Skip to content
felipesauerPublic

About

Your decisions, handed to your agents' sessions and held at the edits they govern — append-only and signed in the repository, and checkable by anyone. Tamper-evident, not tamper-proof. CLI and MCP server for Claude Code, VS Code and Cursor.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Latest commit

 

History

719 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
mnema, a chain of signed blocks

Your decisions, handed to your agents' sessions and held at the edits they govern — append-only and signed in the repository, and checkable by anyone.

CI Release License: Apache-2.0 Node 22.22.2 or a later 22, or 24.15.0 or later

mnema keeps the calls behind your agents' work as signed, append-only facts in the repository. A session opens with the ones in force, a rule can refuse or pause the write it governs, and mnema verify checks the record with no key and no network.

How mnema fits: an agent session opens with the decision in force; a write under the path a rule refuses is denied; a write elsewhere lands; a decision the agent records is signed into the chain in the repository; mnema verify checks the chain
Remember Enforce Prove
With the plugin, each agent session opens with the decisions in force, by name and id. A rule addressed at a path can refuse an agent's write there, or hold it for a person where the host allows. Every write is signed and hash-chained; anyone can verify it, even in a browser.

Claude Code · VS Code · Cursor CLI · GitHub Action · SDK · mnema site. The Action, the SDK and the VS Code extension run from a checkout; nothing is on npm yet.

Tamper-evident, not tamper-proof: what is still in the record has not changed since it was signed, and a stranger can check that without your keys and without installing this.

Quick start · How it works · Features · Watch it · What it proves · Docs

Quick start

# install: npm i -g the four release tarballs; the exact line is in docs/install.md
claude plugin marketplace add felipesauer/mnema   # the plugin hands each session the record
claude plugin install mnema@mnema
cd your-repository && mnema init
mnema decision record "Keep money as integer cents" "Float sums drift; cents are exact."
mnema verify

The whole install, the other hosts and the first record, line by line, are in docs/install.md and docs/first-record.md.

How it works

Record, rule, hand over, verify — over a signed, append-only record committed with the code
  1. Record. An agent over MCP, or you at the command line, writes a decision with its reasoning and the options turned down.
  2. Rule. A person accepts it, and mnema link addresses it at a path. The rule can govern that path, ask for a person there, or refuse a write.
  3. Hand over. With the plugin, each session opens with what is in force, and each edit meets the rules for its file.
  4. Verify. Every fact is signed and hash-chained. mnema verify, a second reader in Python, or the page mnema site writes checks it.

More in docs/how-it-works.md; what each host does and does not reach is in docs/agent-hosts.md.

Features

Feature What it does
Opens every session With the plugin, the decisions in force, the adopted patterns and the notes near the work. Agent hosts
Rules at each edit In Claude Code, the rules for a file land beside the write. Agent hosts
Refuses a write refuses-a-write stops an agent's write there, in Claude Code, VS Code and Cursor CLI. Features
Asks for a person asks-for-a-person holds the write until someone decides, in Claude Code and VS Code. Features
Supersede, never edit A change of mind is a new decision. The old one leaves the opening and stays in the record. How it works
Take a note back mnema retract appends a signed retraction, and nothing is erased. Features
Every write signed The command line and the MCP server sign each write before they return. How it works
mnema verify No key, no network. It names the level it reached, not yes or no. What it proves
A second reader A dependency-free Python verifier, written from the format's spec alone. Verify without installing
A page that verifies itself mnema site writes one HTML file, and the reader's browser checks it. The page
A pull-request check The Action comments what a PR does to the record and fails when it is not signed. Packages
The git log, read against it trailer, commits, why and aging tie commits to decisions. Features

Watch it

mnema init, a decision recorded and accepted, the decisions the next session is handed, and verify
The first record: the command line in an empty repository, from init to verify. Recorded from the built binary by recordings/first-record.sh.
mnema at a shell, the first door, and the console answering reads
At a terminal, mnema alone asks what you want to do here, and its first door opens the console: a session that reads the record and refuses to write. It needs a window at least 80 columns wide and 42 rows tall. Driven through a pseudo-terminal by recordings/console.json.
An agent's write refused by a rule addressed at its path
A write refused: the rule addressed at the path stops an agent's edit there. Recorded from the built binary by recordings/a-write-refused.sh.
A decision superseded: it leaves what the next session is handed, and stays in the record
A decision superseded: a later call takes its place, the old one leaves what the next session is handed and stays in the record. Recorded from the built binary by recordings/a-decision-superseded.sh.

A case in the suite runs the scripts again against the built binary and fails when a recording no longer shows what the binary draws, so none of them can go on showing an older product in silence (the-recordings-are-what-the-binary-draws.test.ts).

What it proves — and what it does not

mnema verify reads the events and the committed public keys of a project's trees — no private key, no network — and prints each verdict verbatim, naming the level it reached.

  • What holds. A changed or reordered event breaks the hash chain, and an edit made without the signing key fails the signed checkpoints.
  • What does not hold. Nothing proves that nothing was removed: a hash chain shows what changed, never what is gone, and the history a git remote keeps is what covers omission. A record forged whole under a fresh key verifies clean, and a key is not proven to be the person a name says. A refusal of a write covers the editing tools of Claude Code, the VS Code agent (Copilot) and Cursor, and not their shell: sed -i on a protected file goes round it.
  • What a green verify means. That nothing verifiable is broken, not that the record is honest, and the gate protects the shape of a change, not who may make it.

The whole table, claim by claim, is in docs/what-it-proves.md; what was measured, and what it does not show, is in docs/measured.md.

Docs

Install · Your first record · How it works · Agent hosts · Features · What it proves · Verify without installing · The page that verifies itself · What was measured · Where it fits · Packages · Build from source · Contributing

License

Apache-2.0. See LICENSE and NOTICE.

About

Your decisions, handed to your agents' sessions and held at the edits they govern — append-only and signed in the repository, and checkable by anyone. Tamper-evident, not tamper-proof. CLI and MCP server for Claude Code, VS Code and Cursor.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages