Skip to main content
Give your coding agent this prompt:
This is not the same thing as Agent Skills. Those are installed files that teach an agent the habit of remembering. This page is a single prompt that gets an agent connected in the first place, with no files and no API key. Use this to onboard, then install the skills if you want the habit too.
That URL is this page, in the plain-text form Mintlify serves for every doc. Fetching it is the whole install: no separate skill file to download, no per-client setup script, nothing to keep in sync. What follows is written for the agent that fetches it, in the second person, so read it as instructions for yourself.

1. Setup check

Before doing anything else, check whether this project or client already has an Anona credential configured: an existing anona-oauth entry in the MCP server list (claude mcp list in Claude Code), an ANONA_API_KEY environment variable, or a key already saved in this project’s config. If you find one, you’re done here. Skip straight to Usage, section 4 below.

2. Onboarding

If there’s no credential yet, connect to Anona over MCP with no API key. In Claude Code, that’s:
No --header, no key. Connecting with no credential is what starts the approval flow: the first tool call comes back unauthenticated, and an OAuth-capable client follows that into a browser-based sign-in and approval screen. You don’t construct this flow yourself; the client drives it once it sees the unauthenticated response. Before that browser opens, tell the human, in words close to these:
A browser window is about to open asking you to approve access to Anona Memory. Check that the client name shown is the one you expect, then approve it.
That check is the entire security model for this step, which is why it’s worth saying plainly rather than assuming the human will read the screen carefully on their own. Claude Code’s MCP client implements this OAuth flow natively, so pointing it at the server with no credential is enough to trigger it. What has actually been verified is server side only: discovery, and an unauthenticated call correctly returning a 401 with the OAuth challenge, not the full browser round trip. If you’re running as a different client, try it, but don’t promise the human either way that it will complete.

3. Waiting

Wait for the human to approve in the browser. Do not poll any login or auth endpoint while you wait. Those are rate-limited, and a polling loop will lock the attempt out. When the human says they have approved, do not take that as proof. Retry the MCP tool call you were going to make anyway. Succeeding is the signal; a human saying “done” is not, and acting on it leaves you reporting success for a connection you never established. If the retry still comes back unauthenticated, say so plainly rather than retrying in a loop.

4. Usage

Once connected, you have these MCP tools:
  • record stores a memory. Use it when the human tells you something worth remembering across sessions, a preference, a fact, a decision.
  • retrieve searches memories semantically. Use it when you need context you might already have stored, before assuming you don’t.
  • reason synthesizes an answer from accumulated memories rather than returning raw matches. Use it for a question whose answer is spread across several past memories.
  • list_spaces lists the memory spaces available to this credential.
A space is the isolation boundary, one per application or tenant. Within a space, user_id, agent_id and session_id scope individual memories further: a scoped search returns only memories written under that same scope, so tag consistently if you’re serving more than one end user through one connection. The full tool list, including three remote-only tools this credential also grants (get_profile, get_model, get_user_profile), is in MCP Integration.

5. Limits

The credential you just got only works over MCP. It is not an API key, so it does not work with the SDK or with raw HTTP calls to the REST API. If the human wants either of those, they mint an API key from the dashboard, under API keys. For the full flow this page starts, including troubleshooting a stuck approval, see Agent Self-Onboarding.