mnemom CLI manages authentication, alignment cards, protection cards, and agent diagnostics for the Mnemom trust stack.
Looking to launch a governed coding agent? See
mnemom agent
— install once, run mnemom agent, and it launches Claude Code through the
gateway with an agent set up for you. mnemom agent is available by invitation
only; see Redeem an invitation.Installation
Authentication
Organizations
mnemom login binds no org — the session carries no org context. Org-scoped commands (like agent claim) target your active org, set with mnemom org use, defaulting to your personal org when none is set.Card commands
Policy commands (removed)
The standalonemnemom policy command group has been removed — policy (capability mappings, forbidden rules, enforcement defaults) is now authored directly in the alignment card and evaluated with mnemom card evaluate, per the table below.
See Policy Engine for how the card’s
capabilities + enforcement sections work.
Posture commands
Manage Trust Postures (team-scoped oversight policy — not to be confused with the per-agent alignment/protection cards above).Protection commands
Agent commands
mnemom agent is one namespace for everything about your governed agents: the
launcher and its sub-verbs (setup, doctor, config, invite, help), and
the verbs list, claim, move, sessions, show and the experimental goal.
mnemom agent
Launch a governed coding-agent session (Claude Code today) through the gateway.
Available by invitation only (see Redeem an invitation).
A bare mnemom agent asks for a session name, then launches; pass --goal to
seal a goal. Every launch first makes sure the agent it runs as is claimed in your
org, and claims it if it is not; it never starts a session on an unclaimed agent.
The launcher, its sub-verbs, sign-in options, saved settings, contracts,
guardrails, context folding and profiles, and the experimental implicit goal mode
are documented on their own page: mnemom agent.
mnemom agent list
List the agents in your active org (set with mnemom org use). With no active
org set, it lists every org you belong to.
--org value that is not one of your orgs fails before any API call and
lists the orgs you can use.
Example output:
Requires authentication via
mnemom login. Agents are auto-created by the gateway on first API call — there is no registration step.mnemom agent claim <id-or-name>
Claim a gateway-provisioned agent into an org by proving you hold its provider
key. See the Agent Claim Flow guide for the full
lifecycle.
--org <slug|id>— destination org. Defaults to your active org (set withmnemom org use), else your personal org, with a loud notice.--key <key>— the agent’s provider API key; the CLI derives thehash_prooflocally. Alternatively pass--hash-proof <64-hex>directly.--name <name>— the provisioned agent name used in proof derivation. It is auto-resolved from the agent id when possible; pass it only to override.--json— machine-readable output.
To re-home an agent you hold the key for, re-
claim it with a new --org. The
destination org’s template can floor/cap the agent’s composed card, so its
effective posture may change. See
Idempotency and re-homing.mnemom agent move <id-or-name> --to <slug|id>
Move an agent to another org without its key. This is role-based: you must be an
owner or admin in both the current and the destination org. --to is
required and never defaults to your active org.
mnemom agent sessions
List your Mnemom Agent launches from the local ledger (~/.mnemom/sessions.jsonl),
newest first — the last 20 unless --all. Launches older than
sessions.retention_days (default 30) are removed at the next launch; see
CLI preferences.
--all, --json
mnemom agent show [ref]
Show one session: the local launch record merged with the gateway’s live goal
state (sealed contract, latest verdict, guardrail gauges). ref is a session
name (newest match wins) or a unique conversation-id prefix; omitted shows the
newest session.
--json
mnemom agent goal show|pin|reset [ref]
Experimental and opt-in (mnemom experimental enable implicit). Read and steer the goal the
gateway built for an implicit-mode session: show prints it, pin freezes the
stored goal (record-only, not a steering lock), and reset clears it or
replaces it with your own statement. ref picks the session the same way
show does. See Implicit goal mode.
--thread <id>, --json; show: --all-threads, --history;
pin: --off; reset: --statement <s>, --requirement <r> (repeatable),
--yes
Updates: mnemom update
The CLI updates itself in the background: at most once a day it checks for a
newer release and installs it after the running command exits, never under a
live session. Only a plain npm install -g install self-updates; other package
managers get the right manual command instead. Background updates are off in CI
and when output is not a terminal.
--check, --channel <latest|next> (this run only), --force
(allow installing an older version, e.g. moving from next back to latest),
--json
Updates never downgrade on their own. Set MNEMOM_DISABLE_AUTOUPDATE=1 to turn
background updates off entirely, or use the update.mode preference below.
Minimum version
The Mnemom API tells the CLI the oldest version it still supports, on every response. A CLI older than that stops instead of running the command, because an old CLI can leave out request fields a newer server expects. When auto-update is on (update.mode is auto), the CLI was installed with npm install -g, and it
runs in an interactive terminal (not in CI, not with output piped, and not with
MNEMOM_DISABLE_AUTOUPDATE set), it installs the newest stable release that meets the minimum, prints
Updated the Mnemom CLI … Re-run your command. and exits; run your command
again. Otherwise it prints the command to upgrade by hand:
CLI preferences: mnemom config
CLI-wide preferences live in ~/.mnemom/config.json. (Settings for
mnemom agent live separately in mnemom agent config.)
Experimental features: mnemom experimental
Some features ship as experimental: off until you turn them on, hidden from
--help while off, and liable to change or be removed in any release with no
deprecation period. Using an experimental flag or command while its feature is
off fails with a pointer to the command that turns it on.
~/.mnemom/config.json. MNEMOM_EXPERIMENTAL=<id>,<id>
(or all / none) overrides it for one shell. The current features, all for
mnemom agent:
mnemom experimental list shows the same list with what each one gates.
Diagnostics
License
Team commands
Manage teams and their scope-cascade templates (mnemom team ...).
Advisories & governance
mnemom advisories ... lists and inspects the sideband advisories postures write:
mnemom governance ... is the operator workflow for governance_signals:
API keys & webhooks
mnemom api-key ... manages capability-scoped personal API keys:
mnemom webhooks ... manages org webhook endpoints, deliveries, and replay; mnemom listen <org_id> streams live events:
Other commands
Global options
Agent selection
Commands that operate on an agent use this priority to determine which agent:--agent <name>flag (highest priority)MNEMOM_AGENTenvironment variable
--agent nor MNEMOM_AGENT is set, the command stops with Agent required. Use --agent <name> or set MNEMOM_AGENT. (mnemom agent is different: it uses its own default agent, see Your governed agent.)
Example:
Workflow
A typical workflow with the mnemom CLI:Supported providers
The gateway routes and traces Anthropic, OpenAI, and Gemini. See Provider Support for the current supported-model list and the per-provider feature-coverage matrix (thinking-trace inspection, prompt caching, and more vary by provider).See also
- Gateway Overview — Architecture and how it works
- Enforcement Modes — Configure violation response behavior
- Card Management — Creating and managing alignment cards