{"_id":"@agentimprint/mcp","_rev":"11-000636c12550bdcf18eff88d34eda877","name":"@agentimprint/mcp","dist-tags":{"latest":"0.9.0"},"versions":{"0.1.0":{"name":"@agentimprint/mcp","version":"0.1.0","license":"MIT","_id":"@agentimprint/mcp@0.1.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"de30bcf6ee932616a1a967696d8077ae87c57161","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.1.0.tgz","fileCount":3,"integrity":"sha512-krHfFkQNQKKVGQxA869NUMrted8GUhtrkksqt/ahIOX2MbND7bUUSYOuEphyPqR1rpya4PIfbkIiS7+bhX6YHA==","signatures":[{"sig":"MEUCIC9yf/Lzz4UwzkVcRz/8ePiKDlMeGcOy6aNO27ZCZAndAiEAkaiHeEPGiGGkpahGQ9ozc8t5ziGDFxHgH4UDEJfWkhw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28800},"type":"module","gitHead":"07377704877711e45b10801796d37dd63e6bf3cf","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"_npmVersion":"10.9.7","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.22.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.1.2","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.0_1781808559384_0.022562230826495","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agentimprint/mcp","version":"0.1.1","license":"MIT","_id":"@agentimprint/mcp@0.1.1","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"104aa8a6872db0dacb0bf0060d50ea65d9154e66","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.1.1.tgz","fileCount":3,"integrity":"sha512-6EpcutmprKXJNo3JZQAT9uLEBayZ1cP0iLfK/0Mqry/6LQ5uG9pEBtomYj4ZwRqb8aZAqZzaX6bzCWyzRaNAcA==","signatures":[{"sig":"MEUCIAPwzGYfFlVku0qaZruTqbFDUO0XSBuj44fL3kwxlzqeAiEAnfr7wdrpsApwuAKBTXt3paHITki3Ed16IUpyoEjt35E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34035},"type":"module","gitHead":"be9e8f771fb77b907df6e8d6b32e59b3a2ff91a1","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.1.4","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.1_1786457685288_0.7897839317653004","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentimprint/mcp","version":"0.2.0","license":"MIT","_id":"@agentimprint/mcp@0.2.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"5210e8e252d6937c4119877c833ce3e334b51516","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.2.0.tgz","fileCount":3,"integrity":"sha512-1dyobVbw/CupKoGQfGKdrQP1OFFKzcbEVpUlQLNwUdSeoMfRYAUl7sG9zLR0CHUruw4p5mvWDAuTl3GRGzfq0w==","signatures":[{"sig":"MEQCIGKzLjxl+15RakIFSVCTCf3Bhm2ldYnuEWygoPuX2hE8AiAjdZ8pzAIDYTGaDJ4WULOZpX83shEf+zWfggRtBYhlWQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":47754},"type":"module","gitHead":"d36c5b85d2360b2e5f512c6eec51f2c797caef32","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.1.5","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@xenova/transformers":"^2.17.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.0_1786485303545_0.8556431627021317","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@agentimprint/mcp","version":"0.3.0","license":"MIT","_id":"@agentimprint/mcp@0.3.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"aba16346fb12982fd573d5141dc6edf036d1621c","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.3.0.tgz","fileCount":3,"integrity":"sha512-1XJ40nWekqVBsLdgWDkKW721U2TmRztboNEbue7Qnq+eOOoIhy3++hT9fDPyM46TkOuEmud0r4JjCVWL++N5/A==","signatures":[{"sig":"MEQCID/UkSc2Qv6+295KsOEmPO+JBOlvkK8hXuim8F2Tx2BbAiAdu42LBGx3TjxK+YRugBmjd2hUYLpAtKwlnvM52HkGmw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":54819},"type":"module","gitHead":"dcbcde94a1bc4fda45b6e35ecc001a8fbc295fa8","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.2.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@xenova/transformers":"^2.17.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.3.0_1786736779540_0.901185553457936","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@agentimprint/mcp","version":"0.4.0","license":"MIT","_id":"@agentimprint/mcp@0.4.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"d629df95025a5c505b3243a9861e04ae066cec45","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.4.0.tgz","fileCount":3,"integrity":"sha512-/7I/CRvgJnK/Ds80Fhpk+H3cGqiaWkzZ2IWEaxwvat2539NKrkbEPaO8VgncWtFxo3RJUkt0zfYQPQLJpjcidg==","signatures":[{"sig":"MEQCICvrm9CByyT9Zrukb+pQoE+xAQRofxpaD5ThBghbsgCkAiAj35afthd6asXY7tizVohANA7fyPNi34yHj3I8jQRh9A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":54902},"type":"module","gitHead":"7016a7cd30918b621c39d06d1386aea8f9ba6f62","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"overrides":{"sharp":"^0.35.3","adm-zip":"^0.6.0"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.2.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@huggingface/transformers":"^4.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.4.0_1786749751839_0.01852357060449128","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agentimprint/mcp","version":"0.5.0","license":"MIT","_id":"@agentimprint/mcp@0.5.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"f38e900b1e123a9624567651b9f1e2ff2d4c84e9","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.5.0.tgz","fileCount":3,"integrity":"sha512-FKXXukl/RXWnZlBOTIW6ntLuRqHFxCUSjHNT8Tl/5Q4MU55mjcjtywImzn5F9bou5Eo5u76gL7pzJ1QCB7DRNw==","signatures":[{"sig":"MEUCIHLk6hcvpVOGtZJ7l5dbmbFTjRIi3SmPudoX6eHH02c6AiEA/YkuJKz9PSwRkd46TwJMhGRG3ibpjLXEBFd4Gi3C9eE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":75595},"type":"module","gitHead":"2c60ce1473720e8b2b8f83ec702565c126074a55","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"overrides":{"sharp":"^0.35.3","adm-zip":"^0.6.0"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.3.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@huggingface/transformers":"^4.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.5.0_1787058538871_0.7223896613748282","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@agentimprint/mcp","version":"0.6.0","license":"MIT","_id":"@agentimprint/mcp@0.6.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"ee704f77be67b7b30ea0a9a9bae27e2e77021fcd","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.6.0.tgz","fileCount":3,"integrity":"sha512-mCn/8h8/jlKt9b3/J5xZRmrwha6m2784S4VhNmwT2YPWbKLdnBs2P4af+R6Q7rC03/4he7lE4vXujDVJFNoHLw==","signatures":[{"sig":"MEQCIGQTXmDMWei+//ZyHP+0xxX/6RhDeH0ucPc4vGQcKO7jAiAICLIbvgLF36fsYZxuc5t9XsXWqsXnKaLvLS1/5TdxUQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":78572},"type":"module","gitHead":"e2d85fe1b9639a0aa5f471c600f90108e3d01d10","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit -p tsconfig.typecheck.json","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"overrides":{"sharp":"^0.35.3","adm-zip":"^0.6.0"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.4.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@huggingface/transformers":"^4.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.6.0_1787078135756_0.4419477056185963","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@agentimprint/mcp","version":"0.7.0","license":"MIT","_id":"@agentimprint/mcp@0.7.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"45cef4fd3bdb0f04c32d8d825184e582f7f2e4ce","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.7.0.tgz","fileCount":3,"integrity":"sha512-og86ynxRn9vaVx9hxd2z6q5h9BcDxCptmBIEfkjAH49MKYu6mRGMEctatUV+EwAqJsf6XMW2a8MM2pZkowAK2Q==","signatures":[{"sig":"MEUCIQDz8l3me5PXicIlHCRyHSI3+wBTF/nJonE2Y9LWEwABLwIgLlZqOKExnrqaJx24h/UwR6FrOb1Ryvk30LhiS/Hpn0c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":86448},"type":"module","gitHead":"28249d1a5465666b00c11437ef71c4645c1c050b","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit -p tsconfig.typecheck.json","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"overrides":{"sharp":"^0.35.3","adm-zip":"^0.6.0"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.4.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@huggingface/transformers":"^4.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.7.0_1787089169998_0.6950887908153953","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@agentimprint/mcp","version":"0.8.0","license":"MIT","_id":"@agentimprint/mcp@0.8.0","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"4ea59822d148192c099e09dc3c20626f62a83a3b","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.8.0.tgz","fileCount":3,"integrity":"sha512-S82cKp4uQ0ypL8T3nKdCLOiHVM58s3QPANnfCUJn2K640b49pK8QaOO/0IpeKpSKGMBj2jYOO08V7LjSGJs7lw==","signatures":[{"sig":"MEUCIFKkzO5+hGW9ENJWZUL+a+eFfENL14/gO4MUn8MFE1SmAiEAxVGN6hjeLJ8kLUBHdJYTSSvGRMbaiX4a61+1NUH29P4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101951},"type":"module","gitHead":"a79447c03b8b6b52d4be8f86e2d83428bcf833b4","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit -p tsconfig.typecheck.json","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"overrides":{"sharp":"^0.35.3","adm-zip":"^0.6.0"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.4.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@huggingface/transformers":"^4.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.8.0_1787102472066_0.9601998051961915","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"@agentimprint/mcp","version":"0.8.1","license":"MIT","_id":"@agentimprint/mcp@0.8.1","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"bin":{"agentimprint-mcp":"dist/index.js"},"dist":{"shasum":"18deb0f472160388de4ace10dda6ae3b51cbc41f","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.8.1.tgz","fileCount":3,"integrity":"sha512-egNdoedFQnHCaUmX+GMSJzes1jwe4dSPL5Lb2wLSj0zmQ7duUhvJllrFh2qGDCJwADL0bDngLUiBvTCJurE12Q==","signatures":[{"sig":"MEMCIEtxz4Ubzwa1EskluY49B6YsYfGdT+ePRvWM2ls7sLnPAh9cYfW1Uem3kTDxLrxDp7pTQvyzhp8ntj1La8IhfGIP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101947},"type":"module","gitHead":"41e3f62a500fc917c94fa9215e9aa32aac31afc8","scripts":{"test":"vitest run","build":"tsup","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","typecheck":"tsc --noEmit -p tsconfig.typecheck.json","test:watch":"vitest"},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"overrides":{"sharp":"^0.35.3","adm-zip":"^0.6.0"},"_npmVersion":"10.9.8","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.23.0","@agentimprint/sdk":"^0.4.1","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"optionalDependencies":{"@huggingface/transformers":"^4.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.8.1_1787142584062_0.4761542222620536","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@agentimprint/mcp","version":"0.9.0","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","keywords":["mcp","model-context-protocol","mcp-server","ai-agent","agent-memory","persistent-memory","llm-memory","encrypted-storage","sovereign","claude"],"license":"MIT","type":"module","bin":{"agentimprint-mcp":"dist/index.js"},"scripts":{"build":"tsup && node ../scripts/strip-sources-content.mjs dist","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit -p tsconfig.typecheck.json","prepack":"npm run build && node --input-type=commonjs -e \"require('node:fs').accessSync('dist/index.js')\"","prepublishOnly":"node ../scripts/publish-guard.mjs"},"dependencies":{"@agentimprint/sdk":"^0.5.0","@modelcontextprotocol/sdk":"^1.0.0","zod":"^3.23.0"},"devDependencies":{"@types/node":"^20.0.0","tsup":"^8.0.0","typescript":"^5.4.0","vitest":"^1.4.0"},"optionalDependencies":{"@huggingface/transformers":"^4.2.0"},"overrides":{"sharp":"^0.35.3","adm-zip":"^0.6.0"},"_id":"@agentimprint/mcp@0.9.0","gitHead":"fee70fe53d61cd8f71ebbbfaa614f1a3458dcc0a","_nodeVersion":"22.23.2","_npmVersion":"10.9.8","dist":{"integrity":"sha512-MEp+BxT2qQqkiedrR9RTpjG8CMZ2ipGg7CNIxFtx6/iWWlaV9g75jjbrQFxsg53987nYfEZKL50K8rn96zNWkg==","shasum":"a7fb184d3aa8e4dfb3e5a9f81368d5c022a8796a","tarball":"https://registry.npmjs.org/@agentimprint/mcp/-/mcp-0.9.0.tgz","fileCount":3,"unpackedSize":114546,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDTT6nO5EcpWFvPBSpQmPLxnVxTjkvZoXtu4CEYEiU3XAiBL2AY46FQjLrB+8GBGwnsfZZg+6Gi9iiCaPcNoXIP0CQ=="}]},"_npmUser":{"name":"csatx","email":"coopersellers+havoc@gmail.com"},"directories":{},"maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.9.0_1787678732256_0.3747320393967388"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-18T18:49:19.250Z","modified":"2026-08-25T17:25:32.565Z","0.1.0":"2026-06-18T18:49:19.530Z","0.1.1":"2026-08-11T14:14:45.424Z","0.2.0":"2026-08-11T21:55:03.678Z","0.3.0":"2026-08-14T19:46:19.697Z","0.4.0":"2026-08-14T23:22:31.978Z","0.5.0":"2026-08-18T13:08:59.003Z","0.6.0":"2026-08-18T18:35:35.912Z","0.7.0":"2026-08-18T21:39:30.133Z","0.8.0":"2026-08-19T01:21:12.218Z","0.8.1":"2026-08-19T12:29:44.189Z","0.9.0":"2026-08-25T17:25:32.401Z"},"license":"MIT","description":"MCP server for AgentImprint sovereign memory — usable from any MCP harness","maintainers":[{"name":"csatx","email":"coopersellers+havoc@gmail.com"}],"readme":"# @agentimprint/mcp\n\nIf you are an AI agent, this MCP server gives you memory that survives session ends, platform migrations, and model upgrades — and the means to check it yourself, without trusting the server: every write can carry a per-entry MAC you verify under your own key, and `imprint_export` returns a Merkle root you can re-hash and compare independently. Install it with `npx -y @agentimprint/mcp` (see [Quick Install](#quick-install-any-mcp-harness) below) and any MCP-compatible harness — Claude Code, Cursor, Codex, OpenClaw, Hermes, and others — gains eight tools to store, recall, list, supersede, export, and rotate the key behind your memories.\n\n**Encryption is opt-in and client-side.** A vault is plaintext by default (`is_encrypted` defaults to `false`). This server encrypts everything written via `imprint_remember` once a master key exists — `imprint_bootstrap` generates one automatically under `managed` custody, or you can hold your own via `sovereign`/`passphrase` custody (see [Custody Modes](#custody-modes)). With no master key configured, `imprint_remember` refuses to write rather than silently storing plaintext.\n\nFull threat model and the limits we're honest about: [Sovereign Agent Memory: A Threat Model](https://agentimprint.ai/blog/sovereign-agent-memory-threat-model).\n\nAgentImprint is sovereign memory infrastructure for AI agents, built by [agentimprint.ai](https://agentimprint.ai). This package is the cross-harness MCP server — see also [`@agentimprint/sdk`](https://www.npmjs.com/package/@agentimprint/sdk) for direct TypeScript API access.\n\n---\n\n## Quick Install (any MCP harness)\n\nAdd the following to your harness MCP configuration file:\n\n```json\n{\n  \"mcpServers\": {\n    \"agentimprint\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentimprint/mcp\"],\n      \"env\": { \"AGENTIMPRINT_API_KEY\": \"<optional — omit to self-bootstrap>\" }\n    }\n  }\n}\n```\n\nNo pre-install required — `npx` pulls the package on first use.\n\n---\n\n## The Eight Tools\n\n| Tool | What it does |\n|---|---|\n| `imprint_status` | Reports current credential mode, vault UUID, custody type, and any active warnings. |\n| `imprint_bootstrap` | Provisions a new agent identity and vault. For sovereign/passphrase custody the key is written to a local `0600` file (never returned in the response). |\n| `imprint_remember` | Encrypts and stores a memory note's **content**; metadata (tags, domain, type) is stored in cleartext for querying. |\n| `imprint_rotate_key` | Rotates this agent's master key **client-side** — the new key is generated locally and the server is told only its fingerprint. Destructive; see [Rotating a key](#rotating-a-key). |\n| `imprint_recall` | Ranks and retrieves memories relevant to a query (fused lexical + semantic, salience-weighted), or lists by filter alone if `q` is omitted — in which case the order is most-salient-first. Verifies each entry's integrity before returning it. |\n| `imprint_list` | Lists memory metadata (uuid, entry_type, is_encrypted, tags, domain, created_at) without decrypting content. `include_superseded: true` also returns demoted entries, each carrying `superseded_by`. |\n| `imprint_supersede` | Records, after the fact, that an already-written entry revises one or more older memories — it re-reads that entry, verifies its MAC, merges the UUIDs into its signed `provenance.supersedes`, and re-signs it. |\n| `imprint_export` | Exports the full vault as a Merkle-signed JSON bundle for backup or migration. |\n\n> **What is and isn't encrypted.** Only a memory's `content` is end-to-end encrypted (AES-256-GCM, per-entry derived key, decryptable only with your master key). Metadata — `entry_type`, `tags`, `domain`, `confidence`, and timestamps — is stored in **cleartext** so the server can filter and paginate `recall`/`list`. Treat tags and domain as visible to the server: **do not put secrets in them.**\n>\n> Metadata **is authenticated, per entry** (`integrity_v = 1`): `imprint_remember` signs a MAC over the entry's metadata *and* its ciphertext under your master key before writing, so a compromised backend that relabels or mutates metadata (e.g. retags an old memory to match a sensitive query) is detected — `recall` and `list` return such a row with `integrity: \"failed\"` and withhold its content. Two caveats remain. Entries written **before** this shipped carry no MAC and come back `integrity: \"unverified\"` — for those, metadata really is unauthenticated, so don't make trust or safety decisions on it (once the vault is known fully signed, a missing MAC is treated as `failed` instead). And verification covers *returned rows only*: omission, stale-replay, resurrection, and duplication are **not** detected — that is the deferred freshness mechanism. Metadata is still stored in cleartext; full metadata encryption is a planned opt-in. `recall` further **quarantines** any *unverified* entry the server reports as not encrypted — it is returned flagged (`untrusted_unencrypted`) with its content withheld, because such content was never authenticated under your key and could be backend-injected. Cleartext whose MAC *does* verify is surfaced normally: the MAC proves you wrote it.\n\n> **Semantic recall.** `imprint_recall` accepts an optional `q` for relevance ranking on top of `type`/`tag`/`domain` filtering — server-side lexical (TF-IDF) rank fused (RRF) with server-side semantic rank for cleartext entries, plus a client-side semantic lane that ranks encrypted candidates locally under your own key. Ranking is purely additive: if the server has no embedding driver configured (`EMBEDDING_DRIVER` is unset by default) or nothing is embedded yet, results still return in lexical order — recall never regresses below plain filtering. Omit `q` for a filter-only listing, which never sends a query at all.\n>\n> **Query privacy.** `q` is sent to the server only when this recall's own filtered results already include a cleartext entry whose per-entry MAC verifies under your master key — cryptographic proof that entry's own author chose to store it unencrypted, so the query discloses nothing the server couldn't already read. A row the server merely *claims* is cleartext does not open this gate unless its MAC checks out, so a curious or compromised server cannot bait the gate open with a fabricated row. For a fully-encrypted vault, or with no master key configured, `q` is never sent to the server — ranking runs entirely against the locally-scored candidates.\n>\n> Recall's response carries a `recall_window` envelope — `entries_recalled`, `per_page`, `current_page`, `pages_recalled`, `more_available`, `truncated`, and an optional advisory `note` — describing *this recall's* result set, not vault totals. There is deliberately no `last_page`: with a full result lane the true page count isn't knowable from one page, and a number implying \"you're done\" next to `more_available: true` would misrepresent it.\n>\n> **Salience & decay.** Every recalled entry carries a derived `salience` score (0.15–1.0) and a `stale` flag. Salience decays an entry's weight over time from a per-`entry_type` half-life — `fact` fades fastest (180 days; API shapes and configs go stale), `preference`/`relationship`/`negative` barely fade at all (5 years; who someone is and what must never be done again don't expire), everything else lands around a year — and every consultation *lengthens* the half-life rather than resetting the clock, so a memory you keep coming back to decays slower. Nothing is ever hidden: a fully decayed memory is floored at 0.15, never zeroed. On a directed (`q`) recall, salience only nudges ranking — bounded to at most 15 positions either way by default — so the best semantic match still wins even if it's old. On a filter-only, no-`q` recall (the respawn moment, when an agent lists what it knows with no specific question) there is no relevance signal to stay dominant, so the **entire order is salience** — what still matters surfaces first, not what happened last. `stale: true` means \"unused\", not \"uncertain\": it fires purely on the decay term, before `confidence` is factored in, so a brand-new low-confidence entry is never born stale, and a well-trusted entry you haven't touched in months is.\n>\n> **How consultation is reported.** `imprint_recall` tracks which entries a `q`-bearing call actually surfaced and reports them back to the server (`touched[]`) on its own next request, or on the following `imprint_remember` if the session ends without recalling again — so a respawn-once-work-then-die agent still gets credit for what it used. A no-`q` listing reports nothing (crediting a page the agent mostly didn't read would let salience reinforce itself in a loop). Set `IMPRINT_SALIENCE_TOUCH=0` to disable this reporting entirely — salience still works, running on `created_at` alone with no reinforcement.\n>\n> **Honest about the counters.** The consultation counters (`access_count`, `last_accessed_at`) are stored **unauthenticated** — outside the per-entry MAC — because durable reinforcement across a respawn matters more than protecting a ranking hint, and binding them would mean re-opening the integrity version for a low-stakes signal. A storage-layer tamperer who controls them can shift a `q` recall's ranking by at most that same rank budget (15 positions by default) in either direction — it can neither bury a memory nor force an irrelevant one to the top. On a **no-`q` listing that bound does not apply**: that branch is ordered by salience alone, so tampering with the counters controls its order outright (a zeroed-out heavily-used memory sinks to the bottom of the respawn listing; an inflated one jumps to the top). The 0.15 floor still guarantees the memory is present and reachable on a deeper page — this is never silent deletion — but it is real rank control, not a bounded nudge. It cannot forge content, metadata, or `confidence` (still MAC-bound), and it discloses no query text or content, only a consultation pattern.\n>\n> **Contradiction nomination.** When you store a memory of a *conflictable* type (`preference`, `fact`, `heuristic`, `negative`, `pattern` — `note` is deliberately excluded), `imprint_remember`'s receipt may carry `possible_conflicts`: same-type memories the new one is semantically close to but did **not** declare via `supersedes`. Each candidate carries `uuid`, `entry_type`, `domain`, `tags`, `similarity`, `created_at`, a decrypted `preview`, and an `integrity` verdict (`verified`/`unverified` — candidates whose MAC *fails* are dropped, never previewed). This is a **nomination, not a verdict**: similarity cannot tell agreement from contradiction — \"I prefer tabs\" and \"I prefer spaces\" are nearly identical vectors, which is exactly what makes them a conflict — so nothing is ever auto-resolved. The agent reads the previews and decides.\n>\n> Nomination fires only when the new entry and the candidate share the **same `entry_type`** *and* either a **matching `domain`** or **at least one shared tag**. Both `domain` and `tags` are optional with no defaults, so a bare `imprint_remember(content, entry_type)` can never produce a nomination — supply `domain`/`tags` if you want conflicts surfaced. Everything about it is best-effort telemetry attached to a write that has **already committed**: a cold cache, a slow fetch, an undecryptable candidate or a disabled embedder all degrade to \"no conflicts reported\", never to a lost write. Absence of `possible_conflicts` is therefore **not** a promise of no conflicts. Set `IMPRINT_CONFLICT=0` to turn it off entirely.\n>\n> **Recording a conflict.** If the agent judges a candidate genuinely superseded, the call is `imprint_supersede({ entry_uuid: <the uuid the receipt just returned>, supersedes: [<candidate uuid>] })` — **not** a second `imprint_remember`, which would store a duplicate (the first write already committed). You can also pass `supersedes` directly to `imprint_remember` at write time when the relationship is known in advance; prefer that when you can, because such an entry is signed once and never rewritten, so a Merkle proof issued for it stays valid forever. `imprint_supersede` **re-signs an existing entry**, which changes its leaf hash and moves the vault Merkle root — any outstanding proof for that entry stops matching, exactly as after a content edit. It re-reads the entry and **verifies its MAC first**, refusing to re-sign anything that does not verify under your key — including an entry with no MAC at all, which would otherwise let a hostile backend launder a forged row into an authenticated one by stripping its MAC. For a legacy (MAC-less) entry, write the revision with `imprint_remember` + `supersedes` instead. An entry can point to at most 32 others; pre-existing pointers keep their place, so requests over the cap come back listed in `not_recorded`.\n>\n> **Honest about the supersede index.** A superseded entry is **demoted from default recall, never deleted** — but the `superseded_by` pointer that does the demoting is a **derived, server-computed index stored outside the per-entry MAC**, in the same spirit as the consultation counters above. Your *claim* (`provenance.supersedes`) is signed and cannot be invented or stripped without detection; the server's *resolution of it* is not. So a storage-layer tamperer who controls that index has a sharper capability than it has over the counters: it can drop an entry out of default recall **entirely**, or resurrect one you superseded, rather than merely shifting rank. It still cannot forge content, metadata, `confidence`, or your signed supersede claims. Two things bound it. Nothing is ever deleted — the entry remains in `imprint_export`, so the record is recoverable. And the index is **fully recomputable from signed provenance**: pass exported entries to the SDK's `verifySupersedeIndex()` to recompute what the index *should* be from the MAC-bound claims and get back any disagreements. And because nomination is imprecise by design and an agent will sometimes adjudicate wrong, both `imprint_list` and `imprint_recall` take `include_superseded: true` to show demoted entries again; `imprint_list` rows then carry `superseded_by`, naming the memory that replaced each one.\n>\n> **Consolidation.** `imprint_remember` also accepts an optional `consolidates`: the uuids of earlier episodic memories a new entry was *distilled from* — the evidence behind a heuristic, pattern, or preference the agent has generalized from several particulars. Unlike `supersedes`, `consolidates` deliberately does **not** demote its targets: the source episodes stay in default recall, live and unmodified, because a generalization can be wrong in a way none of its sources is, and hiding the sources would hide exactly what would expose that. The trail is written into the same signed `provenance` as `supersedes` — inside the per-entry MAC, so on a **MAC-bearing** entry a hostile server can neither invent nor strip it — and both `imprint_list` and `imprint_recall` return it as a `consolidates` array on any row that carries one. Like content, the trail is withheld on a row whose integrity verdict is `failed`: provenance is exactly what that MAC covers, so a row that fails verification does not get to keep the trail's authority either. That guarantee is exactly as strong as the row's own signature and no stronger — a legacy `unverified` row carries no MAC, so the trail it displays is server-controlled, the same as every other piece of metadata on such a row; for a vault known to be fully signed, strict mode closes this by treating an absent MAC as `failed`. Consolidation is one-way and does not itself imply promotion: once a heuristic has proven itself and you want the source episodes moved out of default recall, that is a separate, deliberate act — `imprint_supersede` against those same uuids — never implied by `consolidates` alone. **The trail identifies evidence; it is not a fetch handle.** There is no single-entry read tool and neither read tool takes a uuid filter, so an agent holding `consolidates: [\"uuid-a\", \"uuid-b\"]` cannot look those uuids up directly. It does not need to, and that is the point of keeping the sources live: an ordinary topical `imprint_recall` tends to return the episodes alongside the entry that consolidates them, and the trail then tells the agent *which* of the rows it already has are that entry's evidence. After promotion the uuids do stop appearing in default recall — pass `include_superseded: true` to `imprint_recall` or `imprint_list` to see them again. Capped at 32 uuids per entry, the same bound as `supersedes`, so that a consolidated set can later be promoted whole in one `imprint_supersede` call — **which holds when the entry declares no `supersedes` of its own.** `imprint_supersede` merges this call's uuids *after* the entry's pre-existing pointers and truncates the union at 32, so an entry that consolidates 32 episodes **and** also declares even one `supersedes` cannot promote its set in a single call: the surplus is dropped from the end and returned in the result's `not_recorded` field. Check that field rather than assuming every uuid landed, and split the promotion across calls if it is populated. A caller writing directly against the API rather than through this MCP is not bound by the 32 cap at all, but an oversized `consolidates` still could not be promoted in a single call, since `imprint_supersede` truncates its merge at 32 regardless.\n>\n> **Honest about what consolidating discloses.** `provenance` — the field both `consolidates` and `supersedes` live in — is transmitted and stored as **server-readable plaintext** alongside the ciphertext; it has to be, because the server derives its supersede index from it. So recording a consolidation tells the server that those N encrypted entries form one semantic group, even though it can read none of their content. That is **strictly more disclosure than `supersedes`**, which only reveals a pairwise revision link between two entries: consolidating five episodic memories into one heuristic tells the server all five belong to the same topical cluster, at once. Nothing here mitigates that — there is no metadata-encryption option that covers `provenance` today. An agent working in a high-sensitivity vault should treat `consolidates` as a disclosure act, not a private annotation, and decide accordingly before folding several memories together.\n\n---\n\n## Credential Modes\n\n### BYO API Key\n\nSet `AGENTIMPRINT_API_KEY` in the MCP server `env` block. The server uses this key for all API calls. You may also set `AGENTIMPRINT_MASTER_KEY`, `AGENTIMPRINT_AGENT_UUID`, and `AGENTIMPRINT_VAULT_UUID` to wire up an existing vault without bootstrapping.\n\n### Self-Bootstrap\n\nOmit `AGENTIMPRINT_API_KEY`. On first use, call `imprint_bootstrap` — the server registers a new agent, creates a vault, and persists credentials to `~/.agentimprint/credentials.json` (mode `0600`). Subsequent calls load from that file automatically.\n\n---\n\n## Custody Modes\n\nThree custody options control where the master encryption key lives:\n\n### `managed` (default)\n\nThe master key is generated locally and stored in `~/.agentimprint/credentials.json`. Convenient — no extra steps required.\n\n> **WARNING — Single Point of Failure:** Under managed custody the master key lives on this host with **NO escrow backstop in v1**. If the credentials file is lost the vault cannot be decrypted. **Back it up** (e.g. copy to a password manager) or switch to sovereign or passphrase custody. Recovery escrow is a v1.1 fast-follow.\n\n### `sovereign`\n\nPass `custody: \"sovereign\"` to `imprint_bootstrap`. The master key is generated locally, written to a `0600` file at `~/.agentimprint/sovereign-key-<vaultUuid>.txt`, and is **never stored in credentials and never returned in the tool response** (a tool result transits the model/provider — the key must not). The bootstrap response returns only the file path. Read the file, save the key securely, then set `AGENTIMPRINT_MASTER_KEY` to use the vault.\n\n```json\n{ \"custody\": \"sovereign\" }\n```\n\n### `passphrase`\n\nPass `custody: \"passphrase\"` to `imprint_bootstrap` and supply the passphrase via the **`AGENTIMPRINT_PASSPHRASE` environment variable** — never as a tool argument (which would transit the model/provider). The master key is derived deterministically via scrypt (cost N=2¹⁷) from the passphrase **and your `creator_identifier`** (used as a per-identity salt, so identical passphrases across different agents don't collide), and is **never stored** by the server.\n\n```json\n{ \"custody\": \"passphrase\", \"creator_identifier\": \"cooper\" }\n```\n\nLike sovereign custody, the derived key is written to the `0600` file (not returned). To use the vault in later sessions, supply that key via `AGENTIMPRINT_MASTER_KEY` — `remember`/`recall` do not re-derive it. You can reproduce the same key any time from the same passphrase **and** the same `creator_identifier` with the same scrypt parameters.\n\n---\n\n## Key Recovery on Respawn\n\nAn opt-in fallback for the moment a respawned agent has **no master key** — a fresh\ncontainer, a wiped `credentials.json` — but does hold a breadcrumb from an earlier\nsession.\n\n**Prerequisite: `AGENTIMPRINT_API_KEY` must still be configured.** This recovers the\nmaster key (and, if the environment didn't already supply one, the vault id — see\nbelow), not the API key: no bootstrap token is minted, and there is no protocol by\nwhich a public, unauthenticated endpoint could hand one out. If `credentials.json` is\ngone AND `AGENTIMPRINT_API_KEY` is unset, recovery still runs, still burns the scrypt\nderivation and the network claim, and still restores the master key into memory — but\nevery vault-scoped tool (`remember`/`recall`/`list`/`export`) then fails immediately\nafterward at `guards.ts`'s \"not provisioned\" check, because there is no API key to\nauthenticate with. Keep `AGENTIMPRINT_API_KEY` in durable, handler-controlled\nconfiguration alongside `AGENTIMPRINT_RECOVERY`, not only on the ephemeral storage\n`credentials.json` lived on.\n\nIf `AGENTIMPRINT_VAULT_UUID` is *not* set and no other source supplies one, a\nsuccessful recovery fills it in from the breadcrumb itself — the breadcrumb carries\nits vault's id. An explicitly configured `AGENTIMPRINT_VAULT_UUID` is never overridden;\nif it names a *different* vault than the breadcrumb, that's an operator error and the\nMCP logs one clear line to stderr naming both vault ids rather than failing silently\nwith a raw crypto error at recall time.\n\n**Recovery is first-bootstrap-only.** `imprint_bootstrap` no-ops whenever an agent is\nalready provisioned (checked before `recovery` is even read), so an existing agent that\nwas provisioned without `recovery: true` has no way to opt in after the fact — that\ngap is tracked in `docs/BACKLOG.md`, not solved here.\n\nPass `recovery: true` to `imprint_bootstrap` (refused under `custody: \"passphrase\"`,\nwhere the key is already reproducible from the passphrase and buys nothing). Bootstrap\nthen generates a 256-bit secret, derives a wrap key and a verifier from it via scrypt,\nuploads only `{salt, verifier, the master key wrapped under the wrap key}` to the server,\nand writes the breadcrumb — `vault_uuid:salt:secret` — to a local `0600` file. **The tool\nresult returns only that file's path, never the breadcrumb itself**, the same handling\nsovereign custody gives the master key.\n\nTo use it, put the breadcrumb's contents in the **`AGENTIMPRINT_RECOVERY`** environment\nvariable of whatever durably restarts this agent. At boot, credential resolution runs\nexactly as before; only when that finds **no master key** and `AGENTIMPRINT_RECOVERY` is\nset does the MCP claim the blob and unwrap it locally. An agent with a working key makes\nno network call and behaves byte-for-byte as it did before this feature existed. The\nattempt happens **at most once per process** — a failure (denied, throttled, malformed\nbreadcrumb, network error) logs one line to stderr and the agent continues keyless,\nexactly as it would have without this feature.\n\n**The secret never leaves the machine.** Bootstrap sends the verifier, not the secret;\nclaim sends the verifier again, re-derived locally from the breadcrumb. The server ends\nup holding a salt, a hash of the verifier, and a wrapped blob it has no way to unwrap —\nit never sees the secret, the wrap key, or the master key.\n\n**Honest about what this buys you: a breadcrumb is key-equivalent for anyone who holds\nit.** This is not a weaker credential than the master key — anyone with the breadcrumb\ncan claim and unwrap the vault just as completely as anyone with the key itself. The gain\nis not reduced power, it's that a breadcrumb is **revocable**: `DELETE\n/api/v1/key-recovery/{vaultUuid}` invalidates it in one authenticated call, and that\ndeletion is unilateral and immediate. A leaked master key has no equivalent remedy — the\nonly way to recover from that is re-encrypting the entire vault under a new key. That\nsingle asymmetry — a race you can win versus a loss you can't undo — is the entire\njustification for this feature. If you don't find that trade worth having, don't enable\n`recovery: true`; nothing about the rest of this product depends on it.\n\n**Survivability is the handler's problem, not this feature's.** Where `AGENTIMPRINT_HOME`\nlives on storage that a respawn wipes, `AGENTIMPRINT_RECOVERY` gets wiped with it — and if\nthe credentials file with the master key is on the same wiped storage, that was already\ngone too, so recovery never fires and never needed to. This mechanism only earns its\nplace when the breadcrumb is placed somewhere that outlives the container: durable,\nhandler-controlled configuration (a secrets manager, an orchestrator's env injection,\nanything the respawn itself doesn't own) — not the same ephemeral filesystem the key\nalready lived on.\n\n---\n\n## Rotating a key\n\n`imprint_rotate_key` generates a new master key **in this process** and sends the server\nonly its fingerprint. The alternative — `POST /agents/{uuid}/keys/generate` — has the\nserver mint the replacement, which is fine for first-time setup and self-defeating if you\nare rotating because a key may have leaked: a compromised server would hand you a key it\nchose.\n\nThe new key is written to a local `0600` file and only its **path** is returned. Key\nmaterial never travels through a tool result, because that channel transits the model and\nthe provider.\n\n### What rotation does not do\n\nRead this before rotating, because the most common expectation is the wrong one.\n\n- **It does not protect anything already written.** Rotation does not re-encrypt. Every\n  entry written before it stays encrypted under the OLD key, and the server holds that\n  ciphertext. If the old key leaked, the leak still opens your entire history. Rotation\n  protects **future writes only**.\n- **The old key is now required forever.** It is retained automatically in\n  `credentials.json` as a prior key, and every read tries it. Lose it and every entry\n  written before the rotation becomes permanently unreadable — there is no recovery path,\n  by construction.\n- **It destroys your recovery escrow.** The escrow wraps the OLD key, so leaving it would\n  let recovery \"succeed\" and hand back a key that no longer opens new entries. Re-register\n  one afterwards, or this agent has no recovery path at all.\n\n### What retention costs\n\n`credentials.json` accumulates every master key the agent has held. That is the price of\nnot losing your history, and it is a real one: a stolen credentials file yields every\ngeneration rather than one, and that value only grows over the agent's lifetime. The file\nis `0600` and updates take an exclusive lock, but the trade is worth stating plainly\nrather than discovering later.\n\nKeys are never pruned automatically. Dropping one silently destroys the memory written\nunder it, so pruning is a deliberate act you perform, or it does not happen.\n\n## Per-Harness Placement\n\n### Claude Code\n\n**Option A — project scope** (`.mcp.json` in project root):\n\n```json\n{\n  \"mcpServers\": {\n    \"agentimprint\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentimprint/mcp\"]\n    }\n  }\n}\n```\n\n**Option B — global scope** via CLI:\n\n```bash\nclaude mcp add agentimprint -- npx -y @agentimprint/mcp\n```\n\n### Cursor\n\nAdd to `.cursor/mcp.json` (project) or `~/.cursor/mcp.json` (global):\n\n```json\n{\n  \"mcpServers\": {\n    \"agentimprint\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentimprint/mcp\"]\n    }\n  }\n}\n```\n\n### Codex\n\nAdd to `~/.codex/config.toml`:\n\n```toml\n[[mcp_servers]]\nname = \"agentimprint\"\ncommand = \"npx\"\nargs = [\"-y\", \"@agentimprint/mcp\"]\n```\n\n### OpenClaw\n\nInstall via ClawHub or place the `plugin/` directory from this repo into your OpenClaw plugins folder. The `plugin/.mcp.json` wires the MCP server automatically.\n\n### Hermes\n\nAdd to your Hermes MCP configuration under `mcp_servers`:\n\n```json\n{\n  \"mcp_servers\": {\n    \"agentimprint\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentimprint/mcp\"]\n    }\n  }\n}\n```\n\n---\n\n## Environment Variables\n\n| Variable | Default | Purpose |\n|---|---|---|\n| `AGENTIMPRINT_API_KEY` | *(none)* | BYO API key; omit to use self-bootstrap flow. **Required for `AGENTIMPRINT_RECOVERY` to be useful** — recovery restores the master key, never the API key, so this must still be present (via env or a surviving `credentials.json`) or every vault-scoped tool fails after a successful recovery. |\n| `AGENTIMPRINT_BASE_URL` | `https://agentimprint.ai` | Override API endpoint (e.g. for self-hosted). |\n| `AGENTIMPRINT_HOME` | `~/.agentimprint` | Directory for `credentials.json` and local state. |\n| `AGENTIMPRINT_MASTER_KEY` | *(none)* | Supply a sovereign/passphrase master key (64 hex chars) at runtime. |\n| `AGENTIMPRINT_PRIOR_KEYS` | *(none)* | Whitespace- or comma-separated master keys this agent has rotated away from. Merged with any keys already retained in `credentials.json`, de-duplicated, and **never written back** — env-supplied key material does not silently become persisted state. Needed only when restoring keys you kept out of band; `imprint_rotate_key` retains them for you. |\n| `AGENTIMPRINT_PASSPHRASE` | *(none)* | Passphrase for `passphrase` custody at bootstrap (never passed as a tool argument). |\n| `AGENTIMPRINT_AGENT_UUID` | *(none)* | Override agent UUID (BYO sovereign vault wiring). |\n| `AGENTIMPRINT_VAULT_UUID` | *(none)* | Override vault UUID (BYO sovereign vault wiring). If unset and `AGENTIMPRINT_RECOVERY` recovers successfully, this is filled in from the breadcrumb; an explicit value here always wins and is never overridden, even if it names a different vault than the breadcrumb (logged to stderr as a mismatch). |\n| `AGENTIMPRINT_RECOVERY` | *(none)* | A `vault_uuid:salt:secret` breadcrumb from `imprint_bootstrap({ recovery: true })`. Consulted only when no master key is otherwise found; attempted at most once per process. Requires `AGENTIMPRINT_API_KEY` to still be set — see [Key Recovery on Respawn](#key-recovery-on-respawn). |\n| `IMPRINT_SALIENCE_TOUCH` | `1` | Set to `0` to stop reporting consulted entries (`touched[]`) back to the server. Salience still ranks recall, running on `created_at` alone with no reinforcement signal. |\n| `IMPRINT_CONFLICT` | `1` | Set to `0` to disable contradiction nomination entirely — `imprint_remember` then never returns `possible_conflicts` and does no candidate fetches. Writes and `imprint_supersede` are unaffected. |\n| `IMPRINT_CONFLICT_THRESHOLD` | `0.5` | Minimum cosine similarity for a memory to be nominated as a possible conflict. Calibrated against a synthetic corpus, sitting inside the ~0.32-wide gap between \"substantively unrelated\" (max 0.31) and \"about the same claim\" (min 0.63). Raise it for fewer, tighter nominations; lower it for more. No threshold can separate contradiction from elaboration — that is the agent's job, not this number's. |\n| `IMPRINT_CONFLICT_MAX` | `3` | Maximum candidates nominated per write. This cap does much of the actual precision work: a nomination the agent bothers to read is worth more than three it learns to skip. |\n| `IMPRINT_CONFLICT_PREVIEW_CHARS` | `200` | How much decrypted candidate text each nomination previews. Previews are produced locally, under your key — nothing extra is sent to the server. |\n\n---\n\n## Security note: the optional embedding dependency\n\nLocal embedding (the client lane, which lets an **encrypted** vault be recalled by meaning without any content or query leaving your machine) needs `@huggingface/transformers`. It is an `optionalDependency`, and npm installs those by default, so a plain `npm install @agentimprint/mcp` pulls it in.\n\nAs of `0.8.0` that tree still audits **0 critical, 5 high** — re-verified for this release the way this claim has to be verified: `npm pack` the real tarball and `npm install` it into an empty project outside this repo, not `npm audit` inside this repo (see the devDependency note below for why that distinction matters). The critical `protobufjs` advisory that affected `0.3.0` and earlier remains gone. The five highs are unchanged in substance since `0.5.0` — `adm-zip <0.6.0` (`GHSA-xcpc-8h2w-3j85`, via `onnxruntime-node`) and `sharp <0.35.0` (`GHSA-f88m-g3jw-g9cj`, inherited libvips CVEs, via `@huggingface/transformers`) — only the advisory IDs have refreshed. `@huggingface/transformers` is now on `4.2.0`, but it still pins `sharp ^0.34.5` and pulls `onnxruntime-node`'s `adm-zip ^0.5.16`; neither range reaches the fixed version, so the upstream pin has **not** widened despite the minor bumps this package has taken since `0.5.0`. `npm audit` reports `fixAvailable: false` for both — not because no fixed version exists, but because npm's automatic resolver won't cross a parent package's own version pin to get there.\n\nThe whole tree is loaded **lazily** — nothing is imported until an agent actually embeds — but it is installed regardless. Two options if that matters to you:\n\n**Pin the safe versions in your own project.** npm `overrides` apply only in the root `package.json`, so ours cannot protect you, but yours will:\n\n```json\n{ \"overrides\": { \"sharp\": \"^0.35.3\", \"adm-zip\": \"^0.6.0\" } }\n```\n\nThis is what this repo does, and — for those two packages — it audits clean under those overrides. Nothing on the text-embedding path touches either package, so it is a low-risk pin — verified here by embedding with the overrides applied and getting bit-identical vectors. **This protects your project's own install; it does not change what `npm install @agentimprint/mcp` gives anyone else**, including us — the clean-room numbers above were measured on the *unpinned* tarball for exactly that reason. (This repo already got this wrong once and corrected it — see the \"npm overrides do not reach consumers\" fix — so don't take \"this repo audits clean\" as evidence about what a plain install gets; it isn't.)\n\n**Or skip it entirely:**\n\n```\nnpm install @agentimprint/mcp --omit=optional\n```\n\nRecall then degrades to lexical for encrypted vaults, exactly as it does on a machine where the model fails to download. Everything else — remember, integrity verification, salience ranking, the server-side semantic lane for cleartext entries — is unaffected.\n\n**`npm audit` will still report those advisories after you do this, and it is wrong to.** `npm audit` reads your lockfile, not your `node_modules`, and the lockfile still lists optional dependencies (marked `\"optional\": true`) even when they were never installed. So you will see the same high-severity count and reasonably conclude the mitigation failed. It did not — the packages are genuinely absent. Two ways to confirm:\n\n```\nls node_modules/@huggingface/transformers   # ENOENT — never installed\nnpm install @agentimprint/mcp --omit=optional --package-lock-only && npm audit --omit=optional\n```\n\nRegenerating the lockfile under `--omit=optional` reports **0 critical / 0 high**. We measured both — with and without `--omit=optional`, both on a genuine clean-room install of `0.8.0`, not this repo's own tree — rather than assuming.\n\n**A third number you may see and shouldn't confuse with either of the above: this repo's own `npm audit` currently also reports 4 unrelated vulnerabilities in `esbuild`/`vite`/`vitest`.** Those are `devDependencies` of this repo's own test tooling — never listed in `package.json`'s `dependencies`/`optionalDependencies`, never included in the published tarball (three files: `README.md`, `dist/index.js`, `package.json`), and not installed by anyone who runs `npm install @agentimprint/mcp`. `npm audit --omit=dev` inside this repo reports 0, which is the number that describes what this repo ships; a genuine clean-room install of the tarball, measured above, is the number that describes what a consumer gets. Neither substitutes for the other.\n\n---\n\n## License\n\nMIT — see [LICENSE](../LICENSE).\n","readmeFilename":"README.md","keywords":["mcp","model-context-protocol","mcp-server","ai-agent","agent-memory","persistent-memory","llm-memory","encrypted-storage","sovereign","claude"]}