Mem0SAFE
MCP server for long term agent memory with Mem0. Also useful as a template to get you started building your own MCP server with Python!
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP-Mem0: Long-Term Memory for AI Agents
A template implementation of the Model Context Protocol (MCP) server integrated with Mem0 for providing AI agents with persistent memory capabilities.
Use this as a reference point to build your MCP servers yourself, or give this as an example to an AI coding assistant and tell it to follow this example for structure and code correctness!
Overview
This project demonstrates how to build an MCP server that enables AI agents to store, retrieve, and search memories using semantic search. It serves as a practical template for creating your own MCP servers, simply using Mem0 and a practical example.
The implementation follows the best practices laid out by Anthropic for building MCP servers, allowing seamless integration with any MCP-compatible client.
Features
The server provides three essential memory management tools:
- `save_memory`: Store any information in long-term memory with semantic indexing
- `get_all_memories`: Retrieve all stored memories for comprehensive context
- `search_memories`: Find relevant memories using semantic search
Prerequisites
- Python 3.12+
- Supabase or any PostgreSQL database (for vector storage of memories)
- API keys for your chosen LLM provider (OpenAI, OpenRouter, or Ollama)
- Docker if running the MCP server as a container (recommended)
Installation
Using uv
- Install uv if you don't have it:
pip install uv
- Clone this repository:
git clone https://github.com/coleam00/mcp-mem0.git cd mcp-mem0
- Install dependencies:
uv pip install -e .
- Create a
.envfile based on.env.example:
cp .env.example .env
- Configure your environment variables in the
.envfile (see Configuration
93b5b39fc540OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mem0-mcp --env LLM_API_KEY=${LLM_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- uvx mem0-mcp{
"mcpServers": {
"mem0-mcp": {
"command": "uvx",
"args": [
"mem0-mcp"
],
"env": {
"LLM_API_KEY": "${LLM_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
}
}
}
}Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_all_memories | read | Get all stored memories for the user. |
save_memory | write | Save information to your long-term memory. |
search_memories | read | Search memories using semantic search. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
public/Mem0AndMCP.png
Gates applied: no_behavioural_pass.
93b5b39fc540full audit observations/trust-audit/mcp-server/coleam00__mem0-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 93b5b39fc540 | SAFE | B | 89 | first audit |
Questions
What is the Mem0 MCP server?
MCP server for long term agent memory with Mem0. Also useful as a template to get you started building your own MCP server with Python!
What tools does Mem0 expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mem0 safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mem0 need?
It reads LLM_API_KEY, OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (93b5b39fc540), read on 2026-09-28. The repository is watched and re-audited when it changes.