Skip to main content
mnemom agent launches your coding-agent CLI (Claude Code today) with its model traffic routed through the Mnemom gateway. Every session runs under a governed agent identity, shows up in your traces, and can carry a sealed per-session goal contract that the gateway grades each turn against and re-anchors the agent when it drifts. It is designed to be one command: install once, then mnemom agent.

Install once

Access to mnemom agent is still by invitation (see below). mnemom login opens a browser sign-in (device-code fallback on headless machines); set MNEMOM_API_KEY instead for CI. The CLI keeps itself up to date in the background. If the Mnemom API needs a newer CLI than the one you run, the CLI stops. In an interactive terminal, with a plain npm install -g install and auto-update on (the default), it updates itself and asks you to run the command again. Otherwise (CI, scripts, piped output, or other installs) it prints the upgrade command, npm i -g @mnemom/mnemom@latest, for you to run. See Updates.
You need a coding-agent CLI to launch. Install Claude Code first (claude on your PATH), or point at any install with --cli <name|/full/path>.

Redeem an invitation

Mnemom Agent is rolling out to an invited cohort. If you received an invitation, redeem it once:
That signs you in (or creates your Mnemom account), unlocks Mnemom Agent for your organization, and credits your starter µ. mnemom agent invite <token> does the same as a sub-verb. Without an invitation, mnemom agent stops before launching anything. It says Mnemom Agent isn’t enabled for your organization yet and shows how to redeem an invitation. Nothing is started or charged. To request an invitation, contact us at mnemom.ai/contact. mnemom agent doctor shows the same access check. Mnemom staff (@mnemom.ai accounts) are enabled by default and skip this step.

Run

With no arguments in a terminal, mnemom agent asks for one thing and then launches: a session name, which labels the session in your traces and in mnemom agent sessions. Enter takes the current folder name. Goal alignment is not prompted for. Pass --goal to turn it on: the gateway seals your one-line goal as a contract and nudges the agent back when it drifts, for a little µ per turn. Without --goal the session runs governed with goal alignment off. Either way the launch prints goal alignment: on or off. Skip the prompt when you already know what you want:
Non-interactive runs (pipes, CI) never prompt; they need a session name. Before Claude Code starts, mnemom agent makes sure the agent the session runs as is claimed in your org (see Your governed agent). It never starts a session on an unclaimed agent. Your first launch in a terminal can also ask two one-time questions:
  • How Claude Code should sign in to Anthropic, when there is a choice. See Sign-in options.
  • Whether to look at what Mnemom would have saved on your recent sessions. See Savings estimates.

Permission prompts

By default, mnemom agent starts Claude Code with --dangerously-skip-permissions, so Claude Code does not ask before it edits files or runs commands. Claude Code calls this Bypass Permissions mode. The first time, it shows a warning and asks you to accept it before the session starts. Claude Code recommends this mode only in a sandboxed container or VM. To keep Claude Code’s permission prompts, pass --no-yolo:
--no-yolo applies to that launch only; there is no saved setting for it, so pass it on every launch where you want the prompts. mnemom agent --dry-run shows which mode a launch would use (yolo: on or off).

Resume a session

Each mnemom agent launch starts a new Claude Code session, even when you reuse a session name. To pick up where you left off, relaunch through mnemom agent and pass Claude Code’s resume flag after --:
When Claude Code exits normally, the last line mnemom agent prints is the command to resume it, for example:
If you named an agent with --agent, the command includes it. mnemom agent show <name> prints the same command.
Claude Code prints its own hint just above that line: claude --resume <session-id>. Do not run that command: it reopens the conversation outside Mnemom, with no governance, no µ billing and nothing in your traces. Use the mnemom agent command instead.
The resumed session runs governed, like any other launch, and the conversation carries on where it stopped. Resuming with -- --resume <session-id> or -- --continue keeps that session’s context profile unless you pass --context-profile (CLI 0.17.12 and later; earlier versions keep it only on --resume <session-id>). If the session has no recorded profile, or there is no earlier session in this folder, your default profile applies (see Context profiles). A sealed goal does not carry over: pass --goal again to seal one for the resumed session. If you have turned on implicit goal mode, relaunching an implicit session by the same name asks “Resume previous session?”. Answer yes to continue that session and its inferred goal. See Implicit goal mode for details.

Implicit goal mode (experimental)

A sealed goal (--goal) is one way to turn on goal alignment. The other is implicit mode: no statement to write up front — the gateway infers the goal from your messages and revises it as you steer. Guardrail ceilings (--max-turns, --budget, --stall) still apply. Implicit mode is an experimental, opt-in feature. It is never on by default, on any cell, including cells where the gateway supports it. It runs only after you opt in. Experimental features may change or be removed in any release, with no deprecation period. To opt in, turn on the experimental feature:
Once you have opted in, a launch with no --goal runs in implicit mode:
To use implicit mode only on the launches where you ask for it, also run mnemom agent config set goal_mode off (or set goal_mode = "off" in ~/.mnemom/launcher.toml), then pass --implicit on those launches. To opt out, run mnemom experimental disable implicit. Until you opt in, --implicit is refused with a pointer to mnemom experimental enable implicit, and a saved goal_mode = "implicit" is ignored with the same pointer. --implicit cannot be combined with --goal/--requirement/--allow/--forbid/--goal-id — a sealed contract always wins on the gateway, so the launch refuses the combination rather than silently ignore --implicit. With the feature on, mnemom agent goal reads and steers the inferred goal of a session:
What counts as your words, approvals, pin and reset, the mnemom agent goal show|pin|reset commands and the known limits are on Implicit goal mode. In implicit mode the launcher tells the gateway which recent turns you typed and which Claude Code inserted (a scheduled tick, a skill body, hook output), read from Claude Code’s own transcript. In terminal mode it runs a small local proxy in front of the gateway to do this. Set MNEMOM_AGENT_TURN_HEADER=0 to turn it off. mnemom agent sessions and mnemom agent show report a session’s goal mode as ON (sealed), IMPLICIT, or OFF — see Sessions below.

Preflight: mnemom agent doctor

A read-only check with an actionable hint for anything not ready: your settings file, the coding-agent CLI, your Anthropic key source, gateway health (a 200 plus the x-mnemom-verdict header that proves governance is live), a gateway that belongs to a different Mnemom deployment than the rest of the CLI, your Mnemom Agent access for the active org, and the CLI’s auto-update status. It writes nothing, never reads your key’s value, and exits non-zero when the machine is not launch-ready, so a script can gate on it.

Account and µ balance

mnemom agent runs on µ and has no free tier. Before launching it checks the µ balance on the org the agent lives in (by default your personal org). With no µ, the launch stops with a top-up link; top up at https://mnemom.ai/settings/billing and the balance updates the moment the top-up completes. An accepted invitation credits your starter µ automatically.

Defaults out of the box

A launch always uses one Mnemom deployment end to end: the gateway must belong to the same deployment the CLI signs in to and reads your agents and sessions from. A --gateway (or saved gateway) on a different deployment is refused at launch and by mnemom agent setup, with the fix; a local gateway on localhost is exempt.

Saved settings: mnemom agent config

Configure the launcher once and stop retyping flags. Settings live in a human-editable TOML file at ~/.mnemom/launcher.toml. Your Anthropic key is never stored there; it lives separately in ~/.mnemom/launcher.json (mode 0600), so the file you open and share never carries a credential.

Settable keys

Precedence

Settings resolve highest-wins:
Guardrails saved in config apply only when a session has a goal, so a saved ceiling never forces an unrequested contract. An example ~/.mnemom/launcher.toml:

Your governed agent

Every mnemom agent session runs as a claimed agent. An unclaimed agent belongs to no org and is billed to no one, so the launcher never starts a session on one. If you do not name an agent, the launcher uses agent-<your handle>, derived from your Mnemom login. Before Claude Code starts, on every launch, it:
  1. asks the gateway which agent it serves for this launch’s credential and agent name. With an Anthropic API key, the answer is cached after the first launch. With a Claude subscription sign-in, the gateway is asked every time;
  2. checks whether that agent is claimed. An agent that is already claimed is left where it is and never claimed again;
  3. if it is not claimed, claims it into the org this launch bills: your active org (set with mnemom org use), else your personal org. Your active org setting is not changed. A newly claimed agent also gets its default cards.
The launcher prints one line naming the agent and saying whether it was already claimed or has just been claimed, and into which org. Each agent it confirms as claimed is recorded on this machine. The launch stops, and Claude Code is not started, when the answer is definite:
  • the agent for this credential and name belongs to another Mnemom account. Pick a name of your own with --agent <name>;
  • the agent is not claimed and can’t be claimed, for example because this launch has no org to claim it into. The message says what went wrong;
  • the gateway does not support the subscription identity check yet. Launch with --auth api-key instead.
If Mnemom or the gateway can’t be reached, or returns a temporary error, the launcher retries. If it still can’t get an answer, it launches on the agent this machine last confirmed as claimed for the same credential, agent name and gateway, and prints a warning saying so. If there is no such record, the launch stops and asks you to try again. It never falls back to an agent it knows is unclaimed. This works the same way in a terminal, a script or CI. There is no prompt to confirm the claim.

Default cards

A newly claimed agent gets a default coding posture. Both cards are published off, because alignment and protection analysis are billed: the alignment card has autonomy_mode and integrity_mode set to off and principal.relationship: delegated_authority; the protection card has mode: off, with thresholds 0.60 / 0.80 / 0.95 and all four screen surfaces declared so it is ready when you turn it on. Turn them on with mnemom card and mnemom protection. The goal contract does the nudging.
--no-setup only skips the card writes. The agent is still checked and, if needed, claimed. mnemom agent setup uses an Anthropic API key. Bring your own agent any time with --agent <slug>.

Managing agents

The agent-management verbs live under the same namespace:

Sessions: mnemom agent sessions / show

Every real launch is appended to a local ledger, ~/.mnemom/sessions.jsonl. Entries older than 30 days are removed at the next launch; change that with mnemom config set sessions.retention_days <days> (or MNEMOM_SESSIONS_RETENTION_DAYS).
show merges the local launch record with the gateway’s live goal state for that conversation — the sealed contract (if any), the latest verdict, and guardrail gauges (turns 3/10, etc., flagged when a ceiling was crossed) — so you can check on a session after the fact without re-reading your terminal scrollback. It also prints the command that resumes the session through mnemom agent (see Resume a session). Each row’s Goal column, and show’s goal-mode field, read ON (sealed contract), IMPLICIT, or OFF. For an implicit-mode session, show also prints the statement the gateway inferred.

Launch shapes

Contracts and guardrails

A goal (--goal) seals a contract on the first turn; add requirements, path rules and guardrail ceilings on the command line. Passing any contract flag makes --goal required.
The CLI prints the contract statement and its sha256[0:16] so you can confirm what was sealed. The gateway echoes the full hash back on every response as x-mnemom-contract-hash.

Limits

The contract is sealed on the first turn of a session and cannot change afterwards: a later request that sends a different or invalid contract header is ignored and the sealed contract keeps governing, so a client hiccup mid-session never kills a governed session. To change the contract, start a new session.

What guardrails do

Guardrails (--max-turns, --budget, --stall) observe and nudge, never block. Each ceiling is checked once per turn; when one is crossed the gateway appends a short [mnemom guardrail] line to your next message telling the agent which ceiling it hit, and marks the crossing on the response headers and in your traces. The session keeps running. A ceiling you leave unset falls back to the cell’s default for that guardrail, if the cell has one; otherwise it is simply off.

Context folding

Context folding summarizes older turns so a long session keeps fitting the model’s context window. It is on by default. Unless you choose a profile, the gateway’s own default profile applies.
Precedence: --context/--no-context wins, else MNEMOM_AGENT_CONTEXT (0/false/off/no turn it off), else config set context, else on.

Context profiles

--context-profile picks how the gateway folds the session. With no profile set anywhere, nothing is sent and the gateway’s default applies.
Precedence: --no-context (always off; combining it with any other --context-profile is refused), else --context-profile, else the profile of the session being resumed (with --continue or --resume <session-id>), else MNEMOM_AGENT_CONTEXT_PROFILE / config set context_profile, else off when folding is turned off by context = false or MNEMOM_AGENT_CONTEXT, else the gateway’s default.

How Claude Code signs in

Claude Code can sign in to Anthropic three ways under mnemom agent: an Anthropic API key (the default), your Claude Team or Enterprise subscription, or the API key your Anthropic Console login created. Your first launch in a terminal asks which one when there is a choice, and saves the answer. Sign-in options covers each one, where the API key is looked up, and what you see when something is missing.

Flags

Anything after -- is passed straight through to the coding-agent CLI. Flags of experimental features (--implicit, --slack, --context-handoff, --compaction-intercept) are hidden from --help until you turn the feature on with mnemom experimental enable.