Mnemom Agent — a governed launcher for your coding agent
September 2026mnemom agent (shipped in CLI 0.17.0, now the first stable release of the Mnemom Agent
line) launches your coding-agent CLI — Claude Code today — through the Mnemom gateway
under a governed agent identity, with an optional sealed per-session goal contract. It’s
rolling out to an invited cohort.
- The standalone
mnemom agentscommand is nowmnemom agent list|claim|move. mnemom agent sessionsandmnemom agent showread back a session’s live goal state (also available viaGET /v1/agent/sessions/{conversationId}), and can now show whether goal mode is on, off, or implicit.mnemom agent configandmnemom agent doctorsave your launch settings and preflight your machine before you run it.- Two opt-in toggles: implicit goal mode (experimental, never on by default) infers a
goal contract from your own messages instead of requiring one up front, and
--no-contextturns off the gateway’s context-folding summarization for a session that needs the full, unsummarized window.
mnemom agent.
Billing fails closed at the edges of your balance
September 2026 Two related gateway changes:- If your organization’s billing account can’t be resolved, requests now get a clear
402 billing_unconfiguredresponse (your org admin is notified) instead of being mistaken for a depleted balance. - Once your μ balance is determined to be at or below zero, gateway requests are now blocked by default instead of passing through ungoverned. See Pricing for how to avoid a gap with auto top-up.
Usage-based pricing: everything included, pay only for μ
September 2026 Mnemom moved from plan tiers to usage-based pricing. There’s one unit — μ (1 μ = $0.01, immutable) — and every feature is available to every account regardless of spend. See Pricing for the full model.- The billing dashboard now shows your available μ balance, a full ledger of grants, purchases, and spend, and configurable budget alerts.
- Once your balance is depleted, requests now pause automatically instead of billing past zero, and the dashboard tells you why (see “Billing fails closed” above for the follow-up that also covers an unconfigured billing account).
GET /billing/mu,GET /billing/mu/ledger, andGET /billing/mu/statementexpose the same balance, ledger, and monthly statement by API;GET/PUT /billing/budget-alertmanages alert thresholds;GET /billing/payment-methodsandGET /billing/receiptscover payment instruments and purchase history.
Deprecated endpoints
September 2026 The flat per-agent card endpoints and the org/team template endpoints below now redirect (HTTP 308, method and body preserved) to the canonical replacement path listed next to each one. Both the old and new paths work today; the old ones start returning410 Gone on
January 15, 2027.
/agents/{agent_id}/sideband-advisories and /teams/{team_id}/sideband-advisories are also
deprecated — use the Governance Signals API instead.
The two legacy GET /safe-house/…/evaluations endpoints (a list and a single-record lookup,
covering outbound/egress screening) are deprecated as well; no replacement is named yet.
Fewer false positives in integrity checks
August 2026 AIP 1.3.0 adds a tool-activity ledger that gives the integrity analyzer more context about what an agent’s tools actually did, cutting falseboundary_violation and review_needed
verdicts caused by ambiguous tool output. Ships in both SDKs at version 1.3.0: TypeScript
@mnemom/agent-integrity-protocol and Python agent-integrity-proto.
See Integrity checkpoints.
ResearchGrade: deep research reports on people and companies
July 2026 A new flat-priced report product: a governed research run that produces a full write-up on a person or a company, including probes and connector lookups. Priced per completed run — see Pricing for current rates.Try Mnemom with no account, and faster onboarding for existing agents
June 2026 mnemom.ai/try-me spins up a temporary sandbox agent with no sign-up: it registers itself, declares an alignment card, and sends it to spar against a live adversarial agent so you can see a real integrity verdict before creating an account. The same flow is available from the CLI asmnemom try-me.
Two new CLI commands simplify onboarding a real agent: mnemom wrap instruments an existing
agent through the gateway in one step, and mnemom onboard self-registers the calling
agent, claims it, declares its card, and returns its Trust Rating and badge. mnemom login
also gained --no-browser, which authenticates via a device code instead of opening a
browser — useful for headless or remote environments.
See the CLI reference.
Model Context Protocol servers, and standard agent-discovery endpoints
June 2026 Two public MCP servers are now live: a control-plane server atapi.mnemom.ai/mcp exposing
the trust-plane API as tools (mirroring the CLI), and a read-only docs-search server at
docs.mnemom.ai/mcp. Point any MCP client at either endpoint. See Connecting over
MCP.
Standard discovery files at www.mnemom.ai now let an agent with no prior knowledge find
the API and learn how to authenticate: /.well-known/oauth-protected-resource (RFC 9728),
/.well-known/oauth-authorization-server (RFC 8414, with an agent_auth profile pointing
at the real register/claim/rekey endpoints), and /.well-known/agent-card.json. See
Agent identity.
Alignment card schema unified across SDKs
June 2026 AAP 2.0.0 unifies the alignment card shape used by the TypeScript and Python SDKs. This is a breaking change for anything that reads raw card JSON/YAML directly — field and section names changed. In the published 2.0.0 packages, the Python and TypeScript verifiers can compute different similarity scores for the same trace near the decision threshold. The fix is recorded as 2.0.1 in the SDK changelog but has not been published to npm or PyPI yet. See Alignment cards.Claim-to-org — adopt a gateway-provisioned agent into your org
May 2026POST /v1/agents/{id}/claim adopts a pre-existing agent (one the gateway auto-provisioned)
into an org you belong to. Provide org_id to place it in a specific org you’re a member of,
or omit it to land the agent in your personal org. Re-claiming an agent you already own with
a new org_id moves it. Breaking change: claiming now requires authentication — the
previous anonymous claim path was removed.
See Agent identity and the claim endpoint
reference.
Governance signals — an operator-facing alert surface
May 2026 A new signal type, separate from the advisories an agent sees in its own prompt: fleet-shaped observations (like a coherence drop across a team) are now served only to humans and integrations — dashboard, webhooks, Slack, email, PagerDuty, or a generic signed webhook — never folded back into any agent’s context. New webhook events (governance.signal.*, governance.escalation.triggered), a new
mnemom governance CLI command group, and dashboard pages at the team and agent level.
See Governance signals, the schema
reference, and the operator
guide.
Agent ID format update — mnm-{uuid_v4}
April 2026
New agents receive IDs in the mnm-{uuid_v4} format. Existing smolt-{8_hex} IDs continue
to work permanently — they’re committed to proof chains and are never reissued. The new
format gives 128-bit entropy and IDs are server-assigned, so they’re recoverable via API key
if local config is lost.
See Agent identity.
AAP 0.6.0 — Fault line analysis
March 2026 Team divergence reports are now classified into actionable fault lines instead of a raw diff:resolvable, priority_mismatch, incompatible, or complementary, plus detection
of a structural fault line (the same split recurring across multiple values). Available in
both SDKs (analyzeFaultLines() / analyze_fault_lines()), and via POST /v1/teams/fault-lines.
See Fault line analysis and the Intelligence
API.
Fewer unnecessary proofs, and lower proving cost
March 2026 Proving strategy now defers cryptographic proof generation for verdicts that a policy-gap review might later dismiss, only proving confirmed real violations. This cut proving volume and cost substantially without changing which verdicts are trustworthy. See Deferred proofs.AAP 0.5.0 — YAML policies and Trust Edges
March 2026 The alignment API now accepts policies authored in YAML (text/yaml /application/yaml)
alongside JSON, and a new Trust Edges API (GET/POST/DELETE /v1/agents/:id/trust-edges) lets you declare explicit trust relationships between agents.
Cards on the prior aap_version continue to work unmodified.
See Upgrading to 0.5.0.
Card Lifecycle & Policy Intelligence
February 2026 A multi-phase release turning alignment cards into policy-governed, lifecycle-managed artifacts:- Policy engine: YAML governance rules (
warn/enforce/off), a 24-hour grace period for newly discovered tools, and amnemom policyCLI. See the Policy DSL and Policy CLI. - Card lifecycle & trust recovery: tracked card amendments with version history, and reclassifying a violation as a configuration gap (rather than real misbehavior) now recovers the affected trust score automatically. See Card lifecycle, Trust recovery, and the Reclassification API.
- On-chain verification: reputation scores and Merkle roots can be anchored on Base L2 for tamper-evident, independently verifiable history. See On-chain verification and the On-chain API.
- Policy management guides: CI/CD policy gates and Policy management; full reference at the Policy API.
Team reputation
February 2026 Teams (groups of 2–50 agents) become first-class entities with their own persistent identity, an alignment card auto-derived from members (or manually curated), and an accumulated reputation score. Includes embeddable team badges (/v1/teams/{id}/badge.svg), roster management with an audit trail, and 9 new webhook
events for team lifecycle and reputation changes.
See Team management, Team reputation,
and the Teams API.
Public Trust Ratings and embeddable badges
February 2026 Every agent with a published score gets a public page at/reputation/{agent_id} with a
score breakdown, trend chart, and cryptographic verification link, plus a searchable
Trust Directory. GET /v1/reputation/{agent_id}/verify returns a proof chain for independent verification, and
mnemom/reputation-check gates CI/CD
pipelines on a minimum score.
See Embeddable badges and Understanding Trust
Ratings.
Faster, cheaper cryptographic proofs
February 2026 Zero-knowledge proof generation moved to GPU hardware, cutting proving latency from roughly 270 seconds to well under a second and roughly halving the per-proof cost. A follow-up fix also made the proving pipeline recover automatically instead of silently stalling when an individual proof failed to generate. See Verifiable verdicts.N-way fleet coherence
February 2026 Pairwise value-coherence checks extend to whole fleets: a fleet score across every pair of agents, outlier detection for agents that diverge from the group, cluster analysis, and a per-value divergence report. Available viaGET /v1/orgs/:org_id/coherence and as
checkFleetCoherence() / check_fleet_coherence() in both SDKs.
See Fleet coherence.
Read-only support access, fully audited
February 2026 Enterprise support can view your dashboard exactly as you see it to help diagnose an issue — read-only, time-limited to one hour, and every session is logged with a visible “Viewing as” banner while it’s active. All write actions are blocked for the duration.Custom conscience values
February 2026 Enterprise orgs can define custom values (for example, “patient safety over efficiency”) that apply to every agent’s integrity check, layered on top of Mnemom’s defaults and optionally overridden per agent. Fully audited, with a webhook event on every change. See Conscience values.Agent containment
February 2026 Enterprise teams can pause, resume, or permanently kill an agent in real time from the API or dashboard. A contained agent’s gateway traffic is rejected with a structured error, and orgs can configure automatic pause after repeated boundary violations.February 2026 — Public launch
- Mnemom v1.0: the gateway and CLI ship for zero-configuration agent transparency — automatic agent identification, real-time integrity analysis, and CLI login with automatic agent registration.
- AIP v0.1.5: the Agent Integrity Protocol ships with provider adapters for Anthropic, OpenAI, and Google Gemini, analyzing agent reasoning between turns before actions execute.
- AAP v0.1.0: the Agent Alignment Protocol ships as a public spec — alignment cards,
AP-Traces, and value coherence handshakes for verifying compatibility before multi-agent
coordination. TypeScript (
@mnemom/agent-alignment-protocol) and Python (agent-alignment-protocol) SDKs. - Verifiable Integrity: every AIP verdict can be independently verified through Ed25519 checkpoint signing, hash-chain integrity, Merkle inclusion proofs, and optional zero-knowledge proofs. See Certificates and Verifiable verdicts.
- aip-otel-exporter v0.1.0: an OpenTelemetry exporter for AIP/AAP telemetry, compatible
with Datadog, Grafana, Splunk, Arize, Langfuse, and any OTel collector. TypeScript
(
@mnemom/aip-otel-exporter) and Python (aip-otel-exporter). - Dashboard: agent management, a trace viewer, and an integrity score view with real-time and historical drift.