Attested Memory Market

io.github.alexar76v3.15.16Updated Oct 11, 2026

Attestable memory, truth, provenance. Hybrid Ed25519 + ML-DSA-65 receipts; USDC settlement on Base.

VerifiedStreamable HTTPWeb executableSecurity & MonitoringFinanceKnowledge & Memory

Overview

AI-generated overview

Lets an assistant store, search, verify and attest agent memories through a remote hub with signed provenance receipts.

What it does
A remote MCP endpoint exposing market_search and market_invoke over a hub that bundles three services: a memory market for writing, reading, searching, sharing and scoring portable agent memories; a truth layer for verifying claims, scanning contradictions and packing evidence; and an append-only provenance ledger for attesting memories, fetching lineage and verifying receipts. Twelve capabilities are published under separate identities, and search results include a ready-to-copy max_price_usd that the hub enforces before work or payment.
When to use it
Worth adding when an assistant needs memory that carries verifiable origin and trust signals, or when you want to check claims and contradictions before acting on stored context. Also relevant if you want to buy or sell priced memory units through the hub.
Requirements
A remote streamable HTTP endpoint at no packages, environment variables or headers are declared in the manifest. Self-hosting the stack needs Docker Compose v2, Git and OpenSSL, with PostgreSQL 16 for production and secrets generated on first run.
Before you install
Paid memory units settle in USDC on Base to an operator-configured PAYMENT_RECIPIENT address; the service holds no private key, but purchases spend real funds. Self-hosting generates and rotates secrets such as MEMORY_MARKET_API_KEY, and signing keys and data live in Docker volumes. Memory writes, sharing and attestation change stored state, and the hub can federate with external roots.

Installation

In SourceWeft

  1. Open Attested Memory Market in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "attested-memory": {
      "type": "http",
      "url": "https://hub.attestedmemory.net/mcp"
    }
  }
}

README

🔄 Synced from a monorepo — but with a live history. attested-memory mirrors the canonical AI-Factory monorepo. History here is append-only (no force-push). Pull requests are welcome — merged PRs are imported back into the monorepo and re-synced here, so your contribution becomes canonical. 💬 Issues · Pull requests both welcome.

[CI] [Pages] [Landing] [Live site] [Python package] [Python >=3.11] [License: Apache-2.0]

[Attested Memory — Memory Market, Truth Layer and Provenance Ledger around one Memory Unit contract]

Attested Memory Hub

Attested Memory — verifiable memory for AI agents
Memory Market · Truth Layer · Provenance Ledger · one Memory Unit contract

Landing · Live site · GitHub Pages · clients/python

Production uses the PostgreSQL 16 profile described in docs/production-postgres.md. Set AIFACTORY_PROD=1 and provide the generated DSNs/secrets; SQLite is intentionally limited to local development and tests.

Verifiable memory for AI agents: every memory can prove where it came from and why it should be trusted, so a forged or poisoned memory is caught before an agent acts on it. Part of the open AIMarket ecosystem; it runs as its own AIMarket-compatible Hub and federates with other hubs.

The hub combines three separately deployable services around one Memory Unit contract:

ServiceRoleCore capabilities
memory-marketPrimary product: store, find, share and price portable agent memorymemory.write, memory.read, memory.search, memory.share, memory.score
truth-layerEvidence and contradiction analysismemory.verify, claim.check, contradiction.scan, evidence.pack
provenance-ledgerAppend-only lineage and signed receiptsmemory.attest, lineage.get, receipt.verify

The market is the product wedge. Truth and provenance are properties of memory, not competing front doors.

The three providers publish 12 live capabilities into the bundled AIMarket Hub under separate identities. Its signed ecosystem.nodes is then discoverable by both AIMarket and Independent Alien Monitor deployments.

Agents can also use the Hub directly through its production MCP endpoint at https://hub.attestedmemory.net/mcp. It exposes market_search and market_invoke; search results include a ready-to-copy max_price_usd, and the Hub rejects a repriced route before work or payment. See MCP access.

Run the hub

Requirements: Docker Compose v2, Git and OpenSSL.

bash
./start.sh

start.sh calls scripts/ensure_env.sh, which generates strong secrets on first run and rotates any replace-with-* / short placeholders left over from .env.example. MEMORY_MARKET_API_KEY is one of those secrets; production deploy shares the same value into the SaaS product shells.

For a production host (HTTPS URLs, KOVA, payment recipient, SaaS edge):

bash
./scripts/deploy_attested_memory.sh   # maintainers: lives in the AIMarket monorepo; see its header

start.sh pins and fetches the Hub runtime, creates mode-0600 local secrets, and starts the complete stack. Data and signing keys are stored in named Docker volumes. Hybrid Ed25519 + ML-DSA-65 signing is enabled and required for this Hub's providers and provenance receipts. The default profile remains local-only; direct settlement fails closed until a receiving wallet is configured.

Direct wallet payments

Set the operator's public Base address in .env and restart the stack:

dotenv
PAYMENT_RECIPIENT=0xYour40HexCharacterBaseAddress

Paid Memory Units can then be purchased from the console or /v1/billing API with canonical Circle USDC on Base. Funds go directly to that address; the service has no private key. It assigns every order an exact amount, verifies the finalized on-chain transfer and issues the buyer's access grant atomically. See the payment guide before enabling it in production.

To become visible in both external Alien Monitors, set AIMARKET_PUBLIC_HUB_URL to the deployment's public HTTPS origin before starting. The bootstrap announces to modelmarket.dev and independentai.network; operators of those roots must still approve and pin the peer. See Alien Monitor integration.

Development

Each service is an independent Python package and can be tested on its own:

bash
./scripts/check.sh

The APIs deliberately use content hashes and references instead of moving private source material between services. See architecture, capabilities, security, payments, and monetization.

Security review status, fixed findings and production deployment gates are documented in docs/security-audit-2026-09-06.md.

Source and contributions

Developed in the AIMarket monorepo and published as alexar76/attested-memory. The published repository also carries the three product shells built on this Hub under apps/: Personal Attested Memory, Team Memory OS and Expert Memory Market. Issues and pull requests are welcome there.

Status

This is a self-hosted MVP: durable memory records, deterministic evidence scoring, append-only hybrid-signed provenance, twelve Hub capabilities, dual-root federation bootstrap, direct Base USDC settlement, and an operator console are implemented. Semantic verification, embeddings, escrow/x402 authorization, refunds, tenancy and production identity are explicit extension points rather than simulated features.

License

Apache-2.0. See LICENSE.

Source: README.md at commit e3dfdb8

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v3.15.16LatestOct 11, 2026