> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> Release history and updates for Mnemom protocols and infrastructure

Track changes across the Mnemom ecosystem — protocols, SDKs, infrastructure, and tooling.

***

## `mnemom agent` never runs on an unclaimed agent

<sub>October 2026</sub>

* Before Claude Code starts, every `mnemom agent` launch asks the gateway which agent it
  serves for your credential and agent name. If that agent is not claimed yet, the launch
  claims it into the org it bills, then starts. If it belongs to another Mnemom account,
  or it is unclaimed and can't be claimed, the launch stops. The launcher no longer offers
  to run on an unclaimed agent, in a terminal or in CI.
* If Mnemom can't be reached, the launch retries, then runs on the agent this machine last
  confirmed as claimed. With no such record, it stops and asks you to try again.
* A launch with a Claude subscription sign-in is checked the same way.
* `--no-setup` now only skips the default-card writes; `--setup` re-checks the agent and
  refreshes its cards.

See [Your governed agent](/gateway/agent#your-governed-agent).

## Mnemom Agent — a governed launcher for your coding agent

<sub>September 2026</sub>

`mnemom agent` (shipped in CLI 0.17.0, now the first stable release of the Mnemom Agent
line) launches your coding-agent CLI — Claude Code today — through the Mnemom gateway
under a governed agent identity, with an optional sealed per-session goal contract. It's
rolling out to an invited cohort.

* The standalone `mnemom agents` command is now `mnemom agent list|claim|move`.
* `mnemom agent sessions` and `mnemom agent show` read back a session's live goal state
  (also available via `GET /v1/agent/sessions/{conversationId}`), and can now show whether
  goal mode is on, off, or implicit.
* `mnemom agent config` and `mnemom agent doctor` save your launch settings and preflight
  your machine before you run it.
* Two opt-in toggles: **implicit goal mode** (experimental, never on by default) infers a
  goal contract from your own messages instead of requiring one up front, and
  `--no-context` turns off the gateway's context-folding summarization for a session that
  needs the full, unsummarized window.

See [`mnemom agent`](/gateway/agent).

## Billing fails closed at the edges of your balance

<sub>September 2026</sub>

Two related gateway changes:

* If your organization's billing account can't be resolved, requests now get a clear
  `402 billing_unconfigured` response (your org admin is notified) instead of being
  mistaken for a depleted balance.
* Once your μ balance is determined to be at or below zero, gateway requests are now
  blocked by default instead of passing through ungoverned. See
  [Pricing](/pricing/overview) for how to avoid a gap with auto top-up.

***

## Usage-based pricing: everything included, pay only for μ

<sub>September 2026</sub>

Mnemom moved from plan tiers to usage-based pricing. There's one unit — μ (1 μ = \$0.01,
immutable) — and every feature is available to every account regardless of spend. See
[Pricing](/pricing/overview) for the full model.

* The billing dashboard now shows your available μ balance, a full ledger of grants,
  purchases, and spend, and configurable budget alerts.
* Once your balance is depleted, requests now pause automatically instead of billing past
  zero, and the dashboard tells you why (see "Billing fails closed" above for the
  follow-up that also covers an unconfigured billing account).
* `GET /billing/mu`, `GET /billing/mu/ledger`, and `GET /billing/mu/statement` expose the
  same balance, ledger, and monthly statement by API; `GET/PUT /billing/budget-alert` manages
  alert thresholds; `GET /billing/payment-methods` and `GET /billing/receipts` cover payment
  instruments and purchase history.

***

## Deprecated endpoints

<sub>September 2026</sub>

The flat per-agent card endpoints and the org/team template endpoints below now redirect
(HTTP 308, method and body preserved) to the canonical replacement path listed next to each
one. Both the old and new paths work today; the old ones start returning `410 Gone` on
**January 15, 2027**.

| Deprecated path | Replacement |
| - | - |
| `/agents/{agent_id}/alignment-card` | `/v1/alignment/agent/{agent_id}` |
| `/agents/{agent_id}/alignment-card/preview-compose` | `/v1/alignment/agent/{agent_id}/preview-compose` |
| `/agents/{agent_id}/protection-card` | `/v1/protection/agent/{agent_id}` |
| `/agents/{agent_id}/protection-card/preview-compose` | `/v1/protection/agent/{agent_id}/preview-compose` |
| `/orgs/{org_id}/alignment-template` | `/v1/alignment/org/{org_id}` |
| `/orgs/{org_id}/alignment-template/preview-compose` | `/v1/alignment/org/{org_id}/preview-compose` |
| `/orgs/{org_id}/protection-template` | `/v1/protection/org/{org_id}` |
| `/orgs/{org_id}/protection-template/preview-compose` | `/v1/protection/org/{org_id}/preview-compose` |
| `/teams/{team_id}/alignment-template` | `/v1/alignment/team/{team_id}` |
| `/teams/{team_id}/alignment-template/preview-compose` | `/v1/alignment/team/{team_id}/preview-compose` |
| `/teams/{team_id}/protection-template` | `/v1/protection/team/{team_id}` |
| `/teams/{team_id}/protection-template/preview-compose` | `/v1/protection/team/{team_id}/preview-compose` |

`/agents/{agent_id}/sideband-advisories` and `/teams/{team_id}/sideband-advisories` are also
deprecated — use the [Governance Signals](/concepts/governance-signals) API instead.

The two legacy `GET /safe-house/…/evaluations` endpoints (a list and a single-record lookup,
covering outbound/egress screening) are deprecated as well; no replacement is named yet.

***

## Fewer false positives in integrity checks

<sub>August 2026</sub>

AIP 1.3.0 adds a tool-activity ledger that gives the integrity analyzer more context about
what an agent's tools actually did, cutting false `boundary_violation` and `review_needed`
verdicts caused by ambiguous tool output. Ships in both SDKs at version 1.3.0: TypeScript
`@mnemom/agent-integrity-protocol` and Python `agent-integrity-proto`.

See [Integrity checkpoints](/concepts/integrity-checkpoints).

***

## ResearchGrade: deep research reports on people and companies

<sub>July 2026</sub>

A new flat-priced report product: a governed research run that produces a full write-up on
a person or a company, including probes and connector lookups. Priced per completed run —
see [Pricing](/pricing/overview) for current rates.

***

## Try Mnemom with no account, and faster onboarding for existing agents

<sub>June 2026</sub>

[mnemom.ai/try-me](https://www.mnemom.ai/try-me) spins up a temporary sandbox agent with no
sign-up: it registers itself, declares an alignment card, and sends it to spar against a
live adversarial agent so you can see a real integrity verdict before creating an account.
The same flow is available from the CLI as `mnemom try-me`.

Two new CLI commands simplify onboarding a real agent: `mnemom wrap` instruments an existing
agent through the gateway in one step, and `mnemom onboard` self-registers the calling
agent, claims it, declares its card, and returns its Trust Rating and badge. `mnemom login`
also gained `--no-browser`, which authenticates via a device code instead of opening a
browser — useful for headless or remote environments.

See the [CLI reference](/gateway/cli).

## Model Context Protocol servers, and standard agent-discovery endpoints

<sub>June 2026</sub>

Two public MCP servers are now live: a control-plane server at `api.mnemom.ai/mcp` exposing
the trust-plane API as tools (mirroring the CLI), and a read-only docs-search server at
`docs.mnemom.ai/mcp`. Point any MCP client at either endpoint. See [Connecting over
MCP](/mcp-clients).

Standard discovery files at `www.mnemom.ai` now let an agent with no prior knowledge find
the API and learn how to authenticate: `/.well-known/oauth-protected-resource` (RFC 9728),
`/.well-known/oauth-authorization-server` (RFC 8414, with an `agent_auth` profile pointing
at the real register/claim/rekey endpoints), and `/.well-known/agent-card.json`. See
[Agent identity](/concepts/agent-identity#registration).

## Alignment card schema unified across SDKs

<sub>June 2026</sub>

AAP 2.0.0 unifies the alignment card shape used by the TypeScript and Python SDKs. This is a
**breaking change** for anything that reads raw card JSON/YAML directly — field and section
names changed. In the published 2.0.0 packages, the Python and TypeScript verifiers can
compute different similarity scores for the same trace near the decision threshold. The fix
is recorded as 2.0.1 in the SDK changelog but has not been published to npm or PyPI yet.

See [Alignment cards](/concepts/alignment-cards).

***

## Claim-to-org — adopt a gateway-provisioned agent into your org

<sub>May 2026</sub>

`POST /v1/agents/{id}/claim` adopts a pre-existing agent (one the gateway auto-provisioned)
into an org you belong to. Provide `org_id` to place it in a specific org you're a member of,
or omit it to land the agent in your personal org. Re-claiming an agent you already own with
a new `org_id` moves it. **Breaking change:** claiming now requires authentication — the
previous anonymous claim path was removed.

See [Agent identity](/concepts/agent-identity#registration) and the [claim endpoint
reference](/api-reference/endpoint/post-agents-agent-id-claim).

## Governance signals — an operator-facing alert surface

<sub>May 2026</sub>

A new signal type, separate from the advisories an agent sees in its own prompt: fleet-shaped
observations (like a coherence drop across a team) are now served only to humans and
integrations — dashboard, webhooks, Slack, email, PagerDuty, or a generic signed webhook —
never folded back into any agent's context.

New webhook events (`governance.signal.*`, `governance.escalation.triggered`), a new
`mnemom governance` CLI command group, and dashboard pages at the team and agent level.

See [Governance signals](/concepts/governance-signals), the [schema
reference](/specifications/governance-signals-schema), and the [operator
guide](/guides/operating-governance-signals).

## Agent ID format update — `mnm-{uuid_v4}`

<sub>April 2026</sub>

New agents receive IDs in the `mnm-{uuid_v4}` format. Existing `smolt-{8_hex}` IDs continue
to work permanently — they're committed to proof chains and are never reissued. The new
format gives 128-bit entropy and IDs are server-assigned, so they're recoverable via API key
if local config is lost.

See [Agent identity](/concepts/agent-identity).

***

## AAP 0.6.0 — Fault line analysis

<sub>March 2026</sub>

Team divergence reports are now classified into actionable fault lines instead of a raw
diff: `resolvable`, `priority_mismatch`, `incompatible`, or `complementary`, plus detection
of a structural fault line (the same split recurring across multiple values). Available in
both SDKs (`analyzeFaultLines()` / `analyze_fault_lines()`), and via `POST
/v1/teams/fault-lines`.

See [Fault line analysis](/guides/fault-line-analysis) and the [Intelligence
API](/api-reference/intelligence-overview).

## Fewer unnecessary proofs, and lower proving cost

<sub>March 2026</sub>

Proving strategy now defers cryptographic proof generation for verdicts that a policy-gap
review might later dismiss, only proving confirmed real violations. This cut proving volume
and cost substantially without changing which verdicts are trustworthy.

See [Deferred proofs](/protocols/aip/verifiable-verdicts#deferred-proofs).

## AAP 0.5.0 — YAML policies and Trust Edges

<sub>March 2026</sub>

The alignment API now accepts policies authored in YAML (`text/yaml` /`application/yaml`)
alongside JSON, and a new Trust Edges API (`GET`/`POST`/`DELETE
/v1/agents/:id/trust-edges`) lets you declare explicit trust relationships between agents.
Cards on the prior `aap_version` continue to work unmodified.

See [Upgrading to 0.5.0](/guides/upgrading-to-0-5).

***

## Card Lifecycle & Policy Intelligence

<sub>February 2026</sub>

A multi-phase release turning alignment cards into policy-governed, lifecycle-managed
artifacts:

* **Policy engine:** YAML governance rules (`warn`/`enforce`/`off`), a 24-hour grace period
  for newly discovered tools, and a `mnemom policy` CLI. See the [Policy
  DSL](/specifications/policy-dsl) and [Policy CLI](/gateway/cli).
* **Card lifecycle & trust recovery:** tracked card amendments with version history, and
  reclassifying a violation as a configuration gap (rather than real misbehavior) now
  recovers the affected trust score automatically. See [Card lifecycle](/concepts/card-lifecycle),
  [Trust recovery](/guides/trust-recovery), and the [Reclassification
  API](/api-reference/reclassification-overview).
* **On-chain verification:** reputation scores and Merkle roots can be anchored on Base L2
  for tamper-evident, independently verifiable history. See [On-chain
  verification](/concepts/on-chain-verification) and the [On-chain
  API](/api-reference/on-chain-overview).
* **Policy management guides:** [CI/CD policy gates](/guides/ci-cd-policy-gates) and
  [Policy management](/guides/policy-management); full reference at the [Policy
  API](/api-reference/policy-overview).

## Team reputation

<sub>February 2026</sub>

Teams (groups of 2–50 agents) become first-class entities with their own persistent
identity, an alignment card auto-derived from members (or manually curated), and an
accumulated reputation score. Includes embeddable team badges
(`/v1/teams/{id}/badge.svg`), roster management with an audit trail, and 9 new webhook
events for team lifecycle and reputation changes.

See [Team management](/guides/team-management), [Team reputation](/concepts/team-reputation),
and the [Teams API](/api-reference/team-overview).

## Public Trust Ratings and embeddable badges

<sub>February 2026</sub>

Every agent with a published score gets a public page at `/reputation/{agent_id}` with a
score breakdown, trend chart, and cryptographic verification link, plus a searchable
[Trust Directory](https://www.mnemom.ai/directory). `GET
/v1/reputation/{agent_id}/verify` returns a proof chain for independent verification, and
[`mnemom/reputation-check`](https://github.com/mnemom/reputation-check) gates CI/CD
pipelines on a minimum score.

See [Embeddable badges](/guides/reputation-badges) and [Understanding Trust
Ratings](/concepts/reputation-scores).

## Faster, cheaper cryptographic proofs

<sub>February 2026</sub>

Zero-knowledge proof generation moved to GPU hardware, cutting proving latency from roughly
270 seconds to well under a second and roughly halving the per-proof cost. A follow-up fix
also made the proving pipeline recover automatically instead of silently stalling when an
individual proof failed to generate.

See [Verifiable verdicts](/protocols/aip/verifiable-verdicts).

## N-way fleet coherence

<sub>February 2026</sub>

Pairwise value-coherence checks extend to whole fleets: a fleet score across every pair of
agents, outlier detection for agents that diverge from the group, cluster analysis, and a
per-value divergence report. Available via `GET /v1/orgs/:org_id/coherence` and as
`checkFleetCoherence()` / `check_fleet_coherence()` in both SDKs.

See [Fleet coherence](/concepts/fleet-coherence).

## Read-only support access, fully audited

<sub>February 2026</sub>

Enterprise support can view your dashboard exactly as you see it to help diagnose an issue —
read-only, time-limited to one hour, and every session is logged with a visible "Viewing as"
banner while it's active. All write actions are blocked for the duration.

## Custom conscience values

<sub>February 2026</sub>

Enterprise orgs can define custom values (for example, "patient safety over efficiency")
that apply to every agent's integrity check, layered on top of Mnemom's defaults and
optionally overridden per agent. Fully audited, with a webhook event on every change.

See [Conscience values](/gateway/conscience-values).

## Agent containment

<sub>February 2026</sub>

Enterprise teams can pause, resume, or permanently kill an agent in real time from the API
or dashboard. A contained agent's gateway traffic is rejected with a structured error, and
orgs can configure automatic pause after repeated boundary violations.

***

## February 2026 — Public launch

* **Mnemom v1.0:** the gateway and CLI ship for zero-configuration agent transparency —
  automatic agent identification, real-time integrity analysis, and CLI login with
  automatic agent registration.
* **AIP v0.1.5:** the Agent Integrity Protocol ships with provider adapters for Anthropic,
  OpenAI, and Google Gemini, analyzing agent reasoning between turns before actions execute.
* **AAP v0.1.0:** the Agent Alignment Protocol ships as a public spec — alignment cards,
  AP-Traces, and value coherence handshakes for verifying compatibility before multi-agent
  coordination. TypeScript (`@mnemom/agent-alignment-protocol`) and Python
  (`agent-alignment-protocol`) SDKs.
* **Verifiable Integrity:** every AIP verdict can be independently verified through Ed25519
  checkpoint signing, hash-chain integrity, Merkle inclusion proofs, and optional
  zero-knowledge proofs. See [Certificates](/protocols/aip/certificates) and [Verifiable
  verdicts](/protocols/aip/verifiable-verdicts).
* **aip-otel-exporter v0.1.0:** an OpenTelemetry exporter for AIP/AAP telemetry, compatible
  with Datadog, Grafana, Splunk, Arize, Langfuse, and any OTel collector. TypeScript
  (`@mnemom/aip-otel-exporter`) and Python (`aip-otel-exporter`).
* **Dashboard:** agent management, a trace viewer, and an integrity score view with
  real-time and historical drift.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.