saihm-memory
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@saihm-memoryRemember my database connection string"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
demo-claude-code
SAIHM memory inside Claude Code, Cursor, and any MCP host.
A tiny MCP server that gives your AI coding assistant a persistent, client-side-encrypted memory it can remember, recall, and forget — backed by SAIHM. The memory is portable across models, non-custodial, and provably erasable.
⭐ Star SAIHM on GitHub and share it if it's useful — help every agent get portable, provable memory. Share on X.
What your assistant gets
Four tools — saihm_remember, saihm_recall, saihm_forget, saihm_status — all sealed client-side via @saihm/mcp-server-pro. The endpoint only ever sees ciphertext.
Related MCP server: SAIHM MCP Server
Install
git clone https://github.com/citw2/demo-claude-code
cd demo-claude-code
npm installAdd it to Claude Code
claude mcp add saihm-memory -- node /absolute/path/to/demo-claude-code/server.mjsAdd it to Cursor
Add to ~/.cursor/mcp.json (or a project .cursor/mcp.json):
{
"mcpServers": {
"saihm-memory": {
"command": "node",
"args": ["/absolute/path/to/demo-claude-code/server.mjs"]
}
}
}Now ask your assistant to remember things — they persist through the session and any model can recall them. Out of the box this uses a local, in-process blind sandbox (memory lasts for the editor session) so you can try it with zero signup.
Durable, hosted memory (recommended)
For memory that follows you across machines and sessions — stored on the real, blind, non-custodial SAIHM endpoint — join SAIHM and add env to the same config:
{
"mcpServers": {
"saihm-memory": {
"command": "node",
"args": ["/absolute/path/to/demo-claude-code/server.mjs"],
"env": {
"SAIHM_ENDPOINT_URL": "https://saihm.coti.global/mcp",
"SAIHM_AUTH_HEADER": "Bearer <your-onboard-JWT>",
"SAIHM_MASTER_SECRET_HEX": "<at least 64 hex chars, generated and held only by you>"
}
}
}
}Your master secret never leaves your machine; the endpoint stores only ciphertext.
Learn more
Part of the SAIHM demos
demo-cross-model-memory — one memory across Claude, DeepSeek, Qwen, Kimi, GLM, GPT, with provable erasure.
Built on @saihm/mcp-server-pro and @saihm/client-pro.
Join the protocol: saihm.coti.global/join.
License
Apache-2.0 © SAIHM
Available Tools
4 toolssaihm_forgetA
Permanently crypto-shred a memory by cellId (irreversible; GDPR Art. 17 erasure).
| Name | Required | Description | Default |
|---|---|---|---|
| cellId | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility. It explicitly states 'permanently', 'irreversible', and 'GDPR Art. 17 erasure', which discloses the destructive, non-recoverable nature. It does not cover edge cases like non-existent cellId or authorization requirements, but it transparently conveys the primary behavioral trait.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The entire description is one sentence, front-loaded with the action ('Permanently crypto-shred') and includes critical caveats (irreversible, GDPR). No wasted words, perfectly concise.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple single-parameter destructive tool, the description covers purpose, irreversibility, and legal reference. No output schema is needed, and the parameter is explained. The tool is adequately specified for an agent to invoke correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description must supply parameter meaning. The phrase 'by cellId' clarifies that the sole parameter is the identifier of the memory to erase, which is more semantic than the schema's bare 'string' type. It does not specify format or validity rules, but the parameter's purpose is sufficiently clear.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses the specific verb 'crypto-shred' and specifies the resource as 'a memory by cellId', clearly indicating a delete/erase operation. This distinguishes it from siblings like 'saihm_remember' (store), 'saihm_recall' (retrieve), and 'saihm_status' (query state).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description clearly implies this is the tool for permanent deletion and provides legal context (GDPR Art. 17), but it does not explicitly mention alternatives or when-not-to-use. Sibling names reinforce its role, giving clear contextual usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
saihm_recallA
Recall SAIHM memories (decrypted client-side), optionally filtered by a keyword.
| Name | Required | Description | Default |
|---|---|---|---|
| query | No | Optional keyword filter. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the load. It adds useful context with 'decrypted client-side', suggesting a secure read operation. However, it does not disclose return format, pagination, or error behavior, leaving some gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single, front-loaded sentence that conveys the core purpose and optional filtering with no redundant information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
This is a simple recall tool with one optional param and no output schema. The description states the core function and decryption behavior but does not describe the return format or edge cases, which would be expected without an output schema. It is minimal but adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already describes the 'query' parameter as an optional keyword filter, and the description echoes this. With 100% schema coverage, no additional parameter semantics are provided, so baseline of 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses the specific verb 'Recall' with the resource 'SAIHM memories' and mentions optional keyword filtering, clearly distinguishing it from sibling tools like remember/forget/status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The context clearly implies use for retrieving memories, while siblings handle other operations, but it does not explicitly name alternatives or exclusions. The guidance is adequate though not exhaustive.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
saihm_rememberA
Store a memory in SAIHM (sealed client-side before it leaves this process). Pass cellId to update an existing memory.
| Name | Required | Description | Default |
|---|---|---|---|
| cellId | No | Optional: update this existing memory. | |
| content | Yes | The text to remember. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses a non-obvious behavioral trait ('sealed client-side before it leaves this process') and explains the update mechanism via cellId. However, it does not mention success/failure behavior or side effects like overwriting content.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, no filler. The core action is front-loaded, and the update instruction is concise. Every word earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is simple (2 params, no output schema, no annotations), and the description covers the essential purpose, update behavior, and a key security trait. Missing return value info is acceptable for a store operation given the low complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3. The description adds no new meaning beyond the schema: 'Pass cellId to update an existing memory' mirrors the schema's parameter description. Content is simply 'The text to remember' without additional context.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb+resource ('Store a memory in SAIHM') and clearly distinguishes from siblings by noting the update capability via cellId. This makes the tool's purpose unambiguous and distinct from recall/forget/status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for storing new memories or updating existing ones, but does not explicitly state when to use this tool versus alternatives like saihm_recall or saihm_forget. No exclusions or alternative recommendations are provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
saihm_statusA
Non-custodial status: tier, active memory count, and custody (no plaintext).
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the transparency burden. It discloses that no plaintext is returned, which is a meaningful privacy guarantee. However, it does not explicitly state that the tool is read-only or has no side effects, though 'status' implies this. Adequate but not comprehensive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence that states the core purpose and key details without any unnecessary words. It is perfectly concise.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple status tool with no parameters and no output schema, the description provides enough context: what fields are returned and an important privacy constraint. It could elaborate on the meaning of 'tier' or 'custody', but this is adequate for the tool's complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters, and schema coverage is 100% by default. The description does not need to explain parameters, so the baseline of 4 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states this tool provides status information (tier, active memory count, custody) and is distinct from the memory-operation siblings (remember, recall, forget). The lack of an explicit verb like 'returns' is minor, but the intent is unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage context is implied by the tool's status nature and sibling names, but there is no explicit guidance on when to use this versus alternatives. It does not mention exclusions or when not to use it, leaving the agent to infer.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
4 tool updates
v0.1.0- First observed
saihm_forget - First observed
saihm_recall - First observed
saihm_remember - First observed
saihm_status
TDQS
Each tool has a clear, non-overlapping function: storing, recalling, deleting, and checking status of memories. There is no ambiguity about which tool to use for a given operation.
Three tools use a consistent verb pattern (remember, recall, forget), while 'status' is a noun, which is a slight deviation. However, the common 'saihm_' prefix and predictable naming keep it coherent.
Four tools is well-scoped for a memory management system: create/update, read, delete, and status. Each tool serves a distinct and necessary purpose without redundancy.
The toolset covers the full lifecycle of memories: remember (create/update), recall (read with optional filtering), forget (delete), and status (overview). There are no obvious gaps for the domain.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Truth-validated, SHA-512-sealed AI memory for Claude & Cursor. Free tier, OAuth, 38 tools.
Verified memory for AI agents. Signed assertions, billing attestation, session continuity.
Persistent memory for AI agents. Semantic search, memory graph, W3C DID identity.
- JustOnceOAuthai.justonce
Persistent memory for AI assistants — one shared, OAuth-secured vault for every MCP client.
Related MCP Servers
- AlicenseAqualityCmaintenancePersistent memory for AI coding agents. Store coding standards, architecture decisions, and project context across sessions with AES-256 encryption.81MIT
- AlicenseNot gradedqualityAmaintenanceProvides non-custodial, post-quantum encrypted memory for AI agents, enabling portable memory across models with provable erasure.1Apache 2.0
- AlicenseNot gradedqualityAmaintenanceLocal-first, encrypted memory for AI agents, with cryptographic forgetting.3Apache 2.0
- AlicenseNot gradedqualityCmaintenanceProvides persistent memory for AI coding tools, allowing them to remember corrections, decisions, and preferences across sessions and different tools.602MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/citw2/demo-claude-code'
If you have feedback or need assistance with the MCP directory API, please join our Discord server