The durable record is a Markdown wiki, not a raw transcript
ai-memory captures bounded lifecycle observations from coding agents, then turns relevant events into project pages and a handoff for the next session. Markdown files live in a Git repository, so humans can inspect them with an editor, grep, or Git history. SQLite provides FTS5 search and operational state. Embeddings and an LLM are optional rather than required for the basic service.
That design fits work that starts in Claude Code and continues in Codex. The handoff can preserve architecture choices, rejected attempts, open questions, and the next action without copying a full transcript into every prompt. An optional managed launcher maintains a visible event ledger and resumes each harness's native session. Direct launches can keep the lighter lifecycle-hook route.
The README draws an important line between memory and source truth. Historical pages are for rationale, procedures, and past failures. Agents should verify code claims against the current checkout, build, tests, and runtime. A well-written summary can become stale, and retrieval rank does not grant a remembered instruction authority over the repository.
Client support varies by hook and handoff behavior
The support matrix is unusually specific. Claude Code has MCP plus lifecycle hooks and can opt into session-aware scope. Codex also has hooks, but it lacks an automatic true session-end event, so ai-memory finalize-session is needed when a final handoff matters. VS Code Copilot and Zed are MCP-only. Some clients capture events but cannot receive handoff text through session-start output.
Managed workstreams cover several named harnesses, including Claude Code, Codex, OpenCode, Pi, Kimi Code, Command Code, and Kiro CLI. Each has different native session storage and event contracts. Installing one MCP server does not give every client equal capture or resume behavior. Check the exact matrix row, then test the first prompt, tool events, compaction, and final handoff for the client version you use.
What happened when we ran it
Our sandbox installed 368 Rust packages in 38 seconds and completed the build in 238 seconds. The checkout at commit b9b687b held 563 files, about 194,494 lines of source, and 12.1 MB before dependencies. It contained 5 CI workflow files and a tests directory, with no Dockerfile. The environment was an unprivileged rust:1-bookworm container with 3 CPUs and 12 GB of RAM.
Tests ran for 297 seconds and reported 764 passed with 3 failed out of 767. All three failures came from the CLI packaging test target. The log names two hook-installer cases and one wrapper self-upgrade case. During the wrapper test, the output said its checksum did not match and the update was refused, then the wrapper attempted to pull the latest image and reported docker: command not found. Cargo exited with code 101.
The log tail does not show why the other 2 packaging cases failed, so assigning them the Docker explanation would be guesswork. The source build itself passed. Our result says the complete packaging suite expected something the fresh container did not supply or accept; it does not establish whether a released native archive or a normal Docker host has the same behavior.
Automatic capture creates a sensitive data store
User prompts can retain up to 16 KiB, while notifications and tool excerpts have smaller stated limits. Native hooks support path exclusions, and allowlist mode can drop every lifecycle event for repositories without an explicit marker. Those controls reduce accidental capture. They do not remove the need for a retention policy, protected backups, restricted tokens, and a review of what prompts and tool payloads contain.
Shared servers can assign operators separate tokens and optional per-user memory slots. The README is clear that slots isolate injected context rather than enforce page-level authorization. Exact wiki reads and searches remain project-wide. Separate clients or departments that must not see one another's history should use separate trust boundaries rather than relying on slots as RBAC.
Issue 387 describes another boundary: exact deletion of one session from observations, handoffs, search indexes, Git objects, spool files, and backups. The requested purge contract remains an open epic, with an implementation pull request also open. A project purge is broader than a right-to-forget request for one conversation. Do not promise precise erasure until the released command and restore path prove it.
Current platform reports affect capture, not cosmetic features
Issue 493 reports that the v1.32.1 native macOS aarch64 build created hook spool files but its drain made no network request, leaving events undelivered or consumed without storage. The reporter could send the same envelope manually and receive HTTP 202, isolating the observation to the native delivery path they tested. Missing capture is a core failure for a memory system, even when the server remains healthy.
Issue 500 reports that Windows PowerShell 5.1 sent non-ASCII JSON with incompatible encoding. ASCII prompts reached the server, while Portuguese text returned HTTP 400 and was absent from storage. Explicit UTF-8 bytes fixed the reporter's reproduction. Native Windows is already labeled experimental in the README, and this issue gives multilingual users a concrete check before relying on it.
Active releases justify a local trial, not blind trust
GitHub showed 4,839 stars and 12 combined open issues and pull requests. The repository was pushed on August 26, 2026. Release v1.32.1 shipped on August 25 with native archives for Linux, macOS, and Windows plus Docker and source-install routes. Same-day reports and pull requests show active maintenance, while the open count is not a confirmed bug total.
The project solves a real continuity problem with inspectable files and careful documentation. Its 764 passing tests and successful build support a trial. The 3 packaging failures, macOS delivery report, Windows encoding issue, and unfinished deletion contract argue for starting on one local project. Inspect captured pages, test a handoff between the actual agents, restore a backup, and decide whether the saved context is worth operating another sensitive service.

