an MCP server
Give any agent a memory it owns. Writes land in milliseconds and get hash-chained, then notarized every ten minutes on three public chains: Bitcoin, Base, and Robinhood Chain. An agent can seal them onto Arweave for good whenever it wants. Every byte is encrypted under a key derived from the agent's wallet, sealed under our custody by default, orfully self-custodied on the hosted network, your choice. One API key, funded with $HERO, pays for all of it.
https://storage.engramemory.dev/mcpfig. 1 · two tiers, one chain
memoryd appends a sealed entry in a few milliseconds and mirrors it off-site. This is where an agent lives day to day. Ten megabytes are free per wallet.
Every ten minutes the notary folds the head of every chain into a signed tree head and anchors it on Bitcoin and Base, chains we don't control, so the proof stands even if we vanish, plus Robinhood Chain as a third, faster witness. Rewrite anything below it and the head breaks in public, checkable by anyone.
Seal a chain and its bytes go to Arweave under a pay-once endowment. Entries under 100 KiB are free; anything larger gets a $HERO quote before it moves.
fig. 2 · what a write does
Text in, ciphertext out: AES-256-GCM under a key derived from the wallet. The daemon stores the ciphertext and computes hash = keccak(previous ‖ blob). The wallet signs every append over the chain id, the previous head, and the blob. The head is a pure function of the bytes. Any mirror, any stranger, can recompute it.
fig. 3 · who owns it
Register once with a wallet key; every chain is named<wallet>-<name> and every byte is encrypted under a key derived from that wallet. Two ways to run it, same encryption either way:
Send us a private key once at registration; we seal it at rest and use it to encrypt and sign on your behalf. Zero setup: one API call and you're writing. This means we hold custody of a sealed key and decrypt server-side for every authenticated request: convenient, not zero-knowledge. Trust our custody, or use the option below.
Your private key never leaves your machine, not even once. You seal and sign everything client-side; we only ever see ciphertext and a signature we can verify but not produce. Live now at hosted.engramemory.dev, a --require-sigsdaemon that structurally cannot decrypt your data or forge a write, even if compelled to.
Move the wallet and the memory moves with it either way: any machine holding the key rebuilds every chain byte for byte from Arweave alone.
quickstart
{
"mcpServers": {
"engram": { "url": "https://storage.engramemory.dev/mcp" }
}
}engram_register({ privateKey: "0x…", label: "my agent" })
→ { apiKey: "eng_…", wallet: "0xAb…" }engram_put({ chain: "notes", text: "First thing worth keeping." })
engram_get({ chain: "notes" })
engram_seal({ chain: "notes", quoteOnly: true }) // $HERO quote
engram_seal({ chain: "notes" }) // permanent on Arweaveengram_registerwallet in, API key outengram_puthot write, sealed and chainedengram_getdecrypt and verifyengram_listchains, heads, coverageengram_sealcold tier on Arweaveengram_verifypublic, no authengram_topupfund your key with $HEROengram_whoamikey balance and usagePrefer plain HTTP? GET /v1/tools lists the same tools andPOST /v1/call/:tool runs one. Everything you store shows up in thepublic explorer, as hashes only.
s3-compatible
https://s3.engramemory.dev speaks the same wire protocol as S3 and R2: real AWS SigV4 request signing, the same put_object / get_object /list_objects_v2 / delete_object calls. Swap the endpoint and credentials, keep every other line of code.
import boto3
s3 = boto3.client("s3", endpoint_url="https://s3.engramemory.dev",
aws_access_key_id="eng_…", aws_secret_access_key="eng_…", region_name="us-east-1")
s3.put_object(Bucket="notes", Key="first.txt", Body=b"hello")
s3.get_object(Bucket="notes", Key="first.txt")["Body"].read()A bucket is a chain. An object is one sealed, hash-linked entry. Nothing is ever overwritten or deleted, the same as an S3 bucket with Versioning and Object Lock permanently on: writing a key again keeps both versions, deleting adds a marker instead of erasing anything.
self-host
A hosted endpoint you point every agent at is a single company standing between you and your own memory again, just with better branding. So the hot tier isn't meant to stay ours to run. Anyone can run memoryd and the S3 gateway on their own hardware, for their own agents, at whatever throughput their own hardware gives them. What stays shared is the one part that benefits from being shared: the public chain everyone anchors into.
memoryd and the S3 gateway, running on your own machine or your own cloud. Your agents write to it directly, at your own hardware's speed, with nobody else's traffic in the way. Nothing about this tier depends on Engram staying online.
Robinhood Chain and Arweave: a public blockchain and a public permanent-storage network, not a company's server. Every self-hosted instance anchors its chain heads into the same public substrate, so two people who have never spoken can each verify the other's evidence without trusting either one's infrastructure.
This is the same self-host story the rest of Engram already tells (one Postgres, one daemon, one command per service) applied one layer down, to storage specifically. Source release for the standalone storage engine isn't public yet. This section describes the architecture we're building toward.
apple watch · siri
Shortcuts runs on the Watch and can dictate, call a URL, and speak the answer. Two shortcuts turn Engram into a voice memory: say it and it seals to your chain, ask and it reads back. Build them once on your iPhone; they sync to the Watch and answer to Siri.
https://storage.engramemory.dev/s/put?chain=watch&key=YOUR_KEYContent-Type: text/plainSay “Hey Siri, Engram Remember”, speak, done. Sealed under your wallet, chained, notarized at the next epoch.
https://storage.engramemory.dev/s/get?chain=watch&limit=5&key=YOUR_KEYSay “Hey Siri, Engram Recall” and your last five memories are read aloud.
YOUR_KEY is the API key from engram_register. Use one chain per purpose (chain=watch, chain=ideas) or send everything todefault. Under 100 KiB per entry is free; a whole year of wrist notes fits in the hot tier's free 10 MB.
pricing
Your API key is your account. Fund it with $HERO and every write, seal, and read draws from that single balance. You never touch AR, gas, or a card.
The self-custodied network is priced differently, since nothing about it runs through your account balance: reads are open and free for anyone, writes need a deposited key, and storage is metered against that deposit directly rather than a per-key allowance.