Baron Munchausen 0.5.0

Your session ends. Your project doesn’t.

Local memory for coding agents, on your own machine. One call brings back where the project stopped, what was decided and what comes next — after a closed tab, a spent limit or a change of model. And every answer built on it comes back with a verdict.

Install in two minutes See what it proves

grounded
Four sentences in five are backed by a node, and not one is left over.
partial
Some of the answer stands on the graph. The rest is named, not quietly waved through.
ungrounded
Too little support — or the answer never read the graph before it was written.
checking reading the graph

The answer an agent produced

    Asking whether the hosted endpoint answers…

    Real output of memory_ground against a three-node graph. A sentence counts as backed at coverage 0.60 and above, partial from 0.30, and the whole answer is called grounded only when 0.80 of its sentences are backed and none is left over.

    Nine things it does, each with the number attached

    Every line below is a measurement, not a promise. Follow the link and you get the command that reproduces it.
    Sessions do not break One memory_checkpoint returns the head of the thread, the last 3 sessions, every open loose end and the last 5 decisions — after a closed tab, a spent limit or a change of model. The thread
    Memory that does not lie Every answer comes back grounded, partial or ungrounded, with the sentences nothing backs named one by one. Of 15+ memory products surveyed, not one other returns a verdict on the answer. The verdict
    Any model, any client, any chat 26 tools over MCP stdio and JSON-RPC on 127.0.0.1:8765. Codex, Claude Code, Cursor, llama.cpp, LangChain, a curl one-liner and a chat with no tools at all are equal clients — the harness breaks, the memory does not. Clients
    Work continues without you The dispatcher picks up the next task every 15 minutes and puts one back in the queue after 90 minutes with no result. Anything that needs a human decision is deferred and blocks nothing behind it. Planner and dispatcher
    A task channel the harness cannot break openai/codex#36586, open since 2 August 2026: a subagent’s task payload never reaches a non-OpenAI provider. Measured here: 0 characters delivered that way, 34 through a node id in the graph, SHA-256 matching. Tasks through memory
    The graph, in Obsidian Every node is a note with wiki-links, properties and its verdict. A change reaches the vault in under 5 seconds; rewriting one note out of 3500 takes 0.22 s. Obsidian
    It checks itself The pulse walks the whole graph continuously and calls no model at all: 3300 nodes in 571.7 s on 0.72 % of one core. On a 3455-node graph it filed 52 incidents — stale, dead source, orphan. The pulse
    Cheap because the models are open 242 million tokens of orchestra in a week cost $4.61 through an open-model router — under $0.70 a day. Storing and searching are free; the verdict is the only paid call, 0.0035 USDC. Pricing
    1507 public APIs, each with a date The catalogue ships inside the graph and is re-probed on a schedule: 1229 alive, 70 need a key, 110 dead, 98 could not be checked on 8 September 2026. “Could not check” is its own status, never a death certificate. Catalogue

    Not another memory. One verb that memory owes you.

    Runs on your machine
    A memory server in Python 3.12 with no third-party runtime dependency. MCP over stdio for your client, JSON-RPC on 127.0.0.1:8765 for everything else. No model API, no cloud in the loop.
    Grounded by default
    Call memory_ground without a preceding memory_ground_prepare and the verdict is ungrounded, however well the text reads. Memory cannot be skipped quietly.
    A gate before the write
    Every node runs the P1–P6 protocol — freshness, source, numbers, consistency, reproducibility, completeness — and is stored only at four of six or better. What never enters cannot be cited later.
    An audit you can read
    ground_log.jsonl sits next to your store and is append-only: agent, time, query, node ids, verdict. Every pass, not a sample.
    Your graph, empty on day one
    A fresh install ships an empty template and refuses to overwrite a graph that already exists. We sell the tools, never the data.

    Two minutes, three commands

    1. Get the code and start the server

      Standard library only — there is nothing to install first.

      git clone <repository> baron && cd baron
      python3.12 -m mnemos --host 127.0.0.1 --port 8765 --store blank:$HOME/.mnemos/nodes.json

    2. Check the bridge against the live server

      In a second terminal. The self-test speaks the same protocol your client will.

      python3.12 bridge/mnemos_bridge.py --selftest

    3. Register it with your client

      Claude Code below. Claude Desktop, Cursor, Codex, llama.cpp, LangChain and anything else that reads the standard mcpServers block have ready configs in integrations/.

      bash integrations/claude_code_add.sh

    Health check: curl -s http://127.0.0.1:8765/health answers with {"ok": true, …, "nodes": 0, "ground_by_default": true}.

    Free is the engine. Paid is the verdict.

    Free

    Self-hosted, Apache-2.0

    • The whole engine and all 27 tools
    • Reads and writes: checkpoint, search, recent, add, update
    • P1–P6 gate, duplicate gate, audit journal
    • Obsidian export, project thread, limits tracker
    • Local grounding, with no call leaving the machine
    0.0035 USDC per verdict

    Hosted memory_ground

    • The only paid operation on shinegang.click
    • Charged per call, on the calibrated corpus and thresholds
    • Paid in USDC on Base through x402
    • Reads and writes stay free — no per-operation charge
    • The price is temporary and holds until we have measured what a verdict actually costs to produce

    A typical session under the full contract is three calls — prepare, ground, add — of which one is billed. Account plans on the site add volume limits on top; they do not change what an operation costs.

    The graph, and the pulse walking it

    Memory here is a graph, and something walks it around the clock. The pulse steps from node to node along the links, re-reads what it finds, and flags what has gone wrong: a claim that contradicts another, a fact nobody has confirmed in a long time, a source that no longer answers.

    The graph below is the public corpus — the same twenty-two nodes the live verdict at the top of this page answers from. Hover any point to read the claim it holds.

    There is no screenshot of anybody’s Obsidian here, and that is on purpose. A Graph view shows the titles of the notes it contains, so a picture of a private vault hands out private notes as surely as pasting them would. What is drawn is what may be drawn.

    The numbers are from our own graph, on the date shown, and they are four counts and nothing else — no node identifier reaches this page, and none of ours is drawn on it. The stale and dead-source figures are our own faults, published because a product about honest memory that hid its own would be the joke it is named after.

    Open the Hub

    Reading the corpus…
    Reading

    Why he is called a liar

    Karl Friedrich Hieronymus, Freiherr von Münchhausen, was a real cavalry officer who came home from a real war and told stories at dinner. Someone wrote them down and printed them without asking, and after that the name meant one thing: the man nobody believes.

    The stories are two and a half centuries old and out of copyright; the drawing is ours, built out of cells by tools/site/pixel_scene.py and reproducible with one command. It uses four shades of the page’s own ink and not one saturated colour — on this page the only thing allowed to be brass is a verdict.

    We took the name because the mechanism is the same shape as the joke. An agent that answers from memory is in exactly his position: fluent, confident, and unbelievable — until something checks it sentence by sentence and hands back a number. Then the tall tale is either backed or it is not, and either way you can see which.

    The Baron: a pixel portrait in four shades of the page’s own ink, wearing the tricorne that is the mark
    62 × 52 cells, four tones, 2.9 KB of paths. The tricorne is the same silhouette as the mark in the header, three times the size.

    And the engine underneath

    Measured in this repository on 8 September 2026.
    Verdict Three values, two thresholds: a sentence is backed at coverage 0.60, partial from 0.30; the answer is grounded at 0.80 of sentences backed with none unsupported.
    Test suite 1104 passed, 75 skipped, 0 failed on bare Python 3.12 with pytest; every skip is an optional dependency that is missing on purpose.
    Runtime Python 3.12 and the standard library — 0 third-party packages at runtime, one process, one JSON file, one port on loopback.
    Limits tracker Subscription windows and spend for the model clients you already pay for, with the switch command ready. Free, and it stays free.