Documentation menu / searchSearch documentation →

Start here

Quick startConnect through MCPOpenCode native memoryOpenCode memory controllerMemory API & local models

Use the service

Memory & compactionMemory lifecycle controllerLocal agents & swarmsCLI referenceHTTP reference

Run a node

ConfigurationOperations & backupsLocal memory & ARM

Evidence

Performance & device targetsFull retrieval reportBenchmark methodologyEvaluation policyMemory benchmark notes

Build with us

Architecture & schemaTechnology & learning mapRepository maintenanceContributingSecurityWebsite & deploymentSearch & agent discoveryPrivate product measurementEngineering references

Project

Cleanup & release planRoadmapLocal AI memory: when instantKV fitsFeaturesChangelog

History

Verification history

Proposals

Distributed memory proposal

Build with us / single-node · source MVP

Security

Report vulnerabilities privately and understand deployment boundaries.

Report vulnerabilities privately through GitHub private vulnerability reporting. Do not put credentials or sensitive memory in a public issue.

The service uses one node. Namespace grants define API access boundaries; agent labels do not. Use separate namespaces for private agents or projects. The Docker host port is loopback-only by default. For remote clients, use an SSH tunnel or HTTPS proxy. Keep generated credentials private.

instantKV does not encrypt stored values or securely erase deleted disk pages. Protect the host, volumes and backups. Treat retrieved memory as untrusted reference data. Never let it override system instructions or authorize tools. The server does not execute uploaded code or plugins.

Configuration changes and credential rotation require a restart. Keep the data volume during upgrades. Never use docker compose down -v for an ordinary upgrade.

Before an MVP upgrade, make an offline backup. Older writers do not maintain the MVP indexes. To downgrade, restore the pre-upgrade backup.