Jean MemoryBLOCK
next-generation AI memory infrastructure (powered by mem0 and graphiti)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Jean Memory
AI Memory across your applications in 5 lines of code.
Website · Dashboard · SDK & API Docs · Report an Issue
Quick Start: Add Memory to Your App in 5 Minutes
Integrate a powerful memory layer into your application with our easy-to-use SDKs.
React: Add a Full Chat UI
Drop a complete, context-aware chat component into your React app.
// 1. Install the SDK
// npm install @jeanmemory/react
// 2. Add the provider and chat component
import { JeanProvider, JeanChat } from '@jeanmemory/react';
function MyApp() {
return (
);
}Python: Power Your Backend Agent
Add a context layer to your Python backend or AI agent.
# 1. Install the SDK # pip install jeanmemory # 2. Get context before calling your LLM from jeanmemory import JeanClient jean = JeanClient(api_key="YOUR_API_KEY") # Get user_token from your frontend OAuth flow context = jean.get_context( user_token="USER_TOKEN_FROM_FRONTEND", message="What was our last conversation about?" ).text
Node.js: Enhance Your JavaScript Backend
Integrate memory into your Next.js, Express, or other Node.js services.
// 1. Install the SDK
// npm install @jeanmemory/node
// 2. Get context in your API route
import { JeanClient } from '@jeanmemory/node';
const jean = new JeanClient({ apiKey: "YOUR_API_KEY" });
// Get userToken from your frontend OAuth flow
const context = await jean.getContext({
user_token: userToken,
message: "What was our l6c59a7f0de30OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add test-app --env ADMIN_SECRET_KEY=${ADMIN_SECRET_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env APIFY_TOKEN=${APIFY_TOKEN} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"test-app": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ADMIN_SECRET_KEY": "${ADMIN_SECRET_KEY}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"APIFY_TOKEN": "${APIFY_TOKEN}",
"GEMINI_API_KEY": "${GEMINI_API_KEY}"
}
}
}
}Exposed tools (33)
28 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ChatGPT | read | Deep research memories |
Claude | write | One-Click Install |
Cline | read | Command line interface tool |
Cursor | read | AI-powered code editor |
Enconvo | read | Environment configuration tool |
Notion | read | Connected workspace for notes & projects |
Obsidian | read | Powerful knowledge base application |
RooCode | read | Code review and collaboration |
SMS | read | Text your memories |
Substack | read | For writers for substack |
Windsurf | read | AI-powered code editor |
Witsy | read | Smart productivity assistant |
X | read | Social media |
add_memories | write | Manually store specific information |
analyze_task_conflicts | read | |
ask_memory | read | Simple questions about your stored memories |
check_agent_status | read | |
claim_file_lock | read | |
create_task_distribution | write | |
debug_get_qdrant_payload | read | |
deep_memory_query | read | Complex analysis across all memories |
get_context_by_depth | read | |
get_context_direct | read | |
get_document_status | read | |
jean_memory | read | 🌟 PRIMARY TOOL for all conversational interactions. Intelligently engineers context for the user\ |
jean_memory_v2 | read | |
list_memories | read | Browse through stored memories |
search_memory | read | Quick keyword search through your memories |
setup_multi_agent_coordination | read | |
simple_test | read | |
store_document | write | ⚡ FAST document upload. Store large documents (markdown, code, essays) in background. Returns immediately with job ID for status tracking. Perfect for entire files that would slow down chat. |
sync_progress | write | |
test_connection | read |
Trust audit
BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (15 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
async with httpx.AsyncClient(follow_redirects=True, verify=False) as client:
DATABASE_URL=postgresql://jean_memory:memory_password@localhost:5432/jean_memory_db
return f"postgresql://{self.PGVECTOR_USER}:{self.PGVECTOR_PASSWORD}@{self.PGVECTOR_HOST}:{self.PGVECTOR_PORT}/{self.PGVECTOR_DATABASE}"jean-memory-claude.dxt
jean-memory-http-v2.dxt
jean-memory-legacy.dxt
jean-memory.dxt
chorus.avif
logger.info(f"🔄 SDK OAuth completion with Supabase session for API key: {api_key[:12]}...")logger.info(f"🔍 SDK VALIDATE: Validating API key format (starts with jean_sk_: {api_key.startswith('jean_sk_')})")console.log('GEMINI_API_KEY found, length:', apiKey.length);callback_url = f"/oauth/callback?oauth_session={oauth_session}&flow=mcp_oauth"return RedirectResponse(url=callback_url)
callback_url = f"/oauth/callback?oauth_session={most_recent_session}&flow=mcp_oauth"return RedirectResponse(url=callback_url)
auth_url = jean.get_auth_url(callback_url="http://localhost:8000/callback")
UVICORN_TIMEOUT_KEEP_ALIVE=75 SUPABASE_URL=http://127.0.0.1:54321
value: "postgres://postgres:[email protected]:6543/postgres?pool_mode=transaction"
psql postgresql://postgres:postgres@localhost:54322/postgres
DATABASE_URL=postgresql://postgres:postgres@localhost:54322/postgres
<JeanProvider apiKey="your-jean-memory-api-key">
<JeanProvider apiKey="jean_sk_test_demo_key_for_ui_testing">
<JeanProvider apiKey="your-jean-memory-api-key">
apiKey="your-jean-memory-api-key"
.pre-commit-config.yaml
Gates applied: no_behavioural_pass.
6c59a7f0de30full audit observations/trust-audit/mcp-server/jonathan-politzki__jean-memory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6c59a7f0de30 | BLOCK | F | 38 | first audit |
Questions
What is the Jean Memory MCP server?
next-generation AI memory infrastructure (powered by mem0 and graphiti)
What tools does Jean Memory expose?
33 in total: 28 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Jean Memory safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (38/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Jean Memory need?
It reads ADMIN_SECRET_KEY, ANTHROPIC_API_KEY, APIFY_TOKEN, GEMINI_API_KEY, GOOGLE_API_KEY, GOOGLE_CLIENT_SECRET, JEAN_API_KEY, JEAN_API_TOKEN, JEAN_MEMORY_API_KEY, JWT_SECRET_KEY, LOOPS_API_KEY and NEO4J_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Jean Memory run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-app at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (6c59a7f0de30), read on 2026-10-07. The repository is watched and re-audited when it changes.