# Migration

Move from a legacy or direct-client setup while preserving scope, identity, and deletion boundaries.

- Canonical: https://docs.xmemo.dev/docs/migration
- Locale: en-US
- Content-Locale: en-US
- Canonical-Content-Digest: fb66f83d45da488fee5cccfe9563c1ab56211a358d339b0f73df16cfed352b5f
- Edition-Digest: 19a11594e8b12380427895107ff6d271dca38684a10351d2081d6f64a7bd6400
- Source-Revision: sha256:a9d9383136b66e379e92a66eabd971c6ca172b426fff3067024039b4e2ec6f2e

## Move from a direct-token client to OAuth

Where a client supports OAuth, switching removes the stored bearer token from local configuration. Memory, scope and attribution are unchanged by the switch — only the credential path moves.

- Confirm the client appears as OAuth-capable before removing XMEMO_KEY.
- Reconnect and approve memory:read and memory:write.
- Run a harmless recall before writing anything.
- Remove the token from the old configuration file and the environment.

## Before: direct token configuration

```json
{
  "mcpServers": {
    "XMemo": {
      "type": "http",
      "url": "https://xmemo.dev/mcp",
      "headers": { "Authorization": "Bearer ${env:XMEMO_KEY}" }
    }
  }
}
```

## After: OAuth configuration

The hosted server URL is all that remains; the grant supplies the scopes.

```json
{
  "servers": {
    "XMemo": {
      "type": "http",
      "url": "https://xmemo.dev/mcp"
    }
  }
}
```

## Verify the move

Read before you write, so a broken credential surfaces without changing stored memory.

```ts
await client.recallContext('current task and recent decisions', {
  preferWorking: true,
});
```

