Client-owned vaults for memories, private files, and credentials. Start on your device; connect other devices and AI tools when you choose.由你持有的保险库,保存记忆、私人文件和凭据。从本机开始,再按需连接其他设备与 AI 工具。
A conceptual view of a vault, not an app screenshot.保险库概念示意,非应用截图。
01 /Keep data on your device数据保存在自己的设备上
02 /Choose what to connect按需选择连接方式
03 /Grant access explicitly明确授权后再访问
A useful, private foundation实用的私人数据基础
One vault system. More ways to use it.一套保险库, 多种使用方式。
Shared Rust foundations across the command line and mobile clients. Optional services extend how you connect, not who owns your data.命令行与移动客户端共用 Rust 核心。可选服务拓展连接方式,数据仍由你持有。
01
Local vaults & encryption本机保险库与加密
Store memories, knowledge cards, private files, and credentials with local encryption. Read, search, and follow revision history; explicitly private content stays out of ordinary search.记忆、知识卡片、私人文件与凭据在本机加密保存。支持读取、搜索和版本历史;显式标记为私有的内容不进入普通搜索。
Your data, your device自己的数据,自己的设备02
CLI & local daemon命令行与本机守护进程
Use the memories Rust CLI through a local daemon: a Windows named pipe or a Linux/macOS Unix socket, restricted to the current OS user.Rust 命令行 memories 通过本机守护进程工作:Windows 使用命名管道,Linux/macOS 使用 Unix socket,仅限当前操作系统用户。
Local IPC本机进程间通信03
Optional remote daemon可选远程守护进程
Connect through token-authenticated HTTP/WebSocket or relay RPC when needed. Remote access uses the service protocol and remains subject to unlock and elevation checks.按需通过令牌认证的 HTTP/WebSocket 或中继 RPC 连接。远程访问使用相同的服务协议,仍需经过解锁与提权检查。
Centers issue device enrollment and scoped MCP grant tickets. They can disable local self-bootstrap; they provide authorization policy, not vault key escrow.授权中心签发设备注册票据和限定范围的 MCP 授权票据,也可禁止本机自行初始化。它负责授权策略,而不是托管保险库密钥。
Android/iOS clients call the shared Rust service through memories_ffi. A local MCP server and AI skill injection bring authorized ordinary memories and cards into your AI workflow, without returning stored credential values.Android/iOS 客户端通过 memories_ffi 调用共用的 Rust 服务。本机 MCP 服务与 AI skill 注入,让 AI 工作流访问获授权的普通记忆和卡片,不返回已保存的凭据值。
Android / iOS / MCP06
Device pairing & transfer设备配对与保险库传输
Pair devices with invitations, fingerprint checks, and approval. Transfer encrypted vaults by file or a WebSocket relay. Online transfer is explicit and whole-vault, not automatic incremental sync.通过邀请、指纹核对与批准完成设备配对。加密保险库可经文件或 WebSocket 中继传输;在线传输需明确发起,采用整库传输,并非自动增量同步。
Explicit connections明确建立连接
Living context持续更新的上下文
World: a persona’s life in the present.World(世界): 人格的当下状态。
Persona cards hold an identity core, linked archives, and behavior events. World adds a live snapshot of the persona’s surroundings and daily state in profile.world, separate from the core SKILL voice and rules.人格卡片保存身份核心、关联档案和行为事件。World(世界)将场景与日常状态记录为 profile.world 中可持续更新的快照,不混入核心 SKILL 的语气与行为规则。
01
Scene场景
Keep the current place, pose, appearance, and body notes together. A room, a change of clothes, or a moment of rest becomes context the next interaction can use.集中记录当前地点、姿态、装扮和身体状态。所在房间、换上的衣服,或片刻休息,都能成为下一次互动的上下文。
02
Things物品
Give any item a name, description, images, and flexible JSON attributes. A cup, a table, or a wardrobe item can carry the details that matter, without a fixed attribute template.为任意物品记录名称、描述、图片和自由定义的 JSON 属性。杯子、桌子或衣物都能保存需要的细节,不受固定属性模板限制。
03
Ledger日常账本
Track counters, meals, pending and completed orders, and standing arrangements. Keep today’s activity distinct from cumulative totals and what remains in place across days.记录计数、餐食、待办与已完成的指令,以及常设安排。将今日活动与累计记录、跨日保留的状态区分开来。
04
Tools工具
Dice, spinners, and schedules support choices and daily routines. Keep these practical tools alongside the world state, rather than weaving them into personality instructions.骰子、转盘和日程支持随机选择与日常安排。这些实用工具与世界状态放在一起,无需写进人格的核心指令。
05
Weather & forecast天气与预报
Record conditions, temperature, humidity, wind, and an optional forecast. Agents can fetch weather externally and update the snapshot; World does not fetch live weather on its own.记录天气状况、温度、湿度、风况及可选的预报。智能体可从外部获取天气后更新快照;World 本身不会自动获取实时天气。
06
Automation hooks自动化钩子
Define actions for schedules, random intervals, webhooks, or item attribute changes. Agents check timed hooks; the vault does not run a background timer of its own.为日程、随机间隔、Webhook 或物品属性变化设置触发动作。定时钩子由智能体检查,保险库本身不运行后台计时器。
How it fits together各部分如何协作
Local at the core. Connected by choice.以本机为核心, 按需连接。
Start with a local vault. Add a relay, remote endpoint, or authorization Center only if your workflow calls for it.从本机保险库开始。只有在工作流需要时,才添加中继、远程端点或授权中心。
01 / Your tools01 / 你的工具
CLI, mobile, AI命令行、手机、AI
Desktop CLI and MCP use the local daemon. Mobile uses the shared Rust core through FFI.桌面 CLI 与 MCP 使用本机守护进程;移动端通过 FFI 使用共用的 Rust 核心。
memories · memories_ffi→02 / On your device02 / 在你的设备上
Encrypted vaults加密保险库
Local storage, keys, and authorization checks. The local daemon serves the current OS user.本机存储、密钥与授权检查。本机守护进程仅服务当前操作系统用户。
Local is the starting point从本机开始⇢03 / Optional connections03 / 可选连接
These are separate optional services, not a required chain. The stateless memories-relay does not store assets or queue transfers for offline devices.这些是独立的可选服务,不是必须依次经过的链路。无状态的 memories-relay 不存储资产,也不为离线设备排队传输。
A small beginning从简单的一步开始
Your first local vault.创建第一个本机保险库。
You’ll need Rust 1.88+ and a platform C toolchain for bundled SQLite. These examples follow the repository README.需要 Rust 1.88+ 和平台 C 工具链,用于编译随附的 SQLite。以下示例来自仓库 README。
01
Install from source从源码安装
Clone the repository and install the Rust CLI from its root directory.克隆仓库,在仓库根目录安装 Rust 命令行程序。
Terminal终端01
git clone https://github.com/mbcc2006/memories.git
cd memories
cargo install --path crates/cli --locked
02
Start the local daemon启动本机守护进程
Keep this running in a separate terminal. Use a new, dedicated data directory: --home restricts its permissions. Never use an existing general-purpose folder.在单独的终端中保持运行。使用新的专用数据目录:--home 会限制目录权限,切勿指向已有的通用文件夹。
Terminal A · keep running终端 A · 保持运行02
memories --home ./memories-demo daemon
03
Create, write, search创建、写入、搜索
Open another terminal in the same directory. Replace VAULT_ID with the ID returned by vault creation, and create a notes.md file before importing it.在相同目录打开另一个终端。将 VAULT_ID 替换为创建保险库时返回的 ID,并在导入前准备好 notes.md 文件。
Packages are served from r2.ivjn.us. Verify the SHA-256 checksum before you run anything. macOS builds are Apple silicon (arm64) only for now.包托管在 r2.ivjn.us。运行前请先核对 SHA-256。macOS 目前仅提供 Apple 芯片(arm64)版本。
Linux v0.1.4 includes TLS client flags (--insecure / --ca-file). Windows/macOS cards below may still point at older v0.1.3 archives until those packages are rebuilt. Check each package's BUILD-INFO.json commit rather than relying on the version label alone.Linux v0.1.4 已包含 TLS 客户端参数(--insecure / --ca-file)。下方 Windows/macOS 卡片在对应包重建前可能仍指向较旧的 v0.1.3。请核对各包 BUILD-INFO.json 中的提交,不要仅凭版本号判断功能。
Linux x86_64
v0.1.4
GNU/Linux archive (~41 MiB): CLI, relay, FFI, docs, example config. Includes --insecure / --ca-file.GNU/Linux 归档(约 41 MiB):CLI、中继、FFI、文档与示例配置。含 --insecure / --ca-file。
Memories, private files, credentials, and private key material are encrypted in the local store. Keys stay on user devices. Public device keys and fingerprints are intentionally visible. Once unlocked, authorized clients can access permitted content; local encryption is not protection against a compromised endpoint.记忆、私人文件、凭据与私钥材料在本机存储中加密,密钥留在用户设备上。设备公钥与安全指纹有意保持可见。解锁后,获授权的客户端可以访问权限范围内的内容;本机加密不保护已被攻陷的设备。
What can the relay see?中继能看到什么?+
Vault peer sync (/v1/channel) is encrypted end-to-end: the relay sees ciphertext and traffic metadata, not asset plaintext. Remote daemon Relay RPC is different: its authenticated JSON is not end-to-end encrypted, so the relay operator or TLS terminator can read the shared listen token and request/response payloads. Use a trusted relay for RPC. The shipped relay stores no assets or offline queues, but an operator could record traffic or block connections. Verify device fingerprints for peer sync.保险库设备间同步(/v1/channel)采用端到端加密:中继能看到密文和流量元数据,而非资产明文。远程守护进程的 Relay RPC 则不同:其经认证的 JSON 并非端到端加密,中继运营者或 TLS 终止端可以读取共享监听令牌及请求/响应内容。RPC 应使用可信中继。随附的中继不存储资产或离线队列,但运营者仍可记录流量或阻断连接;设备间同步仍需核对设备指纹。
Do I need a relay or a Center?必须使用中继或授权中心吗?+
No. A local vault and daemon are enough to begin. A relay supports online encrypted device transfer, a remote daemon offers token-authenticated access, and a Center issues enrollment and MCP grant tickets. Each is optional and serves a different purpose.不需要。本机保险库与守护进程即可开始使用。中继用于设备间在线加密传输,远程守护进程提供令牌认证访问,授权中心签发设备注册与 MCP 授权票据。它们各有用途,均为可选。
Can AI tools read my credentials?AI 工具能读取我的凭据吗?+
Ordinary MCP access is limited by explicit vault grants. It can work with authorized ordinary memories and cards, but does not return stored credential values or explicitly private content, and cannot inherit terminal elevation. The separately enrolled mcp serve-unattended mode deliberately can return credential plaintext, private content and files from its selected vaults when requested. Enable it only for trusted clients after explicit consent. Skill injection does not change either mode's access boundaries.普通 MCP 访问受明确的保险库授权限制,可处理获授权的普通记忆和卡片,但不返回已保存的凭据值或显式标记为私有的内容,也不继承终端提权。另行注册的 mcp serve-unattended 模式则刻意允许按请求返回所选保险库中的凭据明文、私有内容和文件;仅在明确同意后为可信客户端启用。Skill 注入不会改变两种模式的访问边界。
What is the project’s development status?项目目前处于什么阶段?+
This is a development release using storage format v1, with executable code and security regression tests. It has not undergone an independent cryptographic or application security review. See the security notes for its guarantees and current limits.这是使用 v1 存储格式的开发版,包含可执行代码与安全回归测试,尚未经过独立的密码学审查或应用安全审计。具体保证与当前限制请参阅安全说明。
Begin with what’s yours从自己的数据开始
Make room for your memories.给自己的记忆留个位置。
Explore the code, read the guides, and try a local vault.了解源码,阅读指南,试用本机保险库。