What this is
A coding agent can connect itself to Anona Memory without you navigating the dashboard beyond one approval screen. You approve the connection once, in a browser. You never copy an API key, and never paste a password.The one thing you do
A browser window opens. You sign in with Google. You see the name of the client that is asking for access, and you press Approve. That approval is the whole security model, so read the client name before you press it.The flow
Per-client setup
For Claude Code, that one command is the agent’s whole job: it drives discovery,
client registration, the browser hop, and the token exchange natively. Nothing
else to configure.
If your client is not listed, or is listed as needing an API key, mint one from
the dashboard under API keys and follow the header-based setup in
MCP Integration instead.
What you get
Once connected, the agent has the MCP tools:record, retrieve, reason,
list_spaces, get_profile, get_model, and get_user_profile. See
MCP Integration for what each one does and how transports
differ.
Limits
An OAuth credential minted this way is not an API key. It works over MCP, and only over MCP. It does not work with the SDK or with raw HTTP calls to the REST API. For those, mint a key from the dashboard.Troubleshooting
The approval link expired. It is valid for 15 minutes. Start the flow again from the beginning rather than retrying the dead link. You approved, and the first tool call still fails with “No active API key for this organization.” The account was created and the approval worked; the failure is on our side, not yours. A brand-new account holds no API key by design, and the gateway needs a way to tell the engine which organization you are without one. If you see this, the deployment you are talking to does not have that configured yet. Report it rather than minting a key to work around it. The workaround hides exactly the thing we need to know is broken. The agent says it is connected but no memory is stored. Ask it to runretrieve on something you know it recorded. An agent that treats your “I
approved it” as proof of connection will report success it has not verified;
a tool call that returns data is the only evidence that counts.
Do not poll the login endpoint. It allows 10 attempts per 5 minutes per
address, so a polling loop locks you out within a minute. Wait for the human to
act instead of retrying.
Signed up with a password instead of Google, and the approval broke. The
password path requires verifying your email address first, and starting that
detour interrupts the consent flow you had open. Verify your address, then
start the flow again from the beginning.
A verification email cannot be resent. If it expired before you clicked it,
sign up again with the same address rather than waiting for a second email.
What the new-account response is telling you. It names verifying your
address as the next step, and that is the only thing it actually requires.