Documentation menu / searchSearch documentation →

Start here

Quick startConnect through MCPOpenCode native memoryOpenCode memory controllerMemory API & local models

Use the service

Memory & compactionMemory lifecycle controllerLocal agents & swarmsCLI referenceHTTP reference

Run a node

ConfigurationOperations & backupsLocal memory & ARM

Evidence

Performance & device targetsFull retrieval reportBenchmark methodologyEvaluation policyMemory benchmark notes

Build with us

Architecture & schemaTechnology & learning mapRepository maintenanceContributingSecurityWebsite & deploymentSearch & agent discoveryPrivate product measurementEngineering references

Project

Cleanup & release planRoadmapLocal AI memory: when instantKV fitsFeaturesChangelog

History

Verification history

Proposals

Distributed memory proposal

Build with us / single-node · source MVP

Technology & learning map

Understand the service, memory lifecycle, agent runtime and website stack.

Start with the request path:

OpenCode → MCP controller → local HTTP → Rust policy → redb transaction

OpenCode supplies the model and chooses tool calls. The optional Python controller handles fact identity, provenance, corrections, conflicts and forgetting. Rust handles authorization, bounded retrieval and durable storage. The website is a separate static documentation deployment.

Learn these first

OrderTopicWhat to understandRead the implementation
1Transactions and indexesA fact, its search postings, counters and indexes must change together. A failed write must preserve the old state.Store, architecture
2Memory lifecycleIdentity, observations, current truth, historical evidence, contradictions and explicit corrections are different things.Controller, design
3Revision checks and retriesCompare-and-swap prevents lost updates. Per-slot receipts make identical retries safe. A timeout can follow a committed write.Controller guide, HTTP contract
4RetrievalInverted indexes, BM25 scoring, stemming, WAND skipping, filters, cursors and bounded work determine what reaches the model.Search, memory guide
5Agent integrationMCP exposes tools; the agent chooses when to call them. Prompts and tool schemas affect capture and recall quality.MCP setup, OpenCode controller
6Operating a productPrivate credentials, namespace grants, backups, upgrades, failure messages and finite capacity matter during daily use.Operations, configuration

Rust service

TechnologyJob in this projectStudy more deeply
Rust 2024, Rust 1.98+, CargoTwo workspace crates: embedded core and service/CLI. Ownership, borrowing and types constrain state and resource use.Ownership, lifetimes, error enums, shared state, workspace builds
redbEmbedded durable database. Record, index and checkpoint changes use transactions. One process owns the database.ACID, read/write transactions, crash recovery, ordered composite keys
Ordered indexesTopic, tag, event-time and expiry selection without scanning every record.Key ordering, range scans, index consistency, cursor continuation
BM25 and WANDRank lexical matches using an inverted index; skip candidates with score bounds.Term frequency, document frequency, length normalization, safe score bounds
rust-stemmersEnglish Snowball stemming during indexing and querying.Tokenization, morphology and language-specific retrieval limits
TokioAsync network I/O, process management, shutdown and concurrency control. Storage work uses blocking tasks.Futures, cancellation, semaphores, backpressure, spawn_blocking
AxumHTTP routes, request extraction and middleware.Body limits, authentication, deadlines, structured errors
reqwest + rustlsRust HTTP client and TLS implementation.Timeouts, transport errors, safe retries
Serde, serde_json, TOMLTyped records, JSON wire formats and configuration.Schema evolution, strict validation, serialization
SchemarsJSON Schema generation from Rust API types.Keeping code, generated schemas and tools consistent
clapTyped command-line arguments and help.Usable defaults, validation and error paths
rmcpNative Rust MCP tools over stdio, with local or HTTP-backed access.JSON-RPC, initialization, tool schemas, permission boundaries
SHA-256, UUID, Base64, subtleDigests, unique IDs, wire encoding and constant-time comparisons.Hashes versus encryption; IDs versus authorization
thiserror, anyhow, tracingTyped core errors, application error context and structured diagnostics.Safe logs and errors without credentials or memory contents

The native memory contract defines search and pagination limits. BM25 scores measure query relevance; they are not truth confidence. Queries use English lexical retrieval. Semantic embeddings and graph reasoning remain roadmap work, with separate quality and resource gates.

Memory controller and model runtime

Technology or mechanismJobStudy more deeply
Python 3 standard libraryOptional HTTP adapter, lifecycle controller, CLI and MCP bridge. No pip package is required for these paths.Bounded I/O, subprocess ownership, JSON validation, exception contracts
Scope/entity/attribute slotsStable fact identity across changing values. Hashed keys avoid putting raw labels in tombstones.Normalization, entity ambiguity, isolation and identity collisions
Source quotes and event timePreserve where a fact came from and when it was observed.Grounding, temporal truth, observation time versus write time
Revisions and per-slot receiptsConditional corrections and exact replay handling.Idempotence, lost updates, concurrent writers, partial batch failure
Tombstones and semantic expiryForget removes managed content and blocks replay. valid_until_ms hides expired facts without deleting retry protection.Delete semantics, revival prevention and retention policy
OpenCodeExisting agent runtime and connected model provider. It selects deterministic controller tools through MCP.Agent permissions, fresh sessions, context assembly, tool-use failures
Optional OllamaExplicit local-model extraction and current-turn chat examples. Capture previews proposals before application.Structured output, grounding checks, model locality and failure handling

The service does not make model calls. Model output still needs deterministic validation, and a grounded quote does not prove the model interpreted it correctly. OpenCode’s provider receives the prompt and returned memory used in that session; choose a local provider when inference must stay on your device.

The controller has finite per-slot evidence capacity. It cannot compact evidence or restore a forgotten slot yet. Native TTL must be disabled for its durable namespace. Exact limits and recovery steps.

Website, tooling and evaluation

TechnologyJob
Astro + TypeScriptStatic pages, typed route registry and report-backed evidence pages
Markdown, unified, remark and GFMOne source for guides, HTML pages and agent-readable exports
Plain CSS + self-hosted GeistResponsive layout and typography without a UI framework
PagefindBrowser-side search over built static pages
Cloudflare Workers static assets + WranglerPublish the website and its exports; this deployment has no hosted memory backend
Miniflare/workerdLocal Worker preview and behavior checks
Git + GitHub ActionsSource history, review and separate core/site/packaging checks
rustfmt, Clippy, Rust testsFormatting, static diagnostics and storage/API invariant verification
Python unittest, fake clocks and isolated real-node smokeFocused controller risks, transports, permissions and restart behavior
Prettier, Astro check, TypeScript and export verificationSite style, types, routes, assets and internal links
Optional evaluation environmentDataset retrieval and model QA, with a spending ledger and separate dependencies; it is outside the memory service

Website publication and evaluation policy describe their separate validation boundaries. A retrieval score, model test, server restart and deployed page establish different things.

Small exercises that teach the design

  1. Read the transaction that updates a memory and explain how it removes old search postings. Then trace a quota failure without changing engine code.
  2. Save a preference, submit an older contradiction, then correct the current value with its inspected revision. Explain each receipt.
  3. Retry the same proposal. Change its payload while keeping its source ID. Explain why one is accepted and the other rejected.
  4. Forget a fact, restart, and retry its old proposal. Inspect the tombstone and explain why native TTL would make this unsafe.
  5. Start a fresh OpenCode session and inspect the actual tool calls. Distinguish retrieved memory from anything the model guessed.

Use temporary state for these exercises. The controller guide provides runnable commands and an isolated smoke scenario.