Move from a legacy or direct-client setup while preserving scope, identity, and deletion boundaries.
Move from a direct-token client to OAuth
Where a client supports OAuth, switching removes the stored bearer token from local configuration. Memory, scope and attribution are unchanged by the switch — only the credential path moves.
- Confirm the client appears as OAuth-capable before removing XMEMO_KEY.
- Reconnect and approve memory:read and memory:write.
- Run a harmless recall before writing anything.
- Remove the token from the old configuration file and the environment.
Before: direct token configuration
{
"mcpServers": {
"XMemo": {
"type": "http",
"url": "https://xmemo.dev/mcp",
"headers": { "Authorization": "Bearer ${env:XMEMO_KEY}" }
}
}
}
After: OAuth configuration
The hosted server URL is all that remains; the grant supplies the scopes.
{
"servers": {
"XMemo": {
"type": "http",
"url": "https://xmemo.dev/mcp"
}
}
}
Verify the move
Read before you write, so a broken credential surfaces without changing stored memory.
await client.recallContext('current task and recent decisions', {
preferWorking: true,
});