memex
This server provides a temporal memory store for agents to search, store, correct, retrieve, and monitor memories with full correction history.
Search stored memories by natural-language query with fast vector or thorough hybrid modes, optional date filters, and result limits (
memex_recall).Store new self-contained memories verbatim with optional validity windows, event times, source, metadata, and supersession links (
memex_store).Correct wrong or outdated memories by superseding an existing record while preserving the old one and its history; force option available (
memex_correct).Fetch exactly one memory by ID verbatim, including both directions of its correction chain (
memex_get).List memories by recency, optionally filtered to corrections only or since a given timestamp (
memex_recent).Check backend health and store-wide stats such as current/superseded/expired counts, oldest/newest record, and queue/dead-letter depth (
memex_health).
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@memexrecall what I noted about the database migration failure last week"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
alethech
Verifiable agent continuity protocol — local-first, zero-LLM, zero-blockchain. The art of un-concealing transmission integrity.
Copyright (c) 2026 AliceLabs LLC.
From Greek ἀλήθεια (aletheia, "truth as un-concealment") + τέχνη (techne, "art, craft"). The art of revealing that a memory was not modified after being signed.
This is the reference implementation of the protocol specified in docs/implementacion-nucleo-minimo.md (rev 2 + rev 3 identity layer).
what this is
alethech provides cryptographically verifiable, portable memory continuity for AI agents. It signs memory commits with Ed25519, links them in a hash-linked DAG, rotates keys without losing identity, and can seal a verified history into one encrypted .aleth file for transfer between compatible runtimes and devices.
What this repo IS:
A cryptographic protocol implementation (Ed25519 + SHA-256 + JCS RFC 8785)
An encrypted portable memory container (
.aleth, scrypt + AES-256-GCM)A neutral verified adapter view for plugins and chat integrations
9 CLI commands (
init,commit,evidence,verify,export,import,migrate,key rotate,key revoke)A test suite with mutation-guard paths (each guarantee has a test that fails when the check is defeated)
MIT licensed, published on PyPI as
alethech
What this repo is NOT:
It is NOT a memory store or retrieval system
It is NOT the legacy
memexproject (Python/ChromaDB memory server)It has no MCP server, no Docker, no auto-update, no LLM calls
It depends only on
cryptographyandclick— nomem0ai, nochromadb, noollama
The legacy memex codebase (167 commits, AliceLabs Proprietary License) is preserved in a separate repository: eddyflores100-lang/memex-legacy. It is not part of this repo and not installed by pip install alethech.
Related MCP server: SharedBrain
the property
This memory set forms part of a cryptographically verifiable history associated with a determined identity, whose commits can be independently verified with respect to their integrity, cryptographic authorship, and provenance relations.
When a reference checkpoint exists, it can additionally be verified that the presented history continues from that checkpoint.
The protocol does NOT prove that the agent's claims are true — only that they were signed by the identity that claims them. The truth being un-concealed is the truth about transmission integrity, not about content.
status
Released version 0.8.5; main contains the 0.9 portable-memory work in progress. CI runs the Python suite on 3.10–3.13 plus cross-language conformance and .aleth interoperability across Python, Rust, and TypeScript. No LLM, no required cloud, no blockchain, no consensus.
install
pip install alethechFor development:
git clone https://github.com/eddyflores100-lang/alethech.git
cd alethech
pip install -e ".[dev]"usage
alethech init # generate identity + genesis commit
alethech commit --content <json-file> # create signed MemoryCommit
alethech evidence --tool <name> # create signed EvidenceCommit
--input <file> --output <file>
alethech verify # verify the whole store, offline
alethech export --output <dir> # portable package
alethech import --input <dir> # import external memory
alethech key rotate # rotate operational key
alethech key revoke --key-id <id> # revoke a key
alethech migrate --to v0.2 # migrate identity layerportable encrypted memory (.aleth)
Alethech 0.9 development adds a single encrypted file designed for drag-and-drop transfer:
from alethech import Alethech
agent = Alethech.initialize("./working-store")
agent.commit({"fact": "portable memory"})
agent.seal("memory.aleth", "your-passphrase")
# Plugin-style path: dropped file -> unlock -> verify -> neutral context
context = Alethech.drop_context("memory.aleth", "your-passphrase")The .aleth container uses scrypt + AES-256-GCM. Its authenticated payload can be opened byte-exactly by the Python, Rust, and TypeScript implementations in CI. The portable file may carry the encrypted operational signing key so history can continue on another device, but it excludes root.key and recovery.key.
See docs/ALETH_CONTAINER_SPEC.md and docs/ADAPTER_CONTRACT.md.
what it does NOT do
It does NOT prove that the agent's claims are true. Only that they were signed by the identity that claims them.
It does NOT detect rollback without an external checkpoint.
The local working store is NOT encrypted at rest; the portable
.alethcontainer is encrypted.It does NOT delegate permissions between agents.
It does NOT call any LLM.
what the name means
alethech comes from:
aletheia (ἀλήθεια) — Greek for "truth", more precisely "un-concealment" (Heidegger's reading: truth as the act of revealing what was hidden)
techne (τέχνη) — Greek for "art, craft, technique"
So alethech = "the art of un-concealing". The protocol un-conceals:
whether a memory was modified after being signed
who signed it
what signed timestamp was recorded (NOT physical signing time — only the timestamp recorded in the artifact)
what its provenance is
whether the chain of custody is intact
It does NOT un-conceal whether the content is true — that's the agent's responsibility, not the protocol's.
tests
python -m pytest tests/The Python test suite covers:
crypto primitives (Ed25519, SHA-256, base64url, base32)
JCS canonicalization (RFC 8785) — 56 conformance vectors including:
integer/float serialization per ECMAScript Number.prototype.toString()
-0 serializes as "0" (per RFC 8785 erratum, NOT preserved)
scientific notation format (positive exponents keep '+', negative strip leading zeros)
decimal vs scientific threshold (1e21 / 1e-6)
UTF-16 key ordering with surrogate pairs
string escaping (control chars, non-ASCII preservation)
NaN/Infinity rejection
agent_id derivation (cryptographic binding to public_key)
MemoryCommit signing, tamper detection, wrong-key rejection
EvidenceCommit signing (supports both legacy and V2 identity)
all 9 CLI commands (init, commit, evidence, verify, export, import, migrate, key rotate, key revoke)
checkpoint emission + rollback detection + causal continuity (ancestry check)
identity_mismatch detection
export/import roundtrip preservation
tampered manifest rejection
key rotation with cutoff_head reachability guarantee
ancestry_check mutation guard (3 code-level defeats)
recall-seam defeats (2 data-level mutations: active-keys tampering, cutoff_head mutation)
root_id binding (RootAuthority ↔ IdentityRecord ↔ ControlEvent)
checkpoint continuity (checkpoint HEAD must be ancestor of current HEAD)
IdentityRecordV2 signature verification (against root public key)
import causal continuity (ancestry check before writing)
import hardening (symlinks, path traversal, archive bombs, artifact hash verification)
repository structure
alethech/ # this repo — cryptographic protocol only
├── alethech/ # source: crypto, objects, store, verify, cli, canonical
│ └── integrations/ # langchain + memex hooks
├── alethech-rs/ # Rust SDK (31 tests, cross-validation)
├── alethech-ts/ # TypeScript SDK (15 tests, Web Crypto API)
├── tests/ # Python behavioral, adversarial, mutation and conformance tests
├── conformance/ # 15 adversarial conformance vectors
├── docs/ # protocol specification
├── examples/ # basic_usage.py
├── INTEGRATION.md # how to integrate with memex via MemexAlethechHook
├── CHANGELOG.md # version history
├── SECURITY.md # threat model + vulnerability policy
├── CONTRIBUTING.md # dev setup + PR process
├── CODE_OF_CONDUCT.md # Contributor Covenant
├── CITATION.cff # academic citation
├── LICENSE # MIT
├── README.md # this file
└── pyproject.toml # alethech 0.9.0, deps: cryptography + click onlycross-language validation
The protocol is implemented in three independent languages:
Language | Tests | Dependencies |
Python | CI suite | cryptography + click |
Rust | 31 | ed25519-dalek, sha2, serde |
TypeScript | 15 | 0 (Web Crypto API only) |
All three use the same NIST SHA-256 test vectors, RFC 4648 base32 vectors, and RFC 8785 JCS conformance vectors. The cross-language claim is backed by an executable harness:
python conformance/cross_language_check.pyThis runs all three implementations against the same shared fixtures in conformance/ and asserts byte-exact agreement on canonical bytes for accepted fixtures. The default run is fail-closed: exit 0 = all three ran and agree, 1 = disagreement, 2 = an implementation/runtime is unavailable. CI builds the Rust helper and executes the three-runtime harness. See conformance/CROSS_LANGUAGE.md for the contract and how to add a 4th implementation.
license
MIT.
related repositories
eddyflores100-lang/memex-legacy— Legacy Memex codebase (167 commits, AliceLabs Proprietary License). Python/ChromaDB memory system with MCP integration. Preserved for historical reference. NOT installed bypip install alethech.
Copyright (c) 2026 AliceLabs LLC. MIT License.
Available Tools
6 toolsmemex_correctA
Correct a memory that is wrong or outdated, in one call: stores text as a new record superseding id. The old record is kept, marked superseded, and stays visible in memex_get's history -- nothing is deleted. id must come from a prior memex_recall or memex_get result; an unknown id is rejected. If id is already superseded, this reports the current replacement instead of writing, unless force=true. Do not use this for a brand-new, unrelated fact -- use memex_store instead.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | Id of the record being corrected (from a prior memex_recall or memex_get result). | |
| text | Yes | The corrected fact, verbatim. | |
| force | No | Supersede `id` anyway even if something else already superseded it. | |
| source | No | Optional provenance, e.g. a URL or file path. | |
| event_at | No | Optional ISO-8601 time the described thing happened. | |
| valid_to | No | Optional ISO-8601 end of validity (exclusive). | |
| valid_from | No | Optional ISO-8601 start of validity (inclusive). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses key behavioral traits beyond the annotations: it keeps the old record, marks it superseded, and does not delete anything (aligning with destructiveHint=false). It also explains the behavior when id is already superseded (reports replacement unless force=true). The annotations provide no contradiction; the description adds valuable context about side effects and edge cases. However, it does not mention error response details or permission requirements, which are not covered by annotations, but the core behavioral transparency is strong.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is moderately long but every sentence serves a purpose. It is front-loaded with the primary action, then covers behavioral details, prerequisites, edge cases, and a sibling distinction. No filler or redundancy. It is well-structured as a single cohesive paragraph that reads naturally. Slightly longer than necessary but still efficient for the information density.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has no output schema, so the description must convey enough about behavior. It explains the non-destructive nature, the superseding mechanism, handling of already-superseded ids, and the prerequisite for id. It also differentiates from memex_store. For a mutation tool with 7 parameters (only 2 required), the description covers the critical aspects needed to use it correctly. It does not specify the exact response format, but it mentions 'reports the current replacement' which gives a hint. Overall, it is complete for the tool's complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description adds meaningful context for the key parameters: it emphasizes that 'id' must come from a prior result and that unknown ids are rejected (reinforcing but slightly extending the schema), and it clarifies the 'force' parameter by explaining the default behavior (reports replacement instead of writing) which is not fully explicit in the schema description. This adds value beyond the schema, justifying a score above baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action (correcting a wrong/outdated memory) and the mechanism (stores new text superseding an id). It clearly differentiates from the sibling memex_store by explicitly stating 'Do not use this for a brand-new, unrelated fact -- use memex_store instead.' This makes the tool's purpose unambiguous and distinguishes it from alternatives.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use context (when a memory is wrong or outdated) and a direct exclusion ('Do not use this for a brand-new, unrelated fact') with the alternative named. It also states a prerequisite (id must come from a prior memex_recall or memex_get result, and unknown ids are rejected), which is critical for correct invocation. This is comprehensive guidance for selecting this tool over siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memex_getARead-onlyIdempotent
Fetch exactly one memory by id, verbatim, with its correction chain in both directions: what it replaced (oldest last) and what replaced it (newest last). Use this to resolve a "SUPERSEDED by " marker from memex_recall, or to confirm an id before passing it to memex_correct. An unknown id is an error. Do not use this to find a memory by topic -- use memex_recall instead.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | Record id. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With annotations already declaring readOnlyHint=true, idempotentHint=true, and destructiveHint=false, the safety profile is covered. The description adds valuable behavioral context beyond the annotations: it specifies that unknown ids are errors, and it clarifies the verbatim returning of the memory and the correction chain traversal. This goes beyond the minimal requirement and earns a high score.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is compact and front-loaded: the first sentence captures the core action, scope, and return value. Subsequent sentences provide usage routing. Every sentence contributes value; there is zero redundancy or fluff. This is a model of efficient, well-structured description.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple fetch-by-id tool with one parameter, complete schema, and annotations, the description covers everything an agent needs: what it returns (verbatim memory and correction chain), how to use it (resolve superseded markers, confirm ids), error handling (unknown id is an error), and what it is not for (topic search, routed to memex_recall). No output schema is needed because the return value is described clearly. Nothing essential is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The single parameter 'id' has full schema coverage at 100%. The description adds critical semantic value by explaining that the id must be a valid record id and that unknown ids result in an error. It also implies the id is used for lookup, not filtering. Given the high coverage, the description's explicit error behavior and usage context fully compensate and exceed the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Fetch'), a specific resource ('exactly one memory by id'), and the exact scope (verbatim, with correction chain in both directions). It explicitly distinguishes itself from the sibling memex_recall by stating it is not for topic-based search. This is a clear, specific purpose that an agent can act on without ambiguity.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use guidance: 'Use this to resolve a SUPERSEDED by <id> marker from memex_recall, or to confirm an id before passing it to memex_correct.' It also states an explicit when-not-to-use: 'Do not use this to find a memory by topic -- use memex_recall instead.' This is exemplary routing with clear conditions and named alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memex_healthARead-onlyIdempotent
Check whether the memory backend is up, and see store-wide stats (current/superseded/expired counts, oldest/newest record, queue and dead-letter depth) in one call. Call this after any other memex_* tool returns isError, before retrying. Do not call this to search memory -- use memex_recall for that.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, so safety is covered. The description adds valuable behavioral context beyond those annotations: the intended error-recovery sequence and the specific store-wide metrics included in the health check.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, each earning its place: the first states purpose and output content, the second gives usage context, and the third prevents misuse. No filler or repetition.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter, read-only health-check tool, the description fully covers what it returns, when to call it, and when not to call it. No output schema exists, but the listed stats give enough expectation for an agent to interpret results.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
With zero parameters and 100% schema coverage, there is nothing for the description to add about individual parameters. The baseline for zero-parameter tools is 4, and the description provides no conflicting or redundant parameter information.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb ('Check') and a clear resource ('memory backend'), then lists exact stats the call returns (current/superseded/expired counts, oldest/newest record, queue/dead-letter depth). It explicitly differentiates from memex_recall by stating what this tool is not for.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides unambiguous when-to-use guidance: call after any other memex_* tool returns isError, before retrying. It also gives a direct exclusion and names the alternative (memex_recall) for searching memory.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memex_recallARead-onlyIdempotent
Search stored memories for query. Call before answering questions about prior work, decisions, or past conversations. Default mode="fast" (vector search, ~0.1s); use mode="thorough" only when a fast result looks wrong or stakes are high (~3s, hybrid search). Current facts list first, superseded/expired after, marked. Every hit shows its id, status, and recorded date. Fix a stale hit with memex_correct; see its history with memex_get. Do not use this to store a new fact -- use memex_store instead.
| Name | Required | Description | Default |
|---|---|---|---|
| mode | No | "fast": vector search (default). "thorough": hybrid search, slower, for a second opinion. | fast |
| as_of | No | Optional ISO-8601 date or instant. Answer as memory stood then: records written later are excluded and later supersessions are ignored. | |
| limit | No | Max hits to return. | |
| query | Yes | Natural-language search query. | |
| historical | No | Keep relevance order; do not demote superseded or expired records. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, establishing a safe read-only profile. The description adds valuable behavioral context beyond that: result ordering ('Current facts list first, superseded/expired after, marked'), the presence of id, status, and recorded date on each hit, and the mode-specific latency/behavior differences. It doesn't explicitly describe the historical flag's effect on ordering, but the schema covers its semantic, so a 4 is appropriate given the strong annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single well-structured paragraph that front-loads the core purpose, then moves to usage guidance, then behavioral details, and finally alternative tools. Every sentence contributes new information; there is no fluff or repetition of schema content. The flow is logical and efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has 5 parameters and no output schema, the description is remarkably complete. It explains when to call, how to choose modes, what the results look like (ordering, fields), and points to related tools for correcting or viewing history. The as_of parameter is documented in the schema, and the description doesn't need to repeat it. Nothing essential for an agent to use the tool correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3. The description adds meaningful value beyond the schema: it explains the practical trade-off between fast and thorough modes with approximate latencies and when to choose each, and it clarifies the overall search semantics (hybrid search) not fully captured in the schema's enum descriptions. This lifts it to a 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's verb and resource: 'Search stored memories for `query`.' It further specifies the use case (answering questions about prior work, decisions, or past conversations) and distinguishes itself from siblings by naming memex_correct, memex_get, and memex_store as alternatives for different actions. This leaves no ambiguity about what the tool does.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit when-to-use guidance: 'Call before answering questions about prior work, decisions, or past conversations.' It also gives nuanced usage instructions for the two modes, stating when to prefer thorough over fast ('only when a fast result looks wrong or stakes are high'), and explicitly warns not to use this tool for storing facts, pointing to memex_store instead. This is exemplary usage guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memex_recentARead-onlyIdempotent
List memories by recency, no search query needed -- good for "what changed recently" or catching up after time away. since (ISO-8601) is a lower bound: only records at or after it. kind="corrections" shows only memories that corrected an older one, with the id(s) they replaced. Do not use this to find a memory about a topic -- use memex_recall instead.
| Name | Required | Description | Default |
|---|---|---|---|
| kind | No | "all": every recent record. "corrections": only records that superseded another. | all |
| limit | No | Max records to return. | |
| since | No | Optional ISO-8601 instant; only records at or after it. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish read-only, idempotent, non-destructive behavior. The description adds meaningful behavioral detail beyond that: no search query is needed, `since` is a lower bound, and `kind=corrections` includes the IDs of replaced memories. It does not describe return shape or pagination, but for a simple list tool this is a minor gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is compact, front-loaded with the core purpose, and every sentence earns its place. It contains no filler, redundancy, or irrelevant detail.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only list tool with no required parameters, a complete input schema, and annotations covering the safety profile, this description is sufficient. It tells the agent when to use it, how the parameters behave, and which sibling to prefer for topic-based lookup.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds real semantics: it explains `since` as an ISO-8601 lower bound and clarifies that `kind=corrections` returns corrected memories with the IDs they replaced. This goes beyond the schema's basic descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool lists memories by recency, names concrete use cases, and explicitly distinguishes it from memex_recall for topic search. This makes the tool's purpose unambiguous and differentiated from siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It provides positive guidance ('good for what changed recently or catching up after time away') and an explicit exclusion with an alternative: 'Do not use this to find a memory about a topic -- use memex_recall instead.' This is explicit when-to-use and when-not-to-use guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memex_storeA
Remember or store one new, self-contained memory verbatim -- exact text, not a summary. Optional valid_from/valid_to/event_at/source, and supersedes (ids this replaces; unknown or another user's ids are rejected). The reply echoes recorded_at and any declared window so you can confirm without a recall. Do not use this to correct something already in memory -- use memex_correct with the old id instead of storing a near-duplicate.
| Name | Required | Description | Default |
|---|---|---|---|
| text | Yes | Atomic fact to store verbatim. | |
| source | No | Optional provenance, e.g. a URL or file path. | |
| event_at | No | Optional ISO-8601 time the described thing happened. | |
| metadata | No | Optional provenance metadata with at most 16 relation_declarations_v2 entries | |
| valid_to | No | Optional ISO-8601 end of validity (exclusive). | |
| supersedes | No | Ids this memory replaces (from a prior memex_recall or memex_get result). Each must exist for this user or the write is rejected. | |
| valid_from | No | Optional ISO-8601 start of validity (inclusive). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description explains behavior beyond the annotations: it states that unknown or another user's IDs are rejected, and it reveals the reply echoes recorded_at and any declared validity window so confirmation is possible without a recall. This gives the agent a clear picture of side effects and response characteristics beyond the raw annotation flags. No contradiction with the annotations exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is compact but information-dense, with three sentences that each earn their place: purpose, optional parameters and response behavior, then an explicit exclusion. It front-loads the core action and verbatim requirement before details, making it easy for an agent to parse quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a write tool with one required parameter and a nested metadata object, the description covers what to do, when not to do it, what parameters matter, and what the response will contain. The nested relation declarations are already documented in the schema, so nothing essential is left for the agent to infer.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has 100% coverage, providing descriptions for all parameters, so the baseline is 3. The description adds valuable context, especially for supersedes by explaining that IDs must be valid and owned by the user, and for the temporal parameters by indicating they are optional and represent a validity window. It groups some optional parameters but does not add detail for metadata/relation declarations, which the schema already handles.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's job: to remember or store one new, self-contained memory verbatim. It explicitly highlights that exact text should be stored, not a summary, and it distinguishes this from memex_correct in the closing sentence. An agent can immediately tell what resource this acts on and how it differs from its siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says 'Do not use this to correct something already in memory -- use memex_correct with the old id instead of storing a near-duplicate,' giving both a when-not-to-use condition and the exact alternative. It also implies use for genuinely new memories by emphasizing 'one new, self-contained memory,' giving clear context for the expected use case.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
6 tool updates
v0.1.0- First observed
memex_correct - First observed
memex_get - First observed
memex_health - First observed
memex_recall - First observed
memex_recent - First observed
memex_store
TDQS
Scored across 6 tools
Each tool has a clearly distinct role: recall searches, store adds, correct supersedes, get fetches by id, recent lists by time, and health checks backend status. There is no overlap, and the descriptions actively redirect misuse to the correct tool.
All tools share the memex_ prefix followed by a single lowercase word, forming a predictable memex_<operation> pattern. While recent and health are not verbs, the naming is uniform and immediately readable.
Six tools is a well-scoped size for a memory system: search, store, correct, retrieve, list, and health cover the core operations without redundancy. Each tool earns its place and the count feels neither thin nor heavy.
The surface covers the full memory lifecycle: storing, searching, retrieving by id, correcting with supersession, recency listing, and backend health. Deletion is intentionally omitted with supersession used instead, so there are no dead ends in the intended workflow.
Maintenance
Related MCP Connectors
Persistent memory for AI agents. Search, store, and recall across sessions.
Persistent memory for AI agents. Search and store durable facts, preferences and decisions.
Universal persistent memory and knowledge retrieval layer for AI agents and LLMs.
Universal memory for AI agents and tools. Save, organize and search context anywhere.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceProvides infinite long-term memory for AI agents with persistent, searchable storage of project details, preferences, and snippets. Reduces token costs by retrieving only relevant memories while keeping all data stored locally.157MIT
- AlicenseNot gradedqualityBmaintenanceLocal-first, multi-user shared memory for AI agents with semantic search, offline support, and team synchronization.MIT
- AlicenseNot gradedqualityCmaintenanceProvides fully local long-term memory for AI agents by enabling semantic search over notes and session logs using Ollama embeddings, with no external APIs or databases.MIT
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to capture, structure, remember, and retrieve source-backed memory as local Markdown files, with reviewable writes and no cloud dependency.186MIT