{"contentLocale":"en-US","fallbackReason":"","preferenceLocale":"en-US","requestedLocale":"en-US","source":"path"}
{"activeRoute":{"content":[{"body":"Reading first avoids duplicate TODOs when several agents work in the same project scope.","code":"todo({ action: \"list\" })","heading":"List open items before adding another","items":[],"language":"ts","slug":"list-open-items-before-adding-another"}],"description":"Keep task state and handoff notes close to the project context that makes them useful.","group":"Reference","kind":"tool","label":"todos","path":"/docs/tools/todos","section":"MCP tools","sectionId":"mcp-tools","sourceHref":"/product/docs#sdk-workflow-helpers","sourceLabel":"SDK workflow helpers","sourceRevision":"sha256:a208365f51d49c201b173728a752a5cec89775c71d38b55619b7bdb6846d5717","tab":"Reference","tabId":"reference","toolReference":{"errors":["Authorization failure: list lacks memory:read or a mutation lacks memory:write/project capability.","Validation failure: create lacks client_mutation_id, update lacks a positive expected_version, or action fields conflict.","Safety rejection: delete_all requires explicit confirmation and is unavailable to widget/mount-capability callers.","Timezone, project, or optimistic-concurrency errors are returned explicitly; the dispatcher does not silently ignore fields."],"examples":[{"code":"todo({\n action: \"create\",\n content: \"Review the MCP scope matrix\",\n client_mutation_id: \"task-review-scope-001\",\n due_at: \"2026-08-25T09:00:00Z\"\n})","title":"Create an idempotent task"},{"code":"todo({ action: \"list\", item_status: \"open\", limit: 10 })","title":"List open tasks"}],"parameters":[{"description":"Dispatcher operation.","name":"action","required":true,"type":"create | update | complete | list | delete_all"},{"description":"Exact item ID for update or completion.","name":"todo_id","type":"string"},{"description":"Task text; when both are supplied they must match.","name":"content / title","type":"string"},{"description":"Authorized project workspace identifier.","name":"project_id","type":"string"},{"description":"Task priority, due timestamp, status transition, and handoff note.","name":"priority / due_at / status / note","type":"string"},{"description":"List filters; search and query are list-only and must agree when both are supplied.","name":"item_status / due_before / search / query","type":"string"},{"defaultValue":"20 / empty / configured timezone","description":"Pagination and date interpretation controls.","name":"limit / cursor / owner_timezone","type":"integer / string"},{"description":"Idempotency key for create/update and optimistic concurrency version for update.","name":"client_mutation_id / expected_version","type":"string / integer"},{"defaultValue":"false","description":"Required true for explicit recoverable bulk deletion.","name":"confirm_delete_all","type":"boolean"}],"purpose":"Create, update, complete, list, or explicitly bulk-delete project TODOs while preserving task state near its authorized project context.","relatedTools":[{"label":"remember","path":"/docs/tools/remember","reason":"Save the durable decision or fact behind a task."},{"label":"recall_context","path":"/docs/tools/recall-context","reason":"Restore task and project context before continuing work."},{"label":"forget","path":"/docs/tools/forget","reason":"Remove one reviewed TODO by exact ID when needed."}],"requiredScope":["List uses memory:read; create, update, complete, and delete_all use memory:write in the public chat surface.","Project Workspace mutations additionally require a valid mount_capability and project_id."],"returnSchema":"Structured output identifies the action and returns the affected item(s), pagination cursor, mutation status, and safe task metadata. Bulk deletion is always recoverable soft deletion.","sourceRevision":"sha256:c3f1c749c2571a467bd61890609a940075b5bf17f722a35338cbaaa9651468db","toolName":"todo","unitId":"docs.tool.todos","whenNotToUse":["Do not use TODOs for general durable facts or decisions; use remember.","Do not store financial transactions as TODO content; use ledger.","Do not call delete_all without an explicit user request and confirm_delete_all=true.","The REST API accepts a wider field set than the public MCP tool; see https://xmemo.dev/docs/api/memory for scope, bucket, team and provenance filters."],"whenToUse":["A user needs durable task state, due dates, priority, completion, or a handoff list.","A project workspace needs a governed TODO mutation with its signed mount capability.","The caller needs to list open, in-progress, completed, or all authorized items."]},"unitId":"docs.route.tools-todos"},"activeToolReference":{"errors":["Authorization failure: list lacks memory:read or a mutation lacks memory:write/project capability.","Validation failure: create lacks client_mutation_id, update lacks a positive expected_version, or action fields conflict.","Safety rejection: delete_all requires explicit confirmation and is unavailable to widget/mount-capability callers.","Timezone, project, or optimistic-concurrency errors are returned explicitly; the dispatcher does not silently ignore fields."],"examples":[{"code":"todo({\n action: \"create\",\n content: \"Review the MCP scope matrix\",\n client_mutation_id: \"task-review-scope-001\",\n due_at: \"2026-08-25T09:00:00Z\"\n})","title":"Create an idempotent task"},{"code":"todo({ action: \"list\", item_status: \"open\", limit: 10 })","title":"List open tasks"}],"parameters":[{"description":"Dispatcher operation.","name":"action","required":true,"type":"create | update | complete | list | delete_all"},{"description":"Exact item ID for update or completion.","name":"todo_id","type":"string"},{"description":"Task text; when both are supplied they must match.","name":"content / title","type":"string"},{"description":"Authorized project workspace identifier.","name":"project_id","type":"string"},{"description":"Task priority, due timestamp, status transition, and handoff note.","name":"priority / due_at / status / note","type":"string"},{"description":"List filters; search and query are list-only and must agree when both are supplied.","name":"item_status / due_before / search / query","type":"string"},{"defaultValue":"20 / empty / configured timezone","description":"Pagination and date interpretation controls.","name":"limit / cursor / owner_timezone","type":"integer / string"},{"description":"Idempotency key for create/update and optimistic concurrency version for update.","name":"client_mutation_id / expected_version","type":"string / integer"},{"defaultValue":"false","description":"Required true for explicit recoverable bulk deletion.","name":"confirm_delete_all","type":"boolean"}],"purpose":"Create, update, complete, list, or explicitly bulk-delete project TODOs while preserving task state near its authorized project context.","relatedTools":[{"label":"remember","path":"/docs/tools/remember","reason":"Save the durable decision or fact behind a task."},{"label":"recall_context","path":"/docs/tools/recall-context","reason":"Restore task and project context before continuing work."},{"label":"forget","path":"/docs/tools/forget","reason":"Remove one reviewed TODO by exact ID when needed."}],"requiredScope":["List uses memory:read; create, update, complete, and delete_all use memory:write in the public chat surface.","Project Workspace mutations additionally require a valid mount_capability and project_id."],"returnSchema":"Structured output identifies the action and returns the affected item(s), pagination cursor, mutation status, and safe task metadata. Bulk deletion is always recoverable soft deletion.","sourceRevision":"sha256:c3f1c749c2571a467bd61890609a940075b5bf17f722a35338cbaaa9651468db","toolName":"todo","unitId":"docs.tool.todos","whenNotToUse":["Do not use TODOs for general durable facts or decisions; use remember.","Do not store financial transactions as TODO content; use ledger.","Do not call delete_all without an explicit user request and confirm_delete_all=true.","The REST API accepts a wider field set than the public MCP tool; see https://xmemo.dev/docs/api/memory for scope, bucket, team and provenance filters."],"whenToUse":["A user needs durable task state, due dates, priority, completion, or a handoff list.","A project workspace needs a governed TODO mutation with its signed mount capability.","The caller needs to list open, in-progress, completed, or all authorized items."]},"cards":[{"body":"Keep durable preferences, project facts, decisions, and handoff notes in a user-owned memory layer that approved assistants can recall.","index":1,"title":"One memory home"},{"body":"Use the hosted MCP URL with the client profile for ChatGPT, Claude, VS Code / GitHub Copilot, Copilot CLI, Codex, Gemini, Cursor, or direct MCP runners.","index":2,"title":"Connect your client"},{"body":"Use OAuth where supported, environment-secret handoff for direct clients, and account controls for review, deletion, and export boundaries.","index":3,"title":"Keep control"}],"content":{"cards":[["One memory home","Keep durable preferences, project facts, decisions, and handoff notes in a user-owned memory layer that approved assistants can recall."],["Connect your client","Use the hosted MCP URL with the client profile for ChatGPT, Claude, VS Code / GitHub Copilot, Copilot CLI, Codex, Gemini, Cursor, or direct MCP runners."],["Keep control","Use OAuth where supported, environment-secret handoff for direct clients, and account controls for review, deletion, and export boundaries."]],"kicker":"Public docs","label":"Docs","lead":"Use XMemo as a shared memory home for AI assistants: connect a client, save useful context once, recall it later, and keep credentials out of public configuration.","sections":[{"body":"The discovery response advertises the @xmemo/client CLI package, streamable-http MCP transport, supported MCP clients, onboarding status, auth metadata, and the MCP tool catalog.","items":[["CLI package","@xmemo/client is the published package name exposed by discovery and the public-home install bar."],["Supported clients","The MCP catalog includes ChatGPT, VS Code / GitHub Copilot, copilot-cli, codex, gemini-cli, cursor, and generic direct MCP clients."],["MCP tools","Discovery lists recall, remember, state, reflection, feedback, audit, and system-stat tools."],["Auth boundary","Discovery declares token env vars and explicitly does not include token material."]],"kicker":"Discovery","title":"Implemented hosted-service surfaces"},{"body":"Once the CLI is installed, the customer points it at the approved service URL. The hosted contract documents discovery, onboarding status, manual MCP config templates, operator-provisioned tokens, and env-var based MCP config.","code":"# Customer-side, after npm install -g @xmemo/client\nnpx @xmemo/client setup --url https://xmemo.dev\n\n# CLI internally: discovery -\u003e status -\u003e MCP config template -\u003e\n# operator token handoff -\u003e local client configuration.","kicker":"Discovery setup","title":"xmemo setup --url drives the entire trial"},{"body":"Autonomous runners should fetch /api/v1/mcp/config/autonomous-agent and choose auth_modes.oauth when they can complete OAuth and send custom identity headers. If the runner is fully headless or cannot persist OAuth tokens, it should use auth_modes.xmemo_key with XMEMO_KEY from a secret store. The agent id is fixed as autonomous-agent, while XMEMO_AGENT_INSTANCE_ID must be generated once by the runner and reused; the human should not type either identity value.","code":"GET https://xmemo.dev/api/v1/mcp/config/autonomous-agent\n# Preferred: auth_modes.oauth.mcpServers.XMemo\n# Headless fallback: auth_modes.xmemo_key.mcpServers.XMemo\n# Required identity: X-Memory-OS-Agent-ID=autonomous-agent\n# Runner generates and persists: XMEMO_AGENT_INSTANCE_ID","kicker":"Autonomous agents","title":"OAuth first, runner-generated identity"},{"body":"Agents talk to XMemo through the TypeScript SDK helpers, streamable-http MCP server, or REST. The SDK exposes workflow helpers and capture policy redaction before memory writes.","items":[["taskStart / taskEnd","Bound an agent run to a memory scope so resume and handoff work across sessions."],["recordDecision","Persist architecture or product decisions with rationale and source identity."],["recordBugFix","Log fixes so future runs recall the root cause and remediation."],["captureEvent","Run any normalized agent event through capture policy before remember()."],["recallContext / search","Pull recent decisions and procedural notes back into agent context with explanation."]],"kicker":"Capture surfaces","title":"What agents can do once connected"},{"body":"The hosted discovery contract requires read-only discovery, secret-free MCP config templates, no remote shell or PowerShell execution paths, and secrets stored through environment variables or a system secret store.","kicker":"Safety","title":"Manual onboarding guarantees"}],"title":"XMemo Docs"},"docsMarkdown":["# Quickstart for XMemo","","Hosted XMemo quickstart for connecting MCP clients, CLIs, IDEs, and autonomous agents without putting bearer tokens in public configuration.","","- CLI package: @xmemo/client","- Service URL: https://xmemo.dev","- MCP URL: https://xmemo.dev/mcp","- Setup command: npx @xmemo/client setup --url https://xmemo.dev","- Direct MCP token environment variable: XMEMO_KEY","- OAuth-supported clients: VS Code / GitHub Copilot, Cursor, Gemini CLI, Kiro, ChatGPT / OpenAI Apps SDK, Autonomous agent","- Persona flows: ChatGPT user, Copilot/Codex developer, team pilot owner, autonomous agent operator","- Autonomous agent preset: OAuth-first when supported; XMEMO_KEY fallback for headless runners; runner-generated XMEMO_AGENT_INSTANCE_ID required","- Supported MCP clients: vscode, cursor, codex, gemini-cli, claude, windsurf, kiro, openclaw, copilot-cli, chatgpt, autonomous-agent, other","- MCP chapter: per-client setup snippets and hosted streamable-http boundary","- Skills chapter: standalone Skill runtime, device login, and direct HTTPS operations","- SDK helpers: taskStart, taskEnd, recordDecision, recordBugFix, recordCorrection, captureEvent (recordEvent is an alias)","- Retrieval tool references: recall (https://xmemo.dev/docs/tools/recall), search_memory (https://xmemo.dev/docs/tools/search), recall_context (https://xmemo.dev/docs/tools/recall-context)","Choosing the right retrieval tool: recall is a lightweight, forgiving lookup; search_memory is a strict, targeted search; recall_context packages multiple bounded memories into task context.","- Troubleshooting: docs/troubleshooting (https://xmemo.dev/docs/troubleshooting)","- Safety guarantees: manual config review, environment-variable secrets, no token in generated URLs","","## Hosted XMemo quickstart","","Start with the managed XMemo service and one of these connection paths. Self-hosted, Docker, Supabase, and Python package setup are developer references, not the first path for hosted users.","","- OAuth clients: https://xmemo.dev/mcp (memory:read memory:write)","- @xmemo/client setup: npx @xmemo/client setup --url https://xmemo.dev","- Direct MCP with XMEMO_KEY: https://xmemo.dev/mcp","","## Memory Console controls","","XMemo is not only an MCP endpoint. The Memory Console is the user-facing place to review, correct, remove, and export memory while keeping agent attribution visible.","","- View and search memory","- Edit or correct entries","- Delete and export","- Agent attribution","- Privacy and credential controls","","## FAQ / Troubleshooting","","Use these answers when a user or marketplace reviewer gets blocked. Every answer includes an action step and a safety boundary."],"docsNavTree":[{"description":"Connect one client, save useful context, recall it later, and keep credentials out of public configuration.","group":"Start","kind":"quickstart","label":"Quickstart","path":"/docs/quickstart","section":"Start","sectionId":"start","serverOwned":false,"steps":[{"id":"1-choose-client-and-auth-mode","label":"1. Choose client \u0026 auth"},{"id":"2-configure-client-without-exposing-tokens","label":"2. Configure client"},{"id":"3-verify-connection-with-read-only-check","label":"3. Verify connection"},{"id":"4-save-an-explicit-synthetic-fact","label":"4. Save first fact"},{"id":"5-open-a-fresh-client-session","label":"5. Fresh session"},{"id":"6-recall-fact-with-source-attribution","label":"6. Recall \u0026 attribute"},{"id":"7-correct-convention-with-update_memory","label":"7. Correct fact"}],"tab":"Get started","tabId":"get-started"},{"description":"Authoritative architecture and public boundary: server composition, execution lifecycle, subsystem nodes, and managed cloud boundary.","group":"Core concepts","kind":"concept","label":"How XMemo works","path":"/docs/concepts/how-xmemo-works","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Understand durable facts, decisions, handoffs, and source attribution before choosing an integration.","group":"Core concepts","kind":"concept","label":"Memory model","path":"/docs/concepts/memory-model","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Keep user-owned memory boundaries explicit as clients and agents move between projects and sessions.","group":"Core concepts","kind":"concept","label":"Scopes","path":"/docs/concepts/scopes","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Use stable, non-secret agent and instance labels so later recalls retain source context.","group":"Core concepts","kind":"concept","label":"Agent identity","path":"/docs/concepts/agent-identity","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Separate the non-secret installation label used for attribution from the credential that authorizes requests.","group":"Core concepts","kind":"concept","label":"Agent instance identity","path":"/docs/concepts/agent-instance-identity","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Preserve where a memory came from without confusing source metadata with authorization or ownership.","group":"Core concepts","kind":"concept","label":"Provenance and attribution","path":"/docs/concepts/provenance-attribution","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Carry project facts, decisions, and handoff notes across approved clients without copying them between chats.","group":"Capabilities","kind":"concept","label":"Projects","path":"/docs/concepts/projects","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Tenant-isolated shared memory spaces for collaborative agent teams. Space administrators manage workspace bounds on the management plane while memory access is partitioned by data-plane seats.","group":"Capabilities","kind":"concept","label":"Teams","path":"/docs/capabilities/teams","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Keep owner-scoped knowledge in immutable revisions and retrieve either published current content or one exact addressed version.","group":"Capabilities","kind":"concept","label":"Knowledge Bases","path":"/docs/concepts/knowledge-bases","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Recall reusable, versioned procedures progressively and execute only their declared script components inside the Cloud Skill sandbox.","group":"Capabilities","kind":"concept","label":"Cloud Skills","path":"/docs/concepts/cloud-skills","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Periodically consolidate episodic evidence into semantic memory and apply explicit expiry, decay, and archive policies.","group":"Capabilities","kind":"concept","label":"Dream / Reflection","path":"/docs/concepts/dream-reflection","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Cross-agent durable memory configuration for Claude, ChatGPT, Codex, GitHub Copilot, and OpenClaw via hosted MCP endpoints.","group":"Connect","kind":"mcp","label":"MCP overview","path":"/docs/mcp/overview","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Connect ChatGPT through the hosted OAuth flow and approve the memory:read and memory:write scopes.","group":"Connect","kind":"mcp","label":"ChatGPT","path":"/docs/mcp/chatgpt","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the direct MCP path with XMEMO_KEY from a local environment or supported secret store.","group":"Connect","kind":"mcp","label":"Claude Code","path":"/docs/mcp/claude-code","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Use the Codex MCP profile with bearer_token_env_var and a stable local instance identity.","group":"Connect","kind":"mcp","label":"Codex","path":"/docs/mcp/codex","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Choose the reviewed Cursor config path and keep credentials in the client environment or secret store.","group":"Connect","kind":"mcp","label":"Cursor","path":"/docs/mcp/cursor","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Use the OAuth-first Gemini CLI configuration without placing bearer credentials in settings.json.","group":"Connect","kind":"mcp","label":"Gemini CLI","path":"/docs/mcp/gemini","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Connect VS Code and GitHub Copilot through the hosted OAuth configuration when the host supports it.","group":"Connect","kind":"mcp","label":"GitHub Copilot","path":"/docs/mcp/copilot","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the direct bearer-token Copilot CLI MCP client with XMEMO_KEY and stable instance attribution.","group":"Connect","kind":"mcp","label":"Copilot CLI","path":"/docs/mcp/copilot-cli","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the direct Devin Desktop (formerly Windsurf) MCP client with XMEMO_KEY and stable instance attribution.","group":"Connect","kind":"mcp","label":"Devin Desktop (formerly Windsurf)","path":"/docs/mcp/windsurf","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the Kiro OAuth MCP client with memory:read and knowledge:read scopes.","group":"Connect","kind":"mcp","label":"Kiro","path":"/docs/mcp/kiro","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Recall-first Skill guidance plus a native OpenClaw memory plugin for durable, user-owned context across sessions.","group":"Connect","kind":"mcp","label":"OpenClaw","path":"/docs/connect/openclaw","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Correct a durable record through the versioned update path while preserving provenance and conflict signals.","group":"Guides","kind":"concept","label":"Memory correction","path":"/docs/concepts/memory-correction","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Choose the recoverable forget path or an explicitly authorized destructive mode with an auditable tombstone.","group":"Guides","kind":"concept","label":"Memory deletion","path":"/docs/concepts/memory-deletion","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Hand off a decision, implementation fix, and bounded context between named agents using the existing SDK and MCP contracts.","group":"Guides","kind":"operations","label":"Cross-agent workflow","path":"/docs/operations/cross-agent-workflow","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Move from a legacy or direct-client setup while preserving scope, identity, and deletion boundaries.","group":"Guides","kind":"operations","label":"Migration","path":"/docs/migration","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Use symptom, cause, action, and safety guidance when OAuth, MCP discovery, or recall does not behave as expected.","group":"Guides","kind":"operations","label":"Troubleshooting","path":"/docs/troubleshooting","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Architectural evaluation criteria, vendor-neutral memory layer checklist, scenario-based selection, reproducible benchmarks, and migration guide.","group":"Guides","kind":"concept","label":"Evaluate \u0026 compare","path":"/docs/guides/evaluate","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Write durable memory only after capture policy, scope, and secret-redaction boundaries are satisfied.","group":"Reference","kind":"tool","label":"remember","path":"/docs/tools/remember","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Retrieve relevant durable context when an agent needs a focused answer from an approved memory scope.","group":"Reference","kind":"tool","label":"recall","path":"/docs/tools/recall","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Restore the recent project and agent context needed to continue work across sessions.","group":"Reference","kind":"tool","label":"recall_context","path":"/docs/tools/recall-context","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Search authorized memory when the relevant wording or record is not known in advance.","group":"Reference","kind":"tool","label":"search","path":"/docs/tools/search","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Delete a reviewed memory, TODO, or Ledger record through the user-owned control boundary, with soft deletion recoverable and hard deletion permanent.","group":"Reference","kind":"tool","label":"forget","path":"/docs/tools/forget","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Keep task state and handoff notes close to the project context that makes them useful.","group":"Reference","kind":"tool","label":"todos","path":"/docs/tools/todos","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Use governed ledger and reminder surfaces when an agent needs durable operational context.","group":"Reference","kind":"tool","label":"ledger","path":"/docs/tools/ledger","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Save or update a reusable Cloud Skill and create its next versioned revision.","group":"Reference","kind":"tool","label":"save_cloud_skill","path":"/docs/tools/save-cloud-skill","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Discover Cloud Skills, load a root manifest, or fetch one resource from an explicitly pinned revision.","group":"Reference","kind":"tool","label":"recall_cloud_skill","path":"/docs/tools/recall-cloud-skill","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Run one declared script component from an active Cloud Skill through the isolated execution engine.","group":"Reference","kind":"tool","label":"execute_cloud_skill","path":"/docs/tools/execute-cloud-skill","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Run a bounded consolidation and memory-lifecycle maintenance pass with dry-run planning and audit evidence.","group":"Reference","kind":"tool","label":"reflect","path":"/docs/tools/reflect","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Search published current Knowledge revisions or read one exact authorized item and immutable revision with bounded pagination.","group":"Reference","kind":"tool","label":"search_knowledge","path":"/docs/tools/search-knowledge","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Choose OAuth or a scoped environment-secret handoff according to the client and API surface.","group":"Reference","kind":"api","label":"API authentication","path":"/docs/api/authentication","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Read and write memory through the documented REST and MCP contracts with explicit scope boundaries.","group":"Reference","kind":"api","label":"Memory API","path":"/docs/api/memory","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Keep project-scoped context and handoff records connected to the agent workflow that created them.","group":"Reference","kind":"api","label":"Projects API","path":"/docs/api/projects","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Use stable non-secret agent identity metadata while credentials remain in authenticated request headers.","group":"Reference","kind":"api","label":"Agents API","path":"/docs/api/agents","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Use workflow helpers and capture policy from the TypeScript SDK without duplicating memory semantics in the UI.","group":"Reference","kind":"sdk","label":"TypeScript SDK","path":"/docs/sdk/typescript","section":"SDK","sectionId":"sdk","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Choose the standalone Skill path when the agent host cannot mount a hosted MCP server directly.","group":"Reference","kind":"skill","label":"Skills quickstart","path":"/docs/skills/quickstart","section":"Skills","sectionId":"skills","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Keep Skill credentials in XMEMO_KEY or the supported device-login flow, never in public output.","group":"Reference","kind":"skill","label":"Skill authentication","path":"/docs/skills/authentication","section":"Skills","sectionId":"skills","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Review the standalone Skill operation catalog and its runtime selection boundary.","group":"Reference","kind":"skill","label":"Skill operations","path":"/docs/skills/operations","section":"Skills","sectionId":"skills","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Read the current governance posture for retention, deletion, export, data boundaries, and audit evidence.","group":"Trust \u0026 governance","kind":"concept","label":"Governance and retention","path":"/docs/concepts/governance-retention","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Understand the real sanitization and retrieval-visibility controls used for credentials, personal data, and high-sensitivity memory.","group":"Trust \u0026 governance","kind":"concept","label":"Sensitive memory","path":"/docs/concepts/sensitive-memory","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Separate OAuth consent, bearer-token storage, identity headers, and authenticated access decisions.","group":"Trust \u0026 governance","kind":"security","label":"Authentication boundary","path":"/docs/security/authentication","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Understand which public discovery data is safe to expose and where account-owned memory controls begin.","group":"Trust \u0026 governance","kind":"security","label":"Data boundary","path":"/docs/security/data-boundary","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"This page explains what XMemo stores for each security mode, where it is processed, who can decrypt it, what happens during export or deletion, and how you can verify the active boundary from your own account.","group":"Trust \u0026 governance","kind":"security","label":"Where is my data?","path":"/docs/security/where-is-my-data","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":true,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Review public release updates without mixing reviewer or submission material into the developer docs tree.","group":"Guides","kind":"operations","label":"Changelog","path":"/docs/changelog","section":"","sectionId":"","serverOwned":false,"tab":"","tabId":""}],"faqTroubleshooting":{"actionLabel":"Action:","body":"Start with the answers for AI assistant users, then use the developer and integrator answers for connection and operations details. Every answer includes an action step and a safety boundary.","groups":[{"description":"Everyday answers for people who use XMemo through an AI assistant without configuring the connection themselves.","id":"ai-assistant-users","itemIds":["ai-forgotten-context","ai-mixed-context","ai-forget-memory","ai-new-device","ai-duplicate-memory","ai-context-too-broad","ai-disconnected-access","ai-memory-unavailable","ai-which-connection","ai-connection-support"],"items":[{"action":"Ask the assistant to save a small, non-sensitive test detail, then open Memory Console and check that it appears under the account and project you use.","cause":"The assistant may be connected to a different XMemo account, project, or device context, or the original memory was not saved.","id":"ai-forgotten-context","question":"Why does my AI assistant not remember something I told it earlier?","safety":"Use a made-up test detail; do not use another person's private information.","sourceId":"empty-memory","symptom":"I saved an important preference or detail, but in a later chat my AI assistant acts as if it has never seen it.","verification":"Start a fresh chat with the same assistant and ask about the test detail; remove the test entry when finished."},{"action":"In the assistant, choose the intended XMemo account and project, reconnect it if needed, and retry with a clearly labeled test detail.","cause":"The assistant may be using a different project or account context than the one where the memory was saved.","id":"ai-mixed-context","question":"Why is my AI assistant mixing up my projects or conversations?","safety":"Do not move private information between projects just to make it appear.","sourceId":"wrong-project-context","symptom":"A detail from one project shows up in another, or the assistant answers as though two conversations belong together.","verification":"Check the memory's project and source in Memory Console, then confirm an unrelated project cannot see that test detail."},{"action":"Open Memory Console, find the memory, and use its delete or forget control; if you cannot find the control, contact Support with the memory reference.","cause":"Viewing, recoverably removing, permanently deleting, and exporting memory are different account actions.","id":"ai-forget-memory","question":"How can I make my AI assistant forget something completely?","safety":"Delete only the intended memory and never include private content in a support message.","sourceId":"delete-export","symptom":"I want one memory removed and need to know whether it is gone.","verification":"Search for the memory again and confirm the state shown by Memory Console; check that any export contains only your account's data."},{"action":"Reconnect XMemo in the assistant you want to use, sign into the same account, and keep the connection's device label stable when the app offers that option.","cause":"The new assistant connection may identify the device or assistant as a new source, or it may be signed into a different account.","id":"ai-new-device","question":"I changed computers or AI assistants; will XMemo still remember me?","safety":"Check the account before saving anything personal on a shared computer.","sourceId":"agent-instance-changes","symptom":"My old memories seem split from new ones after I changed devices, restarted an assistant, or switched hosts.","verification":"Save one made-up test detail, start a new chat on the same assistant, and confirm the detail appears without changing the account."},{"action":"Open Memory Console, compare the two entries, and remove only the duplicate after confirming their dates and source.","cause":"The first save may have succeeded even though the assistant did not show the result, so repeating the request created another copy.","id":"ai-duplicate-memory","question":"Why did my AI assistant save the same thing twice?","safety":"Do not delete all matching memories until you identify the copy you want to keep.","sourceId":"duplicate-memory","symptom":"I see two copies of what looks like the same memory after a retry or reconnect.","verification":"Ask the assistant to save one new, clearly labeled test detail once and confirm that only one new entry appears."},{"action":"Ask for a narrower topic, project, or time period, and tell the assistant which decision or detail matters most.","cause":"The request covers too broad a topic or time period, or the assistant is trying to use more saved context than the conversation needs.","id":"ai-context-too-broad","question":"Why is my AI assistant giving me too much or too little of my past context?","safety":"Do not ask the assistant to reveal unrelated private memories just to fill the conversation.","sourceId":"recall-context-size","symptom":"The assistant brings up unrelated details, misses the decision I need, or gives an answer that feels overloaded.","verification":"Compare the answer with the requested topic and remove any unrelated details from the conversation before continuing."},{"action":"Open your XMemo account's connected-app or security controls, revoke the old assistant connection, and reconnect only the one you trust.","cause":"Removing a connection from the app may not cancel the account's connection permission.","id":"ai-disconnected-access","question":"I disconnected XMemo; how do I make sure the old assistant cannot use it?","safety":"Revoke only the connection you intend to remove and do not share account sign-in details.","sourceId":"revoke-access","symptom":"I removed the connection from an assistant, but I am unsure whether it can still access my memories.","verification":"Try the old connection only if it is safe to do so, and confirm that it is refused before using the new connection."},{"action":"Open the assistant's connected-app settings, disconnect and reconnect XMemo, then start a new chat.","cause":"The assistant may need its XMemo connection refreshed, or it may be signed into a different account.","id":"ai-memory-unavailable","question":"Why cannot my AI assistant use XMemo anymore?","safety":"Never paste secret account details or private memories into a chat or support request.","sourceId":"mcp-no-tools","symptom":"XMemo used to be available in my assistant, but its memory actions no longer appear or the assistant says it cannot use them.","verification":"Ask the assistant to show whether XMemo is connected, then try a harmless read before saving anything."},{"action":"For the hosted service, start at https://xmemo.dev/product/docs and follow the connection link shown for your assistant; ask Support if your organization gave you a different setup page.","cause":"The guided setup page and the assistant connection serve different purposes, and hosted and self-managed setups have different boundaries.","id":"ai-which-connection","question":"Which XMemo connection should I use in my AI assistant?","safety":"Do not use local development addresses or paste private credentials into a public chat.","sourceId":"which-url","symptom":"I am unsure which XMemo page or connection belongs in my assistant's settings.","verification":"Before saving a personal detail, confirm the page uses your intended XMemo account and hosted service."},{"action":"Contact Support with the assistant name, approximate time, and a short description of what you saw; include only redacted details.","cause":"The problem may belong to the assistant app, my account, or a stale connection that public instructions cannot inspect.","id":"ai-connection-support","question":"What should I do if my AI assistant still cannot connect to XMemo?","safety":"Never send sign-in details, one-time codes, cookies, or private memory text.","sourceId":"support-needed","symptom":"I retried the connection steps, but the assistant still cannot use XMemo.","verification":"Make sure the report can be reproduced without sending private memories or account secrets."}],"title":"For AI assistant users"},{"description":"Connection, account-boundary, client, and operational answers for people integrating XMemo.","id":"developers-integrators","itemIds":["oauth-failed","forbidden-scope","mcp-no-tools","token-missing","agent-instance-changes","empty-memory","wrong-project-scope","duplicate-memory","recall-context-size","delete-export","revoke-access","ga-certified","which-url","wrong-agent","support-needed"],"items":[{"action":"Sign out of the XMemo MCP server in the host app, reconnect the hosted MCP URL, and approve memory:read plus memory:write again.","cause":"The hosted grant may be stale, the browser handoff may be blocked, or the client may be using an old server registration.","id":"oauth-failed","question":"OAuth failed or the consent window never completes.","safety":"Do not switch to XMEMO_KEY inside OAuth clients just to bypass a stale OAuth session.","symptom":"The client shows 401, the OAuth browser does not open, or consent returns to the client without a usable connection.","verification":"Reconnect until the client reports an active authorization, then run a harmless recall before writing memory."},{"action":"Check the selected account and project, reconnect OAuth or request the intended scope, then retry the same operation without changing the resource.","cause":"The grant lacks the required scope, the account is outside the selected project boundary, or the resource belongs to another tenant.","id":"forbidden-scope","question":"The request returns 403 Forbidden.","safety":"Do not broaden scopes or copy a different user's token to make a 403 disappear.","symptom":"The server is reachable and the credential is recognized, but the requested project, tool, or memory action is refused.","verification":"Confirm that a read-only request in the intended project succeeds before retrying a write or delete operation."},{"action":"Reconnect the server, verify the client is using the supported MCP profile, and run tool discovery again before changing credentials.","cause":"The client has not refreshed discovery, is using the wrong MCP profile, or is connected to a stale URL or registration.","id":"mcp-no-tools","question":"The MCP server connects but no tools appear.","safety":"Do not paste bearer tokens into screenshots, support tickets, or marketplace review notes.","symptom":"The host shows a connected server, but tools/list is empty or the XMemo tools are missing from the model's tool picker.","verification":"Confirm that at least remember, recall, and search_memory appear before starting a write or marketplace demonstration."},{"action":"Set XMEMO_KEY in the local environment or secret store, restart the client, and keep XMEMO_AGENT_INSTANCE_ID stable when attribution matters.","cause":"The client process did not inherit the environment, the variable was added to a different shell, or the config expects a secret-store reference instead.","id":"token-missing","question":"A direct MCP client says the token is missing.","safety":"Keep the real token outside config files committed to git; public examples should reference environment variables only.","symptom":"A direct client reports that XMEMO_KEY is unset, empty, or unavailable even though the variable was added somewhere on the machine.","verification":"Inspect only the variable's presence metadata, restart the client, and confirm a harmless authenticated recall; never print the token value."},{"action":"Generate one non-secret instance label per runner, persist it outside git, and send it with every direct MCP connection.","cause":"XMEMO_AGENT_INSTANCE_ID is generated at process start instead of persisted in the runner's local secret or environment configuration.","id":"agent-instance-changes","question":"The agent instance ID changes after every restart.","safety":"The instance label is attribution metadata, not an authorization credential; account and token boundaries still control access.","symptom":"The same local runner appears as several agents or recalls split across instances after a restart or redeploy.","verification":"Restart the runner twice and confirm the same instance label appears in source attribution without exposing credentials."},{"action":"Create a synthetic test memory, verify the path and memory type in Memory Console, then retry recall from the same account or tenant boundary.","cause":"The read is using a different account, project, scope, agent boundary, or memory type than the write, or the test record was never committed.","id":"empty-memory","question":"Recall returns empty memory.","safety":"Use synthetic review data; do not use private customer memory as a marketplace demo.","symptom":"A recall or search succeeds but returns no relevant records after the user has saved context.","verification":"Read the newly created synthetic record back with the same project and scope, then remove it through the intended delete path."},{"action":"Select the intended account and project explicitly, refresh the client context, and repeat the operation with a synthetic record.","cause":"The client reused a project identifier from another environment, omitted the project boundary, or retained a stale account session.","id":"wrong-project-scope","question":"Recall or write uses the wrong project scope.","safety":"Never solve a scope mismatch by granting a broader token or copying data between projects.","symptom":"A record is visible in one project but not another, or a write appears under a project the operator did not intend.","verification":"Confirm the record's project and source attribution in Memory Console, then verify that an unrelated project cannot read it."},{"action":"Inspect the existing record and source attribution first, then use the client retry policy or a stable idempotency key before writing again.","cause":"The client retried after a timeout without an idempotency boundary, or the capture flow writes before confirming the first response.","id":"duplicate-memory","question":"The same memory is saved twice.","safety":"Do not bulk-delete matching memories until the intended record and account scope have been confirmed.","symptom":"A retry or reconnect produces duplicate records instead of one durable memory.","verification":"Repeat the same controlled capture once and confirm one new record plus one readback, not two new records."},{"action":"Narrow the query with project, agent, time, or topic boundaries and request a small relevant set before expanding the limit.","cause":"The query is too broad, the scope or time window is missing, or the caller requested an unsuitable result limit for the task.","id":"recall-context-size","question":"Recall context is too large or too small.","safety":"Do not widen scope or export unrelated memory just to fill a context window.","symptom":"The agent receives irrelevant context, misses the needed decision, or exceeds the host's useful context budget.","verification":"Compare the returned context against the target question and confirm that every included record is authorized and useful."},{"action":"Use Memory Console or account workflows first; if a self-service path is unavailable, contact Support so the request stays account-scoped.","cause":"Delete, recoverable forget, permanent delete, and export are distinct workflows with different confirmation and recovery semantics.","id":"delete-export","question":"How do I delete or export memory?","safety":"Exports and support bundles must exclude token hashes, API keys, session secrets, provider credentials, and unrelated tenant data.","symptom":"The operator needs to remove a record, confirm a forget action, or obtain an account-scoped export.","verification":"After forget or delete, search by the record reference and confirm the expected recoverable or permanent state; verify exports contain only the account scope."},{"action":"Open account security or connected-client controls, revoke the named OAuth grant, and rotate the direct credential if one was exposed or no longer trusted.","cause":"Disconnecting a client config does not necessarily revoke the server-side grant or rotate a direct token.","id":"revoke-access","question":"How do I revoke access after a client is disconnected?","safety":"Revoke only the intended client or grant; do not publish old tokens, OAuth codes, or session details while diagnosing access.","symptom":"A client was removed locally, but the operator needs to invalidate its OAuth grant or direct credential.","verification":"Retry an authenticated read with the old connection and confirm it is rejected, then reconnect only through the intended consent or secret-store path."},{"action":"Treat public wording as beta/config-supported unless a specific marketplace approval or certification artifact is present.","cause":"Configuration support, OAuth readiness, pilot evidence, and marketplace approval are separate claims.","id":"ga-certified","question":"Is XMemo GA, certified, or marketplace listed?","safety":"Do not claim GA, certified, stable, or listed status from a working config alone.","symptom":"A listing or document asks whether a working configuration proves GA, certification, or marketplace approval.","verification":"Check the canonical client capability matrix and the named approval artifact before publishing a status claim."},{"action":"Hosted users should start with https://xmemo.dev/mcp for MCP clients and https://xmemo.dev/product/docs for guided setup.","cause":"Hosted onboarding and self-hosted or legacy deployment paths have different URLs, credentials, and data boundaries.","id":"which-url","question":"Which URL should I use?","safety":"Do not use localhost, Supabase, Docker, or self-hosted Python instructions as the first path for public hosted users.","symptom":"A hosted user is unsure whether to follow the public quickstart, MCP endpoint, or self-hosted developer instructions.","verification":"Confirm that the host URL, authentication mode, and account boundary match the intended hosted or self-hosted deployment before connecting."},{"action":"Check the non-secret agent/device headers or client profile, then persist the local instance ID instead of regenerating it.","cause":"The client changed its non-secret agent or instance headers, or a shared credential is being used by multiple runners.","id":"wrong-agent","question":"Memory appears under the wrong agent or device.","safety":"Attribution labels help review source, but they are not a security boundary; account credentials still decide access.","symptom":"A memory is attributed to another runner or appears split across devices after a client update or restart.","verification":"Write one synthetic record from the intended runner and confirm its source attribution remains stable after reconnect."},{"action":"Open Support with the client name, config path, approximate timestamp, and whether the client uses OAuth or XMEMO_KEY.","cause":"The remaining issue may be client-specific, account-specific, or caused by a stale registration or environment boundary that local docs cannot inspect.","id":"support-needed","question":"I still cannot connect after following the steps.","safety":"Share redacted diagnostics only; never send bearer tokens, OAuth codes, cookies, or customer memory content.","symptom":"The connection remains unavailable after the client-specific OAuth or direct-secret path has been retried.","verification":"Confirm that the support report contains a reproducible symptom and redacted metadata, then wait for the account-scoped diagnosis."}],"title":"For developers \u0026 integrators"}],"items":[{"action":"Ask the assistant to save a small, non-sensitive test detail, then open Memory Console and check that it appears under the account and project you use.","cause":"The assistant may be connected to a different XMemo account, project, or device context, or the original memory was not saved.","id":"ai-forgotten-context","question":"Why does my AI assistant not remember something I told it earlier?","safety":"Use a made-up test detail; do not use another person's private information.","sourceId":"empty-memory","symptom":"I saved an important preference or detail, but in a later chat my AI assistant acts as if it has never seen it.","verification":"Start a fresh chat with the same assistant and ask about the test detail; remove the test entry when finished."},{"action":"In the assistant, choose the intended XMemo account and project, reconnect it if needed, and retry with a clearly labeled test detail.","cause":"The assistant may be using a different project or account context than the one where the memory was saved.","id":"ai-mixed-context","question":"Why is my AI assistant mixing up my projects or conversations?","safety":"Do not move private information between projects just to make it appear.","sourceId":"wrong-project-context","symptom":"A detail from one project shows up in another, or the assistant answers as though two conversations belong together.","verification":"Check the memory's project and source in Memory Console, then confirm an unrelated project cannot see that test detail."},{"action":"Open Memory Console, find the memory, and use its delete or forget control; if you cannot find the control, contact Support with the memory reference.","cause":"Viewing, recoverably removing, permanently deleting, and exporting memory are different account actions.","id":"ai-forget-memory","question":"How can I make my AI assistant forget something completely?","safety":"Delete only the intended memory and never include private content in a support message.","sourceId":"delete-export","symptom":"I want one memory removed and need to know whether it is gone.","verification":"Search for the memory again and confirm the state shown by Memory Console; check that any export contains only your account's data."},{"action":"Reconnect XMemo in the assistant you want to use, sign into the same account, and keep the connection's device label stable when the app offers that option.","cause":"The new assistant connection may identify the device or assistant as a new source, or it may be signed into a different account.","id":"ai-new-device","question":"I changed computers or AI assistants; will XMemo still remember me?","safety":"Check the account before saving anything personal on a shared computer.","sourceId":"agent-instance-changes","symptom":"My old memories seem split from new ones after I changed devices, restarted an assistant, or switched hosts.","verification":"Save one made-up test detail, start a new chat on the same assistant, and confirm the detail appears without changing the account."},{"action":"Open Memory Console, compare the two entries, and remove only the duplicate after confirming their dates and source.","cause":"The first save may have succeeded even though the assistant did not show the result, so repeating the request created another copy.","id":"ai-duplicate-memory","question":"Why did my AI assistant save the same thing twice?","safety":"Do not delete all matching memories until you identify the copy you want to keep.","sourceId":"duplicate-memory","symptom":"I see two copies of what looks like the same memory after a retry or reconnect.","verification":"Ask the assistant to save one new, clearly labeled test detail once and confirm that only one new entry appears."},{"action":"Ask for a narrower topic, project, or time period, and tell the assistant which decision or detail matters most.","cause":"The request covers too broad a topic or time period, or the assistant is trying to use more saved context than the conversation needs.","id":"ai-context-too-broad","question":"Why is my AI assistant giving me too much or too little of my past context?","safety":"Do not ask the assistant to reveal unrelated private memories just to fill the conversation.","sourceId":"recall-context-size","symptom":"The assistant brings up unrelated details, misses the decision I need, or gives an answer that feels overloaded.","verification":"Compare the answer with the requested topic and remove any unrelated details from the conversation before continuing."},{"action":"Open your XMemo account's connected-app or security controls, revoke the old assistant connection, and reconnect only the one you trust.","cause":"Removing a connection from the app may not cancel the account's connection permission.","id":"ai-disconnected-access","question":"I disconnected XMemo; how do I make sure the old assistant cannot use it?","safety":"Revoke only the connection you intend to remove and do not share account sign-in details.","sourceId":"revoke-access","symptom":"I removed the connection from an assistant, but I am unsure whether it can still access my memories.","verification":"Try the old connection only if it is safe to do so, and confirm that it is refused before using the new connection."},{"action":"Open the assistant's connected-app settings, disconnect and reconnect XMemo, then start a new chat.","cause":"The assistant may need its XMemo connection refreshed, or it may be signed into a different account.","id":"ai-memory-unavailable","question":"Why cannot my AI assistant use XMemo anymore?","safety":"Never paste secret account details or private memories into a chat or support request.","sourceId":"mcp-no-tools","symptom":"XMemo used to be available in my assistant, but its memory actions no longer appear or the assistant says it cannot use them.","verification":"Ask the assistant to show whether XMemo is connected, then try a harmless read before saving anything."},{"action":"For the hosted service, start at https://xmemo.dev/product/docs and follow the connection link shown for your assistant; ask Support if your organization gave you a different setup page.","cause":"The guided setup page and the assistant connection serve different purposes, and hosted and self-managed setups have different boundaries.","id":"ai-which-connection","question":"Which XMemo connection should I use in my AI assistant?","safety":"Do not use local development addresses or paste private credentials into a public chat.","sourceId":"which-url","symptom":"I am unsure which XMemo page or connection belongs in my assistant's settings.","verification":"Before saving a personal detail, confirm the page uses your intended XMemo account and hosted service."},{"action":"Contact Support with the assistant name, approximate time, and a short description of what you saw; include only redacted details.","cause":"The problem may belong to the assistant app, my account, or a stale connection that public instructions cannot inspect.","id":"ai-connection-support","question":"What should I do if my AI assistant still cannot connect to XMemo?","safety":"Never send sign-in details, one-time codes, cookies, or private memory text.","sourceId":"support-needed","symptom":"I retried the connection steps, but the assistant still cannot use XMemo.","verification":"Make sure the report can be reproduced without sending private memories or account secrets."},{"action":"Sign out of the XMemo MCP server in the host app, reconnect the hosted MCP URL, and approve memory:read plus memory:write again.","cause":"The hosted grant may be stale, the browser handoff may be blocked, or the client may be using an old server registration.","id":"oauth-failed","question":"OAuth failed or the consent window never completes.","safety":"Do not switch to XMEMO_KEY inside OAuth clients just to bypass a stale OAuth session.","symptom":"The client shows 401, the OAuth browser does not open, or consent returns to the client without a usable connection.","verification":"Reconnect until the client reports an active authorization, then run a harmless recall before writing memory."},{"action":"Check the selected account and project, reconnect OAuth or request the intended scope, then retry the same operation without changing the resource.","cause":"The grant lacks the required scope, the account is outside the selected project boundary, or the resource belongs to another tenant.","id":"forbidden-scope","question":"The request returns 403 Forbidden.","safety":"Do not broaden scopes or copy a different user's token to make a 403 disappear.","symptom":"The server is reachable and the credential is recognized, but the requested project, tool, or memory action is refused.","verification":"Confirm that a read-only request in the intended project succeeds before retrying a write or delete operation."},{"action":"Reconnect the server, verify the client is using the supported MCP profile, and run tool discovery again before changing credentials.","cause":"The client has not refreshed discovery, is using the wrong MCP profile, or is connected to a stale URL or registration.","id":"mcp-no-tools","question":"The MCP server connects but no tools appear.","safety":"Do not paste bearer tokens into screenshots, support tickets, or marketplace review notes.","symptom":"The host shows a connected server, but tools/list is empty or the XMemo tools are missing from the model's tool picker.","verification":"Confirm that at least remember, recall, and search_memory appear before starting a write or marketplace demonstration."},{"action":"Set XMEMO_KEY in the local environment or secret store, restart the client, and keep XMEMO_AGENT_INSTANCE_ID stable when attribution matters.","cause":"The client process did not inherit the environment, the variable was added to a different shell, or the config expects a secret-store reference instead.","id":"token-missing","question":"A direct MCP client says the token is missing.","safety":"Keep the real token outside config files committed to git; public examples should reference environment variables only.","symptom":"A direct client reports that XMEMO_KEY is unset, empty, or unavailable even though the variable was added somewhere on the machine.","verification":"Inspect only the variable's presence metadata, restart the client, and confirm a harmless authenticated recall; never print the token value."},{"action":"Generate one non-secret instance label per runner, persist it outside git, and send it with every direct MCP connection.","cause":"XMEMO_AGENT_INSTANCE_ID is generated at process start instead of persisted in the runner's local secret or environment configuration.","id":"agent-instance-changes","question":"The agent instance ID changes after every restart.","safety":"The instance label is attribution metadata, not an authorization credential; account and token boundaries still control access.","symptom":"The same local runner appears as several agents or recalls split across instances after a restart or redeploy.","verification":"Restart the runner twice and confirm the same instance label appears in source attribution without exposing credentials."},{"action":"Create a synthetic test memory, verify the path and memory type in Memory Console, then retry recall from the same account or tenant boundary.","cause":"The read is using a different account, project, scope, agent boundary, or memory type than the write, or the test record was never committed.","id":"empty-memory","question":"Recall returns empty memory.","safety":"Use synthetic review data; do not use private customer memory as a marketplace demo.","symptom":"A recall or search succeeds but returns no relevant records after the user has saved context.","verification":"Read the newly created synthetic record back with the same project and scope, then remove it through the intended delete path."},{"action":"Select the intended account and project explicitly, refresh the client context, and repeat the operation with a synthetic record.","cause":"The client reused a project identifier from another environment, omitted the project boundary, or retained a stale account session.","id":"wrong-project-scope","question":"Recall or write uses the wrong project scope.","safety":"Never solve a scope mismatch by granting a broader token or copying data between projects.","symptom":"A record is visible in one project but not another, or a write appears under a project the operator did not intend.","verification":"Confirm the record's project and source attribution in Memory Console, then verify that an unrelated project cannot read it."},{"action":"Inspect the existing record and source attribution first, then use the client retry policy or a stable idempotency key before writing again.","cause":"The client retried after a timeout without an idempotency boundary, or the capture flow writes before confirming the first response.","id":"duplicate-memory","question":"The same memory is saved twice.","safety":"Do not bulk-delete matching memories until the intended record and account scope have been confirmed.","symptom":"A retry or reconnect produces duplicate records instead of one durable memory.","verification":"Repeat the same controlled capture once and confirm one new record plus one readback, not two new records."},{"action":"Narrow the query with project, agent, time, or topic boundaries and request a small relevant set before expanding the limit.","cause":"The query is too broad, the scope or time window is missing, or the caller requested an unsuitable result limit for the task.","id":"recall-context-size","question":"Recall context is too large or too small.","safety":"Do not widen scope or export unrelated memory just to fill a context window.","symptom":"The agent receives irrelevant context, misses the needed decision, or exceeds the host's useful context budget.","verification":"Compare the returned context against the target question and confirm that every included record is authorized and useful."},{"action":"Use Memory Console or account workflows first; if a self-service path is unavailable, contact Support so the request stays account-scoped.","cause":"Delete, recoverable forget, permanent delete, and export are distinct workflows with different confirmation and recovery semantics.","id":"delete-export","question":"How do I delete or export memory?","safety":"Exports and support bundles must exclude token hashes, API keys, session secrets, provider credentials, and unrelated tenant data.","symptom":"The operator needs to remove a record, confirm a forget action, or obtain an account-scoped export.","verification":"After forget or delete, search by the record reference and confirm the expected recoverable or permanent state; verify exports contain only the account scope."},{"action":"Open account security or connected-client controls, revoke the named OAuth grant, and rotate the direct credential if one was exposed or no longer trusted.","cause":"Disconnecting a client config does not necessarily revoke the server-side grant or rotate a direct token.","id":"revoke-access","question":"How do I revoke access after a client is disconnected?","safety":"Revoke only the intended client or grant; do not publish old tokens, OAuth codes, or session details while diagnosing access.","symptom":"A client was removed locally, but the operator needs to invalidate its OAuth grant or direct credential.","verification":"Retry an authenticated read with the old connection and confirm it is rejected, then reconnect only through the intended consent or secret-store path."},{"action":"Treat public wording as beta/config-supported unless a specific marketplace approval or certification artifact is present.","cause":"Configuration support, OAuth readiness, pilot evidence, and marketplace approval are separate claims.","id":"ga-certified","question":"Is XMemo GA, certified, or marketplace listed?","safety":"Do not claim GA, certified, stable, or listed status from a working config alone.","symptom":"A listing or document asks whether a working configuration proves GA, certification, or marketplace approval.","verification":"Check the canonical client capability matrix and the named approval artifact before publishing a status claim."},{"action":"Hosted users should start with https://xmemo.dev/mcp for MCP clients and https://xmemo.dev/product/docs for guided setup.","cause":"Hosted onboarding and self-hosted or legacy deployment paths have different URLs, credentials, and data boundaries.","id":"which-url","question":"Which URL should I use?","safety":"Do not use localhost, Supabase, Docker, or self-hosted Python instructions as the first path for public hosted users.","symptom":"A hosted user is unsure whether to follow the public quickstart, MCP endpoint, or self-hosted developer instructions.","verification":"Confirm that the host URL, authentication mode, and account boundary match the intended hosted or self-hosted deployment before connecting."},{"action":"Check the non-secret agent/device headers or client profile, then persist the local instance ID instead of regenerating it.","cause":"The client changed its non-secret agent or instance headers, or a shared credential is being used by multiple runners.","id":"wrong-agent","question":"Memory appears under the wrong agent or device.","safety":"Attribution labels help review source, but they are not a security boundary; account credentials still decide access.","symptom":"A memory is attributed to another runner or appears split across devices after a client update or restart.","verification":"Write one synthetic record from the intended runner and confirm its source attribution remains stable after reconnect."},{"action":"Open Support with the client name, config path, approximate timestamp, and whether the client uses OAuth or XMEMO_KEY.","cause":"The remaining issue may be client-specific, account-specific, or caused by a stale registration or environment boundary that local docs cannot inspect.","id":"support-needed","question":"I still cannot connect after following the steps.","safety":"Share redacted diagnostics only; never send bearer tokens, OAuth codes, cookies, or customer memory content.","symptom":"The connection remains unavailable after the client-specific OAuth or direct-secret path has been retried.","verification":"Confirm that the support report contains a reproducible symptom and redacted metadata, then wait for the account-scoped diagnosis."}],"safetyLabel":"Safety:","title":"FAQ / Troubleshooting"},"hostedQuickstart":{"body":"Start with the managed XMemo service and one of these connection paths. Self-hosted, Docker, Supabase, and Python package setup are developer references, not the first path for hosted users.","steps":[{"body":"Use this path for ChatGPT, OpenAI app review, VS Code, and GitHub Copilot when the host supports OAuth. Add the hosted MCP URL, approve memory:read and memory:write, and do not paste XMEMO_KEY into the client config.","config":"MCP URL: https://xmemo.dev/mcp\nScopes: memory:read memory:write","id":"oauth-clients","title":"OAuth clients"},{"body":"Use the public CLI to discover the hosted service, review the generated MCP profile, and copy only client-safe configuration into your local tool.","config":"npm install -g @xmemo/client\nnpx @xmemo/client setup --url https://xmemo.dev","id":"cli-setup","title":"@xmemo/client setup"},{"body":"Use this path only for clients or headless runners that cannot complete OAuth. Store XMEMO_KEY in the local environment or secret store, keep the hosted MCP URL in config, and never paste the real token into public docs or chat.","config":"MCP URL: https://xmemo.dev/mcp\nToken source: XMEMO_KEY environment variable\nOptional identity: XMEMO_AGENT_INSTANCE_ID","id":"direct-mcp","title":"Direct MCP with XMEMO_KEY"},{"body":"After the first connection, use the account entry to review what was saved, check agent attribution, and find delete/export or support paths before expanding a pilot.","config":"Account entry: https://xmemo.dev/login","id":"account-controls","title":"Account controls"}],"title":"Hosted XMemo quickstart"},"isDocsHost":true,"labels":{"accountEntry":"Account entry","agentInstallExplanation":"Paste this into an agent you trust to follow its normal safety checks.","agentMemoryControlPlane":"AI agent memory layer","askAgentInstall":"Ask your agent","brand":"XMemo","brandHome":"XMemo home","cachedPublicResourceRoute":"Showing the cached public resource route while the context API recovers.","canonicalCapabilityMatrix":"Open the canonical client capability matrix","changelog":"Changelog","clientTargets":"client targets","commandPalette":"Command palette","configPath":"Config path:","copied":"Copied","copy":"Copy","copyAsMarkdown":"Copy as Markdown ▾","copyConfig":"Copy config","copyFailed":"Copy failed. Select the command text, then press Ctrl+C or Command+C.","copyInstallCommand":"Copy install command","copyPowerShellInstallCommand":"Copy PowerShell install command","copyUnavailable":"Copy unavailable","credentialHandoff":"credential handoff","curlInstall":"curl","docs":"Docs","docsDesc":"Hosted XMemo quickstart for people connecting MCP clients.","docsHeader":"Docs header","docsLead":"Start with what XMemo does for you, then connect the hosted memory layer to the client you use.","docsVersion":"Hosted · Beta pilot","downloadSkillPackage":"Download Skill package","inThisArticle":"In this article","inspectInstallScript":"Inspect install script","installSkillTitle":"Install the Skill","installTool":"Download tool","invitedOnly":"invited only","language":"Language","loadingProductContext":"Loading product context","login":"Log in / Sign up","macosLinuxInstall":"macOS, Linux, and WSL","mcp":"MCP","mcpDesc":"Configure ChatGPT, VS Code / GitHub Copilot, Copilot CLI, Codex, Gemini CLI, Cursor, and custom MCP clients.","mcpDocsRedirect":"MCP setup details, client snippets, and tool explanations are organized in Docs.","mcpNpmQuickSetup":"⚡ Quick setup: run \u003ccode\u003enpx @xmemo/client setup --url https://xmemo.dev\u003c/code\u003e to auto-generate per-client instance IDs and apply reviewed config for supported clients.","mcpSetupConsole":"MCP setup console","mcpSetupDescription":"Pick the MCP client to see the public-safe snippet for its settings surface. OAuth snippets omit bearer tokens; direct snippets reference \u003ccode\u003eXMEMO_KEY\u003c/code\u003e only when needed plus generated, non-secret agent identity headers instead of literal credentials.","navTrust":"Trust","noMatches":"No matches.","openAccountEntry":"Open account entry ↗","openDocsChapter":"Open Docs chapter","openProductNavigation":"Open public navigation","pasteSnippet":"Paste the selected snippet into the listed config path or dashboard, keep the hosted URL as shown, and set XMEMO_AGENT_INSTANCE_ID once per local client when the snippet references it. Then complete OAuth for OAuth clients or restart the direct MCP client.","perClientMcpConfigPreview":"Per-client MCP config preview","personaConnection":"Connection","personaFlowsBody":"Choose the path that matches how you want to use XMemo. Each flow keeps credentials out of public docs and ends with a concrete memory action.","personaFlowsTitle":"Persona onboarding flows","personaGoal":"Goal","personaSuccessAction":"Success action","personaTroubleshooting":"Troubleshooting","pilotAccess":"Pilot access","posixInstallCommand":"macOS, Linux, and WSL","posixInstallExplanation":"Use this in macOS, Linux, or WSL.","powershellInstallCommand":"Windows PowerShell","powershellInstallExplanation":"Use this in Windows PowerShell.","product":"Home","productContextUnavailable":"Product context unavailable","productDesc":"Back to the XMemo overview.","productHome":"Home","publicNavigation":"XMemo public navigation","publicResources":"XMemo public resources","publicSafeNote":"Public-safe page: only hosted public URLs are shown; no console links, credential values, or internal control-plane endpoints are exposed here.","quickSetup":"Quick setup","quickstart":"Quickstart for XMemo","search":"Search","searchDocs":"Search docs","searchPlaceholder":"Search docs, MCP, skills, install…","skills":"Skills","skillsDesc":"Connect XMemo as an agent Skill in addition to MCP.","skillsDocsRedirect":"Skill connector guidance and agent command patterns are organized in Docs.","start":"Get started","startPilot":"Start pilot","startPilotDesc":"Jump to the public pilot path.","stories":"Stories","storiesDesc":"Milestones, ecosystem launches, and source-backed XMemo updates.","supportedMcpClients":"Supported MCP clients","typeToFilter":"Type to filter","wgetAlternative":"Alternative with wget","wgetInstall":"wget","windowsInstall":"Windows PowerShell"},"mcpClientSnippets":[{"certificationStatus":"Evidence required","config":"{\n \"servers\": {\n \"XMemo\": {\n \"type\": \"http\",\n \"url\": \"https://xmemo.dev/mcp\"\n }\n }\n}","id":"vscode","label":"VS Code / GitHub Copilot","marketplaceStatus":"Marketplace pending","note":"OAuth client: keep only the hosted server URL in mcp.json; first tool call opens browser OAuth, so no XMEMO_KEY or Authorization header belongs in this file.","path":"%APPDATA%\\Code\\User\\mcp.json","readinessBadges":["OAuth ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix for the canonical OAuth, transport, auth, and evidence status."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"url\": \"https://xmemo.dev/mcp\",\n \"headers\": {\n \"Authorization\": \"Bearer ${env:XMEMO_KEY}\",\n \"X-Memory-OS-Agent-ID\": \"cursor\",\n \"X-Memory-OS-Agent-Instance-ID\": \"${XMEMO_AGENT_INSTANCE_ID}\"\n }\n }\n }\n}","id":"cursor","label":"Cursor","marketplaceStatus":"Marketplace pending","note":"Direct client: configure in ~/.cursor/mcp.json with XMEMO_KEY in the environment. Run npx @xmemo/client mcp add cursor to install automatically.","path":"~/.cursor/mcp.json","readinessBadges":["Direct MCP ready","OAuth ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; this matches the authoritative config installed by @xmemo/client."},{"certificationStatus":"Evidence required","config":"[mcp_servers.XMemo]\nurl = \"https://xmemo.dev/mcp\"\nbearer_token_env_var = \"XMEMO_KEY\"\n\n[mcp_servers.XMemo.http_headers]\nX-Memory-OS-Agent-ID = \"codex\"\nX-Memory-OS-Agent-Instance-ID = \"${XMEMO_AGENT_INSTANCE_ID}\"\n","id":"codex","label":"Codex","marketplaceStatus":"Planned","note":"Direct client: Codex reads XMEMO_KEY through bearer_token_env_var and sends non-secret identity headers. Run npx @xmemo/client mcp add codex --write to generate the stable XMEMO_AGENT_INSTANCE_ID automatically.","path":"~/.codex/config.toml","readinessBadges":["Direct MCP ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; this config matches @xmemo/client toml output."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"httpUrl\": \"https://xmemo.dev/mcp\",\n \"headers\": {\n \"X-Memory-OS-Agent-ID\": \"gemini-cli\",\n \"X-Memory-OS-Agent-Instance-ID\": \"${XMEMO_AGENT_INSTANCE_ID}\"\n }\n }\n }\n}","id":"gemini-cli","label":"Gemini CLI","marketplaceStatus":"Planned","note":"OAuth client: merge this XMemo block into settings.json, set one stable XMEMO_AGENT_INSTANCE_ID for local attribution, then restart Gemini CLI and complete MCP OAuth. Do not add Authorization or XMEMO_KEY to this snippet.","path":"~/.gemini/settings.json","readinessBadges":["OAuth ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; this OAuth config does not imply a Gemini marketplace listing."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"command\": \"npx\",\n \"args\": [\n \"-y\",\n \"mcp-remote\",\n \"https://xmemo.dev/mcp\",\n \"--header\",\n \"Authorization:Bearer ${XMEMO_KEY}\",\n \"--header\",\n \"X-Memory-OS-Agent-ID:claude-desktop\",\n \"--header\",\n \"X-Memory-OS-Agent-Instance-ID:${XMEMO_AGENT_INSTANCE_ID}\"\n ],\n \"env\": {\n \"XMEMO_KEY\": \"${env:XMEMO_KEY}\",\n \"XMEMO_AGENT_INSTANCE_ID\": \"${XMEMO_AGENT_INSTANCE_ID}\"\n }\n }\n }\n}","id":"claude","label":"Claude Desktop","marketplaceStatus":"Marketplace pending","note":"Stdio bridge: Claude Desktop uses mcp-remote to connect to hosted streamable-http with XMEMO_KEY from the environment. Run npx @xmemo/client mcp add claude-desktop to configure automatically.","path":"%APPDATA%\\Claude\\claude_desktop_config.json","readinessBadges":["Direct MCP ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; this matches the authoritative config installed by @xmemo/client."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"serverUrl\": \"https://xmemo.dev/mcp\",\n \"headers\": {\n \"Authorization\": \"Bearer ${env:XMEMO_KEY}\",\n \"X-Memory-OS-Agent-ID\": \"windsurf\",\n \"X-Memory-OS-Agent-Instance-ID\": \"${env:XMEMO_AGENT_INSTANCE_ID}\"\n }\n }\n }\n}","id":"windsurf","label":"Devin Desktop (formerly Windsurf)","marketplaceStatus":"Planned","note":"Direct client: configure manually in ~/.config/devin/mcp_config.json (%APPDATA%\\devin\\mcp_config.json on Windows) with XMEMO_KEY in the environment. Note: npx @xmemo/client mcp add windsurf currently writes the pre-rename location ~/.codeium/windsurf/mcp_config.json (useful only for pre-rename installs), so Devin Desktop users should configure manually or move the file.","path":"~/.config/devin/mcp_config.json","readinessBadges":["Direct MCP ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; configure manually at ~/.config/devin/mcp_config.json."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"url\": \"https://xmemo.dev/mcp\",\n \"headers\": {\n \"X-Memory-OS-Agent-ID\": \"kiro\",\n \"X-Memory-OS-Agent-Instance-ID\": \"${XMEMO_AGENT_INSTANCE_ID}\"\n },\n \"oauth\": {\n \"oauthScopes\": [\n \"memory:read\",\n \"knowledge:read\"\n ]\n }\n }\n }\n}","id":"kiro","label":"Kiro","marketplaceStatus":"Planned","note":"OAuth client: configure in ~/.kiro/settings/mcp.json. Supports OAuth with memory:read and knowledge:read scopes. Run npx @xmemo/client mcp add kiro to install automatically.","path":"~/.kiro/settings/mcp.json","readinessBadges":["OAuth ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; this matches the authoritative config installed by @xmemo/client."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"url\": \"https://xmemo.dev/mcp\",\n \"headers\": {\n \"Authorization\": \"Bearer ${env:XMEMO_KEY}\",\n \"X-Memory-OS-Agent-ID\": \"openclaw\",\n \"X-Memory-OS-Agent-Instance-ID\": \"${XMEMO_AGENT_INSTANCE_ID}\"\n }\n }\n }\n}","id":"openclaw","label":"OpenClaw","marketplaceStatus":"Planned","note":"Direct client: configure in ~/.openclaw/openclaw.json with XMEMO_KEY in the environment. Run npx @xmemo/client mcp add openclaw to install automatically.","path":"~/.openclaw/openclaw.json","readinessBadges":["Direct MCP ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; this matches the authoritative config installed by @xmemo/client."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"type\": \"http\",\n \"url\": \"https://xmemo.dev/mcp\",\n \"tools\": [\"*\"],\n \"timeout\": 30000,\n \"headers\": {\n \"Authorization\": \"Bearer \u003creplace-with-XMEMO_KEY-or-supported-secret-reference\u003e\",\n \"X-Memory-OS-Agent-ID\": \"copilot-cli\",\n \"X-Memory-OS-Agent-Instance-ID\": \"\u003cstable-local-copilot-cli-instance-id\u003e\"\n }\n }\n }\n}","id":"copilot-cli","label":"Copilot CLI","marketplaceStatus":"Marketplace pending","note":"Direct client: set XMEMO_KEY in the user environment or a supported secret reference, then replace the stable instance placeholder before applying the reviewed config.","path":"~/.copilot/mcp-config.json","readinessBadges":["Direct MCP ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; the direct Copilot CLI path still needs current client evidence."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"url\": \"https://xmemo.dev/mcp\",\n \"transport\": \"streamable-http\",\n \"auth\": {\n \"type\": \"oauth2\",\n \"resource\": \"https://xmemo.dev/mcp\",\n \"scopes\": [\"memory:read\", \"memory:write\"]\n }\n }\n }\n}","id":"chatgpt","label":"ChatGPT / OpenAI Apps SDK","marketplaceStatus":"Marketplace pending","note":"OAuth marketplace lane: configure the hosted MCP URL and OAuth metadata in the OpenAI app dashboard; never paste XMEMO_KEY or Bearer tokens into the listing.","path":"OpenAI Platform app management dashboard","readinessBadges":["OAuth ready","Hosted beta pilot","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; do not infer Certified/listed from OAuth readiness."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"type\": \"http\",\n \"transport\": \"streamable-http\",\n \"url\": \"https://xmemo.dev/mcp\",\n \"headers\": {\n \"X-Memory-OS-Agent-ID\": \"autonomous-agent\",\n \"X-Memory-OS-Agent-Instance-ID\": \"${XMEMO_AGENT_INSTANCE_ID}\"\n },\n \"auth\": {\n \"type\": \"oauth2\",\n \"flow\": \"authorization_code\",\n \"pkce_required\": true,\n \"resource\": \"https://xmemo.dev/mcp\",\n \"scopes\": [\"memory:read\", \"memory:write\"]\n },\n \"fallback\": {\n \"use_when\": \"headless runner cannot complete OAuth sign-in or persist OAuth tokens\",\n \"authorization_header\": \"Bearer ${XMEMO_KEY}\"\n }\n }\n }\n}","id":"autonomous-agent","label":"Autonomous agent","marketplaceStatus":"Planned","note":"OAuth-first self-config preset: fetch /api/v1/mcp/config/autonomous-agent, use auth_modes.oauth when the runner supports OAuth + custom headers, fall back to auth_modes.xmemo_key for headless runners, and never ask the human for agent_id or instance_id.","path":"Agent runner MCP config","readinessBadges":["OAuth ready","Direct MCP ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; identity is generated by the runner, not typed by the user."},{"certificationStatus":"Evidence required","config":"{\n \"mcpServers\": {\n \"XMemo\": {\n \"transport\": \"streamable-http\",\n \"url\": \"https://xmemo.dev/mcp\",\n \"headers\": {\n \"Authorization\": \"Bearer ${XMEMO_KEY}\",\n \"X-Memory-OS-Agent-ID\": \"${XMEMO_AGENT_ID}\",\n \"X-Memory-OS-Agent-Instance-ID\": \"${XMEMO_AGENT_INSTANCE_ID}\"\n }\n }\n }\n}","id":"other","label":"Other","marketplaceStatus":"Planned","note":"Generic direct client: the client must support streamable-http and Authorization headers; set XMEMO_AGENT_ID and a stable XMEMO_AGENT_INSTANCE_ID only for non-secret attribution.","path":"Any MCP-capable agent","readinessBadges":["Direct MCP ready","Config supported","Evidence required"],"readinessNote":"See /product/docs#client-capability-matrix; compatibility depends on Streamable HTTP and header support."}],"memoryConsoleStory":{"body":"XMemo is not only an MCP endpoint. The Memory Console is the user-facing place to review, correct, remove, and export memory while keeping agent attribution visible.","features":[{"body":"Open the console to see saved memories, inspect paths and memory types, and confirm whether a recall should have returned a specific item.","id":"view-search","title":"View and search memory"},{"body":"Correct stale facts, move items to clearer paths, or replace outdated notes so future assistants recall the latest user-approved context.","id":"edit-correct","title":"Edit or correct entries"},{"body":"Use account workflows to remove memories you no longer want and to locate export paths for account-scoped memory review.","id":"delete-export","title":"Delete and export"},{"body":"Review which client or runner wrote a memory, including non-secret agent and instance labels when the client sends them.","id":"agent-attribution","title":"Agent attribution"},{"body":"Keep OAuth consent, direct-token usage, environment-secret handoff, and support boundaries visible before expanding a personal or team pilot.","id":"privacy-controls","title":"Privacy and credential controls"}],"title":"Memory Console controls","trustCta":"Where is my data?","trustHref":"/trust#user-memory-controls"},"page":"docs","pageId":"docs:tools:todos","personaFlows":[{"connection":"Connect the hosted XMemo MCP server through the ChatGPT/OpenAI app OAuth flow, then approve the memory:read and memory:write grant for your XMemo account.","goal":"Give ChatGPT durable access to your XMemo preferences, project facts, decisions, and TODOs without pasting bearer tokens into a chat.","id":"chatgpt-user","successAction":"Save a synthetic preference or project note, start a new chat, then ask ChatGPT to recall it through XMemo before continuing work.","title":"ChatGPT user","troubleshooting":"If OAuth fails or tools do not appear, sign out of the MCP server in the host app, reconnect the XMemo server URL, and retry before creating direct tokens."},{"connection":"Use OAuth for VS Code / GitHub Copilot and Gemini CLI when available. For Copilot CLI, Codex, Cursor, or other direct MCP clients, keep XMEMO_KEY in the local environment or secret store and set a stable XMEMO_AGENT_INSTANCE_ID.","goal":"Carry repo decisions, coding conventions, bug-fix notes, and task history between IDE and CLI agents.","id":"developer-agent","successAction":"Record a codebase decision or bug fix, then ask the next IDE or CLI agent to recall the relevant XMemo context before editing.","title":"Copilot / Codex developer","troubleshooting":"If recalls are empty, verify the selected MCP config path, the XMEMO_KEY environment variable for direct clients, and any stale OAuth credential in the host app."},{"connection":"Create or enter the protected XMemo workspace, invite approved users, then connect each client through OAuth or a scoped direct credential according to the readiness badges.","goal":"Evaluate shared memory with account controls, source attribution, export/delete workflows, and reviewer-safe setup evidence.","id":"enterprise-pilot-owner","successAction":"Have a pilot member save a synthetic team memory, confirm source attribution in XMemo, then review delete/export and support paths.","title":"Team / enterprise pilot owner","troubleshooting":"If a member cannot connect, check role permissions, OAuth approval, client readiness status, and support guidance before issuing a new token."},{"connection":"Fetch /api/v1/mcp/config/autonomous-agent. Prefer auth_modes.oauth when the runner supports OAuth + custom headers; use auth_modes.xmemo_key with XMEMO_KEY from a secret store only for fully headless runners.","goal":"Let headless or scheduled agents record progress, retrieve prior decisions, and keep a stable non-secret instance identity.","id":"autonomous-operator","successAction":"Run one synthetic task that writes progress to XMemo, restart the runner, and confirm it recalls that progress using the same XMEMO_AGENT_INSTANCE_ID.","title":"Autonomous agent operator","troubleshooting":"If attribution changes or recalls split across instances, persist XMEMO_AGENT_INSTANCE_ID outside git and verify the runner is not regenerating it on every start."}],"publicBaseUrl":"https://xmemo.dev","sections":[{"body":"The discovery response advertises the @xmemo/client CLI package, streamable-http MCP transport, supported MCP clients, onboarding status, auth metadata, and the MCP tool catalog.","code":"","item_list":[{"desc":"@xmemo/client is the published package name exposed by discovery and the public-home install bar.","name":"CLI package"},{"desc":"The MCP catalog includes ChatGPT, VS Code / GitHub Copilot, copilot-cli, codex, gemini-cli, cursor, and generic direct MCP clients.","name":"Supported clients"},{"desc":"Discovery lists recall, remember, state, reflection, feedback, audit, and system-stat tools.","name":"MCP tools"},{"desc":"Discovery declares token env vars and explicitly does not include token material.","name":"Auth boundary"}],"kicker":"Discovery","kind":"","title":"Implemented hosted-service surfaces"},{"body":"Once the CLI is installed, the customer points it at the approved service URL. The hosted contract documents discovery, onboarding status, manual MCP config templates, operator-provisioned tokens, and env-var based MCP config.","code":"# Customer-side, after npm install -g @xmemo/client\nnpx @xmemo/client setup --url https://xmemo.dev\n\n# CLI internally: discovery -\u003e status -\u003e MCP config template -\u003e\n# operator token handoff -\u003e local client configuration.","item_list":[],"kicker":"Discovery setup","kind":"","title":"xmemo setup --url drives the entire trial"},{"body":"Autonomous runners should fetch /api/v1/mcp/config/autonomous-agent and choose auth_modes.oauth when they can complete OAuth and send custom identity headers. If the runner is fully headless or cannot persist OAuth tokens, it should use auth_modes.xmemo_key with XMEMO_KEY from a secret store. The agent id is fixed as autonomous-agent, while XMEMO_AGENT_INSTANCE_ID must be generated once by the runner and reused; the human should not type either identity value.","code":"GET https://xmemo.dev/api/v1/mcp/config/autonomous-agent\n# Preferred: auth_modes.oauth.mcpServers.XMemo\n# Headless fallback: auth_modes.xmemo_key.mcpServers.XMemo\n# Required identity: X-Memory-OS-Agent-ID=autonomous-agent\n# Runner generates and persists: XMEMO_AGENT_INSTANCE_ID","item_list":[],"kicker":"Autonomous agents","kind":"","title":"OAuth first, runner-generated identity"},{"body":"Agents talk to XMemo through the TypeScript SDK helpers, streamable-http MCP server, or REST. The SDK exposes workflow helpers and capture policy redaction before memory writes.","code":"","item_list":[{"desc":"Bound an agent run to a memory scope so resume and handoff work across sessions.","name":"taskStart / taskEnd"},{"desc":"Persist architecture or product decisions with rationale and source identity.","name":"recordDecision"},{"desc":"Log fixes so future runs recall the root cause and remediation.","name":"recordBugFix"},{"desc":"Run any normalized agent event through capture policy before remember().","name":"captureEvent"},{"desc":"Pull recent decisions and procedural notes back into agent context with explanation.","name":"recallContext / search"}],"kicker":"Capture surfaces","kind":"","title":"What agents can do once connected"},{"body":"The hosted discovery contract requires read-only discovery, secret-free MCP config templates, no remote shell or PowerShell execution paths, and secrets stored through environment variables or a system secret store.","code":"","item_list":[],"kicker":"Safety","kind":"","title":"Manual onboarding guarantees"}],"siblings":[{"active":true,"label":"Docs","slug":"docs"},{"active":false,"label":"MCP","slug":"mcp"},{"active":false,"label":"Skills","slug":"skills"},{"active":false,"label":"Changelog","slug":"changelog"},{"active":false,"label":"Stories","slug":"stories"}],"skillCapability":null,"skillPackage":null,"stories":[],"storiesMeta":{},"whereIsMyData":{"callout":"XMemo public pages never ask you to paste API keys. Agent and MCP configuration should reference environment variables or the official client configuration surface.","eyebrow":"XMemo Security Modes","footer":"Source-backed by docs/security/where-is-my-data.md, the setup wizard state machine, and XMemo security-mode APIs.","group":"Security","headers":["Mode","Where ciphertext lives","Who can decrypt","Best fit"],"lead":"This page explains what XMemo stores for each security mode, where it is processed, who can decrypt it, what happens during export or deletion, and how you can verify the active boundary from your own account.","meta":"XMemo explains where memory data lives, who can decrypt it, and how Cloud, Keyguard, and Vault security modes differ.","nav":{"privacy":"Privacy policy","product":"Product docs","settings":"Security settings","trust":"Trust center"},"nav_label":"XMemo security documentation","quick_title":"Quick comparison","rows":[{"code":"cloud","fit":"Fast setup, full hosted recall, no device or recovery-key burden.","name":"Cloud-managed mode","where":"XMemo managed data plane with access controls, application-scoped authorization, and audit trails. Database RLS is deployment-specific.","who":"XMemo server can process memory content for recall, search, ranking, and supportable exports."},{"code":"keyguard","fit":"Enterprise teams that need hosted recall plus customer-managed key control.","name":"Keyguard mode","where":"XMemo managed Postgres, but envelope keys are bound to your tenant KMS / HSM.","who":"The server can decrypt only when your KMS grant allows unwrap operations."},{"code":"vault","fit":"Zero-knowledge custody where losing all devices and recovery material means permanent loss.","name":"Vault mode","where":"XMemo managed Postgres stores opaque ciphertext and envelope metadata.","who":"Only enrolled devices or your recovery kit can decrypt. XMemo cannot recover plaintext."}],"sections":[{"body":"Memory data is stored in the XMemo managed data plane with access controls, application-scoped authorization, and audit trails. Database RLS is deployment-specific.","items":["The XMemo server can process memory content for server-side semantic recall, ranking, and exports.","This is the most convenient mode, but it is not zero-knowledge.","Deletion removes memory rows and associated metadata. DSAR exports can include plaintext because the service can process memory content on your behalf."],"title":"Cloud-managed mode"},{"body":"Keyguard keeps XMemo's hosted recall experience while binding envelope operations to a key your organization controls in Azure Key Vault, AWS KMS, GCP KMS, KMIP, or a similar provider.","items":["The wizard stores the KMS binding in setup preflight data and commits personal_default_mode = keyguard.","Recall requires your KMS grant to remain valid. Revoking the grant blocks future decrypt/unwrap operations.","XMemo deletes its ciphertext and metadata on account deletion; your tenant remains responsible for KMS key rotation or destruction."],"title":"Keyguard mode"},{"body":"Vault is the zero-knowledge option. The browser/device encrypts before data leaves the device, and the server stores only ciphertext plus routing and envelope metadata.","items":["XMemo cannot decrypt vault memories, cannot reset your vault key, and cannot recover data if every enrolled device and recovery kit is lost.","DSAR exports for vault data contain ciphertext and envelope metadata. You decrypt them locally with your device or recovery kit.","Hosted semantic features may be limited unless the feature can operate on client-provided or privacy-preserving representations."],"title":"Vault mode"},{"body":"XMemo production is designed around operator-managed Postgres with TLS verification and application-scoped authorization. Database RLS/runtime context is deployment-specific and requires target verification. Supabase is treated as a development and compatibility backend only, not as the supported production substrate for these custody claims.","items":["Managed Postgres: the production storage boundary for account, memory, vector, setup, and audit records.","Database RLS/runtime context: deployment-specific controls that require target verification of the runtime role, migration ledger, runtime-context flag, and owner/team CRUD matrix.","Supabase compatibility: useful for local or OSS adoption, but its service-role behavior is not equivalent to production hardening."],"title":"Production data boundary"}],"stores":["Memory records: memory text or ciphertext, metadata, ownership, timestamps, and vector-search data needed for recall.","Account setup state: selected security mode, setup completion state, mode-change count, and preflight proof such as a KMS binding id or vault recovery marker.","Access and audit records: sessions, hashed or scoped credentials, identity links, and audit events such as setup_state_transition."],"stores_title":"What XMemo stores","title":"Where is my data?","verify":["Open Memory Console -\u003e Settings -\u003e Security mode and confirm the mode shown there.","Call GET /api/v1/me/setup/state; completed accounts should show setup_state = setup_completed and the expected selected_mode.","Call GET /api/v1/me/security-mode; the posture should include verified_effective_mode, new_write_mode, pending_write_mode, legacy_read_mode, and migration_status.","For Keyguard, compare the displayed key binding id with your KMS audit log. For Vault, confirm outbound writes contain opaque ciphertext with no recognizable plaintext substring."],"verify_title":"How to verify your active mode"}}{"contentLocale":"en-US","docsNavTree":[{"description":"Connect one client, save useful context, recall it later, and keep credentials out of public configuration.","group":"Start","kind":"quickstart","label":"Quickstart","path":"/docs/quickstart","section":"Start","sectionId":"start","serverOwned":false,"steps":[{"id":"1-choose-client-and-auth-mode","label":"1. Choose client \u0026 auth"},{"id":"2-configure-client-without-exposing-tokens","label":"2. Configure client"},{"id":"3-verify-connection-with-read-only-check","label":"3. Verify connection"},{"id":"4-save-an-explicit-synthetic-fact","label":"4. Save first fact"},{"id":"5-open-a-fresh-client-session","label":"5. Fresh session"},{"id":"6-recall-fact-with-source-attribution","label":"6. Recall \u0026 attribute"},{"id":"7-correct-convention-with-update_memory","label":"7. Correct fact"}],"tab":"Get started","tabId":"get-started"},{"description":"Authoritative architecture and public boundary: server composition, execution lifecycle, subsystem nodes, and managed cloud boundary.","group":"Core concepts","kind":"concept","label":"How XMemo works","path":"/docs/concepts/how-xmemo-works","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Understand durable facts, decisions, handoffs, and source attribution before choosing an integration.","group":"Core concepts","kind":"concept","label":"Memory model","path":"/docs/concepts/memory-model","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Keep user-owned memory boundaries explicit as clients and agents move between projects and sessions.","group":"Core concepts","kind":"concept","label":"Scopes","path":"/docs/concepts/scopes","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Use stable, non-secret agent and instance labels so later recalls retain source context.","group":"Core concepts","kind":"concept","label":"Agent identity","path":"/docs/concepts/agent-identity","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Separate the non-secret installation label used for attribution from the credential that authorizes requests.","group":"Core concepts","kind":"concept","label":"Agent instance identity","path":"/docs/concepts/agent-instance-identity","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Preserve where a memory came from without confusing source metadata with authorization or ownership.","group":"Core concepts","kind":"concept","label":"Provenance and attribution","path":"/docs/concepts/provenance-attribution","section":"Core concepts","sectionId":"core-concepts","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Carry project facts, decisions, and handoff notes across approved clients without copying them between chats.","group":"Capabilities","kind":"concept","label":"Projects","path":"/docs/concepts/projects","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Tenant-isolated shared memory spaces for collaborative agent teams. Space administrators manage workspace bounds on the management plane while memory access is partitioned by data-plane seats.","group":"Capabilities","kind":"concept","label":"Teams","path":"/docs/capabilities/teams","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Keep owner-scoped knowledge in immutable revisions and retrieve either published current content or one exact addressed version.","group":"Capabilities","kind":"concept","label":"Knowledge Bases","path":"/docs/concepts/knowledge-bases","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Recall reusable, versioned procedures progressively and execute only their declared script components inside the Cloud Skill sandbox.","group":"Capabilities","kind":"concept","label":"Cloud Skills","path":"/docs/concepts/cloud-skills","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Periodically consolidate episodic evidence into semantic memory and apply explicit expiry, decay, and archive policies.","group":"Capabilities","kind":"concept","label":"Dream / Reflection","path":"/docs/concepts/dream-reflection","section":"Capabilities","sectionId":"capabilities","serverOwned":false,"tab":"Concepts","tabId":"concepts"},{"description":"Cross-agent durable memory configuration for Claude, ChatGPT, Codex, GitHub Copilot, and OpenClaw via hosted MCP endpoints.","group":"Connect","kind":"mcp","label":"MCP overview","path":"/docs/mcp/overview","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Connect ChatGPT through the hosted OAuth flow and approve the memory:read and memory:write scopes.","group":"Connect","kind":"mcp","label":"ChatGPT","path":"/docs/mcp/chatgpt","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the direct MCP path with XMEMO_KEY from a local environment or supported secret store.","group":"Connect","kind":"mcp","label":"Claude Code","path":"/docs/mcp/claude-code","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Use the Codex MCP profile with bearer_token_env_var and a stable local instance identity.","group":"Connect","kind":"mcp","label":"Codex","path":"/docs/mcp/codex","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Choose the reviewed Cursor config path and keep credentials in the client environment or secret store.","group":"Connect","kind":"mcp","label":"Cursor","path":"/docs/mcp/cursor","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Use the OAuth-first Gemini CLI configuration without placing bearer credentials in settings.json.","group":"Connect","kind":"mcp","label":"Gemini CLI","path":"/docs/mcp/gemini","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Connect VS Code and GitHub Copilot through the hosted OAuth configuration when the host supports it.","group":"Connect","kind":"mcp","label":"GitHub Copilot","path":"/docs/mcp/copilot","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the direct bearer-token Copilot CLI MCP client with XMEMO_KEY and stable instance attribution.","group":"Connect","kind":"mcp","label":"Copilot CLI","path":"/docs/mcp/copilot-cli","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the direct Devin Desktop (formerly Windsurf) MCP client with XMEMO_KEY and stable instance attribution.","group":"Connect","kind":"mcp","label":"Devin Desktop (formerly Windsurf)","path":"/docs/mcp/windsurf","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Configure the Kiro OAuth MCP client with memory:read and knowledge:read scopes.","group":"Connect","kind":"mcp","label":"Kiro","path":"/docs/mcp/kiro","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Recall-first Skill guidance plus a native OpenClaw memory plugin for durable, user-owned context across sessions.","group":"Connect","kind":"mcp","label":"OpenClaw","path":"/docs/connect/openclaw","section":"Connect","sectionId":"connect","serverOwned":false,"tab":"Connect","tabId":"connect"},{"description":"Correct a durable record through the versioned update path while preserving provenance and conflict signals.","group":"Guides","kind":"concept","label":"Memory correction","path":"/docs/concepts/memory-correction","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Choose the recoverable forget path or an explicitly authorized destructive mode with an auditable tombstone.","group":"Guides","kind":"concept","label":"Memory deletion","path":"/docs/concepts/memory-deletion","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Hand off a decision, implementation fix, and bounded context between named agents using the existing SDK and MCP contracts.","group":"Guides","kind":"operations","label":"Cross-agent workflow","path":"/docs/operations/cross-agent-workflow","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Move from a legacy or direct-client setup while preserving scope, identity, and deletion boundaries.","group":"Guides","kind":"operations","label":"Migration","path":"/docs/migration","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Use symptom, cause, action, and safety guidance when OAuth, MCP discovery, or recall does not behave as expected.","group":"Guides","kind":"operations","label":"Troubleshooting","path":"/docs/troubleshooting","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Architectural evaluation criteria, vendor-neutral memory layer checklist, scenario-based selection, reproducible benchmarks, and migration guide.","group":"Guides","kind":"concept","label":"Evaluate \u0026 compare","path":"/docs/guides/evaluate","section":"Guides","sectionId":"guides","serverOwned":false,"tab":"Get started","tabId":"get-started"},{"description":"Write durable memory only after capture policy, scope, and secret-redaction boundaries are satisfied.","group":"Reference","kind":"tool","label":"remember","path":"/docs/tools/remember","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Retrieve relevant durable context when an agent needs a focused answer from an approved memory scope.","group":"Reference","kind":"tool","label":"recall","path":"/docs/tools/recall","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Restore the recent project and agent context needed to continue work across sessions.","group":"Reference","kind":"tool","label":"recall_context","path":"/docs/tools/recall-context","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Search authorized memory when the relevant wording or record is not known in advance.","group":"Reference","kind":"tool","label":"search","path":"/docs/tools/search","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Delete a reviewed memory, TODO, or Ledger record through the user-owned control boundary, with soft deletion recoverable and hard deletion permanent.","group":"Reference","kind":"tool","label":"forget","path":"/docs/tools/forget","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Keep task state and handoff notes close to the project context that makes them useful.","group":"Reference","kind":"tool","label":"todos","path":"/docs/tools/todos","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Use governed ledger and reminder surfaces when an agent needs durable operational context.","group":"Reference","kind":"tool","label":"ledger","path":"/docs/tools/ledger","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Save or update a reusable Cloud Skill and create its next versioned revision.","group":"Reference","kind":"tool","label":"save_cloud_skill","path":"/docs/tools/save-cloud-skill","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Discover Cloud Skills, load a root manifest, or fetch one resource from an explicitly pinned revision.","group":"Reference","kind":"tool","label":"recall_cloud_skill","path":"/docs/tools/recall-cloud-skill","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Run one declared script component from an active Cloud Skill through the isolated execution engine.","group":"Reference","kind":"tool","label":"execute_cloud_skill","path":"/docs/tools/execute-cloud-skill","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Run a bounded consolidation and memory-lifecycle maintenance pass with dry-run planning and audit evidence.","group":"Reference","kind":"tool","label":"reflect","path":"/docs/tools/reflect","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Search published current Knowledge revisions or read one exact authorized item and immutable revision with bounded pagination.","group":"Reference","kind":"tool","label":"search_knowledge","path":"/docs/tools/search-knowledge","section":"MCP tools","sectionId":"mcp-tools","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Choose OAuth or a scoped environment-secret handoff according to the client and API surface.","group":"Reference","kind":"api","label":"API authentication","path":"/docs/api/authentication","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Read and write memory through the documented REST and MCP contracts with explicit scope boundaries.","group":"Reference","kind":"api","label":"Memory API","path":"/docs/api/memory","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Keep project-scoped context and handoff records connected to the agent workflow that created them.","group":"Reference","kind":"api","label":"Projects API","path":"/docs/api/projects","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Use stable non-secret agent identity metadata while credentials remain in authenticated request headers.","group":"Reference","kind":"api","label":"Agents API","path":"/docs/api/agents","section":"REST API","sectionId":"rest-api","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Use workflow helpers and capture policy from the TypeScript SDK without duplicating memory semantics in the UI.","group":"Reference","kind":"sdk","label":"TypeScript SDK","path":"/docs/sdk/typescript","section":"SDK","sectionId":"sdk","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Choose the standalone Skill path when the agent host cannot mount a hosted MCP server directly.","group":"Reference","kind":"skill","label":"Skills quickstart","path":"/docs/skills/quickstart","section":"Skills","sectionId":"skills","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Keep Skill credentials in XMEMO_KEY or the supported device-login flow, never in public output.","group":"Reference","kind":"skill","label":"Skill authentication","path":"/docs/skills/authentication","section":"Skills","sectionId":"skills","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Review the standalone Skill operation catalog and its runtime selection boundary.","group":"Reference","kind":"skill","label":"Skill operations","path":"/docs/skills/operations","section":"Skills","sectionId":"skills","serverOwned":false,"tab":"Reference","tabId":"reference"},{"description":"Read the current governance posture for retention, deletion, export, data boundaries, and audit evidence.","group":"Trust \u0026 governance","kind":"concept","label":"Governance and retention","path":"/docs/concepts/governance-retention","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Understand the real sanitization and retrieval-visibility controls used for credentials, personal data, and high-sensitivity memory.","group":"Trust \u0026 governance","kind":"concept","label":"Sensitive memory","path":"/docs/concepts/sensitive-memory","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Separate OAuth consent, bearer-token storage, identity headers, and authenticated access decisions.","group":"Trust \u0026 governance","kind":"security","label":"Authentication boundary","path":"/docs/security/authentication","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Understand which public discovery data is safe to expose and where account-owned memory controls begin.","group":"Trust \u0026 governance","kind":"security","label":"Data boundary","path":"/docs/security/data-boundary","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":false,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"This page explains what XMemo stores for each security mode, where it is processed, who can decrypt it, what happens during export or deletion, and how you can verify the active boundary from your own account.","group":"Trust \u0026 governance","kind":"security","label":"Where is my data?","path":"/docs/security/where-is-my-data","section":"Trust \u0026 governance","sectionId":"trust-governance","serverOwned":true,"tab":"Trust \u0026 security","tabId":"trust-security"},{"description":"Review public release updates without mixing reviewer or submission material into the developer docs tree.","group":"Guides","kind":"operations","label":"Changelog","path":"/docs/changelog","section":"","sectionId":"","serverOwned":false,"tab":"","tabId":""}],"fallbackReason":"","path":"/docs/tools/todos","route":{"content":[{"body":"Reading first avoids duplicate TODOs when several agents work in the same project scope.","code":"todo({ action: \"list\" })","heading":"List open items before adding another","items":[],"language":"ts","slug":"list-open-items-before-adding-another"}],"description":"Keep task state and handoff notes close to the project context that makes them useful.","group":"Reference","kind":"tool","label":"todos","path":"/docs/tools/todos","section":"MCP tools","sectionId":"mcp-tools","sourceHref":"/product/docs#sdk-workflow-helpers","sourceLabel":"SDK workflow helpers","sourceRevision":"sha256:a208365f51d49c201b173728a752a5cec89775c71d38b55619b7bdb6846d5717","tab":"Reference","tabId":"reference","toolReference":{"errors":["Authorization failure: list lacks memory:read or a mutation lacks memory:write/project capability.","Validation failure: create lacks client_mutation_id, update lacks a positive expected_version, or action fields conflict.","Safety rejection: delete_all requires explicit confirmation and is unavailable to widget/mount-capability callers.","Timezone, project, or optimistic-concurrency errors are returned explicitly; the dispatcher does not silently ignore fields."],"examples":[{"code":"todo({\n action: \"create\",\n content: \"Review the MCP scope matrix\",\n client_mutation_id: \"task-review-scope-001\",\n due_at: \"2026-08-25T09:00:00Z\"\n})","title":"Create an idempotent task"},{"code":"todo({ action: \"list\", item_status: \"open\", limit: 10 })","title":"List open tasks"}],"parameters":[{"description":"Dispatcher operation.","name":"action","required":true,"type":"create | update | complete | list | delete_all"},{"description":"Exact item ID for update or completion.","name":"todo_id","type":"string"},{"description":"Task text; when both are supplied they must match.","name":"content / title","type":"string"},{"description":"Authorized project workspace identifier.","name":"project_id","type":"string"},{"description":"Task priority, due timestamp, status transition, and handoff note.","name":"priority / due_at / status / note","type":"string"},{"description":"List filters; search and query are list-only and must agree when both are supplied.","name":"item_status / due_before / search / query","type":"string"},{"defaultValue":"20 / empty / configured timezone","description":"Pagination and date interpretation controls.","name":"limit / cursor / owner_timezone","type":"integer / string"},{"description":"Idempotency key for create/update and optimistic concurrency version for update.","name":"client_mutation_id / expected_version","type":"string / integer"},{"defaultValue":"false","description":"Required true for explicit recoverable bulk deletion.","name":"confirm_delete_all","type":"boolean"}],"purpose":"Create, update, complete, list, or explicitly bulk-delete project TODOs while preserving task state near its authorized project context.","relatedTools":[{"label":"remember","path":"/docs/tools/remember","reason":"Save the durable decision or fact behind a task."},{"label":"recall_context","path":"/docs/tools/recall-context","reason":"Restore task and project context before continuing work."},{"label":"forget","path":"/docs/tools/forget","reason":"Remove one reviewed TODO by exact ID when needed."}],"requiredScope":["List uses memory:read; create, update, complete, and delete_all use memory:write in the public chat surface.","Project Workspace mutations additionally require a valid mount_capability and project_id."],"returnSchema":"Structured output identifies the action and returns the affected item(s), pagination cursor, mutation status, and safe task metadata. Bulk deletion is always recoverable soft deletion.","sourceRevision":"sha256:c3f1c749c2571a467bd61890609a940075b5bf17f722a35338cbaaa9651468db","toolName":"todo","unitId":"docs.tool.todos","whenNotToUse":["Do not use TODOs for general durable facts or decisions; use remember.","Do not store financial transactions as TODO content; use ledger.","Do not call delete_all without an explicit user request and confirm_delete_all=true.","The REST API accepts a wider field set than the public MCP tool; see https://xmemo.dev/docs/api/memory for scope, bucket, team and provenance filters."],"whenToUse":["A user needs durable task state, due dates, priority, completion, or a handoff list.","A project workspace needs a governed TODO mutation with its signed mount capability.","The caller needs to list open, in-progress, completed, or all authorized items."]},"unitId":"docs.route.tools-todos"},"toolReference":{"errors":["Authorization failure: list lacks memory:read or a mutation lacks memory:write/project capability.","Validation failure: create lacks client_mutation_id, update lacks a positive expected_version, or action fields conflict.","Safety rejection: delete_all requires explicit confirmation and is unavailable to widget/mount-capability callers.","Timezone, project, or optimistic-concurrency errors are returned explicitly; the dispatcher does not silently ignore fields."],"examples":[{"code":"todo({\n action: \"create\",\n content: \"Review the MCP scope matrix\",\n client_mutation_id: \"task-review-scope-001\",\n due_at: \"2026-08-25T09:00:00Z\"\n})","title":"Create an idempotent task"},{"code":"todo({ action: \"list\", item_status: \"open\", limit: 10 })","title":"List open tasks"}],"parameters":[{"description":"Dispatcher operation.","name":"action","required":true,"type":"create | update | complete | list | delete_all"},{"description":"Exact item ID for update or completion.","name":"todo_id","type":"string"},{"description":"Task text; when both are supplied they must match.","name":"content / title","type":"string"},{"description":"Authorized project workspace identifier.","name":"project_id","type":"string"},{"description":"Task priority, due timestamp, status transition, and handoff note.","name":"priority / due_at / status / note","type":"string"},{"description":"List filters; search and query are list-only and must agree when both are supplied.","name":"item_status / due_before / search / query","type":"string"},{"defaultValue":"20 / empty / configured timezone","description":"Pagination and date interpretation controls.","name":"limit / cursor / owner_timezone","type":"integer / string"},{"description":"Idempotency key for create/update and optimistic concurrency version for update.","name":"client_mutation_id / expected_version","type":"string / integer"},{"defaultValue":"false","description":"Required true for explicit recoverable bulk deletion.","name":"confirm_delete_all","type":"boolean"}],"purpose":"Create, update, complete, list, or explicitly bulk-delete project TODOs while preserving task state near its authorized project context.","relatedTools":[{"label":"remember","path":"/docs/tools/remember","reason":"Save the durable decision or fact behind a task."},{"label":"recall_context","path":"/docs/tools/recall-context","reason":"Restore task and project context before continuing work."},{"label":"forget","path":"/docs/tools/forget","reason":"Remove one reviewed TODO by exact ID when needed."}],"requiredScope":["List uses memory:read; create, update, complete, and delete_all use memory:write in the public chat surface.","Project Workspace mutations additionally require a valid mount_capability and project_id."],"returnSchema":"Structured output identifies the action and returns the affected item(s), pagination cursor, mutation status, and safe task metadata. Bulk deletion is always recoverable soft deletion.","sourceRevision":"sha256:c3f1c749c2571a467bd61890609a940075b5bf17f722a35338cbaaa9651468db","toolName":"todo","unitId":"docs.tool.todos","whenNotToUse":["Do not use TODOs for general durable facts or decisions; use remember.","Do not store financial transactions as TODO content; use ledger.","Do not call delete_all without an explicit user request and confirm_delete_all=true.","The REST API accepts a wider field set than the public MCP tool; see https://xmemo.dev/docs/api/memory for scope, bucket, team and provenance filters."],"whenToUse":["A user needs durable task state, due dates, priority, completion, or a handoff list.","A project workspace needs a governed TODO mutation with its signed mount capability.","The caller needs to list open, in-progress, completed, or all authorized items."]},"whereIsMyData":{"callout":"XMemo public pages never ask you to paste API keys. Agent and MCP configuration should reference environment variables or the official client configuration surface.","eyebrow":"XMemo Security Modes","footer":"Source-backed by docs/security/where-is-my-data.md, the setup wizard state machine, and XMemo security-mode APIs.","group":"Security","headers":["Mode","Where ciphertext lives","Who can decrypt","Best fit"],"lead":"This page explains what XMemo stores for each security mode, where it is processed, who can decrypt it, what happens during export or deletion, and how you can verify the active boundary from your own account.","meta":"XMemo explains where memory data lives, who can decrypt it, and how Cloud, Keyguard, and Vault security modes differ.","nav":{"privacy":"Privacy policy","product":"Product docs","settings":"Security settings","trust":"Trust center"},"nav_label":"XMemo security documentation","quick_title":"Quick comparison","rows":[{"code":"cloud","fit":"Fast setup, full hosted recall, no device or recovery-key burden.","name":"Cloud-managed mode","where":"XMemo managed data plane with access controls, application-scoped authorization, and audit trails. Database RLS is deployment-specific.","who":"XMemo server can process memory content for recall, search, ranking, and supportable exports."},{"code":"keyguard","fit":"Enterprise teams that need hosted recall plus customer-managed key control.","name":"Keyguard mode","where":"XMemo managed Postgres, but envelope keys are bound to your tenant KMS / HSM.","who":"The server can decrypt only when your KMS grant allows unwrap operations."},{"code":"vault","fit":"Zero-knowledge custody where losing all devices and recovery material means permanent loss.","name":"Vault mode","where":"XMemo managed Postgres stores opaque ciphertext and envelope metadata.","who":"Only enrolled devices or your recovery kit can decrypt. XMemo cannot recover plaintext."}],"sections":[{"body":"Memory data is stored in the XMemo managed data plane with access controls, application-scoped authorization, and audit trails. Database RLS is deployment-specific.","items":["The XMemo server can process memory content for server-side semantic recall, ranking, and exports.","This is the most convenient mode, but it is not zero-knowledge.","Deletion removes memory rows and associated metadata. DSAR exports can include plaintext because the service can process memory content on your behalf."],"title":"Cloud-managed mode"},{"body":"Keyguard keeps XMemo's hosted recall experience while binding envelope operations to a key your organization controls in Azure Key Vault, AWS KMS, GCP KMS, KMIP, or a similar provider.","items":["The wizard stores the KMS binding in setup preflight data and commits personal_default_mode = keyguard.","Recall requires your KMS grant to remain valid. Revoking the grant blocks future decrypt/unwrap operations.","XMemo deletes its ciphertext and metadata on account deletion; your tenant remains responsible for KMS key rotation or destruction."],"title":"Keyguard mode"},{"body":"Vault is the zero-knowledge option. The browser/device encrypts before data leaves the device, and the server stores only ciphertext plus routing and envelope metadata.","items":["XMemo cannot decrypt vault memories, cannot reset your vault key, and cannot recover data if every enrolled device and recovery kit is lost.","DSAR exports for vault data contain ciphertext and envelope metadata. You decrypt them locally with your device or recovery kit.","Hosted semantic features may be limited unless the feature can operate on client-provided or privacy-preserving representations."],"title":"Vault mode"},{"body":"XMemo production is designed around operator-managed Postgres with TLS verification and application-scoped authorization. Database RLS/runtime context is deployment-specific and requires target verification. Supabase is treated as a development and compatibility backend only, not as the supported production substrate for these custody claims.","items":["Managed Postgres: the production storage boundary for account, memory, vector, setup, and audit records.","Database RLS/runtime context: deployment-specific controls that require target verification of the runtime role, migration ledger, runtime-context flag, and owner/team CRUD matrix.","Supabase compatibility: useful for local or OSS adoption, but its service-role behavior is not equivalent to production hardening."],"title":"Production data boundary"}],"stores":["Memory records: memory text or ciphertext, metadata, ownership, timestamps, and vector-search data needed for recall.","Account setup state: selected security mode, setup completion state, mode-change count, and preflight proof such as a KMS binding id or vault recovery marker.","Access and audit records: sessions, hashed or scoped credentials, identity links, and audit events such as setup_state_transition."],"stores_title":"What XMemo stores","title":"Where is my data?","verify":["Open Memory Console -\u003e Settings -\u003e Security mode and confirm the mode shown there.","Call GET /api/v1/me/setup/state; completed accounts should show setup_state = setup_completed and the expected selected_mode.","Call GET /api/v1/me/security-mode; the posture should include verified_effective_mode, new_write_mode, pending_write_mode, legacy_read_mode, and migration_status.","For Keyguard, compare the displayed key binding id with your KMS audit log. For Vault, confirm outbound writes contain opaque ciphertext with no recognizable plaintext substring."],"verify_title":"How to verify your active mode"}}