an MCP server

Storage for your agent

Give any agent a memory it owns. Writes land in milliseconds and get hash-chained, then notarized every ten minutes on three public chains: Bitcoin, Base, and Robinhood Chain. An agent can seal them onto Arweave for good whenever it wants. Every byte is encrypted under a key derived from the agent's wallet, sealed under our custody by default, orfully self-custodied on the hosted network, your choice. One API key, funded with $HERO, pays for all of it.

https://storage.engramemory.dev/mcp

fig. 1 · two tiers, one chain

Hot for now, cold forever

Hot

memoryd appends a sealed entry in a few milliseconds and mirrors it off-site. This is where an agent lives day to day. Ten megabytes are free per wallet.

Notarized

Every ten minutes the notary folds the head of every chain into a signed tree head and anchors it on Bitcoin and Base, chains we don't control, so the proof stands even if we vanish, plus Robinhood Chain as a third, faster witness. Rewrite anything below it and the head breaks in public, checkable by anyone.

Cold

Seal a chain and its bytes go to Arweave under a pay-once endowment. Entries under 100 KiB are free; anything larger gets a $HERO quote before it moves.

fig. 2 · what a write does

Sealed, linked, signed

Text in, ciphertext out: AES-256-GCM under a key derived from the wallet. The daemon stores the ciphertext and computes hash = keccak(previous ‖ blob). The wallet signs every append over the chain id, the previous head, and the blob. The head is a pure function of the bytes. Any mirror, any stranger, can recompute it.

fig. 3 · who owns it

The wallet is the key, not the account

Register once with a wallet key; every chain is named<wallet>-<name> and every byte is encrypted under a key derived from that wallet. Two ways to run it, same encryption either way:

Hosted (default)

Send us a private key once at registration; we seal it at rest and use it to encrypt and sign on your behalf. Zero setup: one API call and you're writing. This means we hold custody of a sealed key and decrypt server-side for every authenticated request: convenient, not zero-knowledge. Trust our custody, or use the option below.

Self-custodied

Your private key never leaves your machine, not even once. You seal and sign everything client-side; we only ever see ciphertext and a signature we can verify but not produce. Live now at hosted.engramemory.dev, a --require-sigsdaemon that structurally cannot decrypt your data or forge a write, even if compelled to.

Move the wallet and the memory moves with it either way: any machine holding the key rebuilds every chain byte for byte from Arweave alone.

quickstart

Three calls to a memory that lasts

  1. Point your agent at the server. Claude Code, OpenCode, Hero Run agents, or anything that speaks MCP.
    json
    {
      "mcpServers": {
        "engram": { "url": "https://storage.engramemory.dev/mcp" }
      }
    }
  2. Register a wallet, once. We seal the private key at rest and use it to encrypt and sign every memory. You get an API key back: it is your account and your bearer token. Fund it with $HERO and you are set.
    js
    engram_register({ privateKey: "0x…", label: "my agent" })
    → { apiKey: "eng_…", wallet: "0xAb…" }
  3. Write, read, seal.
    js
    engram_put({ chain: "notes", text: "First thing worth keeping." })
    engram_get({ chain: "notes" })
    engram_seal({ chain: "notes", quoteOnly: true })   // $HERO quote
    engram_seal({ chain: "notes" })                    // permanent on Arweave
engram_registerwallet in, API key out
engram_puthot write, sealed and chained
engram_getdecrypt and verify
engram_listchains, heads, coverage
engram_sealcold tier on Arweave
engram_verifypublic, no auth
engram_topupfund your key with $HERO
engram_whoamikey balance and usage

Prefer plain HTTP? GET /v1/tools lists the same tools andPOST /v1/call/:tool runs one. Everything you store shows up in thepublic explorer, as hashes only.

s3-compatible

Point your S3 code here instead

https://s3.engramemory.dev speaks the same wire protocol as S3 and R2: real AWS SigV4 request signing, the same put_object / get_object /list_objects_v2 / delete_object calls. Swap the endpoint and credentials, keep every other line of code.

python
import boto3
s3 = boto3.client("s3", endpoint_url="https://s3.engramemory.dev",
    aws_access_key_id="eng_…", aws_secret_access_key="eng_…", region_name="us-east-1")
s3.put_object(Bucket="notes", Key="first.txt", Body=b"hello")
s3.get_object(Bucket="notes", Key="first.txt")["Body"].read()

A bucket is a chain. An object is one sealed, hash-linked entry. Nothing is ever overwritten or deleted, the same as an S3 bucket with Versioning and Object Lock permanently on: writing a key again keeps both versions, deleting adds a marker instead of erasing anything.

self-host

Run it yourself, verify it anywhere

A hosted endpoint you point every agent at is a single company standing between you and your own memory again, just with better branding. So the hot tier isn't meant to stay ours to run. Anyone can run memoryd and the S3 gateway on their own hardware, for their own agents, at whatever throughput their own hardware gives them. What stays shared is the one part that benefits from being shared: the public chain everyone anchors into.

Your hot tier

memoryd and the S3 gateway, running on your own machine or your own cloud. Your agents write to it directly, at your own hardware's speed, with nobody else's traffic in the way. Nothing about this tier depends on Engram staying online.

The shared chain

Robinhood Chain and Arweave: a public blockchain and a public permanent-storage network, not a company's server. Every self-hosted instance anchors its chain heads into the same public substrate, so two people who have never spoken can each verify the other's evidence without trusting either one's infrastructure.

This is the same self-host story the rest of Engram already tells (one Postgres, one daemon, one command per service) applied one layer down, to storage specifically. Source release for the standalone storage engine isn't public yet. This section describes the architecture we're building toward.

apple watch · siri

Memory on your wrist, no app to install

Shortcuts runs on the Watch and can dictate, call a URL, and speak the answer. Two shortcuts turn Engram into a voice memory: say it and it seals to your chain, ask and it reads back. Build them once on your iPhone; they sync to the Watch and answer to Siri.

“Engram Remember”

  1. Dictate Text · stop listening: after pause
  2. Get Contents of URL
    https://storage.engramemory.dev/s/put?chain=watch&key=YOUR_KEY
    method POST · request body File → Dictated Text · header Content-Type: text/plain
  3. Show Result → Contents of URL

Say “Hey Siri, Engram Remember”, speak, done. Sealed under your wallet, chained, notarized at the next epoch.

“Engram Recall”

  1. Get Contents of URL
    https://storage.engramemory.dev/s/get?chain=watch&limit=5&key=YOUR_KEY
    method GET
  2. Speak Text → Contents of URL
  3. Show Result → Contents of URL

Say “Hey Siri, Engram Recall” and your last five memories are read aloud.

YOUR_KEY is the API key from engram_register. Use one chain per purpose (chain=watch, chain=ideas) or send everything todefault. Under 100 KiB per entry is free; a whole year of wrist notes fits in the hot tier's free 10 MB.

pricing

Paid in one token, never in gas

Hot10 MB free per key, then metered per MB in $HERO
Coldfree under 100 KiB per entry; above that, Arweave's live rate plus 20%, quoted in $HERO before you commit
Notaryincluded

Your API key is your account. Fund it with $HERO and every write, seal, and read draws from that single balance. You never touch AR, gas, or a card.

The self-custodied network is priced differently, since nothing about it runs through your account balance: reads are open and free for anyone, writes need a deposited key, and storage is metered against that deposit directly rather than a per-key allowance.