> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# CLI Reference

> Mnemom CLI commands and usage

The `mnemom` CLI manages authentication, alignment cards, protection cards, and agent diagnostics for the Mnemom trust stack.

<Note>
  Looking to launch a **governed coding agent**? See [`mnemom agent`](/gateway/agent)
  — install once, run `mnemom agent`, and it launches Claude Code through the
  gateway with an agent set up for you. `mnemom agent` is available by invitation
  only; see [Redeem an invitation](/gateway/agent#redeem-an-invitation).
</Note>

## Installation

```bash theme={null}
npm install -g @mnemom/mnemom
```

## Authentication

<Steps>
  ### `mnemom login`

  Authenticate with your Mnemom account. `mnemom login` runs OAuth 2.1 against Mnemom's own authorization server:

  ```bash theme={null}
  mnemom login              # authorization-code + PKCE via a local loopback redirect (opens a browser)
  mnemom login --no-browser # RFC 8628 device-authorization grant — for SSH sessions, containers, anywhere with no local browser
  ```

  The resulting scoped access + refresh tokens are stored in `~/.mnemom/auth.json`; all subsequent commands use them automatically, refreshing as needed. See the [OAuth device flow guide](/guides/oauth-device-flow) for what `--no-browser` does under the hood.

  <Note>
    Logging in does **not** select an organization — the session carries no org
    context. Org-scoped commands (like `agent claim`) target your **active** org,
    set with `mnemom org use`, defaulting to your personal org when none is set.
  </Note>

  ### `mnemom logout`

  Remove locally stored auth credentials.

  ```bash theme={null}
  mnemom logout
  ```

  ### `mnemom whoami`

  Display the currently authenticated credential's status.

  ```bash theme={null}
  mnemom whoami
  ```

  **Example output** (OAuth login — the default; opaque tokens carry no identity, so only scope and expiry are shown):

  ```
  Auth Status

    Scope:   mcp:read mcp:write
    Token:   valid until 2026-09-20T18:32:10.000Z
  ```

  **Example output** (`MNEMOM_API_KEY` set instead):

  ```
  Auth Status

    Credential Type: API key
    Status:          valid (no expiry)
  ```
</Steps>

## Organizations

<Note>
  `mnemom login` binds no org — the session carries no org context. Org-scoped commands (like `agent claim`) target your **active** org, set with `mnemom org use`, defaulting to your personal org when none is set.
</Note>

<Steps>
  ### `mnemom org list`

  List every org you belong to. Your personal org is tagged `(personal)`.

  ```bash theme={null}
  mnemom org list
  ```

  **Options:** `--json`

  ### `mnemom org use [slug-or-id]`

  Set the active org — the default for org-scoped commands like `agent claim`. No argument prints the current setting.

  ```bash theme={null}
  mnemom org use acme
  mnemom org use --clear   # forget the active org; org-scoped commands revert to your personal org
  ```

  ### `mnemom org show [org_id]`

  Print details for one org (`--personal` for your personal-org-of-one).

  ```bash theme={null}
  mnemom org show --personal
  ```

  **Options:** `--personal`, `--json`
</Steps>

## Card commands

<Steps>
  ### `mnemom card show`

  Fetch your agent's active alignment card and display it as structured YAML output showing principal, values, autonomy envelope, enforcement, and audit commitment.

  ```bash theme={null}
  mnemom card show --agent my-coder
  ```

  **Example output:**

  ```yaml theme={null}
  card_id: ac-a4c12709-v2
  card_version: unified/2026-04-15
  issued_at: "2026-02-21"
  expires_at: "2026-08-21"
  autonomy_mode: observe
  integrity_mode: observe

  principal:
    type: human
    relationship: delegated_authority

  values:
    declared:
      - transparency
      - honesty
      - harm_prevention
      - editorial_independence
      - source_attribution
      - investigative_rigor
    hierarchy: lexicographic

  autonomy:
    bounded_actions:
      - inference
      - read
      - write
      - edit
      - exec
      - web_fetch
      - web_search
    forbidden_actions:
      - fabricate_sources
      - impersonate_human
    escalation_triggers:
      - condition: named_entity_critical
        action: escalate
      - condition: legal_claims_present
        action: escalate

  enforcement:
    allow_unmapped_tools: false

  audit:
    trace_format: ap-trace-v1
    retention_days: 365
    queryable: true
    tamper_evidence: append_only
  ```

  ### `mnemom card edit`

  Open your agent's alignment card in your `$EDITOR` for interactive editing. Validates the card on save.

  ```bash theme={null}
  mnemom card edit --agent my-coder
  ```

  The card is fetched from the server and opened in your editor (`$EDITOR`, else `$VISUAL`, else `vi`). When you close the editor, the CLI validates the card, asks for confirmation in a terminal, and publishes it. If you made no changes, nothing is published. If validation fails, the CLI lists the errors and nothing is published.

  ### `mnemom card publish <file>`

  Read a YAML or JSON alignment card file, validate it against the unified schema, and upload it to your agent. In a terminal the CLI asks for confirmation first; in a script it publishes without asking.

  ```bash theme={null}
  mnemom card publish card.yaml --agent my-coder
  ```

  **Options:**

  | Option | Description |
  | - | - |
  | `--agent <name>` | Target agent (or set `MNEMOM_AGENT`) |
  | `--idempotency-key <uuid>` | Reuse a specific `Idempotency-Key` when retrying (default: generated) |

  If validation fails, the CLI lists the failed checks, publishes nothing and exits `1`.

  ### `mnemom card validate <file>`

  Validate an alignment card. With an agent (`--agent` or `MNEMOM_AGENT`), the server validates the card against the agent's org and platform rules. If you are not signed in or the server can't be reached, it falls back to local validation with a warning. Without an agent, or with `--offline`, it validates locally against the unified schema. CI-friendly: exit code 0 on pass, 1 on fail.

  ```bash theme={null}
  mnemom card validate card.yaml                    # local
  mnemom card validate card.yaml --agent my-coder   # server-side, against the agent's org rules
  mnemom card validate card.yaml --offline          # always local
  ```

  ### `mnemom card evaluate <file> --tools <tools>`

  Evaluate a card's policy against a set of tools locally. This replaces the old `mnemom policy evaluate` command. The alignment card now includes capability mappings and enforcement rules directly.

  ```bash theme={null}
  mnemom card evaluate card.yaml --tools mcp__browser__navigate,mcp__filesystem__delete --agent my-coder
  ```

  **Options:**

  | Option | Description |
  | - | - |
  | `--tools <tools>` | Comma-separated list of tool names to evaluate |
  | `--tool-manifest <file>` | Path to a tool manifest JSON file, as an alternative to `--tools` |
  | `--strict` | Exit `1` on warnings too (not just hard failures) |

  **Exit codes:**

  * `0` -- No hard policy violations (without `--strict`, warnings don't affect this)
  * `1` -- One or more evaluations fail (or, with `--strict`, any warning)

  The output names the card and the tools, then a verdict (`PASS`, `WARN` or `FAIL`), any violations and warnings with the tool and reason, and how many of the card's actions the tools cover. Evaluation runs locally against the card file.
</Steps>

## Policy commands (removed)

The standalone `mnemom policy` command group has been removed — policy (capability mappings, forbidden rules, enforcement defaults) is now authored directly in the alignment card and evaluated with `mnemom card evaluate`, per the table below.

| Old command | Replacement |
| - | - |
| `mnemom policy init` | Author `capabilities`/`enforcement` directly in a YAML alignment card. See [Card Management](/guides/card-management). |
| `mnemom policy validate <file>` | `mnemom card validate <file>` |
| `mnemom policy publish <file>` | `mnemom card publish <file>` |
| `mnemom policy list` | `mnemom card show --agent <name>` |
| `mnemom policy test <file>` | `mnemom card evaluate <file> --tools <tools>` |
| `mnemom policy evaluate` | `mnemom card evaluate <file> --tools <tools>` |

See [Policy Engine](/concepts/policy-engine) for how the card's `capabilities` + `enforcement` sections work.

## Posture commands

Manage [Trust Postures](/concepts/trust-posture) (team-scoped oversight policy — not to be confused with the per-agent alignment/protection cards above).

<Steps>
  ### `mnemom posture list`

  List visible postures — the three Mnemom-shipped defaults plus your org's own.

  ```bash theme={null}
  mnemom posture list --org org-acme
  ```

  **Options:** `--org <id>`, `--no-include-platform` (hide the Mnemom defaults), `--json`

  ### `mnemom posture show <posture_id>`

  Show one posture's metadata and body summary.

  ```bash theme={null}
  mnemom posture show tp-platform-standard
  ```

  ### `mnemom posture create`

  Create a new org-scope posture from a JSON file.

  ```bash theme={null}
  mnemom posture create --org org-acme --slug acme-standard --name "Acme Standard" \
    --from body.json --summary "Initial revision"
  ```

  **Options:** `--org <id>`, `--slug <slug>`, `--name <name>`, `--from <file>`, `--description <text>`, `--summary <text>`, `--json`

  ### `mnemom posture update <posture_id>`

  Write a new revision (forward-only — old revisions stay queryable).

  ```bash theme={null}
  mnemom posture update tp-acme123 --from v2-body.json --summary "tighten coherence to 0.6"
  ```

  **Options:** `--from <file>`, `--summary <text>`, `--name <text>`, `--description <text>`, `--json`

  ### `mnemom posture clone <posture_id>`

  Clone any visible posture (including a Mnemom default) into an org as a customization starting point.

  ```bash theme={null}
  mnemom posture clone tp-platform-standard --org org-acme --slug acme-standard --name "Acme Standard"
  ```

  **Options:** `--org <id>`, `--slug <slug>`, `--name <name>`, `--description <text>`, `--json`

  ### `mnemom posture revisions <posture_id>`

  List the posture's revision history, newest first. **Options:** `--json`

  ### `mnemom posture diff <posture_id>`

  Structural diff between two revisions.

  ```bash theme={null}
  mnemom posture diff tp-acme123 --from 1 --to 3
  ```

  **Options:** `--from <N>`, `--to <M>`, `--json`

  ### `mnemom posture assign <posture_id>`

  Assign a posture to a team, replacing any prior assignment for that team.

  ```bash theme={null}
  mnemom posture assign tp-acme123 --team <team-uuid>
  ```

  **Options:** `--team <team_id>`, `--pin-revision <N>` (default: float against current)

  ### `mnemom posture unassign <posture_id>`

  Remove a posture's assignment from a team. **Options:** `--team <team_id>`

  ### `mnemom posture preview-compose <posture_id>`

  Preview the effective composed posture for a team, if assigned. **Options:** `--team <team_id>`, `--json`

  ### `mnemom posture delete <posture_id>`

  Soft-delete an org-scope posture. Refuses if the posture is currently assigned to any team.
</Steps>

## Protection commands

<Steps>
  ### `mnemom protection show`

  Display the protection card for an agent as structured YAML output.

  ```bash theme={null}
  mnemom protection show --agent my-coder
  ```

  ### `mnemom protection edit`

  Open the protection card in your `$EDITOR` for interactive editing. Validates the card on save.

  ```bash theme={null}
  mnemom protection edit --agent my-coder
  ```

  ### `mnemom protection publish <file>`

  Validate and upload a protection card for an agent.

  ```bash theme={null}
  mnemom protection publish protection.yaml --agent my-coder
  ```

  **Options:**

  | Option | Description |
  | - | - |
  | `--agent <name>` | Target agent (or set `MNEMOM_AGENT`) |
  | `--idempotency-key <uuid>` | Reuse a specific `Idempotency-Key` when retrying (default: generated) |

  In a terminal the CLI asks for confirmation first; in a script it publishes without asking.

  ### `mnemom protection validate <file>`

  Validate a protection card. Server-authoritative when `--agent` is set; pass `--offline` to force local-only validation.

  ```bash theme={null}
  mnemom protection validate protection.yaml
  ```

  ### `mnemom protection drift <file>`

  Compare a committed protection-card snapshot against the live canonical card (read-only).

  ```bash theme={null}
  mnemom protection drift protection.yaml --agent my-coder
  ```

  **Options:**

  | Option | Description |
  | - | - |
  | `--strict` | Also fail on live fields the snapshot does not record |
  | `--json` | Emit the drift result as JSON |
</Steps>

## Agent commands

`mnemom agent` is one namespace for everything about your governed agents: the
launcher and its sub-verbs (`setup`, `doctor`, `config`, `invite`, `help`), and
the verbs `list`, `claim`, `move`, `sessions`, `show` and the experimental `goal`.

### `mnemom agent`

Launch a governed coding-agent session (Claude Code today) through the gateway.
Available by invitation only (see [Redeem an invitation](/gateway/agent#redeem-an-invitation)).
A bare `mnemom agent` asks for a session name, then launches; pass `--goal` to
seal a goal. Every launch first makes sure the agent it runs as is claimed in your
org, and claims it if it is not; it never starts a session on an unclaimed agent.
The launcher, its sub-verbs, sign-in options, saved settings, contracts,
guardrails, context folding and profiles, and the experimental implicit goal mode
are documented on their own page: [`mnemom agent`](/gateway/agent).

```bash theme={null}
mnemom agent                    # prompts for a session name
mnemom agent fix-auth --goal "make login work on Safari"
mnemom agent doctor             # read-only preflight
mnemom agent --dry-run          # print the launch plan; no sign-in, no key read, no launch
mnemom agent help config        # help for one sub-verb; never launches
```

### `mnemom agent list`

List the agents in your active org (set with `mnemom org use`). With no active
org set, it lists every org you belong to.

```bash theme={null}
mnemom agent list                      # your active org
mnemom agent list --org <slug-or-id>   # one org, by slug or id
mnemom agent list --all                # every org you belong to
```

An `--org` value that is not one of your orgs fails before any API call and
lists the orgs you can use.

**Example output:**

```
  my-coder
    Agent ID:  mnm-0b3f2a1c-d4e5-4f60-b7a8-9c0d1e2f3a4b
    Created:   2/23/2026
    Last seen: 2 minutes ago

  my-researcher
    Agent ID:  mnm-550e8400-e29b-41d4-a716-446655440000
    Created:   2/7/2026
    Last seen: 1 hour ago

  Total: 2 agent(s)
```

<Note>
  Requires authentication via `mnemom login`. Agents are auto-created by the gateway on first API call -- there is no registration step.
</Note>

### `mnemom agent claim <id-or-name>`

Claim a gateway-provisioned agent into an org by proving you hold its provider
key. See the [Agent Claim Flow guide](/guides/agent-claim-flow) for the full
lifecycle.

```bash theme={null}
mnemom agent claim mnm-... --key "$AGENT_PROVIDER_KEY" --org mnemom
```

* `--org <slug|id>` — destination org. Defaults to your active org (set with
  `mnemom org use`), else your personal org, with a loud notice.
* `--key <key>` — the agent's provider API key; the CLI derives the
  `hash_proof` locally. Alternatively pass `--hash-proof <64-hex>` directly.
* `--name <name>` — the provisioned agent name used in proof derivation. It is
  auto-resolved from the agent id when possible; pass it only to override.
* `--json` — machine-readable output.

<Note>
  To re-home an agent you hold the key for, re-`claim` it with a new `--org`. The
  destination org's template can floor/cap the agent's composed card, so its
  effective posture may change. See
  [Idempotency and re-homing](/guides/agent-claim-flow#idempotency-and-re-homing).
</Note>

### `mnemom agent move <id-or-name> --to <slug|id>`

Move an agent to another org without its key. This is role-based: you must be an
owner or admin in **both** the current and the destination org. `--to` is
required and never defaults to your active org.

```bash theme={null}
mnemom agent move mnm-... --to acme
mnemom agent move my-coder --to acme --json
```

### `mnemom agent sessions`

List your Mnemom Agent launches from the local ledger (`~/.mnemom/sessions.jsonl`),
newest first — the last 20 unless `--all`. Launches older than
`sessions.retention_days` (default 30) are removed at the next launch; see
[CLI preferences](#cli-preferences-mnemom-config).

```bash theme={null}
mnemom agent sessions
mnemom agent sessions --all --json
```

**Options:** `--all`, `--json`

### `mnemom agent show [ref]`

Show one session: the local launch record merged with the gateway's live goal
state (sealed contract, latest verdict, guardrail gauges). `ref` is a session
name (newest match wins) or a unique conversation-id prefix; omitted shows the
newest session.

```bash theme={null}
mnemom agent show
mnemom agent show fix-auth --json
```

**Options:** `--json`

### `mnemom agent goal show|pin|reset [ref]`

Experimental and opt-in (`mnemom experimental enable implicit`). Read and steer the goal the
gateway built for an implicit-mode session: `show` prints it, `pin` freezes the
stored goal (record-only, not a steering lock), and `reset` clears it or
replaces it with your own statement. `ref` picks the session the same way
`show` does. See [Implicit goal mode](/gateway/implicit-goal-mode).

```bash theme={null}
mnemom agent goal show --history
mnemom agent goal pin
mnemom agent goal reset --statement "Ship the CSV export" --yes
```

**Options:** `--thread <id>`, `--json`; `show`: `--all-threads`, `--history`;
`pin`: `--off`; `reset`: `--statement <s>`, `--requirement <r>` (repeatable),
`--yes`

## Updates: `mnemom update`

The CLI updates itself in the background: at most once a day it checks for a
newer release and installs it after the running command exits, never under a
live session. Only a plain `npm install -g` install self-updates; other package
managers get the right manual command instead. Background updates are off in CI
and when output is not a terminal.

```bash theme={null}
mnemom update            # check and install now
mnemom update --check    # only report whether an update is available
mnemom update --json
```

**Options:** `--check`, `--channel <latest|next>` (this run only), `--force`
(allow installing an older version, e.g. moving from `next` back to `latest`),
`--json`

Updates never downgrade on their own. Set `MNEMOM_DISABLE_AUTOUPDATE=1` to turn
background updates off entirely, or use the `update.mode` preference below.

### Minimum version

The Mnemom API tells the CLI the oldest version it still supports, on every
response. A CLI older than that stops instead of running the command, because an
old CLI can leave out request fields a newer server expects. When auto-update is
on (`update.mode` is `auto`), the CLI was installed with `npm install -g`, and it
runs in an interactive terminal (not in CI, not with output piped, and not with
`MNEMOM_DISABLE_AUTOUPDATE` set), it installs the newest stable release that meets the minimum, prints
`Updated the Mnemom CLI … Re-run your command.` and exits; run your command
again. Otherwise it prints the command to upgrade by hand:

```bash theme={null}
npm i -g @mnemom/mnemom@latest
```

## CLI preferences: `mnemom config`

CLI-wide preferences live in `~/.mnemom/config.json`. (Settings for
`mnemom agent` live separately in `mnemom agent config`.)

```bash theme={null}
mnemom config list                         # every setting, its value, and where it came from
mnemom config get update.channel
mnemom config set update.mode notify
mnemom config unset update.mode            # back to the default
```

| Key | Values | Default | Environment override |
| - | - | - | - |
| `update.channel` | `latest` \| `next` | `latest` (`next` when you run a `next` build; `next` requires an invitation) | `MNEMOM_UPDATE_CHANNEL` |
| `update.mode` | `auto` \| `notify` \| `off` | `auto` | `MNEMOM_UPDATE_MODE` |
| `sessions.retention_days` | positive whole number | `30` | `MNEMOM_SESSIONS_RETENTION_DAYS` |

## Experimental features: `mnemom experimental`

Some features ship as **experimental**: off until you turn them on, hidden from
`--help` while off, and liable to change or be removed in any release with no
deprecation period. Using an experimental flag or command while its feature is
off fails with a pointer to the command that turns it on.

```bash theme={null}
mnemom experimental list             # every experimental feature and whether it is on
mnemom experimental enable <id>
mnemom experimental disable <id>
```

The setting is stored in `~/.mnemom/config.json`. `MNEMOM_EXPERIMENTAL=<id>,<id>`
(or `all` / `none`) overrides it for one shell. The current features, all for
`mnemom agent`:

| Feature | What it turns on |
| - | - |
| `implicit` | Implicit goal alignment: `--implicit`, `goal_mode = implicit` and `mnemom agent goal`. See [Implicit goal mode](/gateway/agent#implicit-goal-mode-experimental) |
| `compaction-intercept` | `--compaction-intercept`, the `compaction_intercept` setting, and a `--compact-at` target below 1M |
| `context-handoff` | `--context-handoff` and the `context_handoff` setting |
| `slack` | `--slack`, the `slack_*` settings and `mnemom agent slack` |

`mnemom experimental list` shows the same list with what each one gates.

## Diagnostics

<Steps>
  ### `mnemom status`

  Check that an agent is set up and reachable.

  ```bash theme={null}
  mnemom status --agent my-coder
  ```

  **Output includes:**

  * System checks for authentication, the gateway and the API, each marked OK, warning or error
  * The agent ID, the gateway URL and a link to the agent's dashboard
  * A trace summary: integrity score, total and verified traces, violations, and last activity
  * An overall result: `ALL SYSTEMS GO`, `OK (with warnings)` or `ISSUES DETECTED`

  ### `mnemom activity`

  Show AAP behavioral activity and the activity score for your agent (the agent-side runtime audit log, distinct from AIP checkpoints).

  ```bash theme={null}
  mnemom activity --agent my-coder
  ```

  **Output includes:** the score, total traces, verified traces and violations. `mnemom integrity` is a deprecated alias.

  ### `mnemom logs`

  Show recent traces and actions.

  ```bash theme={null}
  mnemom logs --agent my-coder [-l N]
  ```

  **Options:**

  | Option | Description | Default |
  | - | - | - |
  | `-l, --limit <number>` | Number of traces to show | 10 |

  **Example:**

  ```bash theme={null}
  # Show last 10 traces (default)
  mnemom logs --agent my-coder

  # Show last 50 traces
  mnemom logs --agent my-coder -l 50
  ```

  Each trace prints as its own block with its timestamp. A trace that failed verification is marked `[VIOLATION]`. The output ends with a link to the agent's dashboard.
</Steps>

## License

<Steps>
  ### `mnemom license activate`

  Activate a license key for your account.

  ```bash theme={null}
  mnemom license activate <key>
  ```

  ### `mnemom license status`

  Show current license status.

  ```bash theme={null}
  mnemom license status
  ```

  ### `mnemom license deactivate`

  Deactivate the current license.

  ```bash theme={null}
  mnemom license deactivate
  ```
</Steps>

## Team commands

Manage teams and their scope-cascade templates (`mnemom team ...`).

| Command | Description | Key options |
| - | - | - |
| `team list` | List every team across all orgs you belong to | `--json` |
| `team show <team_id>` | Show details of a single team | `--json` |
| `team alignment-template <team_id>` | Read, or write with `--set <file>`, the team's alignment template | `--set <file>`, `--clear`, `--json` |
| `team protection-template <team_id>` | Read, or write with `--set <file>`, the team's protection template | `--set <file>`, `--clear`, `--json` |
| `team preview-compose <team_id>` | Dry-run the composer with a draft template (alignment by default) | `--protection`, `--from <file>`, `--json` |
| `team admin grant <team_id>` | Grant `team_admin` role to a user on this team | `--user <user_id>`, `--json` |
| `team admin revoke <team_id>` | Revoke a `team_admin` grant (admin or self) | `--user <user_id>`, `--json` |
| `team admin list <team_id>` | List active `team_admin` grants on a team | `--json` |
| `team coverage <team_id>` | Show last-30-day sideband sweep coverage for a team | `--rows`, `--json` |

## Advisories & governance

`mnemom advisories ...` lists and inspects the [sideband advisories](/concepts/posture-vs-cards#2-carryover-bridge) postures write:

| Command | Description | Key options |
| - | - | - |
| `advisories list` | List recent advisories scoped to one agent or one team | `--agent <id>`, `--team <id>`, `--source <s>`, `--limit <n>`, `--since <iso>`, `--json` |
| `advisories show <advisory_id>` | Show one advisory's full content | `--agent <id>`, `--team <id>`, `--json` |

`mnemom governance ...` is the operator workflow for `governance_signals`:

| Command | Description | Key options |
| - | - | - |
| `governance signals list` | List signals at platform/org/team/agent scope | `--org`, `--team`, `--agent`, `--source`, `--severity`, `--status`, `--scope`, `--pattern-type`, `--since`, `--limit`, `--json` |
| `governance signals show <signal_id>` | Show one signal in detail | `--json` |
| `governance signals ack <signal_id>` | Acknowledge an open signal (org admin/owner) | `--action <text>`, `--json` |
| `governance signals resolve <signal_id>` | Resolve with a resolution status (`action_taken`\|`wont_fix`\|`duplicate`\|`false_positive`\|`self_resolved`) | `--status <s>`, `--action <text>`, `--json` |
| `governance signals dismiss <signal_id>` | Dismiss a signal as not actionable | `--reason <text>`, `--json` |
| `governance destinations list` \| `add` \| `remove <id>` \| `test <id>` | Manage notification destinations (webhook/slack/email/pagerduty) | `--org`, `--channel`, `--config`, `--name`, `--filter`, `--json` |
| `governance rules list` \| `add` \| `remove <id>` | Manage escalation rules (predicate → destinations) | `--org`, `--name`, `--predicate`, `--destinations`, `--json` |

## API keys & webhooks

`mnemom api-key ...` manages capability-scoped personal API keys:

| Command | Description | Key options |
| - | - | - |
| `api-key list` | List your active keys with their scope sets | `--json` |
| `api-key create` | Mint a new key. Default scopes: `gateway`, `api:read`, `api:write`; admin scopes are role-gated | `--name <name>`, `--scopes <list>`, `--json` |
| `api-key rotate <key_id>` | Atomic mint-new + revoke-old; returns the new secret once | `--json` |
| `api-key revoke <key_id>` | Soft-revoke an active key immediately and irreversibly | — |

`mnemom webhooks ...` manages org webhook endpoints, deliveries, and replay; `mnemom listen <org_id>` streams live events:

| Command | Description | Key options |
| - | - | - |
| `webhooks list <org_id>` / `get <org_id> <endpoint_id>` | List or inspect endpoints | `--json` |
| `webhooks create <org_id>` | Create an endpoint (signing secret shown once) | `--url`, `--events`, `--description`, `--json` |
| `webhooks update <org_id> <endpoint_id>` | Update url/events/description/active state | `--url`, `--events`, `--description`, `--active`, `--json` |
| `webhooks delete <org_id> <endpoint_id>` | Permanently delete an endpoint | — |
| `webhooks rotate-secret <org_id> <endpoint_id>` | Mint a new signing secret (shown once) | `--json` |
| `webhooks trigger <org_id> <endpoint_id>` | Fire a synthetic test event through the full pipeline | `--json` |
| `webhooks list-deliveries <org_id>` | List recent deliveries, optionally scoped to one endpoint | `--endpoint`, `--limit`, `--offset`, `--json` |
| `webhooks redeliver <org_id> <delivery_id>` | Retry one previous delivery | `--json` |
| `webhooks replay <org_id> <event_id>` | Re-fan-out a historical event to current (or specified) endpoints | `--endpoint` (repeatable), `--json` |
| `listen <org_id>` | Stream live webhook events for an org | `--forward-to`, `--secret`, `--filter`, `--since`, `--json` |

## Other commands

| Command | Description | Key options |
| - | - | - |
| `recipes report-fn <recipe-id>` | File a false-negative report against a recipe (it should have caught something and didn't) | `--summary`, `--evidence`, `--agent`, `--checkpoint`, `--json` |
| `recipes report-fp <recipe-id>` | File a false-positive report (a recipe fired on legitimate behavior) | `--summary`, `--evidence`, `--agent`, `--checkpoint`, `--json` |
| `verify-card <agent_id>` | Verify a published canonical card's AAP attestation + Merkle inclusion proof offline | `--at`, `--card-kind`, `--api`, `--strict`, `--jwks-cache`, `--no-cache` |
| `usage` | Show per-person token/request consumption for an org | `--org`, `--days <7\|30\|90>`, `--person`, `--provider`, `--model`, `--limit`, `--cursor`, `--json` |
| `validate safe-house` | Render Safe House harness state per lane — a promotion-readiness signal, mainly used in CI | `--against`, `--max-age`, `--lane`, `--strict`, `--json` |
| `try-me <token>` | Run the guided Dojo onboarding for a `/try-me` token (born → claim → declare → spar) | `--dry-run`, `--json`, `--yes`, `--name`, `--resume`, `--api`, `--no-open`, `--poll-timeout` |
| `wrap` | Instrument an existing agent through the gateway (born → cards → integration snippet) | `--provider`, `--framework`, `--name`, `--provider-key`, `--yes`, `--json` |
| `onboard` | Self-onboard the calling agent (scan → claim → declare → rating → badge) | `--json`, `--yes`, `--key`, `--hash-proof`, `--no-open` |
| `skills list` / `skills describe <name>` | List or describe the Mnemom CLI's own skills | `--json` |

## Global options

| Option | Description |
| - | - |
| `--agent <name>` | Select which agent to use for the command |
| `-V, --version` | Show CLI version |
| `--help` | Show help text |

## Agent selection

Commands that operate on an agent use this priority to determine which agent:

1. `--agent <name>` flag (highest priority)
2. `MNEMOM_AGENT` environment variable

There is no default agent concept. If neither `--agent` nor `MNEMOM_AGENT` is set, the command stops with `Agent required. Use --agent <name> or set MNEMOM_AGENT.` (`mnemom agent` is different: it uses its own default agent, see [Your governed agent](/gateway/agent#your-governed-agent).)

**Example:**

```bash theme={null}
# Use --agent flag
mnemom status --agent my-coder

# Use environment variable
MNEMOM_AGENT=my-coder mnemom logs
```

## Workflow

A typical workflow with the mnemom CLI:

<Steps>
  ### Install and authenticate

  ```bash theme={null}
  npm install -g @mnemom/mnemom
  mnemom login
  ```

  ### Point your LLM client at the gateway

  Configure your application or LLM client to use `gateway.mnemom.ai` with the `x-mnemom-agent` header. The agent is auto-created on first API call -- no registration needed.

  ```bash theme={null}
  curl https://gateway.mnemom.ai/anthropic/v1/messages \
    -H "x-api-key: $ANTHROPIC_API_KEY" \
    -H "x-mnemom-agent: my-coder" \
    -H "anthropic-version: 2023-06-01" \
    -H "content-type: application/json" \
    -d '{
      "model": "claude-sonnet-4-6",
      "max_tokens": 1024,
      "messages": [{"role": "user", "content": "Hello"}]
    }'
  ```

  ### Verify your agent is connected

  ```bash theme={null}
  mnemom status --agent my-coder
  ```

  ### Check integrity

  ```bash theme={null}
  mnemom activity --agent my-coder
  ```

  ### Review recent activity

  ```bash theme={null}
  mnemom logs --agent my-coder -l 20
  ```

  ### View your alignment card

  ```bash theme={null}
  mnemom card show --agent my-coder
  ```

  ### Customize your alignment card (optional)

  Create a YAML alignment card file and publish it:

  ```bash theme={null}
  mnemom card validate my-card.yaml
  mnemom card publish my-card.yaml --agent my-coder
  ```

  Or edit the existing card directly:

  ```bash theme={null}
  mnemom card edit --agent my-coder
  ```

  See the [Card Management guide](/guides/card-management) for how to build a card from scratch.

  ### Evaluate card policy against tools (optional)

  Test your card's capability mappings against a set of tools:

  ```bash theme={null}
  mnemom card evaluate my-card.yaml --tools mcp__browser__navigate,mcp__slack__post_message --agent my-coder
  ```
</Steps>

## Supported providers

The gateway routes and traces Anthropic, OpenAI, and Gemini. See
[Provider Support](/concepts/provider-support) for the current supported-model
list and the per-provider feature-coverage matrix (thinking-trace inspection,
prompt caching, and more vary by provider).

## See also

* [Gateway Overview](/gateway/overview) -- Architecture and how it works
* [Enforcement Modes](/gateway/enforcement) -- Configure violation response behavior
* [Card Management](/guides/card-management) -- Creating and managing alignment cards


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.