# Authentication boundary

Separate OAuth consent, bearer-token storage, identity headers, and authenticated access decisions.

- Canonical: https://docs.xmemo.dev/docs/security/authentication
- Locale: en-US
- Content-Locale: en-US
- Canonical-Content-Digest: 7db78d94f9134263232f217ac1a0f2eb57b88ca22e0cf065f3048a20722fd448
- Edition-Digest: 33ebda67a3b2a3543761cdfad2610e22436ebac675fc2685a6fc4320f774b4bb
- Source-Revision: sha256:ee40679d8c2e2aed685ae161cfdb51750fe7be7d9ee62448f8afa4760b35e76c

## Where each credential belongs

The authentication boundary separates OAuth consent, bearer-token storage, non-secret identity headers, and the access decision itself. Mixing them is the most common cause of a leaked token.

- OAuth consent lives in the client; XMemo never sees a pasted token on that path.
- XMEMO_KEY lives in the environment or a supported secret store, never in a config file committed to git.
- Identity headers are plain labels and are safe to write into configuration.
- Public discovery is read-only and secret-free.

## Token-based client configuration

Reference the environment variable from the client config so the real value never appears in the file.

```json
{
  "mcpServers": {
    "XMemo": {
      "type": "http",
      "url": "https://xmemo.dev/mcp",
      "headers": {
        "Authorization": "Bearer ${env:XMEMO_KEY}"
      }
    }
  }
}
```

## What a rejected request looks like

A missing or insufficient credential is rejected before any memory is read. An empty result set is a valid no-match answer and is not an authorization signal.

```text
401 — no valid bearer token or API key was supplied.
403 — the credential is valid but lacks memory:read or memory:write.
200 with zero results — authorized, nothing matched.
```

## Memory Console controls

XMemo is not only an MCP endpoint. The Memory Console is the user-facing place to review, correct, remove, and export memory while keeping agent attribution visible.

### View and search memory

Open the console to see saved memories, inspect paths and memory types, and confirm whether a recall should have returned a specific item.

### Edit or correct entries

Correct stale facts, move items to clearer paths, or replace outdated notes so future assistants recall the latest user-approved context.

### Delete and export

Use account workflows to remove memories you no longer want and to locate export paths for account-scoped memory review.

### Agent attribution

Review which client or runner wrote a memory, including non-secret agent and instance labels when the client sends them.

### Privacy and credential controls

Keep OAuth consent, direct-token usage, environment-secret handoff, and support boundaries visible before expanding a personal or team pilot.
