDescription
add_memory, search_memory, list_memories, update_memory, delete_memory, export_memories, import_memories, memory_stats, restore_memory, archived_memories, consolidate_memories(one action each)Specialized single-purpose memory tools -- the recommended surface
memory (legacy dispatcher, DEPRECATED -- use the granular tools above instead; will be removed in a future release)add, capture, search, list, update, delete, export, import, stats, restore, archived, archive_now, consolidate, compress, entity_search, entity_graph, historyCore CRUD + typed capture (6 context_types) + hybrid search (RRF + rerank + temporal decay) + import/export + soft-archive + restore + on-demand archive sweep + LLM consolidation + LLM compression + temporal KG (entity search / graph / history)
configstatus, sync, set, warmup, setup_sync, setup_status, setup_start, setup_skip, setup_reset, setup_complete, setup_relay, sync_now, export_passport, import_passportServer status, trigger sync, update settings, pre-download embedding model, authenticate sync provider, manage HTTP setup form lifecycle, passport export/import
helptopic="memory" or topic="config"Full documentation for any tool
config__open_relay(HTTP relay mode)Open the zero-config relay setup form (registered via mcp-core)

Plugin trinity (Claude Code marketplace install):

ComponentTriggerPurpose
mnemo:recall-context skillsession start, before significant decisions, "what do I know about X?"Pulls cwd / topic-relevant memories with context_type filtering
mnemo:memory-commit skill"remember this" / "save this" / "ghi nho" / "luu lai"Typed manual capture with context_type decision tree
mnemo:knowledge-audit skillperiodic / "audit memory"Find duplicates, contradictions, stale entries; consolidate
mnemo:session-handoff skillend of sessionCapture decisions / preferences / corrections / conventions / open questions
mnemo:temporal-query skill"as of" / "back in" / "history of" / "what did I think then"Point-in-time snapshots via action="as_of" and version-chain tracing via superseded_by
SessionStart hookevery session initNon-blocking nudge to invoke recall-context
PostToolUse hook (opt-in)CAPTURE_AUTO_ENABLED=trueHint memory-commit after Write/Edit of CLAUDE.md / AGENTS.md / ARCHITECTURE.md / docs/*.md

MCP Resources

URIDescription
mnemo://statsDatabase statistics and server status

MCP Prompts

PromptParametersDescription
save_summarysummaryGenerate prompt to save a conversation summary as memory
recall_contexttopicGenerate prompt to recall relevant memories about a topic

Security

  • Graceful fallbacks -- Cloud → Local embedding, no cross-mode fallback
  • Sync token security -- OAuth tokens stored at ~/.mnemo-mcp/tokens/ with 600 permissions
  • Input validation -- Sync provider, folder, remote validated against allowlists
  • Error sanitization -- No credentials in error messages

Build from Source

git clone https://github.com/n24q02m/mnemo.git
cd mnemo-mcp
uv sync
uv run mnemo-mcp

CLI

The package ships two distinct console scripts:

  • mnemo -- CLI-first memory surface (primary for scripts/agents; it never starts a server): capture, recall, reflect, fetch, and the standing-* family operate directly on a SQLite memory DB. mnemo-pilot is a legacy alias of the same entry point.
  • mnemo-mcp -- the MCP server plus one-shot operator subcommands. A bare invocation (or any ---prefixed flag) starts the server; a leading subcommand runs an action and exits.

CLI-first memory surface (mnemo; every subcommand takes --db <path>, prints a JSON envelope, and exits with a taxonomy-mapped code):

uvx --from mnemo-mcp mnemo recall --db ./mem.db "package naming" --k 3   # try without a persistent install

mnemo capture --db ./mem.db "keep PyPI name mnemo-mcp; repo is mnemo" --tags decision --category decision
mnemo recall --db ./mem.db "release ladder" --k 5        # search a subject's memories
mnemo reflect --db ./mem.db "why keep the alias?" --k 5  # bounded cited reflect over retrieval
mnemo fetch --db ./mem.db <memory_id>                    # fetch one memory by id
mnemo standing-refresh --db ./mem.db onboarding "how do releases cut?" --k 5   # materialize a standing page
mnemo standing-read --db ./mem.db onboarding             # cheap read with staleness info

Server operator CLI (mnemo-mcp):

mnemo-mcp                       # start the stdio server (default transport)
mnemo-mcp --http                # start the Streamable HTTP server
                                # (also via MCP_TRANSPORT=http or TRANSPORT_MODE=http)

mnemo-mcp auth google           # authorize Google Drive sync via OAuth
mnemo-mcp auth google --client-id <ID> --client-secret <SECRET>   # bring-your-own OAuth client
mnemo-mcp logout                # clear the local Google Drive sync token
mnemo-mcp warmup                # pre-download Fastretrieval-managed local embedding + rerank models

mnemo-mcp config status         # report whether stored config exists
mnemo-mcp config delete --yes   # delete the stored (encrypted) config
mnemo-mcp relay status          # show the active browser-setup relay session
mnemo-mcp relay open            # open the relay setup form in a browser
mnemo-mcp relay reset           # clear relay session state
mnemo-mcp doctor                # environment diagnostics (Python, backend, store, mode)
SubcommandPurpose
auth <provider>Authorize a sync credential provider (currently google); --client-id / --client-secret supply a bring-your-own OAuth client
warmupPre-download the Fastretrieval-managed local Qwen3 ONNX embedding + rerank models so first use works offline
config status | config delete [--yes]Inspect or remove the stored encrypted configuration
relay status | relay open | relay resetInspect, open, or clear the zero-config browser setup session
doctorReport Python version, credential backend, store dir, config, relay session, and storage mode

Remote (HTTP mode)

Deployed over HTTP, mnemo speaks Streamable HTTP transport and is OAuth-gated. Point any MCP client that supports remote HTTP + OAuth at https://<your-host>/mcp and authenticate on first connect; each authenticated user gets an isolated per-user credential store (see Trust Model). To stand up an instance, see Deploy to Cloudflare.

Public OCI image publication is discontinued. Existing historical registry tags remain untouched; new container deployments build from source or use the Cloudflare-managed registry.

Deploy to Cloudflare

Deploy to Cloudflare

Run your own mnemo instance serverless on Cloudflare (Containers + D1 + Vectorize + KV).

Paused 2026-09-13 (maintained instance only): the CF deploy token was removed from the account as off-manifest (process violation), so the CD deploy-cf job no-ops behind the CF_DEPLOY_ENABLED repo variable. The maintained instance freezes at its last deployed release until a token is re-established via the documented process and the variable is set to true. Self-hosting on your own account (below) is unaffected.

Prerequisites: a Cloudflare account on the Workers Paid plan — required for Containers, D1, and Vectorize (the Cloudflare free tier does not include them) — and the wrangler CLI.

  1. git clone https://github.com/n24q02m/mnemo && cd mnemo-mcp
  2. wrangler login
  3. Provision the storage bindings mnemo uses -- the memories database, the embedding index, and the encrypted credential store:
    wrangler d1 create mnemo-memories
    wrangler vectorize create mnemo-memory-vectors-1536 --dimensions 1536 --metric cosine
    wrangler kv namespace create mnemo-kv
    
    Paste the returned D1 database ID and KV namespace ID into wrangler.jsonc (the Vectorize index binds by name, so no ID is needed), then create the memories schema (tables, indexes, and the FTS5 full-text index) in the database you just made:
    wrangler d1 migrations apply mnemo-memories --remote
    
    The SQL lives in migrations/0001_init.sql, and the D1 binding in wrangler.jsonc points at that folder via migrations_dir: "migrations". Full-text search uses FTS5, which D1 ships; vector similarity is served by Vectorize rather than by an in-database extension, because D1 cannot load one.
  4. Build the HTTP container from this checkout and push it to your Cloudflare managed registry (CF Containers cannot pull from external registries directly), then set <YOUR_ACCOUNT_ID> in wrangler.jsonc:
    docker build --target http -t mnemo-mcp:local .
    wrangler containers push mnemo-mcp:local
    # set image to registry.cloudflare.com/<YOUR_ACCOUNT_ID>/mnemo-mcp:local
    
  5. Set <YOUR_PUBLIC_URL> (e.g. https://mnemo.example.com) and <YOUR_WORKER_DOMAIN> (e.g. mnemo.example.com) in wrangler.jsonc, then set the secrets:
    wrangler secret put CREDENTIAL_SECRET              # per-user vault key (encrypts the cf-kv credential store)
    wrangler secret put MCP_RELAY_PASSWORD             # shared password gating the browser setup form
    wrangler secret put MCP_DCR_SERVER_SECRET          # required once PUBLIC_URL is set (multi-user, per-JWT-sub)
    
  6. wrangler deploy and complete setup in the browser relay form at your Worker domain. Save each subject's models, endpoints and provider keys there, not in Worker environment variables. The managed route uses Minimax-free completion and paid Cohere embedding/reranking through Cloudflare AI Gateway -- obtain the required budget authorization before exercising the paid tiers (Provider Spend Gate); see the per-task configuration. Storage maps to Cloudflare via MCP_STORAGE_BACKEND=cf-kv (credentials / tokens, encrypted), MEMORY_DB_BACKEND=cf-d1 (the memories database + FTS5 full-text; unset or sqlite keeps the local SQLite file at DB_PATH), and Vectorize (embeddings, cosine). Cloud embedding, reranking and completion resolve per authenticated subject. Remote startup does not probe shared provider credentials or download local Fastretrieval models. Missing subject configuration never selects a process-wide provider/model fallback.

Authority & Sync Boundary

On Cloudflare deployments, Cloudflare D1 + Vectorize + KV is the sole production authority:

  • D1 (MEMORY_DB_BACKEND=cf-d1): Authoritative storage for memory rows, metadata, bitemporal valid ranges, and FTS5 search.
  • Vectorize (MCP_VECTORIZE_IDX): Dense vector index for semantic similarity search.
  • KV (MCP_STORAGE_BACKEND=cf-kv): Encrypted per-user credential and session store.
  • Sync boundary: MEMORY_DB_BACKEND=cf-d1 disables Google Drive OAuth and all external sync paths even if SYNC_ENABLED is toggled on or stale S3/Google settings remain. SYNC_ENABLED=false independently disables sync on non-CF deployments.
  • Local & self-host bootstrap: Local stdio (~/.mnemo-mcp/memories.db) and self-hosted instances retain optional passport sync (Google Drive Device Code OAuth or S3/R2/B2) for workstation migration.

Deployment (maintained instance)

Every tagged release deploys automatically: the CD deploy-cf job checks out the released tag, builds the http-slim image, pushes it to the Cloudflare-managed registry as immutable :<release-tag>, deploys the Worker, and gates on a canary health check -- a release is live at exactly its own version. A beta dispatch redeploys the beta; a stable dispatch is maintainer-gated. Manual wrangler deploy against the maintained instance is not permitted: it would break the release-tag ↔ live-image correspondence. Self-hosting on your own Cloudflare account (the button above) is unaffected.

Trust Model

This plugin implements TC-Local (machine-bound, single trust principal). The mode/storage/encryption breakdown below is the full classification.

ModeStorageEncryptionWho can read your data?
stdio (default)~/.mnemo-mcp/config.jsonAES-GCM, machine-bound keyOnly your OS user (file perm 0600)
HTTP self-hostSame as stdioSameOnly you (admin = user)
HTTP multi-user remote (PUBLIC_URL)Per-JWT-sub credential storeAES-GCMOnly the authenticated user (per-sub isolation)

Workspace username (HTTP setup form)

The browser setup form has an optional workspace username field. Entering the same username always lands you in the same per-sub bucket, so your credentials and memories stay reachable across a re-authorization and across devices, instead of being tied to the one-off subject minted for each /authorize round-trip. Leaving it blank keeps the previous per-authorize behaviour.

Trust boundary: when the form is gated by a shared MCP_RELAY_PASSWORD, the username is a partition key, not a secret -- anyone who knows that password can type any username and reach that bucket. That is fine for a trusted group; an untrusted multi-tenant deployment needs a per-user secret or delegated OAuth instead.

One-time migration: existing users must re-enter their credentials once after this change. Nothing is deleted; credentials stored under the old random subject are simply no longer addressed.

License

Apache-2.0 -- See LICENSE.

Related MCP servers

Open-source MCP server for web search, content extraction, and library documentation indexing.

16
Python
Apache-2.0
View repository →

Token-efficient code review knowledge graph with semantic search and call-graph resolution.

66
Python
Apache-2.0
View repository →

IMAP/SMTP email for AI agents — read, send, organize folders, and manage attachments across multiple accounts with auto-discovery.

30
TypeScript
Apache-2.0
View repository →

AI-assisted Godot game development with 17 composite tools for scene, script, and asset management.

34
TypeScript
Apache-2.0
View repository →

Read-only Lunch Money accounts, transactions, categories and budgets. Unofficial connector.

0
TypeScript
MIT
View repository →
R3r3 logo

r3

Active

Local Redis memory MCP for AI apps with hybrid caching and optional Mem0 cloud backup.

2
TypeScript
MIT
View repository →