Atlas / MCP servers / mem0ai / Mem0

Mem0CAUTION

mcp/mem0ai/mem0-1

None

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
662
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[!CAUTION] ## This project has been archived mem0-mcp-server is no longer actively maintained and this repository is now a public archive. Thank you to the 640+ stargazers, 140+ forkers, and every contributor who helped shape this project. Your support and feedback meant the world to us. Looking for Mem0 MCP? We now offer an official cloud-hosted MCP server. Check out the docs to get started. Quick install across all major clients: ``bash npx mcp-add \ --name mem0-mcp \ --type http \ --url "https://mcp.mem0.ai/mcp" \ --clients "claude,claude code,cursor,windsurf,vscode,opencode" ``

[](https://pypi.org/project/mem0-mcp-server/) [](LICENSE) [](https://smithery.ai/server/@mem0ai/mem0-memory-mcp)

mem0-mcp-server wraps the official Mem0 Memory API as a Model Context Protocol (MCP) server so any MCP-compatible client (Claude Desktop, Cursor, custom agents) can add, search, update, and delete long-term memories.

Tools

The server exposes the following tools to your LLM:

Read from source at commit 8f0f2573eddcOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mem0-mcp-server --env MEM0_API_KEY=${MEM0_API_KEY} -- uvx mem0-mcp-server
claude-desktop
{
  "mcpServers": {
    "mem0-mcp-server": {
      "command": "uvx",
      "args": [
        "mem0-mcp-server"
      ],
      "env": {
        "MEM0_API_KEY": "${MEM0_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
list_entitiesreadList users/agents/apps/runs with stored memories.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (2)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 8f0f2573eddcfull audit observations/trust-audit/mcp-server/mem0ai__mem0-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-288f0f2573eddcCAUTIONB83first audit
06

Questions

What is the Mem0 MCP server?

None

What tools does Mem0 expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mem0 safe to connect to an agent?

With care. The audit graded it B (83/100) and found 2 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mem0 need?

It reads MEM0_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mem0 run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mem0-mcp-server.

How current is this page?

The grade is for one exact copy of the source (8f0f2573eddc), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement