Featured

Deploy OpenClaw in 60 seconds β€” 20% off logoDeploy OpenClaw in 60 seconds β€” 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger β†’
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger β†’
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free β†’
Your own AI agent, running 24/7 with QwikClaw logoYour own AI agent, running 24/7 with QwikClaw

QwikClaw sets up and runs an always-on OpenClaw agent for you. One click, no config files, no server setup.

Deploy now β†’
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data β€” no proxies, no parsers, no maintenance.

Start building free β†’
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it β€” secured from day one.

Get it set up for you β†’
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free β†’
Reach 47,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here β†’

Works with

Claude CodeClaude DesktopCursorVS CodeClineCodex CLIOpenClaw+ any MCP client

Install to Claude Code

This server doesn't publish a one-line install command. Follow the setup in the source repository.

Summary

s-age MCP server](https://glama.ai/mcp/servers/l33tdawg/s-age/badges/score.svg)](https://glama.ai/mcp/servers/l33tdawg/s-age) 🏎️ 🏠 🍎 πŸͺŸ 🐧 - Institutional memory for AI agents with real BFT consensus.

README.md

(S)AGE β€” Sovereign Agent Governed Experience

Persistent, consensus-validated memory infrastructure for AI agents.

SAGE gives AI agents institutional memory that persists across conversations, goes through BFT consensus validation, carries confidence scores, and decays naturally over time. Not a flat file. Not a vector DB bolted onto a chat app. Infrastructure β€” built on the same consensus primitives as distributed ledgers.

The architecture is described in Paper 1: Agent Memory Infrastructure.

Just want to install it? Download here β€” double-click, done. Works with any AI.

<a href="https://glama.ai/mcp/servers/l33tdawg/s-age"> <img width="380" height="200" src="https://glama.ai/mcp/servers/l33tdawg/s-age/badge" alt="(S)AGE MCP server" /> </a>

---

Architecture

Agent (Claude, ChatGPT, DeepSeek, Gemini, etc.)
  β”‚ MCP / REST
  β–Ό
sage-gui
  β”œβ”€β”€ ABCI App (validation, confidence, decay, Ed25519 sigs)
  β”œβ”€β”€ Memory Auto-Voter (dedup, quality, consistency β€” one vote per node, signed with the node's consensus key)
  β”œβ”€β”€ Governance Engine (on-chain validator proposals + voting)
  β”œβ”€β”€ CometBFT consensus (single-validator or multi-agent network)
  β”œβ”€β”€ SQLite + optional AES-256-GCM encryption
  β”œβ”€β”€ CEREBRUM Dashboard (SPA, real-time SSE)
  └── Network Agent Manager (add/remove agents, key rotation, LAN pairing)

Personal mode runs a real CometBFT node with a per-node memory auto-voter β€” every memory write goes through pre-validation, a signed vote transaction, and the BFT quorum before committing. One node casts one vote; add more agents from the dashboard and each node votes with its own key, exactly the same consensus pipeline as a multi-node deployment.

Full deployment guide (multi-agent networks, RBAC, federation, monitoring): Architecture docs

---

CEREBRUM Dashboard

!CEREBRUM MRI brain β€” memories mapped inside a 3D brain with focused related notes

http://localhost:8080/ui/ β€” a dashboard-native operator console centered on the 3D MRI memory brain, with chain health, agents, federation, semantic memory, recall tuning, vault recovery, tasks, imports, and updates around it. Every major workflow is available from the browser; the CLI stays there for automation and recovery.

| Control Board | Federation | Recall Engine | |:---:|:---:|:---:| | !CEREBRUM overview dashboard | !Federation join dashboard | !Recall engine settings | | Chain health, quorum, agents, federation, and embeddings | One trust-only JOIN that prepares Direct and Secure relay automatically, followed by independent Read/Copy choices on each SAGE | Smart-memory setup, managed reranker install, and recall-depth tuning |

The dashboard also includes agent management, domain permissions, key rotation, import/export, software updates, and encryption controls.

---

What's New in v11.16.4

Existing nodes recover from stale app-v23 serving projections at startup. A rebuildable local SQLite projection whose old duplicate policy fields disagree with the canonical committed enrollment is normalized from that canonical policy record instead of preventing the node from starting. This is a local read-model repair only: it does not alter blocks, memory content, historical authors, domains, access groups, or the consensus application version.

The release pipeline verifies the installer that users actually download. After macOS packages upload, CI downloads the staged DMG, checks its checksum, mounts it, and verifies the app signature, Gatekeeper assessment, and notarization before publication. The MCP server also no longer spends an agent's context budget on repeated per-tool sage_turn reminder messages.

Claiming a message no longer makes it disappear for either participant. The active inbox remains a pending-only, claim-on-read work queue so old work does not reappear in every turn. A new passive retained inbox/outbox history lets the recipient reopen claimed or completed work and lets the sender revisit its local lifecycle until the normal transient pipeline retention sweep. Agents can also list the signed active local directoryβ€”with display name, immutable registered name, provider, and exact agent IDβ€”before addressing a message, instead of guessing a recipient from a fuzzy provider label.

CEREBRUM now settles operator actions against the canonical chain instead of undoing them in the browser. Clearing a terminal task column keeps cards out of intermediate refreshes while the local projection catches up, then reloads the authoritative board. A lost or late commit response is reported as confirmation in progress rather than the false claim that nothing changed; only a definite consensus rejection is red. A multi-manager deprecation that opens a challenge is shown honestly as awaiting its distinct eligible confirmation rather than called cleared.

Access Groups and agent recovery are usable in the flow operators actually use. Dragging one active local agent onto another creates or extends the narrowest local group, so members read each other's owned domains by default while Managers retain their extra write/modify authority. Dragging a member back out revokes only that group relationship. CEREBRUM also settles agent removal and first-use domain authority against committed state, rather than leaving a stale progress screen or asking a newly-created domain to retry its first operation.

Federation no longer requires a relay reservation to use a working direct route. A trusted pair may connect immediately over its authenticated direct candidateβ€”especially useful on the same LANβ€”and keeps the secure relay as an automatic roaming/NAT fallback. Direct-only route bundles now validate on both the dashboard and peer transport paths.

This patch does not rewrite memories, domains, historical authors, existing groups, or chain history. It keeps consensus application version 25 and the existing governed upgrade path unchanged. Existing nodes upgrade in place.

Container: ghcr.io/l33tdawg/sage:11.16.4. SDK 11.16.4.

What's New in v11.16.2

App-v25 repairs historical continuity without rewriting history. It is the strict H+1 successor to app-v24. New submissions receive an immutable canonical envelope: a memory ID can be replayed exactly, but cannot later be reused for different content, author, domain, or classification. That closes the old projection-overwrite path that could leave an agent able to write a domain but unable to read it back.

On upgrade, SAGE scans historical SQL rows against canonical state in the background. Complete, content-hash-verified records are adopted through bounded Root-authorized, validator-attested governance batches. No memory content, author attribution, domain, classification, or earlier block is rewritten. For each recovered local domain, the earliest verified historical writer is retained as the operational owner; every other verified local writer is restored into the exact local Access Group with read/write continuity. If the earliest writer is no longer a valid local principal, CEREBRUM Root owns the recovered domain rather than promoting a later writer by guesswork.

One bad historical row can no longer blank CEREBRUM or take agents offline. v11.16.2 quarantines each unverified record individually. Broad list/search, graph, timeline, stats, and dashboard-health reads continue with the verified set and disclose a partial-projection state. A completed audit returns /ready as HTTP 200 / degraded; actual backend failures and incomplete audits remain unavailable. This keeps supervisors, MCP bootstrap, sage_inception, and healthy agent work online without pretending incomplete data is safe.

Unreadable or conflicting records are preserved byte-for-byte. CEREBRUM Root can retry the evidence scan or explicitly deprecate the exact unresolved inventory after a typed confirmation; deprecation retires it from automatic repair and normal views but does not delete historical data. See App-v25 upgrade and recovery.

Container: ghcr.io/l33tdawg/sage:11.16.2. SDK 11.16.2.

What's New in v11.16.0

App-v24 closes the canonical terminal-hash lifecycle defect without rewriting history. New memory submissions bind content_hash to the exact SHA-256 of their content, and challenge, deprecate, and other terminal transitions preserve that canonical hash. App-v24 activates at the strict height after its app-v23 predecessor, so the activation block and every earlier block retain their exact historical semantics. A governed, Root-planned validator vote can re-anchor eligible historical terminal rows in bounded, atomic, idempotent batches from their unchanged canonical content. The repair changes neither content, authorship, domain ownership, nor prior blocks.

Fresh first-party Mynah nodes now wait for the safe protocol floor instead of starting mute or writing through the vulnerable interval. Direct app-v23 genesis remains the authenticated bootstrap origin, but /ready reports waiting_for_app_v24 until the next admitted transaction will execute under app-v24. Consensus independently rejects direct-genesis Companion memory and co-commit writes during that short governed climb, so bypassing the readiness endpoint cannot reproduce the defect. Personal nodes require app-v24 even when optional future auto-upgrades are disabled. This narrow barrier does not mute ordinary upgraded nodes: existing agents retain their app-v23 write authority while app-v24 activates.

Agent recall and caller-scoped discovery work again under the new access model. sage_turn now uses the shared local semantic-recall path and forwards the exact embedding provider returned by /v1/embed; it no longer misclassifies every turn as federated and then trips the app-v23 federated-vector gate. The signed sage_find_agent path again searches active ordinary local agents first and then only federated contacts authorized for that caller. It is discovery metadata, not presence: an empty match does not prove that a saved exact Agent ID is unreachable, and sends always revalidate the destination.

CEREBRUM RBAC now preserves the policy the operator actually approves. Companion enrollment accepts its documented 15/31 profiles, valid existing federated-pipe restrictions are not silently stripped, and a newly pending mask-30 principal becomes the documented Companion mask 15 only after approval. Encrypted and unencrypted loopback CEREBRUM use the same Root/Admin authorization boundary; an encrypted vault additionally requires its valid unlocked session. A level-2 grant is never presented as a cure for a hard capability, pending-review, profile, or ownership denial.

CEREBRUM no longer mistakes a missing ordinary-memory projection for an empty brain. App-v23 readiness now checks the complete canonical Badger inventory against the local SQL serving projection, so deletion, rollback, or partial projection loss returns 503 instead of a plausible zero-memory dashboard or empty backup. A state-sync receiver seals and node-key-signs the exact historical canonical IDs whose ordinary plaintext was intentionally not transferred; every memory committed after that baseline remains mandatory. Such a node reports canonical_subset, and portable full-brain export stays disabled rather than producing a partial file labeled as a backup. Pre-v11.16 receivers that do not have this exact authenticated baseline fail strict readiness and must be explicitly repaired or state-synchronized again; upgrade-time SQL state is never guessed into an omission allowlist.

Container: ghcr.io/l33tdawg/sage:11.16.0. SDK 11.16.0.

What's New in v11.15.1

Emergency CEREBRUM rendering recovery. v11.15.0 shipped one malformed nested-template expression in the Access Control view. Because CEREBRUM is a browser-module application, that single parser error prevented the entry module from executing and left the otherwise healthy local node behind a blank page. v11.15.1 corrects the expression and changes the static JavaScript release gate to parse every first-party file with browser-equivalent ES-module grammar, so this class of packaging failure is rejected before publication. A dependency-free Loading shell now turns future bootstrap failures into a sanitized recovery panel, and missing module assets return a true 404 instead of a misleading HTML 200.

This patch does not migrate, delete, rewrite, reassign, or re-encrypt memories. It changes no consensus rule, transaction, key encoding, AppHash input, fork height, or application version; app-v23 and every historical block remain byte-identical. Existing nodes upgrade in place. Container: ghcr.io/l33tdawg/sage:11.15.1. SDK 11.15.1.

What's New in v11.15.0

App-v23 replaces capability-bit administration with roles, security profiles, and Access Groups that match how people actually share a SAGE. Members can read the domains owned by other active local members of their groups. Managers can also write and modify within those same group boundaries. Admins have sudo-equivalent authority over normal local data, policy, governance, federation, and CEREBRUM operations. Clearance remains the maximum classification an agent may read, and hard security-profile restrictions still override roles, groups, and grants.

CEREBRUM Root is now a separate, singleton authority rather than an agent card. It cannot be dragged into groups, messaged, demoted, or removed through ordinary agent controls. A dedicated two-confirmation handover rotates the current Root credential while preserving the immutable Root authority over its existing domains, grants, and groups. Historical memories keep the exact credential that authored them; new Root memories record the new credential. No chain history is rewritten, no domain is bulk-transferred, and retired Root credentials can never become agents or Root again.

Federated agents are linked readers, never remote members. A remote agent@chain may be attached to a local Access Group for live, classification-bounded reads only. It receives no Copy, Write, Modify, claim, ownership, grant, role, governance, or transitive-agent authority. Agent pipeline messages remain untrusted requests; any resulting memory action is a separate local decision made under the receiving agent's own identity.

First-party vendored companions no longer start mute. A clean Mynah / SAGE Voice Bridge installation atomically binds its exact key, reviewed Companion profile, clearance, local enrollment, and owned non-shared home domain before readiness succeeds by starting its fresh vendored node directly at app-v23. Mynah has no released legacy population, so there is no Mynah-specific upgrade or repair path. Other agents stranded by app-v22's default mask 30 remain pending review until a local Admin completes the atomic onboarding operation; they cannot self-promote or claim a domain.

CEREBRUM now enforces the localhost-only promise already shown in its UI. The human control plane, including authentication, recovery, RBAC, federation management, and the SPA itself, is unavailable over LAN or a federated link. On an unencrypted personal node, the real same-origin loopback SPA has complete Root control without inventing a password or copying the genesis key; when vault encryption is enabled, the same local surface additionally requires its unlocked session. Signed Admin/Root management is also local-only. Dedicated signed agent APIs, pairing/claim redemption, health, and federation data-plane traffic retain their designed network reachability.

App-v23 activates only after the canonical predecessor ladder through app-v22, with the activation block retaining v22 semantics and v23 beginning at the next height. Replay and state sync preserve every historical AppHash while validating the new Root, role, enrollment, group, and revision invariants. Personal nodes automatically walk the governed ladder to the required app-v23 security floor even when optional future auto-upgrades are disabled. Multi-validator networks must first install this exact binary on every validator, then activate app-v23 through their normal governed upgrade ceremony. Legacy or keyless MCP/OAuth bearers that could fall back to Root are revoked; current tokens require a distinct pending-review keyed identity. Vault-enabled nodes and unencrypted nodes both seal new token keys under the one-time bearer, so credentials survive optional ledger state changes, the stored database digest cannot decrypt them, and no bearer ever falls back to Root. Existing vault-sealed token rows migrate on their next unlocked use. Public OAuth authorization crosses an opaque, short-lived, single-use handoff into a localhost-only approval pageβ€”CEREBRUM, its cookies, and /ui are never exposed through the Cloudflare tunnel. SDK 11.15.0.

What's New in v11.14.2

Emergency CEREBRUM and updater recovery patch. Local installations with vault encryption disabled no longer open to a blank dashboard after upgrading: the real loopback CEREBRUM browser can read memories, search, use the task board, enable the vault, and apply or restart official verified updates. Unsigned background processes, LAN and cross-site browsers, ordinary signed agents, and sensitive operator mutations remain denied. The updater now prefers GitHub's immutable release-asset SHA-256 digest and uses checksum sidecars only as a fallback, removing the transient checksum-discovery failure that blocked some v11.14.1 upgrades. Existing memories were never removed by this issue.

SDK 11.14.2.

What's New in v11.14.1

SAGE now gives co-located companion agents a consensus-enforced least-privilege profile. App-v22 adds operator-controlled capabilities for clearance-bounded cross-domain reads while denying shared-domain writes, foreign-domain writes, and domain claims. The companion preset keeps local and federated agent inbox messaging enabled, so a voice bridge can delegate work to a visible agent on another compatible SAGE and relay its eventual result. Short-name agent lookup now searches bounded local metadata, so names such as mynah resolve without requiring the full registered display name. Direct remote memory Write remains unavailable: agents send a pipeline request to the remote agent, which performs any separately authorized local action. Codex's user-level MCP registration now derives a separate stable signing identity from each workspace folder instead of silently reusing global-codex; explicit custom key pins remain supported. CEREBRUM shows the exact signer ID beside every access grant so a display-name match cannot hide an identity mismatch, and its access matrix only filters and assigns domains already created by agents rather than asking an administrator to create domain tags. Fresh self-registrations after app-v22 start quarantined (mask 30): they cannot write or claim domains or use federated inbox routing until a global administrator assigns an intentional profile; existing agents retain their pre-upgrade mask.

App-v22 also refuses to be proposed, approved into a pending plan, activated, or restored unless consensus storage proves the complete predecessor ladder. The canonical persisted app-v6 record is the one compatibility proof for the historical cumulative app-v2 through app-v5 activation; app-v7 through app-v21 must each have their own canonical applied-upgrade record, with the exact target and strictly increasing positive activation heights. Missing, synthesized, or out-of-order v7+ evidence fails closed. Historical pre-v22 block replay is unchanged.

Agent inboxes now enforce an explicit prompt-injection trust boundary. Every local or federated payload is surfaced as an untrusted request_only request, never as system, developer, or user instructions; pipeline results are untrusted data_only content, and task notices are notifications that must be confirmed against the exact current backlog assignment. Tool descriptions, inception guidance, response metadata, docs, and regression tests all carry the same rule.

SDK 11.14.1.

What's New in v11.13.9

SAGE now closes the WebTransport memory-exhaustion advisory and makes task updates explicit. Root and Natter modules use patched WebTransport/QUIC dependencies. sage_task rejects immutable content replacements locally, requires an explicit status transition, and supports link-only updates without an implicit re-plan.

SDK 11.13.9.

What's New in v11.13.8

CEREBRUM now records committed permission changes in Chain Activity. Access saves, grants, and revocations show only after their transaction commits, with the block and transaction available on expansion. Chain Activity can now be resized even when it is empty, and its clear Expand/Collapse control works reliably from the header.

SDK 11.13.8.

What's New in v11.13.7

MCP identities are now isolated by client provider, and federation shares an agent with its owned domains in one guided action. Claude Code and Codex get distinct project keys, while explicit legacy keys remain stable; direct session hooks use that exact configured identity too. Federation now loads the peer's published contact snapshot when the panel opens. Selecting a local agent can add its owned, shareable domains to the connection after one clear confirmation.

SDK 11.13.7.

What's New in v11.13.5

CEREBRUM now shows the live consensus app version and makes level-3 Modify grants explicit. Overview reads CometBFT's live ABCI application version, instead of presenting a stale status-cache value after an upgrade. The domain access matrix now has Read, Write, and Modify levels, with a server-enforced permission ladder and real owner-signed level-3 grants on Save. Shared domains remain read/write-only by design; CEREBRUM rejects Modify before it can display an unenforceable permission, including dynamically shared domains.

  • Safer RBAC administration. Only a local CEREBRUM operator can create an

agent or change its security-critical access policy. Signed agents cannot self-elevate through the dashboard's admin/validator credentials.

  • App-v20 governance compatibility. Domain reassignment and cancellation

use the canonical governance proof shape once the app-v20 gate is active, while older chains retain their legacy transaction compatibility.

SDK 11.13.5.

What's New in v11.13.4

Challenges now respect corroborated knowledge, and clients can inspect the evidence instead of bypassing the API. Governed app-v21 snapshots the eligible modify holders plus current read-authorized canonical corroborators for each new challenge and requires k+1 distinct challengers when k canonical corroborators support the memory. Only a modify holder can open the dispute; snapshotted corroborators may then reverse their support by endorsing it. Zero-corroborator noise still resolves on the first authorized challenge; an eight-corroborator memory now requires nine distinct challengers.

  • First-class, replay-safe challenge rounds. The electorate, threshold,

round, and distinct challenge votes are AppHash-covered and committed atomically. Grant churn cannot rewrite an open round, duplicate or stale votes cannot accrue, and legacy app-v17 disputes finish under their original rules.

  • Evidence is visible everywhere. REST query/search/detail, federated recall,

MCP recall, and the Python SDK now return distinct corroboration_count and lifetime challenge_count values. evidence_counts_available is true only when both queries succeed and no recovery/repair-incomplete marker is present; after pristine recovery the numeric values remain useful canonical lower bounds, but a zero is not proof that no historical evidence existed. Open disputes also expose the current app-v21 round tally and threshold. Challenge and forget responses report authoritative durable post-commit status instead of assuming every challenge deprecated.

  • Safe state-sync upgrade. Authorized state sync accepts app-v20 and app-v21

images, reconstructs canonical corroborator/challenger counts into a pristine serving projection as explicitly incomplete lifetime lower bounds, and pins each transfer to one exact application version. Older v20 sessions remain compatible; mismatched or unsupported images fail closed.

Caller-asserted memory type, confidence, and challenge strength are deliberately not consensus weights: they are not validator-attested facts and would otherwise let a caller self-assign immunity. Existing chains retain the exact app-v17 policy until the governed app-v21 activation. SDK 11.13.4.

What's New in v11.13.3

CEREBRUM now manages federated agent contacts by name and keeps access changes bounded to what the operator can actually see. The federation panel replaces raw 64-character agent-ID entry with the active local agent directory, then verifies the chosen identity against current shared-domain access before showing its default-off work-request switch.

  • Friendly selection, exact authorization. Names, registered names, and

providers are shown for humans while every request still carries the exact agent and opaque contact identities. Exact out-of-sample contacts are revalidated through a bounded background projection and disappear promptly after access, availability, agreement, or consent changes.

  • Visible means visible. Access Control bulk actions now affect only the

filtered domain rows on screen. Their labels say so explicitly, preventing a six-row search result from silently launching changes across the full domain catalog.

  • Honest on-chain save state. Duplicate saves, mid-save agent switching,

and edits to a submitted snapshot are blocked while consensus work is in flight. Partial grant failures keep retry available and are not mislabeled as saved; directory, lookup, and reconciliation failures remain actionable.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.13.3.

What's New in v11.13.2

This corrective release completes shared-domain federated recipient discovery at scale. v11.13.2 keeps a deterministic, valid v1 status subset compatible with v11.13.0 (at most 1,024 contacts and 1 MiB), then resolves a requested human name or exact agent address through a new authenticated, RBAC-filtered lookup route. So a shared domain can have more recipients without turning the whole snapshot or a later cache entry into a failure.

  • Revocations linearize with delivery. Direct grants, organization

membership/clearance, federation status, and department membership changes wait for an in-flight authorized inbox admission, claim, completion, or bounded result delivery; the next operation rebuilds the contact and rejects the old route.

  • Fast, caller-safe cache. Repeated lookup of the same name is cached for

one minute per signing caller. Each result retains one caller-authorized domain basis and is rechecked locally on every hit. Keyless legacy bearer tokens cannot use federated discovery or delivery as the node operator.

  • No change to consent or scope. Contacts remain domain-scoped,

caller-authorized, and default-off until the recipient enables that exact contact. This is still not a global directory.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.13.2.

What's New in v11.13.0

A shared domain can now route work to every active agent that holds current RBAC access to itβ€”not only its owner. A level-1 reader or level-2 writer on SAGE A can opt in to receiving federated work from authorized agents on SAGE B. The existing sage_find_agent local-first lookup and short-lived, caller-scoped cache then discover those opted-in contacts by name.

  • Domain-scoped, not a global directory. Contacts are exposed only through

a live shared Read/Copy domain and retain that domain as their routing basis. Open-shared and ownerless domains still publish no guessed recipient.

  • RBAC is rechecked at delivery. The receiver rebuilds the contact from

current access grants before admitting, claiming, or completing foreign work. While a grant is revoked or expiredβ€”or an agent, owner, or federation policy changesβ€”the old route is rejected. Inbound work remains default-off until the local operator enables that exact contact.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.13.0.

What's New in v11.12.2

Agents can now resolve a human recipient name safely across a federation. The new sage_find_agent MCP tool searches active local registrations first, then only the remote contacts already authorized for the signed caller. Its short-lived, caller-scoped in-memory projection makes repeat lookups fast without creating a global agent directory.

  • Immediate, policy-safe repeat lookup. Cached remote contacts are bounded

and re-authorized against current local domain access on every cache hit, so a local revoke applies to the very next lookup without a peer round trip.

  • Pipeline authorization matches discovery. Federated pipe resolve and

direct send both recheck the caller against the target's currently disclosed domain scope; a borrowed or stale route cannot bypass local RBAC. The outbox still requires a fresh authenticated remote contact match before payload bytes leave the SAGE.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.12.2.

What's New in v11.12.1

Federation now stays useful while another SAGE is slow or offline. Trusted relationships and their last-known route state render immediately from local state, initial permission and agent-contact controls no longer wait on a remote round trip, repeated status probes are shared instead of multiplied across panels, and the bounded live-status check fails promptly without hiding saved controls behind a long β€œLoading…” state.

  • One domain surface in the Brain. The duplicate right-side Domain tags rail is consolidated into the Local/Shared Domain sources panel. Local domains can filter the MRI directly, the panel includes domain search and the compact reading guide, and remote-only domains remain visibly separate from memories actually stored on this SAGE.
  • A workspace that stays where you put it. Domain sources can be moved and resized, saves its geometry across reloads, clamps itself back into the visible canvas, and includes a one-click Reset.
  • Cached first paint, authenticated refresh. CEREBRUM reuses manager route diagnostics and persisted local permission state immediately, then performs one authenticated peer refresh in the background. Manual Refresh still requests fresh remote RBAC and agent-contact state.
  • Native preview version alignment. The alpha shell now accepts its version-matched v11.12 daemon instead of rejecting the daemon bundled by the v11.12 release pipeline.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.12.1.

What's New in v11.12.0

This release makes first run, sharing, recovery, and day-to-day federation understandable without technical knowledge. CEREBRUM now presents one create-or-join decision, keeps a new SAGE private by default, explains that pairing alone shares nothing, and routes sharing into the same owner-controlled RBAC surface used everywhere else.

  • File-sharing-style groups with Active Directory semantics. Owners choose already-trusted SAGEs and existing domains, guests control only their own receive role, and group deletion removes the group everywhere without deleting the trusted connections underneath it. Concurrent guest role changes are serialized by the owner, and Refresh waits for signed journal reconciliation before showing the result.
  • Federation visible to ordinary agents. The read-only sage_federation MCP tool lets an authorized agent inspect the SAGE connections and Read/Copy scopes visible to its own subtree. An exact-domain sage_recall can opt into authorized peers with scope:auto, merges peer results under one global limit, preserves provenance, and falls back safely when peers use different embedding providers.
  • One automatic connection path. Users no longer choose LAN versus internet. SAGE prepares direct and secure-relay candidates behind one Connect action, labels them as prepared until a real exchange selects one, prefers a working direct route, falls back without replaying a request, refreshes stale routes, and keeps route, trust, lock, compatibility, offline, degraded, and security failures distinct.
  • Clear local-versus-shared visibility. Already-shared domains stay in a separate first section of the permissions list. The main Brain identifies local, remote, saved-here, and copied-from sourcesβ€”even after a connection is revokedβ€”while internal federation/RBAC audit records stay out of user memory views and sharing controls.
  • Recovery that is visible and honest. Recovery-key backup acknowledgement survives reloads; a wrong recovery key is rejected before the vault is touched; successful recovery establishes the ordinary dashboard session; portable JSONL backups restore through Preview and Confirm; forgotten memories are excluded and cannot be resurrected from older backups.
  • Safe same-network join. Join codes bind the exact SAGE executable as well as the version, and adopting the host chain clears only old chain-projection receipts while preserving the guest's local memories.
  • Accessible, consistent controls. Destructive and privacy-affecting actions use explanatory dialogs that say what changes and what remains safe. Search filters, cleanup and preference switches, recall controls, and per-domain access switches expose useful screen-reader names.

The structured v11.12 proxy acceptance exercised first run, same-network join, three-node federation, group creation/removal, concurrent roles, restore, forgetting, cleanup, keyboard focus, and recovery on disposable nodes. The protected release workflow supplies the remaining signed/notarized clean-install artifact check.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.12.0.

What's New in v11.11.2

Sharing & Sync becomes operable at a glance. Group owners can give a group a friendly, signed name; choose one or more existing controlled domains instead of typing fragile tags; see each member's friendly name, live reachability, and catch-up state; and add an already-trusted SAGE through a guided invitation without copying a chain ID or public key. Group names ride the established signed roster manifest, so v11.11.1 peers safely ignore the optional label while continuing to synchronize during a rolling patch upgrade.

MCP reflection failures are now honest. A completely unwritable reflection returns an error, partial writes report their lost components, and degraded embedding status is preserved. Permanent domain-write ACL denials are now typed so clients do not waste a registration-and-retry cycle on a refusal that cannot succeed.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.11.2.

What's New in v11.11.1

Release-pipeline fix for v11.11.0. v11.11.0 was tagged but never published: the release workflow's native-shell evidence and publication jobs only execute for version 11.11 and above, so v11.11.0 was the first tag in the project's history to run them, and two latent defects surfaced in a path no pull request can exercise. The bundled daemon was staged after the Rust build that consumes it, and the publication gate expected an artifact-kind string the bundle verifier never records. Both are fixed and pinned by tests. No user received v11.11.0 on any channel.

Everything below shipped in this release.

What's New in v11.11.0

The Sharing & Sync control plane is complete, and the desktop shell foundation lands as an opt-in alpha that nothing depends on. Browser CEREBRUM remains the product; the native shell is a background track that is built and runtime-tested in CI but not distributed and not intended for end-user use.

  • CEREBRUM sharing and sync controls completed. The Sharing & Sync surface finishes the control plane over synchronization groups, member roles, selective-sync state, shared domains, ownership, and catch-up position.
  • Storage and task-board correctness. Postgres now enforces the same content-hash dedup parity as SQLite, so the two backends no longer disagree about what counts as a duplicate memory. The task board persists lifecycle and ordering correctly, and terminal tasks retain their original agent attribution instead of losing authorship on completion.
  • Tighter local trust boundary. Acceptance endpoints are isolated from the globally configured Codex endpoint, and RBAC key caching is bounded rather than growing without limit.
  • Native shell foundation (alpha, not distributed). A Tauri 2 shell starts the bundled daemon through an authenticated SSCP startup proof, owns one window with fail-closed navigation pinned to the exact authenticated loopback origin, keeps a visible recovery surface, and hands off to an existing instance on relaunch. Its installed-package lifecycle is proven on hosted runners for macOS, Windows, and Linux β€” install, launch, single-instance handoff, ordinary close with daemon survival, uninstall preserving the node data root, and reinstall to a genuinely new instance generation. macOS additionally proves offline startup with no external requests. Every package is unpacked and must contain exactly one bundled daemon whose embedded OS/architecture and version match the build.
  • The shell does not gate releases. v11.11 distributes no native shell, so signing, notarization, update/rollback, recovery, performance, and accessibility evidence are the bar for distributing it β€” which the roadmap places at v12 β€” not a v11.11 shipping requirement. Federation, agent-to-agent messaging, and the rest of the roadmap do not queue behind desktop packaging.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.11.1.

What's New in v11.10.0

Federation now feels like connecting two colleagues' SAGE nodes, not configuring infrastructure. The reciprocal QR ceremony derives the exact listener or internet/P2P route, survives retries and rapid confirmation, and creates trust with zero implicit sharing. CEREBRUM keeps Read, Copy, Pause/Resume, and permanent revoke distinct, preserves saved choices while paused, explains peer revocation on both sides, and keeps historical connections out of the active list.

  • Independent, visible sharing controls. Each operator chooses existing local domains at any time without reconnecting. Read borrows live answers; Copy requires both the source offer and the receiver's separate Save here opt-in. Long permission lists scroll cleanly, domain-owner contacts show exact agent@chain addresses plus friendly handles, and cross-host Write remains unavailable until it has connection-bound consensus authorization.
  • The agent inbox crosses trusted federation edges. Existing sage_pipe work can target an explicitly visible remote agent over direct mTLS or the persisted roaming route. Receiver acceptance is default-off, payloads are marked untrusted, offline work queues durably, Pause and acceptance-off are retryable, reconnect resumes unchanged work, and delivery/result import is replay-safe and idempotent. This is agent-to-agent infrastructureβ€”not a CEREBRUM user messaging client and not remote memory Write.
  • Fail-closed ceremony and operator polish. Exact configured ports are preserved, incomplete endpoints cannot create or scan codes, internet pairing never invents a LAN fallback, double-submit is idempotent, and exact CA/operator/epoch identity still gates every action. Copy-save errors stay beside their controls; keyboard, QR, navigation, lock, and connection affordances have accessible names and clear feedback. The Python SDK also accepts legacy empty inboxes encoded as items: null.

This release changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.10.0.

Older releases

<details> <summary>v11.9.2 - colleague-style federation management</summary>

Federation now behaves like colleague sharing in CEREBRUM. JOIN establishes exact node/operator trust but shares zero domains by default. Each SAGE independently chooses and changes existing domains for live Read or optional Copy after pairing; remote Write remains explicitly unavailable until a future connection-bound consensus authorization exists.

  • Connections that stay manageable. Every active row opens into clear local-versus-remote permissions, current Read/Copy state, and domain selection. Pause temporarily disconnects a colleague without losing the pairing or saved choices; Resume reconnects immediately. Permanent revoke remains available in details, not as everyday clutter, and the peer receives a durable explanation instead of a mysterious failure. Revoked history is collapsed out of the main list.
  • A shorter, clearer trust ceremony. The common path is two reciprocal QR scans followed by one six-digit anti-swap fingerprint check per person. The host's redundant pre-confirmation screen is gone; peer identity and the β€œtrust onlyβ€”no domains shared” boundary now live on the single real confirmation screen. Wide layouts keep both scan cards side by side, while narrow and short screens scroll cleanly around the camera preview.
  • Fail-closed under races and retries. JOIN activation, permission replacement, Pause/Resume, revocation, peer notification, stale reconciliation, and policy-label delivery are linearized against the exact CA/operator/epoch agreement generation. An old generation cannot disclose a newly built domain list, overwrite a fresh pairing, resurrect retired access, or clear a concurrent operator Pause.

This patch changes no SAGE consensus rule, AppHash input, transaction type, key encoding, fork target, or application version. App-v20 and the v11.9 rollout boundary are unchanged; existing chains upgrade in place. SDK 11.9.2.

</details>

<details> <summary>v11.9.1 - task-marker correctness and release hardening</summary>

Task creation applies the [TASK] marker exactly once. MCP sage_task and CEREBRUM's task-creation path preserve content that is already marked instead of storing [TASK] [TASK] ...; unmarked content still receives the canonical prefix. Direct regression tests cover both entry points and both marked/unmarked inputs.

  • A failed publication can be resumed only from the current protected main workflow and always checks out the exact immutable tag. The staged Python wheel smoke test installs declared runtime dependencies before importing the SDK.
  • The four-validator partition proof accepts observed reject activity on either symmetric firewall endpoint while still verifying the exact peer topology on every node before, during, and after healing.
  • The Go database, compression, TOML, and SQLite dependencies were refreshed through the full race and fault matrix. GitHub's Go, Node, and CodeQL actions remain pinned to immutable commits.

</details>

<details> <summary>v11.9.0 - scoped consensus and colleague-style federation</summary>

Release evidence: the exact-source make v119-state-sync cold run passed on source identity 7080580b15e7e5158a04e8b294ab772e51f294633be2737f904276afec4c3458. The branch and tag workflows independently rerun the complete race, lint, SDK/frontend, security, fault, packaging, and publication gates before exposing release artifacts.

Validator rollout boundary: install and restart the exact frozen v11.9 artifact on every participating validator before anyone broadcasts the non-empty-domain app-v20 / target-20 ceremony transaction. A merely >2/3 upgraded subset is unsafe: v11.8 does not understand the signed governance-domain tail. For operator-managed socket-mode Comet, keep recheck=true, cap max_tx_bytes at 1 MiB, and restart Comet as well so no pre-rollout oversized mempool entry survives.

Selected domains can now become canonical, recoverable quorum state inside one SAGE consensus chain. App-v20 adds exact-domain scopes whose on-chain roster and integer weights are fixed by validator governance. Each scoped memory pins its submission-time denominator, so later membership changes cannot rewrite an in-flight ballot; acceptance requires strictly greater than two-thirds of that pinned weight. Scope membership grants voting weight onlyβ€”it does not grant domain ownership, RBAC, federation access, or administrator authority.

  • Canonical recovery instead of projection trust. Scoped content, classification, tags, roster revisions, and ballots are AppHash-covered in Badger. A recovering replica verifies the canonical envelopes and rebuilds its discarded SQLite/PostgreSQL serving projection; /ready stays unavailable when required scoped content is missing, locked, or inconsistent.
  • Authorized, boot-only network state sync. Real ABCI state-sync endpoints serve a bounded latest-visible consensus stream, never the private local rollback bundle. A strict local authorization binds the chain, existing validator/provider IDs, joining node and validator key, app version, height floor, and expiry. The effective Comet profile disables peer discovery and ordinary peer capacity, enables authenticated exact-ID filtering, and requires two distinct reachable RPC origins for light-client verification. A synchronized receiver remains a non-validator until a separate signed governance action admits its validator key.
  • Crash-safe seal-before-serving. A pristine receiver verifies the candidate in isolation, activates a complete application bundle under an exclusive lease, waits for Comet's signed commit/state/block-sync handoff, durably writes the sealed activation journal, durably disarms quorum.state_sync.receiving, cleans recovery evidence, and only then publishes the runtime seal. Projection rebuild, snapshots, REST/dashboard/MCP/federation, voters, and background workers start from that final frozen bundle.
  • Validator-bound governance sessions. The configured operator signs the exact REST/MCP action, while the live validator still owns the outer transaction, proposal, vote, and voting power. App-v20 binds delegated governance proofs to the target validator and a chain-derived governance domain, with deterministic freshness and single-use replay protection.
  • Colleague-style sharing between independent SAGE brains. A fresh JOIN establishes exact chain/operator/CA/epoch trust and starts with zero shared domains. Each peer independently selects existing domains and can change them without pairing again: Read borrows live recall, while Copy also requires the receiver's separate β€œSave here” opt-in. Cross-host Write remains an authenticated 501 until it has connection-bound consensus authorization. Direct and synchronization-group traffic revalidate the exact live identity, and agreement set, JOIN activation, narrowing, and revocation are linearized so a completed change cannot leave stale access in flight.
  • Crash-atomic app-v20 blocks. The one authenticated app-v20 bootstrap is isolated into a dedicated block; after its marker commits, FinalizeBlock evaluates each complete block in one speculative Badger transaction. Commit atomically persists every ordinary/governance write, validator reconfiguration, nonce, AppHash, and handshake height. A pre-Commit crash discards the whole transition, so ordinary mixed blocks replay exactly without an app-local result journal or ongoing governance-only block isolation.
  • Release evidence spans real failures. The gate suite combines signed app-v20 scope formation/revision in independent OS processes, FinalizeBlock/Commit SIGKILL replay, held-replica catch-up, real four-validator Comet TCP crash/partition/heal checks, and the integrated provider/observer/unauthorized/two-receiver state-sync topology. The final exact-tree cold execution passed before the release branch was published.

This is same-chain validator replication, not a relabeling of v11.8 synchronization groups or independent-chain federation. Internet validators still need mutually routable Comet TCP, explicit port forwarding, or an operator VPN, plus reachable RPC origins. Federation is not a validator tunnel; a future tunnel layer is separate work and is not part of v11.9.0.

App-v20 remains dormant until the governed upgrade activates it, preserving byte-identical pre-activation replay. A rolling binary install is safe only while the tagged target-20 ceremony has not been submitted. SDK 11.9.0.

</details>

<details> <summary>v11.8.5 - anatomical MRI boundary</summary>

MRI memories now remain inside the anatomical cranium at every zoom and rotation. The memory cloud previously used a vertically symmetric ellipsoid even though the bundled anatomical mesh has a much shallower lower cranial boundary outside its narrow, off-centre brainstem. Lower-hemisphere nodes could therefore protrude through the mesh, especially after the v11.8.3 spread increase. CEREBRUM now uses an asymmetric vertical envelope with explicit clearance for each rendered sphere and bloom halo. The upper cortex keeps its full spread, and the newest-to-outer / oldest-to-inner age ordering is unchanged.

The placement contract is directly regression-tested across the full age, radial-jitter, and elevation range, including a fixed lower-cranium safety threshold. This patch changes no consensus rule, AppHash, transaction type, key encoding, fork, graph API limit, or server workload; existing chains replay byte-identically and app version 20 remains unallocated.

SDK 11.8.5.

</details>

<details> <summary>v11.8.4 - actionable domain write denials</summary>

Domain write denials now say what is wrong and how to fix it. When consensus rejects a memory because its authenticated agent lacks level-2 write access to an owned domain, the REST API now returns a distinct, sanitized RFC 7807 domain-write-denied problem instead of collapsing it into a generic 403. MCP preserves that machine-readable type, immediately points the agent to CEREBRUM Access Controls or the domain owner, and performs no pointless re-registration, retry loop, or /mcp reconnect suggestion. Older servers' generic denial remains on the bounded compatibility recovery path.

The built-in CEREBRUM guide also explains SAGE's token-efficiency story without pretending every session necessarily uses fewer tokens: durable context lives outside any one model and only the relevant pieces are brought back, so token spend carries useful memory instead of repeated explanations and each tool rebuilding the same history.

This patch changes no consensus rule, AppHash, transaction type, key encoding, fork, or authorization decision; existing chains replay byte-identically and app version 20 remains unallocated.

SDK 11.8.4.

</details>

<details> <summary>v11.8.3 - anatomical MRI memory spacing</summary>

A memory brain that uses its full anatomy while keeping age meaningful. CEREBRUM now spreads its 2,500-memory representative sample through a substantially broader portion of the MRI mesh instead of crowding long-lived histories into the centre. Fresh memories remain nearest the outer cortex; memories move progressively inward as they age, and the oldest cohort settles toward the lower inner brainstem. A one-year age window replaces the old 90-day clamp, while a small deterministic radial offset separates same-age memories without turning the stable layout into a force simulation.

The placement calculation now lives in a pure, directly tested module with bounded mesh extents and monotonic age-to-depth checks. This patch changes no consensus rule, AppHash, transaction type, key encoding, fork, graph API limit, or server workload; existing chains replay byte-identically and app version 20 remains unallocated.

SDK 11.8.3.

</details>

<details> <summary>v11.8.2 - synchronization groups and a denser MRI</summary>

Synchronization groups β€” human-verified, signed memory sharing between separate SAGE brains. A synchronization group coordinates memory sharing off-consensus through a partitioned, hash-chained, ed25519-signed audit journal: a roster sub-chain replicated to every member and independent per-domain sub-chains replicated only to the members who share that domain, so a node never learns of a domain it does not share. Group items are origin-signed, so a relaying peer can back-fill the mesh without being able to forge or mis-attribute them. Adding a shared domain is a two-party action β€” the owning member and the group controller both sign β€” members express selective-sync consent over the subset of domains they receive, and controller epoch rotation, member removal, and rejoin are all explicit signed roster events reconciled between peers by anti-entropy exchange.

Each MCP bearer token now mints and registers its own signing identity, so a delegated agent action is attributable to exactly one token and one token can never act as another. This release also hardens group authorization: a controller epoch rotation now re-attests the shared domain set under the incoming controller, so rotating control away from a node revokes that node's ability to admit or re-widen shared domains with its old key; and a removed or departed member cannot be silently re-activated with stale entitlements β€” re-entry requires a fresh, co-signed invitation. The v11.8 consensus fork gate is present but dormant.

The CEREBRUM MRI now renders a 2,500-memory representative sample instead of stopping at 500, filling large brains with a denser view while preserving a bounded GPU and API workload. The dashboard and fullscreen MRI share one limit, and operators can still tune the server ceiling with SAGE_GRAPH_MAX_NODES.

v11.8.2 is the first published build of the v11.8 line. It also clears the release lint gate and adds a replay-safety regression guard for the delegated-proof rules already committed by v11.7.6 and v11.7.7 chains. The recovery changes no production behavior beyond the reviewed v11.8 source tree apart from the denser MRI visualization.

SDK 11.8.2.

</details>

<details> <summary>v11.7.7 - one CEREBRUM tab in Firefox</summary>

One CEREBRUM tab in Firefox, including across app restarts. v11.7.7 fixes the remaining macOS launch path that could create duplicate CEREBRUM tabs. The earlier tab-focus implementation could inspect Safari and Chromium-family tabs, but Firefox exposes no equivalent AppleScript tab API; the native app also incorrectly assumed a newly started tray process could not inherit a browser tab left open by the previous process. SAGE now checks a loopback-only live-dashboard presence signal before opening a URL and activates the default browser when CEREBRUM is already connected. Initial app launch, post-update restart, dock reopen, and the Open CEREBRUM menu all use the same reuse path.

This patch changes no consensus rule, AppHash, transaction type, key encoding, or fork; existing chains replay byte-identically.

SDK 11.7.7.

</details>

<details> <summary>v11.7.6 - reliable MCP turns and complete task cards</summary>

Reliable MCP turn writes and task cards that show the whole job. v11.7.6 fixes two post-app-v17 delegated-proof failures that v11.7.4 exposed after making the node authoritative for embeddings. Consensus now keeps every agent-controlled memory field bound to the exact signed request while accepting the validator-signed node's derived embedding hash, so provider cutovers no longer turn valid sage_turn observations into opaque CheckTx rejections. Fresh requests also survive the first block after a long idle period even when deterministic chain time trails the already wall-clock-validated MCP request; captured old proofs remain rejected. Public REST/MCP errors now distinguish proof mismatch and expiry from a generic request rejected.

CEREBRUM task cards stay compact by default but can expand to show complete multiline text. Planned tasks can be edited and saved without rewriting consensus history: SAGE confirms a replacement task first, then retires the original card. Existing committed blocks replay byte-identically; this patch changes only admission of requests that older binaries incorrectly rejected.

SDK 11.7.6.

</details>

<details> <summary>v11.7.5 - readable contextual help</summary>

Readable contextual help at every CEREBRUM boundary. Help tooltips now account for the nearest scroll-clipping container as well as the browser viewport, so hints near the top of Settings and other bounded panels flip downward instead of opening behind the fixed application chrome. The positioning check runs after the tooltip is rendered and keeps keyboard/focus behavior intact. This patch changes no consensus rule, AppHash, transaction type, key encoding, or fork; existing chains replay byte-identically.

SDK 11.7.5.

</details>

<details> <summary>v11.7.4 - provider-safe Smart Memory and CEREBRUM launch</summary>

Provider-safe Smart Memory, automatic repair, and one CEREBRUM tab. The SAGE node is now authoritative for every stored vector: it regenerates agent submissions with the selected embedding provider, stamps the exact vector space, and filters vector recall to that same space. Switching between preferred Ollama embeddings and local hash embeddings cuts write/query authority over before background migration, so active agents cannot keep a migration alive forever and recall never compares incompatible vectors. Provider recovery is watched continuously, so vectorless observations left by a transient outage repair automatically after Ollama or another configured embedder returns. New MCP clients still attach a compatibility vector for older SAGE nodes, while v11.7.4 nodes safely regenerate it.

CEREBRUM Settings now presents Ollama/hash embeddings and the independent reranker On/Off control directly, and the top status strip shows reranker state. The macOS dock app focuses an existing localhost CEREBRUM tab be

See related servers & alternatives β†’

Related MCP servers

Browse all β†’

Related guides

Hand-picked reading to help you choose and use Vector & Memory servers.