Skip to main content

What it does

anona login opens a browser, you approve access once, and a credential is stored on your machine. anona mcp is a small stdio server your MCP client launches. It attaches that credential to every request and renews it when it expires. The token exists before the client ever starts, so there is nothing to authenticate from inside the client.

Install

Or run it with nothing installed:
If you have Node and no Python, the same two commands ship in the JavaScript package, which has no runtime dependencies:
The two behave the same and read and write the same credential file, so you can sign in with one and run the other.
Both packages install a binary called anona. With both installed you get whichever comes first on your PATH. That is harmless, because they share ~/.anona/credentials.json. Two things follow. A client configured with anona mcp keeps working if you uninstall one package only if the other is still on PATH. And the two share one lock: both take ~/.anona/credentials.json.nodelock while they refresh, so a Python and a Node anona mcp that find the token expired in the same instant refresh one after the other, not both. anona login and anona logout take the same lock. If that lock were ever bypassed, the server would treat the second use of a refresh token as theft and revoke both credentials, and you would sign in again.

Sign in

anona login names the server it is signing in to, and warns if a stored credential for a different server will be replaced. For a self-hosted deployment, pass --base-url https://your-host or set ANONA_BASE_URL; the flag works before or after the command, and wins over the variable. A browser opens on the approval screen. If you have no account, you create one there. Read the client name before you approve it: that screen is the whole security model. Over SSH or in a container the browser cannot open on its own, so anona login prints the URL and you open it yourself. Pass --no-browser to skip the attempt to open one and only print the URL. The approval redirects back to a local port on the machine running anona login, so open the URL in a browser on that machine, or forward that port to the one you are using. Check where you stand at any time:
status reports whether a credential is stored, which server it is for, and when its access token expires. It reads only the local file, so it cannot tell you the server still accepts it: a revoked credential, or one unused for 30 days, still shows as found. If anona mcp reports an authorization failure, run anona login again. status never prints a token.

Connect a client

That registers a stdio server, so the client needs no URL and no header. The tools (record, retrieve, reason, list_spaces, and the rest of the MCP tools) are available the next time the client starts. For a client that runs its own OAuth, skip the CLI and point it at the remote server directly: claude mcp add --transport http anona-oauth https://memory.anonalabs.com/mcp.

One approval, then silence

The access token lasts 1 hour and the refresh token lasts 30 days. The 30 days are rolling: each refresh issues a new refresh token with a fresh 30 days, so a credential you use does not expire. You are asked to approve again only after 30 days of total silence, or after you revoke the app under MCP → Connected apps in the dashboard. To sign out on this machine, run anona logout. That deletes the local file. It does not revoke anything on the server; do that under Connected apps.

Limits

This credential is MCP-only. The data plane rejects it, so the Python and JavaScript SDKs and raw REST calls need an API key, which you mint from the dashboard under API keys. Signing in with anona login does not give you one. Whether you need one is a separate decision: everything on this page works without it.
The proxy handles one message at a time. It reads a request, waits for the answer, then reads the next. A slow reason call can take up to 120 seconds, and for that long every other request from the same client waits behind it. If your agent issues parallel memory calls, expect them to queue. anona logout and anona login do not touch ~/.anona/config.env, which is where an API key for anona-mcp and the agent skills lives. The two are separate credentials.