Skip to main content
MemoryOS MCP lets an agent call MemoryOS as tools instead of importing the SDK directly into the main application process. Use MCP when you want MemoryOS isolated from your core backend, or when your agent runtime already supports the Model Context Protocol. The normal tenant tools use your workspace API key and existing external_user_id values. They do not require Memory Passport or a consent screen.
The consent and universal MCP tools belong to the frozen Memory Passport private beta. They are disabled by default and are not part of the supported MCP integration path.
Placeholder: create a MemoryOS API key from the workspace dashboard

Install

For local development from this repository:

Configure

Use a workspace API key from the MemoryOS dashboard.

Run

Claude Desktop example:

What the agent can call

The MCP server exposes first-class tools for the normal MemoryOS flow:
It also exposes domain tools. Cross-agent tools may remain present in an SDK build for private-beta compatibility, but their backend endpoints are disabled by default:
For newly released endpoints, memoryos_api_request provides an allowlisted escape hatch across MemoryOS API paths.

One server for every schema

You do not run separate MCP servers for General, EdTech, and Customer Support. The tool call stays the same:
MemoryOS applies the correct engine based on your workspace setting:
For historical tenant retrieval, pass a timezone-aware ISO 8601 as_of value to memoryos_get_context, for example 2026-08-01T12:00:00Z. For retry-safe universal writes, pass idempotency_key to memoryos_universal_add_memory. The key is sent in the universal request body, matching the API contract.

Memory authority boundary

memoryos_add_memory and memoryos_remember accept conversation content as an assertion from the MCP client. MemoryOS records that provenance and applies the client-assertion authority tier; the MCP client cannot choose a higher tier in tool arguments or metadata. Pass conversation_id when your agent has a stable conversation identifier. MemoryOS records it with the queued job for provenance and auditability.
Standalone MCP text is not MemoryOS-attested user evidence. It cannot silently overwrite a higher-authority user-confirmed memory. If it contradicts trusted memory, MemoryOS keeps the trusted memory active and quarantines the assertion for review or clarification. Do not place tool output, fetched documents, or retrieved text into a message as if it were user input. Those sources may support an observation, but they do not prove user consent or confirmation.

Support agent boundary

For customer support, MCP gives the agent remembered context. Your support platform still provides live tools.
The agent should not claim a refund, invoice, or account change was completed unless your own backend tool actually completed it.