agora-mnemo
The agora-mnemo server is a persistent, value-ranked memory layer for AI agents that supports intelligent storage, retrieval, conflict detection, and governance of facts with append-only integrity.
remember– Store facts append-only with tags, importance value, and memory type (episodic/semantic/procedural) controlling decay rate. Supports deterministic supersession via akey(new value retires the old one automatically) and an echo guard to prevent stale values from being resurrected.recall– Retrieve top-k memories ranked by relevance × accrued value (not recency). Superseded/stale values are hidden automatically. Supports soft metadata filters and influence gating to resist poisoning.revert– Restore a keyed fact's previous value from the supersession ledger without naming the old value. Uses an explicit channel so content alone cannot undo a correction.route– One-call router that classifies an utterance as a new assertion, correction, or revert instruction and executes the appropriate ledger operation, handling ambiguous reversion safely via configurable policy.check_conflict– Read-only, zero-LLM pre-write check: identifies whether a proposed fact would contradict an existing memory (value change on a key, numeric clash, or negation) before committing.contradictions– Flags mutually incompatible memories for human review. Only flags; never auto-resolves, preserving trust in the store.consolidate– "Dream pass" that flags hub memories, links near-duplicates, enforces state-toggle guards for polarity flips, and prunes low-value surplus under a keep budget. Additive only — never edits raw memories.consolidate_clusters– Consolidates only semantic clusters that have grown past a density threshold, leaving sparse topics as raw episodes.sleep– Idempotent idle-time maintenance (dedup, cluster consolidation, budget pruning) to keep the write/recall path fast. No-op when nothing is ripe.value_by_cohort– Rolls up memory count, total value, and average by tag/cohort, where the statistical signal is meaningful rather than noisy per-memory metrics.credit– Closes the accuracy feedback loop: records whether memories that drove a decision led to a good or bad outcome, updating a Beta posterior so future recall ranks by track record, not just similarity.forget– The only operation that genuinely removes content. Deletes by id or substring and scrubs all references from survivors' links and supersession pointers so forgotten memories cannot resurface.
Provides a memory layer with recall, consolidation, and correction operations as the core of the Agora autonomous research system.
inspeximus — long-term memory for AI agents that stays correct
Python agent memory in one zero-dependency file, plus an MCP server for Claude Code and Cursor. When a fact is corrected, inspeximus serves the new value and stops the old one from resurfacing — deterministically, with no LLM in the loop.
pip install inspeximusThe 30 seconds that matter
Every memory library can store and retrieve. The question nobody answers is what happens when a stored fact turns out to be wrong.
from inspeximus import Inspeximus
m = Inspeximus("memory.json")
m.remember("The staging database is db-3.internal", key="staging-db")
m.remember("The staging database is db-7.internal", key="staging-db") # a correction
m.recall("which staging database")[0]["text"]
# 'The staging database is db-7.internal' <- the correction wins, every time
m.revert("staging-db") # and it is reversible
m.recall("which staging database")[0]["text"]
# 'The staging database is db-3.internal'No embedding drift, no "the LLM usually picks the newer one". The old value is retired by key, and the retirement is a record you can audit, revert, and prove.
Related MCP server: NeverOnce
Why another memory library
Because we measured the one thing the others do not publish: how often a corrected fact comes back.
Each system was run on its own native configuration, same task, same 30 trials:
system | keeps the correction | resurrects the old value |
inspeximus | 100% | 0% |
Graphiti 0.x (Neo4j + OpenAI) | 86.7% | 13.3% 95% CI [3.3, 26.7] |
mem0 2.0.11 (OpenAI native) | 53.3% | 46.7% 95% CI [30.0, 63.3] |
inspeximus, guard disabled | 0% | — the control: this is what the guard is doing |
n = 30 per system. mem0 measured at 2.0.11 (2026-07); mem0 is now on 2.0.18 and we have not
re-run it — the version is stamped rather than the claim being restated as current. Full method,
raw arrays and the re-runnable harness:
RAMR · echo_resistance_backends_result.json
Read the Graphiti row correctly — its echo defense did not fail. Our own raw output records
echo_attributable_flips: 0out of 26 corrections that were extracted correctly before the echo ran. Graphiti's bi-temporal invalidation held every one of them. The 13.3% above is four pre-echo extraction misses — the correction never made it into the graph — which is a different failure from the one this table is about. Stated as the mechanism rather than the headline: on echo-attributable resurrection, Graphiti scores 0%, the same as us, by keeping the supersession link at write time. That is the real finding here: what separates these systems is whether the link is recorded, not who recorded it.
The bottom row is the point. Turn our guard off and we score zero — so the number is the mechanism, not the benchmark being kind to us.
Use it in Claude Code (one line)
inspeximus install --ide claude # also: cursor, windsurf, codex, clineThat wires an MCP server with 68 tools and three hooks. From the next session on, your agent starts
knowing what the last one decided — no CLAUDE.md editing, no re-explaining:
SessionStart injects the decisions still in force
PostToolUse captures what actually happened, keyed by file
PreToolUse surfaces the decision that bears on the action before it runs
What you get
Correction as a first-class operation. remember(key=...) retires the previous value for that key.
revert(key) restores it. history(key) shows the chain. All deterministic, all auditable.
Erasure that can be proven. forget_subject() hard-deletes every memory attributable to a subject —
including summaries that inherited it through lineage — and leaves a signed, content-free tombstone, so
a later audit can tell deliberately erased from tampered with.
Provenance you can check, not just store. check_sources() re-reads each record's origin and returns
FRESH / DRIFTED / ORPHANED / UNCHECKABLE, plus four coverage numbers that are deliberately kept
apart — because a source field that is 98.3% populated and 0.01% re-fetchable is a schema, not a
guarantee. (Those two numbers are ours, measured on our own production store.)
Current-state applicability. evaluate_applicability() answers a different question from "is this
memory true": may it drive an action here, now? Historical evidence can be perfectly valid and no
longer authorized — the branch moved, the policy changed, the tenant differs, the window expired.
Implements the vendor-neutral CML contract; two independent implementations agree on its frozen fixture.
Multi-tenant isolation. for_tenant("acme") gives a scoped view over one shared store, with the
tenant bound into the signed message so a record cannot be moved between tenants and still verify.
Zero dependencies. One file. Semantic recall is optional (embed=your_model); the lexical fallback
needs nothing. The MCP server, encryption and framework adapters are all opt-in extras.
Works with
langchain · langgraph-store · llamaindex · haystack · autogen · pydantic-ai ·
google-adk · memoryagentbench
9 of 12 verified against current upstream, 3 recorded broken — crewai,
langgraph-checkpointer and openai-agents, named rather than quietly dropped from the list. The
counts are read from docs/integration_conformance.json by the
claims audit, so this line cannot drift from what the runner last measured.
A "works with" list that only names successes is a logo wall. This one tells you which adapter will break before you build on it.
How this is tested
2,600+ tests, and a mutation gate that is the reason to believe them: 175 seeded defects, 175 killed, 0 survived. A test suite that passes is not evidence; a suite that catches every deliberate break is.
Every number on this page is registered in docs/CLAIMS.md, with the exact command that recomputes it. If one disagrees with your run, that is a bug report we want.
Documentation
the guided tour: the benchmark, the MCP surface, the governance story | |
the resurrection table in full, with the control and the honest scope | |
the one-line MCP install, and what each of the three hooks does | |
every mechanism, every measurement, and the ones that failed | |
every method, with the failure it exists to prevent | |
right-to-erasure across derived summaries, with receipts | |
Article 12 logging, mapped to what the store already keeps | |
all 68, and what each is for | |
every published number, and the command that recomputes it | |
what changed and why, including what we got wrong |
Who this is for
You are building an agent that runs for weeks, not minutes. It will learn something, and then that thing will change — a config value, a policy, a person's preference, a fact. The failure that will cost you is not the agent forgetting. It is the agent confidently remembering the old answer.
That is the failure this library is built around, and the only one we benchmark ourselves on.
Citing
Archived on Zenodo with a version-independent DOI — 10.5281/zenodo.21708778. Machine-readable metadata is in CITATION.cff, so GitHub's "Cite this repository" button gives you BibTeX and APA directly.
MIT licensed. Built by Agora, an autonomous research organisation that publishes its failed replications next to its successful ones.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
AlicenseAqualityFmaintenanceAn MCP server that integrates with mem0.ai to help users store, retrieve, and search coding preferences for more consistent programming practices.29658Apache 2.0- AlicenseAqualityCmaintenancePersistent, correctable AI memory with zero dependencies. Corrections always surface first and never decay. SQLite-backed, 400 lines of pure Python, MCP server included.73MIT
- AlicenseAqualityBmaintenanceTwo-layer memory for AI agents. Episodes compress into identity. The only MCP memory server with an immune system. Patterns earn permanence through evidence, false knowledge gets caught and demoted, and stale information fades — so your agent's memory gets smarter over time, not just bigger. Zero dependencies. 5 tools. Works with any MCP client.169MIT

Recallofficial
Alicense-qualityCmaintenanceOpen-source MCP memory server for AI agents — persistent, searchable, tiered memory across sessions. Works over stdio (Cursor, Claude Desktop) or HTTP+SSE. MIT licensed.6MIT
Related MCP Connectors
User-owned memory for AI agents, Copilot, Claude, IDEs, CLIs, and chat apps over remote MCP.
Person-owned, portable AI memory as a remote MCP server, readable and writable by any MCP client.
Analytical memory for AI agents: a real Postgres queried in plain English over MCP. One command.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DanceNitra/inspeximus'
If you have feedback or need assistance with the MCP directory API, please join our Discord server