Skip to main content
Track changes across the Mnemom ecosystem — protocols, SDKs, infrastructure, and tooling.

Mnemom Agent — a governed launcher for your coding agent

September 2026 mnemom agent (shipped in CLI 0.17.0, now the first stable release of the Mnemom Agent line) launches your coding-agent CLI — Claude Code today — through the Mnemom gateway under a governed agent identity, with an optional sealed per-session goal contract. It’s rolling out to an invited cohort.
  • The standalone mnemom agents command is now mnemom agent list|claim|move.
  • mnemom agent sessions and mnemom agent show read back a session’s live goal state (also available via GET /v1/agent/sessions/{conversationId}), and can now show whether goal mode is on, off, or implicit.
  • mnemom agent config and mnemom agent doctor save your launch settings and preflight your machine before you run it.
  • Two opt-in toggles: implicit goal mode (experimental, never on by default) infers a goal contract from your own messages instead of requiring one up front, and --no-context turns off the gateway’s context-folding summarization for a session that needs the full, unsummarized window.
See mnemom agent.

Billing fails closed at the edges of your balance

September 2026 Two related gateway changes:
  • If your organization’s billing account can’t be resolved, requests now get a clear 402 billing_unconfigured response (your org admin is notified) instead of being mistaken for a depleted balance.
  • Once your μ balance is determined to be at or below zero, gateway requests are now blocked by default instead of passing through ungoverned. See Pricing for how to avoid a gap with auto top-up.

Usage-based pricing: everything included, pay only for μ

September 2026 Mnemom moved from plan tiers to usage-based pricing. There’s one unit — μ (1 μ = $0.01, immutable) — and every feature is available to every account regardless of spend. See Pricing for the full model.
  • The billing dashboard now shows your available μ balance, a full ledger of grants, purchases, and spend, and configurable budget alerts.
  • Once your balance is depleted, requests now pause automatically instead of billing past zero, and the dashboard tells you why (see “Billing fails closed” above for the follow-up that also covers an unconfigured billing account).
  • GET /billing/mu, GET /billing/mu/ledger, and GET /billing/mu/statement expose the same balance, ledger, and monthly statement by API; GET/PUT /billing/budget-alert manages alert thresholds; GET /billing/payment-methods and GET /billing/receipts cover payment instruments and purchase history.

Deprecated endpoints

September 2026 The flat per-agent card endpoints and the org/team template endpoints below now redirect (HTTP 308, method and body preserved) to the canonical replacement path listed next to each one. Both the old and new paths work today; the old ones start returning 410 Gone on January 15, 2027. /agents/{agent_id}/sideband-advisories and /teams/{team_id}/sideband-advisories are also deprecated — use the Governance Signals API instead. The two legacy GET /safe-house/…/evaluations endpoints (a list and a single-record lookup, covering outbound/egress screening) are deprecated as well; no replacement is named yet.

Fewer false positives in integrity checks

August 2026 AIP 1.3.0 adds a tool-activity ledger that gives the integrity analyzer more context about what an agent’s tools actually did, cutting false boundary_violation and review_needed verdicts caused by ambiguous tool output. Ships in both SDKs at version 1.3.0: TypeScript @mnemom/agent-integrity-protocol and Python agent-integrity-proto. See Integrity checkpoints.

ResearchGrade: deep research reports on people and companies

July 2026 A new flat-priced report product: a governed research run that produces a full write-up on a person or a company, including probes and connector lookups. Priced per completed run — see Pricing for current rates.

Try Mnemom with no account, and faster onboarding for existing agents

June 2026 mnemom.ai/try-me spins up a temporary sandbox agent with no sign-up: it registers itself, declares an alignment card, and sends it to spar against a live adversarial agent so you can see a real integrity verdict before creating an account. The same flow is available from the CLI as mnemom try-me. Two new CLI commands simplify onboarding a real agent: mnemom wrap instruments an existing agent through the gateway in one step, and mnemom onboard self-registers the calling agent, claims it, declares its card, and returns its Trust Rating and badge. mnemom login also gained --no-browser, which authenticates via a device code instead of opening a browser — useful for headless or remote environments. See the CLI reference.

Model Context Protocol servers, and standard agent-discovery endpoints

June 2026 Two public MCP servers are now live: a control-plane server at api.mnemom.ai/mcp exposing the trust-plane API as tools (mirroring the CLI), and a read-only docs-search server at docs.mnemom.ai/mcp. Point any MCP client at either endpoint. See Connecting over MCP. Standard discovery files at www.mnemom.ai now let an agent with no prior knowledge find the API and learn how to authenticate: /.well-known/oauth-protected-resource (RFC 9728), /.well-known/oauth-authorization-server (RFC 8414, with an agent_auth profile pointing at the real register/claim/rekey endpoints), and /.well-known/agent-card.json. See Agent identity.

Alignment card schema unified across SDKs

June 2026 AAP 2.0.0 unifies the alignment card shape used by the TypeScript and Python SDKs. This is a breaking change for anything that reads raw card JSON/YAML directly — field and section names changed. In the published 2.0.0 packages, the Python and TypeScript verifiers can compute different similarity scores for the same trace near the decision threshold. The fix is recorded as 2.0.1 in the SDK changelog but has not been published to npm or PyPI yet. See Alignment cards.

Claim-to-org — adopt a gateway-provisioned agent into your org

May 2026 POST /v1/agents/{id}/claim adopts a pre-existing agent (one the gateway auto-provisioned) into an org you belong to. Provide org_id to place it in a specific org you’re a member of, or omit it to land the agent in your personal org. Re-claiming an agent you already own with a new org_id moves it. Breaking change: claiming now requires authentication — the previous anonymous claim path was removed. See Agent identity and the claim endpoint reference.

Governance signals — an operator-facing alert surface

May 2026 A new signal type, separate from the advisories an agent sees in its own prompt: fleet-shaped observations (like a coherence drop across a team) are now served only to humans and integrations — dashboard, webhooks, Slack, email, PagerDuty, or a generic signed webhook — never folded back into any agent’s context. New webhook events (governance.signal.*, governance.escalation.triggered), a new mnemom governance CLI command group, and dashboard pages at the team and agent level. See Governance signals, the schema reference, and the operator guide.

Agent ID format update — mnm-{uuid_v4}

April 2026 New agents receive IDs in the mnm-{uuid_v4} format. Existing smolt-{8_hex} IDs continue to work permanently — they’re committed to proof chains and are never reissued. The new format gives 128-bit entropy and IDs are server-assigned, so they’re recoverable via API key if local config is lost. See Agent identity.

AAP 0.6.0 — Fault line analysis

March 2026 Team divergence reports are now classified into actionable fault lines instead of a raw diff: resolvable, priority_mismatch, incompatible, or complementary, plus detection of a structural fault line (the same split recurring across multiple values). Available in both SDKs (analyzeFaultLines() / analyze_fault_lines()), and via POST /v1/teams/fault-lines. See Fault line analysis and the Intelligence API.

Fewer unnecessary proofs, and lower proving cost

March 2026 Proving strategy now defers cryptographic proof generation for verdicts that a policy-gap review might later dismiss, only proving confirmed real violations. This cut proving volume and cost substantially without changing which verdicts are trustworthy. See Deferred proofs.

AAP 0.5.0 — YAML policies and Trust Edges

March 2026 The alignment API now accepts policies authored in YAML (text/yaml /application/yaml) alongside JSON, and a new Trust Edges API (GET/POST/DELETE /v1/agents/:id/trust-edges) lets you declare explicit trust relationships between agents. Cards on the prior aap_version continue to work unmodified. See Upgrading to 0.5.0.

Card Lifecycle & Policy Intelligence

February 2026 A multi-phase release turning alignment cards into policy-governed, lifecycle-managed artifacts:
  • Policy engine: YAML governance rules (warn/enforce/off), a 24-hour grace period for newly discovered tools, and a mnemom policy CLI. See the Policy DSL and Policy CLI.
  • Card lifecycle & trust recovery: tracked card amendments with version history, and reclassifying a violation as a configuration gap (rather than real misbehavior) now recovers the affected trust score automatically. See Card lifecycle, Trust recovery, and the Reclassification API.
  • On-chain verification: reputation scores and Merkle roots can be anchored on Base L2 for tamper-evident, independently verifiable history. See On-chain verification and the On-chain API.
  • Policy management guides: CI/CD policy gates and Policy management; full reference at the Policy API.

Team reputation

February 2026 Teams (groups of 2–50 agents) become first-class entities with their own persistent identity, an alignment card auto-derived from members (or manually curated), and an accumulated reputation score. Includes embeddable team badges (/v1/teams/{id}/badge.svg), roster management with an audit trail, and 9 new webhook events for team lifecycle and reputation changes. See Team management, Team reputation, and the Teams API.

Public Trust Ratings and embeddable badges

February 2026 Every agent with a published score gets a public page at /reputation/{agent_id} with a score breakdown, trend chart, and cryptographic verification link, plus a searchable Trust Directory. GET /v1/reputation/{agent_id}/verify returns a proof chain for independent verification, and mnemom/reputation-check gates CI/CD pipelines on a minimum score. See Embeddable badges and Understanding Trust Ratings.

Faster, cheaper cryptographic proofs

February 2026 Zero-knowledge proof generation moved to GPU hardware, cutting proving latency from roughly 270 seconds to well under a second and roughly halving the per-proof cost. A follow-up fix also made the proving pipeline recover automatically instead of silently stalling when an individual proof failed to generate. See Verifiable verdicts.

N-way fleet coherence

February 2026 Pairwise value-coherence checks extend to whole fleets: a fleet score across every pair of agents, outlier detection for agents that diverge from the group, cluster analysis, and a per-value divergence report. Available via GET /v1/orgs/:org_id/coherence and as checkFleetCoherence() / check_fleet_coherence() in both SDKs. See Fleet coherence.

Read-only support access, fully audited

February 2026 Enterprise support can view your dashboard exactly as you see it to help diagnose an issue — read-only, time-limited to one hour, and every session is logged with a visible “Viewing as” banner while it’s active. All write actions are blocked for the duration.

Custom conscience values

February 2026 Enterprise orgs can define custom values (for example, “patient safety over efficiency”) that apply to every agent’s integrity check, layered on top of Mnemom’s defaults and optionally overridden per agent. Fully audited, with a webhook event on every change. See Conscience values.

Agent containment

February 2026 Enterprise teams can pause, resume, or permanently kill an agent in real time from the API or dashboard. A contained agent’s gateway traffic is rejected with a structured error, and orgs can configure automatic pause after repeated boundary violations.

February 2026 — Public launch

  • Mnemom v1.0: the gateway and CLI ship for zero-configuration agent transparency — automatic agent identification, real-time integrity analysis, and CLI login with automatic agent registration.
  • AIP v0.1.5: the Agent Integrity Protocol ships with provider adapters for Anthropic, OpenAI, and Google Gemini, analyzing agent reasoning between turns before actions execute.
  • AAP v0.1.0: the Agent Alignment Protocol ships as a public spec — alignment cards, AP-Traces, and value coherence handshakes for verifying compatibility before multi-agent coordination. TypeScript (@mnemom/agent-alignment-protocol) and Python (agent-alignment-protocol) SDKs.
  • Verifiable Integrity: every AIP verdict can be independently verified through Ed25519 checkpoint signing, hash-chain integrity, Merkle inclusion proofs, and optional zero-knowledge proofs. See Certificates and Verifiable verdicts.
  • aip-otel-exporter v0.1.0: an OpenTelemetry exporter for AIP/AAP telemetry, compatible with Datadog, Grafana, Splunk, Arize, Langfuse, and any OTel collector. TypeScript (@mnemom/aip-otel-exporter) and Python (aip-otel-exporter).
  • Dashboard: agent management, a trace viewer, and an integrity score view with real-time and historical drift.