Primary question: Can you quit Claude Code mid-task and have Codex pick up the same directory without re-explaining the architecture?
RepoDaily adoption score
RepoDaily rates this as 92/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.
6 source(s) across 4 source category/categories, plus a RepoDaily-specific evidence module when available.
7 workflow step(s), 5 next-action step(s), and 6 command/install signal(s) were detected.
Trending momentum is +730 stars, with maintenance/release/issue signals counted when present.
Risk is marked medium, with 8 security note(s) and 4 explicit skip condition(s).
3 opportunity lens item(s), 4 alternative(s), and 4 type-specific section(s) support differentiation.
License source or license wording is present.
9 AI/agent-related signal(s) were detected in the article text and metadata.
Project overview
akitaonrails/ai-memory is a Rust project that answers a question every multi-CLI developer now has: what happens to the context when I quit Claude Code and open Codex in the same directory? The README's pitch is blunt — continue without re-explaining the architecture, the failed approaches, or the open questions. It works by installing MCP configuration plus lifecycle hooks into each supported agent, capturing sessions into local storage (an SQLite database plus markdown wiki files), and feeding handoffs to whichever agent starts next.
The support matrix is the real draw. Claude Code, Codex, Command Code, Devin CLI, OpenCode, Cursor, Gemini CLI, Oh My Pi/OMP and Pi each get agent-specific integration: Claude Code can enable per-session auto-scope isolation through a local stdio bridge (`install-mcp --session-aware`), Devin CLI hooks ride the `PostCompaction` event and inject context via `hookSpecificOutput.additionalContext`, Pi gets a generated TypeScript extension with an HTTP MCP bridge, and Crush is managed-only via `ai-memory run crush`. Linux is the primary Docker/server target with published `linux/amd64` and `linux/arm64` images plus Arch/AUR packages shipping system and user systemd units; macOS gets native tarballs for aarch64 and x86_64; native Windows is experimental, shipping `ai-memory-windows-x86_64.zip` with `ai-memory.exe`.
Under the hood the project shows discipline you more often find in infrastructure vendors than in agent tooling. Rust 1.95 is pinned in `rust-toolchain.toml`; four gates run before every PR (`cargo fmt --all -- --check`, `cargo clippy --workspace --all-targets -- -D warnings`, `cargo test --workspace`, `cargo deny check`); a CHANGELOG entry under `## [Unreleased]` is a blocking merge requirement for user-facing changes; all SQLite writes pass through a single writer actor (`WriterHandle`); and file writes are atomic only — tmp + rename + fsync. SQLite is bundled via rusqlite's `bundled` feature and libgit2 vendored via git2's `vendored-libgit2`, so builds need nothing beyond a standard C toolchain.
Version 1.28.1 shipped on 2026-08-18 — one day before this trend snapshot — with a transitive-dependency DoS fix (h2 0.4.14 → 0.4.16, RUSTSEC-2026-0258, reachable from `--transport http` deployments because h2 sits under the axum/hyper stack the server runs on) and seven new credential redaction shapes in the built-in sanitizer. With 730 stars in the window and rank 4 on 2026-08-19, the project is trending on the strength of a concrete promise plus visible maintenance hygiene.
Why it is trending now
- 730 stars in the trend window and rank 4 on 2026-08-19.
- The headline feature — vendor-neutral handoff between coding CLIs — names a pain that hits anyone running more than one agent in the same repositories.
- 1.28.1 released 2026-08-18, the day before the snapshot: h2 DoS fix for RUSTSEC-2026-0258 plus seven new built-in credential redaction patterns (GitHub `gho_`/`ghu_`/`ghs_`/`ghr_`, AWS `ASIA…`, Stripe `rk_live_`, Google `1//…`, Meta `EAA…`, Telegram bot tokens, GoHighLevel `pit-…`).
- A support matrix covering ten-plus agent surfaces, from Claude Code's `--session-aware` stdio bridge to Crush's managed session-database resume.
Problem it solves
- Quitting one coding CLI and starting another throws away the accumulated mental model: architecture, dead ends, open questions.
- Context compaction in Claude Code and Codex destroys raw chat history while the session is still running.
- Anything an agent writes to persistent memory can contain live credentials that outlive the conversation.
- Every vendor exposes a different hook and config surface, so memory capture has to be adapted agent by agent.
- Cloud memory products put your code context on someone else's infrastructure.
How it works
- Install per agent: MCP config plus lifecycle hooks; on Claude Code, `install-mcp --session-aware` adds per-session auto-scope isolation through a local stdio bridge.
- Hooks capture lifecycle events and enforce capture exclusions — `[capture] ignore_paths` in the nearest `.ai-memory.toml` keeps file-tool events under private paths out of the spool; `--check-capture` validates locally.
- At session end the hook writes a handoff; the next session-start hook for any supported agent fetches it before your first prompt. Manual handoffs are project-wide and take precedence over automatic ones.
- When Claude Code or Codex compacts, the `PreCompact` hook writes a fresh `sessions/<id>.md` summary, recoverable through `memory_recent` even after raw chat history is gone.
- Agents query memory proactively: `memory_query` runs FTS5 plus entity/graph/vector RRF over compiled wiki pages, followed by source-authority ranking and raw-observation fallback; `memory_explore` returns a 'catch me up' prose digest.
- A built-in sanitizer redacts credential shapes listed in `BUILTIN_PATTERN_STRS` client-side, before an excerpt reaches the local spool or the wire; matched text is replaced with `[REDACTED]`.
- On the server, all SQLite writes go through one writer actor (`WriterHandle`); the CLI stays a thin HTTP client and never opens the database or wiki directory directly.
Integration surface: what actually works, agent by agent
- Claude Code — MCP config + lifecycle hooks; `install-mcp --session-aware` opts into per-session auto-scope isolation via a local stdio bridge; assistant-turn capture on `Stop` is double opt-in (`--capture-assistant` plus a server-side `capture_assistant` flag) and off by default.
- Codex — MCP + hooks, but no automatic session-end hook: run `ai-memory finalize-session` when you want a final summary or handoff.
- Command Code — MCP config at `~/.commandcode/mcp.json` and four stable hook events in `~/.commandcode/settings.json`; `Stop` is only a turn boundary, so `ai-memory finalize-session --agent command-code` closes the session; `ai-memory run command-code` adds v3 native-session resume and visible-event import.
- Devin CLI — hooks use `PostCompaction` and inject handoffs via `hookSpecificOutput.additionalContext`; subagent events are omitted because Devin does not expose them.
- OpenCode, Cursor, Gemini CLI — MCP config + lifecycle hooks; OpenCode uses remote MCP plus a generated TypeScript plugin that enforces capture exclusions.
- Pi and Oh My Pi — generated extensions (`~/.pi/agent/extensions/ai-memory.ts` for Pi; native `.omp` MCP config plus a TypeScript extension for OMP) enforce capture exclusions.
- Crush — managed-only: `ai-memory run crush` resumes its project-local session database and supplies portable context through a temporary supported global-context file; no hook installer is provided.
- Agents with MCP but no hook surface — ask the agent to call `memory_handoff_begin` before quitting; the next hooked agent consumes the handoff automatically.
Command surface: the verbs that matter
- `install-mcp` / `install-hooks` — per-agent configuration; the `--agent pi` and `--agent omp` variants honor `PI_CODING_AGENT_DIR` after the unreleased fix in #411, which resolved installs that reported success while capture silently did nothing because extensions landed where the agent never loads them.
- `finalize-session` — manual close-out for agents without a true session-end hook (Codex, Command Code).
- `run <agent>` — opt-in managed workstreams; `run command-code` and `run crush` resume vendor session state.
- `--check-capture` — local check of capture-exclusion markers before anything is spooled or sent.
- `serve --bind 0.0.0.0:…` — non-loopback exposure; the server fails closed without `AI_MEMORY_AUTH_TOKEN`, and `--allow-insecure-no-auth` is the documented dangerous override for an intentional plain-HTTP LAN deployment.
- `generate-auth-token` — mints the bearer token checked on every request for non-loopback deployments.
- MCP tools — `memory_query`, `memory_explore`, `memory_recent`, plus `memory_handoff_begin` / `memory_handoff_accept` / `memory_handoff_cancel` with `shared: true` for project-wide batons and root-only `any_owner: true` for recovery.
Architecture read: invariants that keep captured data honest
- Storage is SQLite plus wiki markdown namespaced by `(workspace_id, project_id)`; a purge for project A cannot delete files belonging to project B, and V38 triggers reject mismatched workspace/project entities and cross-project entity/page links.
- All SQLite writes go through a single writer actor (`WriterHandle`) — one choke point for consistency.
- Config is read once at startup; `std::env::var` is banned outside `Config::load`.
- File writes are atomic only: tmp + rename + fsync, never in-place.
- The CLI never opens the SQLite file or the wiki directory; it is always a thin HTTP client to the running server.
- Builds are self-contained: SQLite bundled via rusqlite's `bundled` feature, libgit2 vendored via git2's `vendored-libgit2`, Rust 1.95 pinned in `rust-toolchain.toml` — no system libraries beyond a standard C toolchain.
- Development is milestone-driven with no dead code and no half-built features; stubs must carry `// M<n> TODO` markers in module doc-comments.
Try-it path: one hour to a verdict
- 0–15 min: `git clone`, `cargo build --workspace`, `cargo test --workspace` on Rust 1.95 — or pull the published Docker image (`linux/amd64`, `linux/arm64`) or the macOS tarballs; on Apple Silicon the native binary is the recommended path.
- 15–30 min: install MCP config and lifecycle hooks for two agents — Claude Code and Codex are the documented pair — inside one working directory.
- 30–45 min: do 15 minutes of real work in Claude Code, `/exit`, then start Codex in the same directory and confirm the SessionStart hook fetched the handoff before your first prompt.
- 45–60 min: trigger a compaction and recover the summary with `memory_recent`; ask 'catch me up' and watch `memory_explore` answer; add `[capture] ignore_paths` for a private path and confirm with `--check-capture`.
Who should pay attention?
Good fit if
- Solo developers and small groups who bounce between Claude Code, Codex, Cursor, Gemini CLI or OpenCode inside the same repositories.
- Anyone who wants memory stored on their own disk — SQLite plus markdown wiki under one data directory — rather than a vendor cloud.
- Homelab operators comfortable running a small Rust server or the published Docker images with systemd units from the Arch/AUR packages.
- Linux and macOS users, plus Windows users inside WSL2 (native Windows is experimental).
Skip for now if
- Multi-tenant deployments: SECURITY.md declares ai-memory a single-tenant workstation/homelab service where every authenticated user shares one trust domain and can read the same project memory.
- Anyone requiring encryption at rest in v1 — none is provided; filesystem permissions are the only protection.
- Organizations wanting a general prompt/output DLP filter — capture exclusions are explicitly not that.
- Windows-native shops outside WSL2, given the experimental label and PowerShell/Git Bash compatibility fallbacks.
Risks and cautions
The codebase shows unusually strict discipline — a blocking changelog gate, four CI checks, documented invariants, and a 7-day-response / 30-day-patch security SLA — but the declared threat model stops at single-tenant, v1 ships without encryption at rest, and capture correctness depends on each vendor's hook contract, where #411 already produced installs that reported success while capture silently did nothing.
- Single-tenant trust model: any authenticated user can read the same project memory; there is no multi-tenant boundary.
- No encryption at rest in v1, and existing installations are not automatically migrated to the 0700/0600 permission defaults that new files get.
- Hook-contract fragility: issue #411 shows installs can report success while capture silently does nothing when `PI_CODING_AGENT_DIR` is set.
- Native Windows remains experimental; WSL2 is the supported path.
- Non-loopback deployments demand operator discipline — bearer token, TLS reverse proxy, `AI_MEMORY_AUTH__SECURE_COOKIE` for the web UI — and inside a container the fail-closed check downgrades to a warning, so the host-side `-p` publish spec is what decides reachability.
- Reporting path: private GitHub security advisory, response within 7 days, patch target within 30 days, credit in the changelog.
- Sanitizer: `BUILTIN_PATTERN_STRS` runs client-side before excerpts reach the local spool or the wire; 1.28.1 added seven shapes — GitHub `gho_`/`ghu_`/`ghs_`/`ghr_`, AWS `ASIA…` STS keys anchored to the published 20-character format so ordinary text like `ASIAPACIFICREGION` is not redacted, Stripe `rk_live_`, Google `1//…` OAuth refresh tokens, Meta `EAA…` Graph tokens, Telegram bot tokens, GoHighLevel `pit-…` tokens that do not expire until revoked.
- 1.28.1 (2026-08-18) bumped h2 0.4.14 → 0.4.16 for RUSTSEC-2026-0258, an unbounded-empty-DATA-frame DoS reachable from `--transport http` deployments.
- The server fails closed before serving unauthenticated non-loopback HTTP; `--allow-insecure-no-auth` is the explicit dangerous override; inside containers the check warns instead, so `-p 127.0.0.1:49374:49374` is the safe publish form.
- `AI_MEMORY_ALLOWED_HOSTS` (default `127.0.0.1`, `localhost`) returns 403 on foreign Host headers — a DNS-rebinding defense that is not a substitute for a token.
- Inbound HTTP bodies are capped at 10 MB.
- Auth ladder: static root bearer token, database-user tokens that provide attribution but never admin access (the first database user makes every `/admin/*` route root-only), and optional OIDC hook-edge tokens.
- Unix permissions on new files: 0700 data directories and 0600 config, SQLite, managed-workstream segment, and backup files, independent of umask; Windows relies on filesystem ACLs.
Alternatives to compare
| Approach | When to use | Trade-off |
|---|---|---|
mem0 | You want an API-first memory layer serving many LLM applications, not specifically coding-CLI hook integration. | Open-source core with paid cloud tiers. |
Letta (MemGPT) | You are building your own agents and want agent-native persistent memory behind a server API. | Open source. |
Vendor-native session memory (Claude Code project files, Cursor memories) | You stay inside one vendor's CLI and never hand off across vendors. | Included with the product. |
Hand-rolled markdown handoff notes (CLAUDE.md / AGENTS.md files) | You want zero infrastructure and will maintain the notes by hand. | Free but manual, with no capture, redaction, or compaction recovery. |
What this trend reveals
A hardened multi-tenant wrapper
SECURITY.md scopes ai-memory to a single trust domain; a reverse proxy enforcing tenancy plus per-tenant data directories could open it to shared infrastructure, but nothing in the source pack ships that today.
Re-read the SECURITY.md threat model and search the issue tracker for multi-tenant requests before assuming any tenancy support exists.
Extract the redaction engine as a standalone crate
The builtin credential pattern list — including the 20-character AWS anchoring that avoids redacting `ASIAPACIFICREGION` — is generic enough to reuse in any tool that spools agent transcripts.
Check whether `BUILTIN_PATTERN_STRS` is published as a separate crate; if it is not, that is the gap.
MCP-only vendors are reachable without new code
The docs already define the no-hook path: an agent with MCP but no lifecycle hooks calls `memory_handoff_begin` before quitting, and the next hooked agent consumes the baton automatically.
Pick one MCP-only client, call `memory_handoff_begin`, then confirm a hooked agent fetches the handoff at session start.
RepoDaily verdict
ai-memory is the rare trending tool whose README promises less than its engineering delivers: a pinned toolchain, a blocking changelog gate, single-writer SQLite storage, client-side credential redaction, per-project isolation enforced by V38 triggers, and a threat model that openly states what it will not defend against. The cross-vendor handoff is the feature that draws you in; the sanitizer and the documented auth ladder are what make storing agent transcripts on your own disk defensible. Adopt it as the single-tenant service it declares itself to be — behind loopback, or behind a token plus a TLS reverse proxy — and skip it for now if you need multi-tenancy or encryption at rest.