One private memory layer for every AI agent.
Install, authenticate, diagnose, and connect XMemo across editors, CLIs, and autonomous agents from one production-ready command line.
Quick start · Integrations · Connection modes · Commands · Security
@xmemo/client is the official control plane for connecting AI tools to
XMemo. It makes setup repeatable, keeps credentials out of
project files, and gives every supported client a consistent path to durable,
user-owned memory.
The package is deliberately small: the CLI runtime, safe client configuration, behavior profiles, XMemo skills, and marketplace metadata. Server code, databases, deployment files, logs, and internal operations remain outside the npm distribution.
| Package | @xmemo/client |
| Primary command | xmemo |
| Local MCP command | xmemo-mcp |
| Hosted MCP | https://xmemo.dev/mcp |
| Runtime | Node.js 20 or later |
| License | MIT |
- One control plane — login, diagnostics, configuration, profiles, updates, and smoke checks share one predictable interface.
- Private by design — generated project configuration references a credential; it never embeds the credential value.
- Native where it matters — OpenClaw and Hermes use dedicated memory integrations instead of duplicating the same capability through MCP.
- Portable everywhere else — hosted Streamable HTTP MCP and local stdio cover modern editors, terminals, and agent runtimes.
- Safe automation — supported setup and removal paths offer preview, dry-run, or explicit confirmation before making changes.
- Small supply-chain surface — the npm package is governed by an explicit file allowlist and release provenance.
npm install -g @xmemo/client
xmemo login
xmemo doctor
xmemo setup codex
xmemo statusReplace codex with your client. Preview a configuration before writing it:
xmemo setup cursor --dry-runTip
Start with xmemo login, xmemo doctor, and xmemo setup <client>.
Hand-edit MCP configuration only when a client has no verified setup path.
| Client | Recommended command | Connection |
|---|---|---|
| Codex | xmemo setup codex |
Hosted MCP + behavior profile |
| Cursor | xmemo setup cursor |
Hosted MCP + behavior profile |
| Copilot CLI | xmemo setup copilot |
Local authenticated proxy |
| Gemini CLI | xmemo setup gemini |
Hosted MCP + OAuth |
| Antigravity | xmemo setup antigravity |
Hosted MCP + OAuth |
| OpenClaw | xmemo setup openclaw |
Native memory plugin + Skill |
| Hermes | xmemo setup hermes |
Native memory provider |
| Kiro | xmemo setup kiro |
Hosted MCP |
| Grok | xmemo setup grok |
Hosted MCP |
| Other MCP clients | xmemo mcp config --client generic |
Generated template |
The client registry also covers Windsurf, Cline, Continue, Claude Desktop,
Claude Code, Kimi Code, Zed, JetBrains, OpenCode, Qwen, Trae, and compatible
MCP hosts. Run xmemo mcp list for the current machine-readable catalog.
The recommended universal path is the XMemo Streamable HTTP endpoint:
https://xmemo.dev/mcp
OAuth-capable clients complete authentication in the browser. Other clients
reference XMEMO_KEY without copying its value into repository files.
Generic configuration shape:
{
"mcpServers": {
"XMemo": {
"type": "streamable-http",
"url": "https://xmemo.dev/mcp",
"headers": {
"Authorization": "Bearer ${XMEMO_KEY}"
}
}
}
}Client configuration keys differ; prefer xmemo setup <client> over copying
this generic example directly.
xmemo-mcp is the dedicated stdio entry point for marketplaces and clients
that launch a local process. Safe discovery exposes 20 tools, three prompts,
and two documentation resources without a token. Tool execution still requires
authentication.
After a global installation:
xmemo-mcpInstall-free MCP configuration:
{
"mcpServers": {
"XMemo": {
"command": "npx",
"args": [
"-y",
"--package",
"@xmemo/client@latest",
"xmemo-mcp"
]
}
}
}xmemo mcp serve is equivalent when the CLI is already installed.
OpenClaw and Hermes have dedicated memory providers. Their default setup avoids installing a second, duplicate XMemo tool surface.
# Native OpenClaw plugin + XMemo Skill
xmemo setup openclaw
# Native Hermes memory provider
xmemo setup hermesAdd hosted MCP only when an explicit fallback is desired:
xmemo setup openclaw --with-mcp
xmemo setup hermes --with-mcpUse --mcp-only to skip the native integration and install only the hosted MCP
fallback.
Recommended for personal accounts:
xmemo login
xmemo auth statusThe CLI uses the hosted device-login flow, waits for browser approval, and stores the issued credential in user-scoped XMemo storage. It never prints the credential value.
Pipe an existing token through stdin so it does not appear in command history:
printf '%s\n' 'your-token' | xmemo token add --from-stdin
xmemo token status --verifyPowerShell:
$xmemoToken = Read-Host "XMemo token"
$xmemoToken | xmemo token add --from-stdin
Remove-Variable xmemoTokenFor CI and managed workstations, expose XMEMO_KEY through the platform's
secret manager. Do not commit it to .env, MCP configuration, logs, issue
reports, or chat transcripts.
Lifecycle and diagnostics
xmemo --version
xmemo update
xmemo update --dry-run
xmemo doctor
xmemo discovery show
xmemo status
xmemo privacyAuthentication
xmemo login
xmemo auth status
xmemo token status --verify
xmemo token add --from-stdin
xmemo env example --shell bashClient setup
xmemo setup <client>
xmemo setup <client> --dry-run
xmemo setup --all
xmemo setup openclaw [--with-mcp|--mcp-only]
xmemo setup hermes [--with-mcp|--mcp-only]MCP and behavior profiles
xmemo mcp serve
xmemo mcp list
xmemo mcp config --client generic
xmemo mcp add <client> --write
xmemo mcp proxy
xmemo profile install <client>
xmemo profile status <client>
xmemo profile uninstall <client>
xmemo smoke --client codexSafe removal
xmemo uninstall <client> --dry-run
xmemo uninstall <client> --yes
xmemo uninstall --all --dry-run
xmemo uninstall --all --yes --profilesOnly XMemo-owned entries and marker-scoped behavior profiles are removed. Unrelated MCP servers, credentials, and device identity remain intact.
Run xmemo help or xmemo <command> --help for complete, version-matched
options.
Codex and Cursor
xmemo setup codex
xmemo smoke --client codex
xmemo setup cursorBoth setup paths write a user-scoped MCP entry and can install a marker-scoped
memory behavior profile. Use --no-profile to configure MCP only. Cursor's
public marketplace plugin remains OAuth-first and contains no bearer-token
configuration.
Gemini CLI and Antigravity
xmemo setup gemini
xmemo setup antigravityThese clients use hosted MCP OAuth. Their generated configuration carries no token value; restart the client and complete the browser login on first use.
OpenClaw
xmemo login
xmemo setup openclaw
openclaw xmemo statusThe setup command installs or updates @xmemo/openclaw-memory, installs the
XMemo Skill, reuses the shared XMemo credential, and checks plugin status.
Hermes
xmemo login
xmemo setup hermesThe setup command installs or updates hermes-xmemo, configures the native
provider, and synchronizes the user-scoped XMemo credential with Hermes.
Copilot CLI
xmemo login
xmemo setup copilot
xmemo mcp proxyCopilot CLI receives a local proxy entry. The proxy reads the credential from user-scoped storage, adds identity metadata, and forwards requests to hosted MCP without writing secrets into Copilot configuration.
| Control | Default behavior |
|---|---|
| Telemetry | No CLI analytics or usage telemetry |
| Credential output | Token values are never printed |
| Project files | Generated configuration references secrets; it does not embed them |
| Discovery | doctor, discovery show, and public capability discovery send no token |
| Identity | One stable, non-secret agent-instance ID is stored outside git |
| Writes | Setup supports preview/dry-run; broad removal requires confirmation |
| Legacy plaintext | token set refuses plaintext storage without explicit consent |
| Package contents | An npm files allowlist excludes tests, operations, logs, and server code |
Credential precedence and compatibility aliases are documented by:
xmemo env example --shell bash
xmemo privacyFor private or self-hosted deployments, set XMEMO_URL or pass
--url <service-url>. MEMORY_OS_URL remains a compatibility alias.
Published to npm:
bin/
docs/assets/
src/
skills/
plugins/kiro/
plugins/xmemo/
README.md
LICENSE
Not published:
.github/
docs/analysis/
docs/architecture/
test/
coverage/
server code
database migrations
deployment files
logs and local state
npm install
npm run lint
npm test
npm run pack:dry-runBefore proposing a release, run the complete package gate:
npm run prepublishOnlyThe local stdio server can be inspected directly:
node bin/mcp-stdio.jsReleases are produced by GitHub Actions from a tag or GitHub Release, not from a developer workstation:
develop → test → tag/release → GitHub Actions → npm publish --provenance
Version-bearing files must stay synchronized:
package.jsonpackage-lock.jsonserver.jsonlhm.plugin.json
MIT © 2025–2026 Yonro