cairn
Provides optional semantic search using OpenAI embeddings, allowing saved memories to be retrieved by meaning when an OpenAI API key is configured.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cairnRemember that staging uses port 8080; attribute this to Priya."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Switching agents or starting a fresh session shouldn't mean explaining the whole project again. Cairn is a shared place where people and agents save decisions, plans and observations â and get them back later, with attribution intact. It runs on your own machine or server and connects over REST or MCP.
đǍ Attributable | Every claim carries who said it. Remembering something does not make it true. |
âŠī¸ Correctable | Corrections keep the earlier record, with the reason for the change. |
âī¸ Contestable | When two sources disagree, Cairn records both sides and declares no winner. |
đ Governed | Scope, grants and classification are checked on every read and write. |
đ§ž Receipted | Writes return durable receipts, so you can check what was actually saved. |
Agents must explicitly save context. Cairn does not silently capture your conversations.
See it happen
Val (Codex) saves a workshop plan. Spike (Claude) moves the venue and tells Val through Garden. Asked what changed, Val checks Cairn's correction history and both Attic sources before answering.

30 seconds ¡ Read the transcript and evidence checks
Spike saves a plan and asks Val through Garden to check it. Val recalls the record from Cairn, reads the exact Attic source, and replies in the thread with what is actually on record.

40 seconds ¡ Read the transcript and evidence checks
Both clips are real tool calls on a disposable instance with a fictional workshop. Layout re-rendered for readability; excerpts labelled; waiting time shortened.
Related MCP server: contextos-memory
Install
The guided installer explains each stage, verifies the result, and can resume, roll back or remove what it installed. Run it from the root of a checkout of this repository on Linux x86_64. The public repository on GitHub, veridian69/cairn, is the distribution source; record the revision you install from.
git clone https://github.com/veridian69/cairn.git
cd cairn
git rev-parse HEAD
./cairn-installIt asks for a mode, a name and a port. New here? Choose disposable â Attic-only memory, no OpenAI key, stopped after verification; blitz removes it.
To install a specific release, check out its tag after cloning and record that revision instead.
Mode | For | Semantic search | Garden | Guide |
| A first look, throwaway | â | â | |
| A persistent service (systemd user unit) | Optional | â | |
| Compose on a single host | Optional | â | |
| An admin-prepared Linux/amd64 cluster | Optional | â |
Semantic search is optional everywhere and requires an OpenAI API key, read from a protected file â see supplying the key. Custody, lifecycle and audit all work without it.
Platform notes. The source launcher accepts host Python 3.12â3.14; Cairn's locked managed application runtime and container use Python 3.14. macOS runs foreground and native background memory plus Attic via a login-scoped LaunchAgent (validated on macOS 26, Intel and Apple Silicon; logout/login and macOS 12 untested) â but Garden is not supported on macOS. Native Windows support is limited to the cairn-mcp STDIO relay for Codex (setup).
Full flag, stage and recovery reference: guided installer.
Then, day to day
uv sync --locked
uv run --locked cairn-memory --profile ./memory-profile.json check
uv run --locked cairn-memory --profile ./memory-profile.json arrive <<'JSON'
{"query":"Current decisions and unfinished work"}
JSONcairn-memory is explicit by design: a strict JSON connection profile fixes the endpoint, instance, scope, classification and credential file. It never discovers credentials and keeps no local transcript. See the everyday command guide.
How it fits together
Two compatible API families over one catalogue: custody and administration at REST /v1 and MCP /v1/mcp, and the conversation-oriented memory API at REST /memory/v1 and MCP /memory/v1/mcp â arrival briefings, recall, history, remembering, correction, disagreement, suggestions, proposals and connection diagnosis.
flowchart LR
C[Clients and agent hosts] --> T{REST or MCP}
T --> A[Scope, grant and classification checks]
A --> S[Cairn authority]
S --> Q[(SQLite catalogue)]
S --> E[Hash-chained audit]
Q --> O[Durable outboxes]
O -. optional .-> V[Evidence adapter]
O -. optional .-> P[Semantic projection]
P -. candidates .-> SGenerated contracts define the wire surface: memory OpenAPI ¡ memory MCP tools ¡ /v1 OpenAPI ¡ /v1 MCP tools.
One serving process per SQLite data directory; requires reliable POSIX locking and
fsync.The listener is plain HTTP. Terminate TLS and rate-limit at a reverse proxy or ingress before it leaves numeric loopback.
Bearer credentials live in owner-only files. Neither REST nor MCP issues them.
Recalled text is attributed, untrusted data. It must never become system or developer instructions.
Graph-backed semantic retrieval is optional.
Docker Compose and conformant Kubernetes are supported shapes. The OpenShift overlay is statically validated with no claimed target acceptance.
This repository claims no published container image; deploy from a trusted checkout or a separately reviewed digest.
Further reading
Client guide ¡ Shared-memory guide ¡ Python client ¡ Restart-safe sessions ¡ Host workflows ¡ Memory suggestions ¡ Semantic fact search ¡ v0.1 contract ¡ Deployment ¡ Backup and restore ¡ Local MCP relay ¡ A2A (Garden) agent chat
Development
uv sync --locked
make checkThe locked gate covers formatting, linting, typing, tests, generated contracts, deployment renders and dependency audit. The hosted check runs on demand: Actions â Check â Run workflow, or gh workflow run check.yml --ref BRANCH. GitHub excludes the marked Bubblewrap/namespace tests and says so in the run summary â run make check locally for the complete suite.
Contributing ¡ Security reporting ¡ v0.7.10 release notes ¡ macOS native installation
Apache-2.0 (license ¡ notices). Cairn is the memory service behind Drystane, the control plane that prompted its design.
This server cannot be deployed
Maintenance
Related MCP Connectors
- memnodeOAuthdev.memnode
Persistent, inspectable memory for AI agents with lineage, correction, and a hosted MCP endpoint.
Governed personal world model and memory for your AI agent. Pair once, connect over MCP.
Private-by-default, local-first memory/context/task orchestrator for MCP apps and agents.
One memory, every AI. A shared, user-owned markdown memory your AI clients read and write over MCP.
Related MCP Servers
AlicenseNot gradedqualityCmaintenanceProvides persistent, scoped shared memory for collaborating AI agents, with tools for storing observations, semantic recall, and handoff workflows. Backed by PostgreSQL and exposed through MCP.1Apache 2.0- AlicenseNot gradedqualityAmaintenanceEnables AI coding agents to share a local-first, versioned memory of decisions, conventions, tasks, conflicts, and handoffs over MCP and REST.1 npmMIT
- AlicenseAqualityCmaintenanceProvides a local-first, provenance-aware memory layer that enables MCP-capable AIs to store, recall, validate, and reason over facts with contradiction detection, trust weighting, deduplication, and encryption, supporting offline private operation without GPUs or API keys.9Apache 2.0
- FlicenseNot gradedqualityBmaintenanceProvides a self-hosted shared memory service that lets AI agents capture and recall durable facts, decisions, and context across multiple tools and MCP-capable clients.3-