XMemo Memory
Persistent, user-owned memory for agents. Use the standalone runtime to remember, recall, search, preserve restart continuity, manage TODOs and expenses, inspect account overview, activity and stats diagnostics, or diagnose XMemo when MCP tools are unavailable. Not for codebase search, web search, or short-lived in-session notes.
Rank
62
Safety
84
Downloads
3.0k
Updated
Oct 9, 2026
Version
1.1.40
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 3K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 3K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.1.40release · observed Oct 3, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17a1msk02m47p48n5f9yv1exx8882nq:xmemo- Install using `clawhub skill install s17a1msk02m47p48n5f9yv1exx8882nq:xmemo` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/xmemo/xmemo before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-xmemo-xmemo/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: xmemo-memory description: Persistent, user-owned memory for agents. Use the standalone runtime to remember, recall, search, preserve restart continuity, manage TODOs and expenses, inspect account overview, activity and stats diagnostics, or diagnose XMemo when MCP tools are unavailable. Not for codebase search, web search, or short-lived in-session notes. --- # XMemo Memory Give your agent durable memory that survives across sessions, projects, and tools. ## First Successful Run After ClawHub installs this Skill, follow First-run sign-in below: ### First-run sign-in (keep it short) When no credential exists, follow this exact sequence: 1. Ask once in the user's language using this canonical first-message template (translate when addressing the user in another language, but keep the template in English): "XMemo is your personal cloud memory — it lets AI remember your projects, preferences, and todos across sessions and tools, so you never have to repeat yourself. Using XMemo requires an account; you can create a new account or sign in to an existing one in your browser. Sign in or create an account to get started?" Show only this simple introduction and login question first, without doctor, MCP, token, commands, diagnostics, or technical setup. 2. On yes: run `node scripts/xmemo-skill.mjs login --allow-plaintext` directly so output is visible while the command is waiting (for example a background task or streaming shell). As soon as the verification URL and one-time code appear, show only those plus "approve it in your browser" — nothing else. Then wait for the command to exit. A short tool timeout must not kill it before approval or expiry. 3. When login succeeds: run `node scripts/xmemo-skill.mjs auth status --verify`, tell the user in one line that XMemo is connected, and continue the original task. Silently run `node scripts/xmemo-skill.mjs profile --status later --if-unset` with no user prompt, so the existing recall re-offer turns on. 4. On no: do not start login or create temporary access; continue the original task without XMemo; do not ask again in the same session unless the user brings it up. 5. Do not explain runtime selection, doctor details, secret-store setup, or other features during sign-in unless the user asks. ### Diagnostics and Advanced Setup For troubleshooting or non-interactive environments: - Check public service reachability: `node scripts/xmemo-skill.mjs doctor --anonymous` - For account-backed memory, prefer an `XMEMO_KEY` supplied by a managed secret store (see [references/auth-setup.md](references/auth-setup.md)). - Inspect or verify credentials: `node scripts/xmemo-skill.mjs auth status --verify` If a command fails, follow its printed next action and read [references/troubleshooting.md](references/troubleshooting.md). ## Runtime Selection Two parallel integration paths: 1. **Bundled Skill script** at `scripts/xmemo-skill.mjs` (direct REST API integration, Node.js >= 22.22.0). 2. **XMemo MCP to
_meta.json
{
"ownerId": "kn780jpfqajgpf1q4nzm2ckcpd888tyw",
"slug": "xmemo",
"version": "1.1.40",
"publishedAt": 1791008797148
}references/agent-profile.md
# XMemo Agent Profile & Session Integration This reference describes configuring project-level agent instructions (such as `AGENTS.md`, `CLAUDE.md`, or custom agent prompts) to use XMemo in every session. For other operations and guides, see: - [auth-setup.md](auth-setup.md) for full authentication setup, secret stores, vault integration, and token lifecycle. - [command-details.md](command-details.md) for direct memory operations, REST endpoints, and scope authorization. - [ledger-operations.md](ledger-operations.md) for financial bookkeeping and ledger transactions. - [memory-operations.md](memory-operations.md) for core memory, knowledge, and continuity workflows. - [runtime-operations.md](runtime-operations.md) for the command matrix, execution details, output safety, and exit codes. - [troubleshooting.md](troubleshooting.md) for step-by-step diagnosis and repair. ## Integration Rules To have XMemo used automatically in every session, the project's agent instruction file (for example `AGENTS.md` or `CLAUDE.md`) can include an XMemo profile block: - **When to offer**: Offer once at the end of first-run sign-in (in the connection confirmation message), or whenever the user explicitly asks for every-session use. Never repeat the offer unprompted if the user declines. After "later", offer again only when a recall note specifically suggests it. After "don't ask again", never offer again. - **If already configured**: If the project's instruction file already contains the `## XMemo memory` section, do not offer or write it again; replace it only when the user explicitly asks to update it. - **Consent before write**: Run `node scripts/xmemo-skill.mjs profile`, display the block to the user, and write or modify the file only after the user gives explicit confirmation in the same conversation. - **Single section**: Keep it as one section under its `## XMemo memory` heading so any future update replaces that section instead of duplicating it. ## Later and Don't Ask Again When the user chooses "later" or "don't ask again" during first-run sign-in or a subsequent offer: 1. Record the response using `node scripts/xmemo-skill.mjs profile --status later` or `node scripts/xmemo-skill.mjs profile --status never`. 2. State is persisted in a small local file in the XMemo folder of the user's home directory. 3. After "later", each successful recall increments a local counter that counts recalls on this computer across all projects. When recall has been used at least 5 more times since the last offer and fewer than 3 offers have been made in total, recall prints a single guidance note on standard error suggesting an offer can be made once more if the current project lacks the section, and the agent checks the current project's file before offering. 4. The guidance note itself counts as an offer, ensuring no more than 3 offers are ever made in total. 5. After "never" or when no status is recorded, recall never prints a guidance note. ## Generating the Profile
references/auth-setup.md
# XMemo Authentication & Credential Setup
This reference describes credential resolution order, secret store integrations (Meta Muse Vault, OpenClaw Secret Egress), device login, token storage, temporary sandbox access, and credential lifecycle management for the bundled `xmemo` Skill.
For other operations and guides, see:
- [memory-operations.md](memory-operations.md) for core memory, knowledge, and continuity workflows.
- [ledger-operations.md](ledger-operations.md) for expense tracking, ledger audits, and account diagnostics.
- [runtime-operations.md](runtime-operations.md) for the command matrix, execution details, output safety, and exit codes.
- [troubleshooting.md](troubleshooting.md) for step-by-step diagnosis and repair.
## Hosted Discovery Boundary
The public `agent-discovery` field `standalone_skill.operations` describes the
generic commands accepted by `POST /v1/skill/operations`; it is not the full
standalone command catalogue. `restart-snapshot` and `restart-restore` use the
separate direct endpoints `/v1/restart/snapshot` and `/v1/restart/restore`, so
they are deliberately absent from that operations list.
Do not infer that a restart command is available merely because a discovery
document mentions a memory scope. It requires a formal account credential and
the service must authorize the specific request. The temporary-agent manifest
intentionally omits restart continuity: temporary access stays limited to
`remember`, `recall`, and `search` in its isolated sandbox.
## Credential Lookup Priority
Credential lookup follows a strict priority order:
1. **`XMEMO_KEY` environment variable**: Always highest priority. When set, credential resolution trims leading and trailing whitespace and returns the token. If the trimmed value is non-empty, resolution short-circuits with no daemon socket or file access, and the token is never copied to disk. If the trimmed value is empty, `XMEMO_KEY` is treated as unset and resolution continues to Meta Muse Vault or the local user credential file.
- **OpenClaw Secret Egress (`openclaw-secret`)**: When `XMEMO_KEY` contains an OpenClaw egress sentinel (`oc-sent-v2.<name>.end`), OpenClaw's egress proxy manages the plaintext key in its Gateway shared store and injects it outbound strictly for `https://xmemo.dev`. The skill requires `secrets.egressProxy.enabled: true` and Gateway-hosted execution (`HTTPS_PROXY` and `NODE_USE_ENV_PROXY=1`). Neither scripts, agents, nor logs ever see the real key. In OpenClaw, configure the secret:
- Secret entry name: `XMEMO_KEY`
- Allowed hosts: `xmemo.dev`
- Egress proxy: enable `secrets.egressProxy.enabled`
- Execution target: Gateway-hosted exec only (sandboxed or remote `node` exec environments do not receive egress proxy sentinels).
`auth status` reports `Credential Source: openclaw-secret`. Sentinels are rejected by `saveToken` / `auth add`, redacted in responses, and never stored on disk. `logout` preserves OpenClaw secrets, refuses references/command-details.md
# XMemo Direct Memory Operations & Command Details
This reference documents detailed execution semantics, REST endpoints, JSON envelopes, input validation, and scope authorization for direct memory operations, knowledge context, continuity snapshots, and credential lifecycle commands.
For other operations and guides, see:
- [auth-setup.md](auth-setup.md) for full authentication setup, secret stores, vault integration, and token lifecycle.
- [memory-operations.md](memory-operations.md) for core memory and continuity workflows.
- [ledger-operations.md](ledger-operations.md) for expense tracking, ledger audits, and account diagnostics.
- [runtime-operations.md](runtime-operations.md) for the command matrix, output safety, JSON envelopes, and exit codes.
- [troubleshooting.md](troubleshooting.md) for step-by-step diagnosis and repair.
## Direct Memory Operations (`read`, `update`, `forget`)
- `read` is a strictly read-only command backed by
`GET /v1/memories/{id}/explain?include_embedding=false`. It retrieves a specific
memory record by its exact ID with a minimal projection (`id`, `path`,
`content`, `version`, `truncated`). `read --json` returns a harmonized
`{ ok: true, id, path, content, version, truncated }` envelope, where `version`
is `null` when unversioned (rendered as `(unknown)` in terminal text). Unlike
`recall` or `search` which perform semantic retrieval, `read` fetches the
targeted memory record directly. It supports character-level pagination via
`--offset` and `--limit`, setting `truncated: true` when text extends beyond
the requested window. Empty content is a valid memory value. Soft-deleted or
missing records return 404 `not_found`, and authentication/authorization
errors (401/403) are preserved without downgrade.
- `update` modifies an existing memory in place backed by
`PATCH /v1/memories/{id}`. It accepts `--id` (required), `--content`, `--path`,
`--metadata` (JSON string), `--bucket`, and `--scope`. Requires `memory:write`
scope. The server validates the request: client errors such as 400
`invalid_memory_id` are transparently reported as parameter errors and are
never downgraded to `not_found`. Non-existent memories return 404 `not_found`,
and 401/403 errors remain preserved. `update --json` returns
`{ ok: true, id, path, updated: true, ... }`.
- `forget` performs soft-deletion of an existing memory or ledger record backed by
`POST /v1/memories/{id}/forget`. It accepts `--id` (required; accepts memory ID,
logical reference, or `ledger-list` transaction ID), `--reason` (optional
explanation), and mandatory `--confirm`. Authorization strictly requires BOTH an
owner-scoped API key AND an accepted delete-capable scope: `memory:delete`,
`delete:memories`, `memory:write`, `write:memories`, `memory:*`, `memory:admin`,
`admin`, or `*`. Standard credentials carrying `memory:write` are accepted by
the server's delete gate; read-only tokens (such as `ledger:read` or `memory:read`
aloactivepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/xmemo/skills/xmemo",
"sourceUrl": "https://clawhub.ai/xmemo/skills/xmemo",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T10:28:29.338Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-xmemo-xmemo/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xmemo-xmemo/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T10:28:29.338Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "3K downloads",
"href": "https://clawhub.ai/xmemo/xmemo",
"sourceUrl": "https://clawhub.ai/xmemo/xmemo",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T10:28:29.338Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.1.40",
"href": "https://clawhub.ai/xmemo/xmemo",
"sourceUrl": "https://clawhub.ai/xmemo/xmemo",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T06:26:37.148Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-xmemo-xmemo/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xmemo-xmemo/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.1.40",
"description": "**Sign-in flow updated to clarify account requirements and simplified onboarding** - The first-run sign-in prompt now clearly informs users that an account is required, and offers both sign-in and new account creation in the initial message. - Wording of the onboarding message was revised for clarity and user-friendliness. - No changes were made to command-line arguments or workflow logic. - Documentation was updated; the outdated skill-card.md was removed.",
"href": "https://clawhub.ai/xmemo/xmemo",
"sourceUrl": "https://clawhub.ai/xmemo/xmemo",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T06:26:37.148Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
