Governed memory for AI agents. Memory with receipts. Local, plain files, zero network calls.
MCP Server: ai.magnemo/magnemo
The ai.magnemo/magnemo MCP server provides “governed memory for AI agents.” It describes memory that includes receipts and is stored as local, plain files. The server is designed for zero network calls, emphasizing filesystem-based operation.
🛠️ Key Features
Governed memory for AI agents
Memory with receipts
Local storage as plain files
Zero network calls
🚀 Use Cases
Persisting agent memory with auditability (“receipts”)
Running agent setups where local, file-based storage is required
Agent memory management in environments without network access
⚡ Developer Benefits
No network dependency (zero network calls)
Predictable local persistence using plain files
Receipt-based memory to support traceability
⚠️ Limitations
The provided description specifies only local, plain-file storage and zero network calls; no additional capabilities are stated.
Tools gave your agent hands. MCP gave it a nervous system. Magnemo gives it a brain.
Magnemo is a memory for your AI, kept on your computer in plain files. Your AI writes down what it learns as it works; nothing becomes memory until you approve it, and every memory shows who wrote it and who approved it.
Open Claude Code in any of your project folders, and paste this. (Its magnemo mount step writes .mcp.json, the file Claude Code reads. In Cursor, Windsurf or another client, use the block for your client under "Install in your client".)
text
Set up Magnemo in this project:
1. Install it: pip install magnemo. It needs Python 3.11 or newer. If pip can't find it, install uv (curl -LsSf https://astral.sh/uv/install.sh | sh) and then run: uv tool install magnemo
2. Initialize the vault: magnemo init
3. Register the MCP server: run magnemo mount — it writes this project's MCP config itself.
4. Verify: run magnemo doctor and confirm everything passes.
5. Stage the first memory: one line on what this project is, using magnemo stage. Show me the note id.
6. Then tell me the exact command to approve it. After I approve, run magnemo bootpack and tell me what you remember — then remind me to restart you, so the memory mounts for every session after this one.
If anything fails, show me what went wrong and fix it if you can.
You'll know it worked — your AI will tell you who it is now.
For builders. Magnemo is an MCP server with four tools — retrieve, stage,
bootpack, handoff — and a CLI for your side: review, promote, reject.
It runs on your machine, in plain markdown files you own. The package imports no network
module (magnemo doctor scans for one on every run); the only traffic is git push to a
backup destination, if you add one. Every promotion is recorded with who wrote the entry,
the name given for the yes, when, and through which gate. Trust is computed from that
record, never asserted. It mounts beside any memory you already
run (a folder of notes, Obsidian, a RAG stack). Python 3.11+, zero dependencies,
Apache-2.0.
Fresh vault? THE CHARTER section will say it isn't promoted yet — that is the
governance speaking: Magnemo never fabricates canon. Stage a charter, review it,
promote it, and every boot thereafter serves it back verbatim.
(magnemo not found after install? pip's script folder isn't on PATH —
python3 -m magnemo always works.)
Open beta — read KNOWN_LIMITS.md before trusting it with anything you can't lose. Honest caveats, no fine print.
Install in your client
One server, said ten ways. Every block below is the same thing: uvx magnemo-mcp with MAGNEMO_VAULT pointing at
the folder your memory lives in (make one with magnemo init ./vault). Tested on this Mac where it says so;
the rest is from each client's own docs and marked untested — corrections welcome, open an issue.
Claude Code — tested: a Claude Code session mounts the server, lists the four tools and calls them (last run
Oct 4, 2026: Claude Code 2.1.289, magnemo-mcp 0.6.7).
bash
claude mcp add magnemo -e MAGNEMO_VAULT=/absolute/path/to/vault -- uvx magnemo-mcp
(claude mcp list shows magnemo … ✔ Connected. Add -s project to write it into the repo's .mcp.json for your team.)
Only have the desktop app? claude may not be a command in your shell. On a Mac the app keeps its own copy at
~/Library/Application Support/Claude/claude-code/<version>/claude.app/Contents/MacOS/claude; run that in place of claude.
Claude Desktop — untested end to end here. Download the extension from the latest release —
magnemo-0.6.7.mcpb — and open it; Claude Desktop asks for the
vault folder and does the rest. (The connectors directory listing follows once it is accepted.)
Cursor — untested here (not installed on this Mac); the link and the block follow Cursor's docs.
Or ~/.cursor/mcp.json (or .cursor/mcp.json in the project):
After the install, the loop is the same everywhere: your agent writes to staging, you review.
bash
magnemo yes# promote the top of the queue (yes <id-fragment> · yes --all)
magnemo no <id> --reason "…"# reject one — the reason is required; rejections teach
magnemo review # the interactive queue, when you want to read first
magnemo doctor # python, vault, config, ledger, and the mount — scans the package for network modules too
Anything that speaks MCP over stdio mounts the same way. The remote door (ChatGPT and hosted clients) is on its way in 0.7.0.
Agents draft, people keep — the one rule
Agents get four MCP tools. Promotion is not one of them.
The CLI is the other door, and magnemo yes does not yet check who runs it: read KNOWN_LIMITS.md first.
Actor
Door
Can do
Agents
MCP server (stdio)
retrieve canonical memory · stage → staging only, the one write tool · bootpack on wake · handoff at the boundary
You
CLI + git (any editor)
review the queue · promote / reject · edit anything · own everything
The vault
code
vault/
dev/ knowledge/ playbooks/ decisions/ debt/ ← example: a dev team's partition
ops/ knowledge/ playbooks/ clients/ decisions/ style/ ← example: an ops team's partition
shared/ tickets/ changelog/ ← interop bus (gated)
_staging/ agent writes await review here
_index/ machine-managed
_ledger/ trust_ledger.jsonl — append-only, never forgets
Every note is markdown with provenance frontmatter (author, written, source,
status, reviewed_by, supersedes, strength). Provenance is the file format.
Privacy
Your memory lives on your computer, in plain files you can open. No network calls of its own. Add a backup remote and it pushes there, nowhere else.
The precise version: the package imports no network module, and magnemo doctor scans for one every time it runs. If you add a backup destination, the engine runs git push to it. The full page: https://magnemo.ai/privacy
Guarantees (Phase 1 — Governed Recall)
Through the MCP server, agent writes NEVER reach canonical stores directly — staging only, always.
Search returns canonical (promoted) notes only. Staged notes are not searched. The boot pack shows staged material marked as staged: the titles of open threads and of the top staged notes, and the last handoff's cut line with a pointer to its note.
Partition walls enforced per agent (MAGNEMO_PARTITIONS); cross-partition = DENIED.
Supersession is explicit: old notes archive with a forward link. Nothing deletes.
Rejections are kept and recorded — rejections teach.
Every promote/reject lands in the append-only Trust Ledger with actor + reason.