Local-first intent and provenance for Codex, Claude Code, Cursor, Gemini CLI, and MCP agents.
MCP Server: io.github.hacksurvivor/pathmark
This MCP server provides local-first intent and provenance for Codex, Claude Code, Cursor, Gemini CLI, and MCP agents. Its scope centers on carrying intent across agents while avoiding the conversion of stale code facts into hidden memory, using the project’s published TypeScript-oriented tooling and npm package.
🛠️ Key Features
Local-first intent
Provenance support
Agent-memory to carry intent across agents
Avoids hidden memory from stale code facts
🚀 Use Cases
Using Codex alongside other agent tools
Keeping intent consistent across Claude Code, Cursor, and Gemini CLI
Integrating with MCP agents while preserving provenance
Supporting workflows involving memory and agent-memory semantics
⚡ Developer Benefits
Aligns “intent” across multiple agent environments
Reduces reliance on hidden memory derived from code facts
Fits into an MCP server setup
⚠️ Limitations
Described functionality is focused on intent/provenance and agent-memory; no additional tools or interfaces are specified.
Pathmark v0.1.17 stops Claude Code from gating every memory lookup:
pathmark setup claude-code --apply-permissions adds allow rules for Pathmark's ten local read-only tools, so recall and search run without a permission prompt, and in auto mode without a safety-classifier round-trip that can fail transiently;
it backs up ~/.claude/settings.json, adds only missing rules, keeps every other setting, and never rewrites a file it cannot parse;
the allow list is tested against the tools' own readOnlyHint/openWorldHint annotations, so anything that writes, deletes, or may call an external model always keeps its prompt.
See the v0.1.17 release notes or the complete changelog. The npm badge above always shows the currently published version.
Pathmark gives Codex, Claude Code, opencode, Gemini CLI, Cursor, and any MCP-capable harness one local intent and provenance layer. Save decisions, constraints, preferences, and approved conclusions once. Use them from the next agent without pasting a recap.
Code remembers implementation. Pathmark remembers intent. Repository code, architecture, tests, CI, and intentional agent instructions remain authoritative for how the software works. Raw sessions are searchable evidence, not automatically trusted truth.
Your context stays on disk at ~/.pathmark/memory/memory.jsonl. You do not need an account, hosted database, API key, or vendor backend to start.
OpenAI Build Week 2026
Pathmark is a Developer Tools submission for OpenAI Build Week 2026. The project existed before the challenge, so the submission is deliberately scoped to the meaningful extension built after the submission period opened on July 13, 2026.
During the eligible period, Codex with GPT-5.6 helped audit and extend Pathmark from a working local memory layer into safer long-running developer infrastructure:
fixed a reproduced multi-process SQLite index race;
added revision history, superseding, expiration, retention, diagnostics, backup, compaction, and preview-first hard purge;
added namespace-scoped reads and writes plus default secret redaction;
added scoped import/export, optional AES-256-GCM portable exports, local hybrid reranking, and portable harness ingestion;
hardened CI and npm delivery with required CodeQL and dependency review, immutable Action pins, protected tags, OpenSSF analysis, and SLSA provenance.
The primary Codex session for this work is 019f5fc3-d7e6-7b41-8a30-d161c90b98fb. The qualifying release range is v0.1.6 through v0.1.7; the pre-challenge baseline is commit 4c0e87dfdbd2ba4c643abd8b887cc228bdb08b73.
See the Build Week implementation record for the before/after boundary, commit evidence, Codex collaboration details, and a fast judge test.
Why Pathmark
You do not work in one tool. You ask Codex to patch, Claude Code to review, opencode to clean up, and Gemini CLI to challenge the plan. Each tool starts cold unless you carry the context across.
Pathmark gives those tools one place to read and write intent and evidence:
One local JSONL store across harnesses.
Standard MCP tools include remember, search_memory, recall_memory, session_trace, rate_recall, consolidate_memory, audit_memory, and conclusion-first chat / ask_memory.
Client-side synthesis by default, so your coding agent reads the context and answers.
Optional Codex CLI, local command, and OpenAI-compatible synthesis modes.
Plain files you can inspect, back up, delete, or migrate.
Pathmark stays provider-neutral. Codex gets one optional synthesis preset. The core server works with any MCP client that can use local tools.
Install Pathmark in each harness and point them at the same PATHMARK_STORE_DIR. One tool saves raw context with remember or proposes a durable conclusion with create_conclusion; an approved conclusion and raw evidence can then be recovered with recall_memory, search_memory, get_context, or ask_memory.
Pathmark sits below the agents as an intent, evidence, and provenance bus for your coding workflow.
Tools
Pathmark exposes these MCP tools:
Tool
Purpose
remember
Save raw searchable evidence. Raw evidence is not treated as durable approved intent.
create_conclusion
Propose a higher-signal durable conclusion or preference. Approval is required by default before recall.
search_memory
Search memories and conclusions.
recall_memory
Transparent recall: returns context plus the exact memory IDs, timestamps, sources, matches, tags, and previews used. Accepts optional tags, exact ids, and compact includeRecords: false output.
session_trace
Return a bounded chronological audit trail for one session: prompts, exact injected memory IDs, redacted tool inputs/results, and answers.
rate_recall
Label exact IDs from a chat / ask_memory recall as relevant or irrelevant so audit precision is measured.
pathmark setup list
pathmark setup claude-code
pathmark setup opencode --json
pathmark setup gemini-cli
pathmark setup kimi
See docs/compatibility.md for Codex, Claude Code, opencode, Gemini CLI, OpenClaw, Hermes Agent, Grok CLI, Kimi, GLM, and generic MCP setups.
Codex
bash
codex mcp add pathmark -- pathmark
Codex users can also enable auto-capture:
bash
pathmark codex install --replace-legacy-hooks
When you want the visible "what memory did you use?" entry in Codex, Claude Code, Cursor, opencode, Gemini CLI, Grok-compatible MCP hosts, or any other MCP harness, call the recall_memory tool before answering. Codex session start injects an approved conclusion snapshot. Before non-trivial prompts, Codex recalls approved conclusions first and uses fresh scoped raw evidence only as a bounded fallback. recall_memory remains the portable visible trace across harnesses.
Claude Code
bash
claude mcp add --scope user pathmark -- pathmark
pathmark setup claude-code --apply-permissions
The second command lets Pathmark's local read-only tools (recall, search, diagnostics) run without a permission prompt, including in auto mode, where they would otherwise wait on the safety classifier. It backs up ~/.claude/settings.json, adds only the missing allow rules, and leaves everything else untouched. Tools that write or delete memory still ask.
--scope user makes Pathmark available in every project; Claude Code's default scope only covers the current directory. For automatic capture and session-start recall (including after context compaction), merge the hooks block from pathmark setup claude-code into ~/.claude/settings.json.
Claude Code's built-in auto-memory lives in per-project folders the other agents cannot see. Bring it into the shared store as evidence (re-runnable; edits update in place with history, and records you delete in Pathmark stay deleted):
The importer creates a memory.jsonl.backup-* file before writing, uses deterministic ids so reruns skip duplicates, and redacts obvious KEY=..., TOKEN=..., PASSWORD=..., and Bearer ... values.
It uses the same store lock as live MCP and Codex writers, so an import cannot overwrite records captured concurrently.
Use a dry run first when migrating another machine:
bash
npm run import:legacy -- --source-dir ~/old-codex-memory --dry-run
Codex Auto-Capture
Install Pathmark as the Codex memory adapter:
bash
pathmark codex install --replace-legacy-hooks
This registers the Pathmark MCP server, enables Codex hooks, and removes old compatible hook commands from Codex. It does not delete or move memory files.
The Codex adapter is proactive by default:
user prompts, final assistant answers, and tool activity are captured locally; intermediate Codex commentary is excluded;
tool activity records include bounded redacted input previews and hashes, status, exit code, duration, and changed files when the hook provides them;
tool-output hashes are captured for correlation, while output text remains private by default and requires PATHMARK_CODEX_CAPTURE_TOOL_OUTPUTS=on;
activity records expire after 30 days and are physically capped at 5,000 records by default;
session start/resume generates one bounded USER/PROJECT/AGENT snapshot from approved canonical conclusions and does not inject raw session history;
each non-trivial user prompt searches approved workspace/project conclusions first, then approved global or explicitly named-project conclusions;
only when no approved conclusion matches, at most two raw records from the current workspace/project/session may be injected as a high-confidence fallback;
raw fallback records must be within the separate automatic-recall horizon, 30 days by default; the full raw archive remains available to explicit search_memory and recall_memory calls;
raw cross-project history is never injected automatically; promote durable cross-project intent through the approval workflow;
broad cross-project history remains available through explicit search_memory / recall_memory calls without silently entering every prompt;
matching memory is injected quietly by default, without adding a raw recall_memory tool result to the conversation;
set PATHMARK_CODEX_VISIBLE_RECALL=on when debugging or auditing to make Codex call recall_memory with the exact pre-capture result IDs and workspace tag; this explicit mode omits the redundant full records copy;
legacy transport envelopes and assistant progress updates are excluded from session-start and proactive relevance results, while realtime delegation envelopes retain only their current <input> payload;
records containing Pathmark boundary escapes, instruction-override patterns, or invisible Unicode controls are tagged memory-quarantined and excluded from automatic recall; injected previews are escaped and explicitly treated as untrusted historical data;
no matching memory means no extra context is injected.
Durable extraction is approval-gated by default. create_conclusion creates a pending proposal; pending and rejected conclusions stay in the canonical JSONL audit trail but are structurally excluded from normal search, exact-ID recall, prompt injection, and snapshots. Use list_pending_conclusions, then approve_conclusion or reject_conclusion. Conclusions created before this workflow are treated as already approved for backward compatibility. Raw remember records remain searchable evidence and are not promoted automatically.
The session snapshot is generated from the same canonical store rather than maintained as a second flat file. It is frozen in the session-start hook output; prompt-time scoped recall remains dynamic.
Set PATHMARK_CODEX_PROACTIVE_RECALL=off if you want Codex hooks to capture memory but stop prompt-time recall.
Set PATHMARK_CODEX_VISIBLE_RECALL=on only when you want an explicit audit/debug recall_memory tool call. Proactive prompt-time recall remains active when this is off.
recall_memory is a point-in-time record of memory used before an answer. It intentionally does not include commands that run later. Use session_trace with the exact session ID to inspect the chronological prompt → injected memories → tools/results → final-answer trail. When explicitly enabled, output previews are capped at 2,000 characters and redacted before storage; hashes preserve correlation without storing output text by default. Upgrading an existing cursor migrates to final-answer-only parsing without duplicating previously captured user or final-answer turns. When the original transcript is available, exact legacy phase: "commentary" records are soft-deleted by timestamp and text during that migration.
Use --replace-legacy-hooks when you want Pathmark hooks to take over from earlier compatible hook commands. Without it, Pathmark installs alongside existing hook commands.
Check the adapter status:
bash
pathmark codex status
The status output is JSON and includes Pathmark hook state, MCP registration state, legacy hook presence, the active store paths, and the current record count.
Remove Pathmark hooks and MCP registration without deleting memory:
bash
pathmark codex uninstall
Configuration
Variable
Default
Description
PATHMARK_STORE_DIR
~/.pathmark/memory
Directory for memory.jsonl.
PATHMARK_MAX_SEARCH_RESULTS
12
Default search limit.
PATHMARK_CODEX_PROACTIVE_RECALL
on
Automatically inject relevant Pathmark context before non-trivial Codex prompts. Use off to capture without prompt-time recall.
PATHMARK_CODEX_VISIBLE_RECALL
off
Opt into an audit/debug recall_memory tool call that exposes exact usedMemories. Proactive memory injection remains active when this is off.
PATHMARK_CODEX_CAPTURE_TOOL_OUTPUTS
off
Store bounded redacted tool-output previews. Output hashes, status, duration, and exit codes remain available when this is off.
PATHMARK_CODEX_MEMORY_SNAPSHOT
on
Generate a bounded approved-conclusion snapshot at Codex session start/resume.
PATHMARK_SNAPSHOT_CHARS
4000
Character budget for generated snapshots; clamped to 500–12000.
PATHMARK_CODEX_RAW_RECALL_DAYS
30
Prompt-time eligibility horizon for raw evidence. 0 disables automatic raw fallback without deleting or hiding explicit search results.
PATHMARK_CODEX_RAW_RECALL_LIMIT
2
Maximum fresh raw records injected when no approved conclusion matches. Clamped to 0–2.
PATHMARK_CODEX_PROACTIVE_CONSOLIDATION
on
At session start, nudge Codex to review a bounded evidence batch when scoped raw history is accumulating without conclusions.
PATHMARK_CONSOLIDATION_MIN_EVIDENCE
8
Minimum unsynthesized user/assistant records before the proactive consolidation nudge appears.
PATHMARK_CONCLUSION_APPROVAL
on
Stage new conclusions for explicit approval. Set off only for trusted legacy automation.
PATHMARK_SYNTHESIS_PROVIDER
client
client, command, codex, or openai-compatible.
PATHMARK_CHAT_COMMAND
unset
Command provider: receives a synthesized prompt on stdin and writes an answer on stdout.
PATHMARK_CODEX_COMMAND
codex
Codex provider command.
PATHMARK_CODEX_MODEL
unset
Optional Codex model override.
PATHMARK_OPENAI_BASE_URL
https://api.openai.com/v1
OpenAI-compatible API base URL.
PATHMARK_OPENAI_API_KEY
unset
OpenAI-compatible API key.
PATHMARK_OPENAI_MODEL
unset
Model id for OpenAI-compatible synthesis.
PATHMARK_CHAT_TIMEOUT_MS
120000
Synthesis command timeout.
PATHMARK_NAMESPACE
unset
Default namespace applied consistently to MCP reads and writes.
PATHMARK_REDACT_MCP_WRITES
on
Redact common secret-shaped values on remember, conclusion, update, supersede, import, and ingest paths.
PATHMARK_RETENTION_DAYS
0
Retention policy used by compaction; 0 disables age-based removal. Conclusions are retained.
Physical cap for activity records; oldest activity is removed automatically. 0 disables the count cap.
PATHMARK_RERANK_COMMAND
unset
Optional trusted local embedding/vector or hybrid reranker. Strict kind/tag/namespace filters are applied before candidates leave the store; the command receives query/candidates as JSON on stdin and returns ranked memory ids.
PATHMARK_HYBRID_CANDIDATES
500
Maximum candidates sent to the optional reranker.
PATHMARK_RETRIEVAL_TIMEOUT_MS
30000
Timeout for the optional reranker.
PATHMARK_EXPORT_KEY
unset
Passphrase for AES-256-GCM portable exports/imports. Never returned by get_config.
PATHMARK_INDEX_LOCK_TIMEOUT_MS
120000
Cross-process wait limit for index initialization or rebuild.
Synthesis Modes
Pathmark separates memory from reasoning.
client
Default. The MCP server returns relevant memory context, and your MCP client model synthesizes the answer. This works across Codex, Claude Desktop, Cursor, and any other MCP client without giving Pathmark a model credential.
bash
PATHMARK_SYNTHESIS_PROVIDER=client pathmark
command
Use any local subscription or model CLI that accepts a prompt on stdin and writes an answer to stdout:
This is useful for Codex users who have persisted ChatGPT/Codex CLI auth locally but do not want to add an OpenAI API key. Pathmark sends the synthesis prompt through stdin, runs Codex in an empty temporary workspace, ignores project rules, and exposes only a minimal environment. Memory records are treated as untrusted data rather than executable instructions.
openai-compatible
Use any provider that exposes /chat/completions, including many Kimi, GLM/Z.ai, OpenRouter, LiteLLM, Ollama-compatible gateways, and self-hosted routers:
Aliases include claude, gemini, kimi, glm, and z-ai.
Gemini CLI setup includes portable SessionStart, BeforeAgent, AfterTool, and AfterAgent hooks for automatic scoped recall and capture. Other harnesses can feed exported transcripts through the generic ingestion surface:
pathmark chat and the MCP chat / ask_memory tools search approved conclusions first. Multi-intent questions can return separate conclusions for separate clauses. In default client mode, approved conclusions produce a safe extractive answer; a configured codex, command, or openai-compatible provider can synthesize richer prose. Raw fallback requires an explicit scope (--namespace / tags) or kind: memory, preventing unscoped cross-workspace history from entering chat.
Every matched chat query records recall activity and returns a recallId when the store is writable. Abstentions and read-only stores return recallId: null. Use MCP rate_recall or pathmark feedback with exact recalled IDs to label relevance. pathmark audit reports precision.status: "labeled", measured precision, and label coverage once feedback exists.
pathmark consolidate is preview-first. With default client synthesis it returns the bounded evidence and exact instructions for the host agent, which can call create_conclusion with supporting evidenceIds. When more eligible evidence remains, the result includes nextCursor and remainingAfterBatch; pass the cursor to review the next stable page. With a configured server-side synthesis provider, it previews structured candidates; --apply stages them as pending conclusions for approve_conclusion or reject_conclusion. It never auto-approves extracted intent.
Applied compaction and purge create a backup before replacing the canonical file. Soft deletion remains available through delete_memory; hard purge physically removes selected records from JSONL and rebuilds the derived index.
pathmark audit is read-only. It separates all raw records from consolidation-eligible user/assistant evidence, then reports capture-to-recall ratio, actionable synthesis backlog, recall age, exact duplicates, stale raw hits, and scope/missing-reference signals. Precision remains unlabeled until explicit feedback exists; Pathmark never substitutes a heuristic for a user label.
Use scoped exports and merge imports as the transport-neutral sync layer:
Pathmark does not silently upload these files. Move them through a trusted filesystem, backup tool, or sync provider of your choice.
Optional hybrid retrieval
Default retrieval stays local SQLite FTS. To enable semantic or embedding-backed reranking without forcing a model dependency, set PATHMARK_RERANK_COMMAND to a trusted local command. It receives one JSON object on stdin containing query and candidates, and must return a JSON array of ranked record ids (or { "ids": [...] }). If it fails or times out, Pathmark falls back to lexical results.
Data Format
Pathmark stores newline-delimited JSON at:
text
~/.pathmark/memory/memory.jsonl
memory.jsonl remains the canonical source of truth. Pathmark also maintains a derived, disposable search index at memory.index.v5.sqlite. Index filenames are schema-versioned so old and new MCP processes can coexist during a rolling restart. The index is rebuilt automatically when the JSONL file changes outside Pathmark, and inactive index versions can be deleted safely after their processes stop.
Each record is inspectable:
json
{"id":"uuid","kind":"memory","text":"The user prefers local-first tools.","tags":["preference"],"source":"mcp","createdAt":"2026-06-29T00:00:00.000Z","updatedAt":"2026-06-29T00:00:00.000Z"}
Deletes are soft deletes by default: the record gets a deletedAt timestamp. Use preview-first purge_memory or pathmark purge --apply for physical erasure. Updates preserve up to 50 prior versions, superseded records link to their replacement, and expired records are excluded from recall. The raw automatic-recall horizon is separate from storage retention: evidence can age out of proactive injection while remaining explicitly searchable.
Malformed JSONL lines are skipped rather than crashing every tool. pathmark codex status reports their count as invalidRecordCount so the source file can be repaired deliberately.
Roadmap
Provider presets for common local AI CLIs where stable commands exist.
Encrypted store option.
Hosted sync as an opt-in layer, not a requirement.
Native auto-capture packages for additional harness plugin systems beyond Codex and Gemini CLI.
Example recipes for Codex, Claude Desktop, Cursor, ChatGPT, and local LLM tools.
Positioning
Pathmark gives your agents a shared working memory that stays on your machine.
Switch agents. Keep the context.
Bring your own subscription. Keep your memory local.
Author and citation
Pathmark is created and maintained by Sergey Moloman, a B2B AI integration specialist and private AI contractor, and founder of RFLX AI.