Fireweed
FreeNot checkedAgent memory where every fact carries a receipt — a deterministic gate decides what is remembered, and erasure issues a signed certificate.
About
Agent memory where every fact carries a receipt — a deterministic gate decides what is remembered, and erasure issues a signed certificate.
README
Agent memory where every fact carries a receipt.
remember(claim = "Priya joined Acme in 2019 under duress.",
evidence = "Priya Raman joined Acme in 2019 as a logistics analyst.")
REFUSED (asserts_more_than_evidence) — the claim adds something the evidence does not say.
claim : Priya joined Acme in 2019 under duress.
evidence: Priya Raman joined Acme in 2019 as a logistics analyst.
recall("Priya's salary")
ABSTAINED (unknown_predicate) — no claims ground "salary"; 1 claim about Priya Raman exists
This is a refusal, not an empty result.
forget("Priya")
ERASED Priya Raman — certificate issued
signature : hmac-sha256:f4d0768ef3b0fec624afec12f25bfd91…
nodes in closure : 1
every probe abstains : True
bystanders surviving : 1
That last one is the artifact behind "delete me from your agent's memory — and prove it."
Install
uvx fireweed-mcp # try it
pip install fireweed-mcp # keep it
claude mcp add fireweed -- uvx fireweed-mcp
No dependencies. No API keys. No model — nothing in this server calls an LLM.
What it does
| tool | |
|---|---|
remember |
admits a claim only if the evidence you cite supports it. Refusals are typed and say what to fix. |
recall |
grounded claims with the byte range they came from; abstains and names the term it could not ground |
verify_receipts |
re-hash every source, re-slice every range — tamper-evident |
forget |
erasure with exact closure and a signed certificate; bystanders survive |
export_memory |
the whole substrate as a portable open-format blob |
Why the refusals are the point
Most memory servers store what the model says and return what's nearest. This one adjudicates.
The rule is the model proposes, deterministic code decides. Across an RPC boundary that stops being a slogan: your agent is the proposer, and it cannot talk its way past the gate, because the gate is not a prompt. Pass a claim and the text you're quoting; pure functions check that the evidence names the subject, preserves the relation, invents no numbers, and asserts nothing the span doesn't say. What survives is stored with a byte range into the source.
Then anyone can check it afterwards — including someone who trusts neither your agent nor this server. That is the whole product.
What it does NOT do
Stated up front, because this project's last headline number turned out to be measuring nothing (see the retraction, which ships with a script that proves it):
- It does not extract memories from free text. You supply the claim and the evidence. Automatic extraction needs a perceiver model; this server deliberately has none.
- It does not make an LLM truthful. It governs what enters the record and what can be proven about it. Your model can still say whatever it likes in its own prose.
- Recall is weak, and measured on both axes. On questions whose answer is genuinely absent, the gate abstains on only 38% — it checks that the question's topic is grounded, not that the asked-for value exists. On a paired corpus of questions the stored facts do answer, it returns the right answer 24% of the time against 75% for plain retrieval-and-read. Both numbers come from a calibrated instrument that prints its own controls before measuring; the method and the failures behind it are written up in the private repo's evaluation notes. The write path, receipts and erasure are unaffected and are the parts to rely on.
Your data
~/.fireweed/mcp/ (FIREWEED_MCP_STORE to change). The substrate is an open format — see
open_format/SPEC.md — and open_format/reference_reader.py reads it with
the standard library alone. Your memory outlives this server, this engine, and any model. A test
asserts that round trip.
Optional: pip install "fireweed-mcp[semantic]" enables paraphrase matching in recall. Without
it the gate refuses more — the safe direction — and memory_stats tells you which mode you're in.
License
FSL-1.1-ALv2 — source-available. Free for everything except building a competing product; converts to Apache 2.0 on 2028-01-01. Full text in LICENSE.md.
Want to use Fireweed in a commercial product or competing service? → [email protected]
Install Fireweed in Claude Desktop, Claude Code & Cursor
unyly install fireweedInstalls into Claude Desktop, Claude Code, Cursor & VS Code — handles npx, uvx and build-from-source repos for you.
First time? Get the CLI: curl -fsSL https://unyly.org/install | sh
Or configure manually
Run in your terminal:
claude mcp add fireweed -- uvx fireweed-mcpStep-by-step: how to install Fireweed
FAQ
Is Fireweed MCP free?
Yes, Fireweed MCP is free — one-click install via Unyly at no cost.
Does Fireweed need an API key?
No, Fireweed runs without API keys or environment variables.
Is Fireweed hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Fireweed in Claude Desktop, Claude Code or Cursor?
Open Fireweed on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Fetch
Web content fetching and conversion for efficient LLM usage.
AWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
by modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
by xuzexin-hzMCP-Agent
A simple, composable framework to build agents using Model Context Protocol by [LastMile AI](https://www.lastmileai.dev)
by lastmile-aiSpring AI MCP Client
Provides auto-configuration for MCP client functionality in Spring Boot applications.
mcp.natoma.ai
A Hosted MCP Platform to discover, install, manage and deploy MCP servers by [Natoma Labs](https://www.natoma.ai)
MCPHub
Website to list high quality MCP servers and reviews by real users. Also provide online chatbot for popular LLM models with MCP server support.
MCP Servers Rating and User Reviews
Website to rate MCP servers, write authentic user reviews, and [search engine for agent & mcp](http://www.deepnlp.org/search/agent)
mkinf
An Open Source registry of hosted MCP Servers to accelerate AI agent workflows.
Compare Fireweed with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All ai MCPs
