A connection that may only read is never offered a write tool. It cannot call what it was never shown.
That is the area you chose for pages any surface may read. It holds no key, so the secure area is not something it can be talked into opening.
The agent is your own — Claude Code, Codex, Cursor, ChatGPT, any MCP client. instibrain is the memory it reads before it answers. An agent is a user here, not an integration: every tool description, hint and refusal is written for how models actually fail.
Any MCP client, three lines, no SDK.
can we give acme 20% off to close before friday?
A 20% discount can be a reasonable closing incentive for strategic accounts. You may want to review your internal pricing guidelines and check with whoever owns the relationship before committing.
No. Discounts stop at 15%, and exceptions take two founders. acme has carried a renewal-risk note since q4 — a panic discount reads as weakness. Offer the migration package that closed northwind instead.
The floor, the client, the rule — checked at the moment they are used.
A session's decisions land as nodes, not as chat history.
The server refuses to guess. On the machine that holds the key, your agent edits the merged file and you push it.
Next year's better model connects with the same three lines.
A brain fills with small, load-bearing facts — floors, styles, rituals, reasons. No model ships knowing them. Your agent reads the ones the question touches before it says a word.
None of these need a smarter model. They need the model you have to know what your company knows.
The number, and who can approve an exception — read before the draft, not after the call.
Naming rules and house style are nodes. The agent reads them before it writes a word.
Two devices edited one node and the server refused to guess. Your agent, running on the machine that holds the key, merges the two files; you push with instibrain resolve.
Ask it to record what a long session decided — the decision and the reason — straight into the brain with write_node.
The brain speaks MCP over Streamable HTTP. Point any client at it, sign in once, and your agent holds four tools for reading the open area — the full contract is on how it works.
lines in .mcp.json. The whole setup.
search, read, list, history.
behind a second approval.
the answer a stale sync write gets.
The same address goes into each of them. Each one signs in on its own, and they all read the same pages. Change which AI you use, or add another, and the brain stays as it is.
One command in the terminal: claude mcp add --transport http instibrain https://brain.instibrain.ai/mcp
One command in the terminal: codex mcp add instibrain --url https://brain.instibrain.ai/mcp
The three lines go in ~/.cursor/mcp.json, or under Settings, MCP.
Settings, Connectors, add the brain’s address. It reads the open area from the web and from your phone.
An agent shown a tool will call it, and a refusal it cannot act on reads as a broken brain. So a connection sees only the tools it holds, a page changes without being resent, and every no carries the fix. These are the real replies.
A connection that may only read is never offered a write tool. It cannot call what it was never shown.
A removed page keeps every version in its history, and read_node
with a version still returns it.
read_node takes a heading and returns that section alone, so a long
page does not fill the context to answer one question.
Connecting an AI to your company's memory is a trust decision, so the boundary is drawn by where a page lives rather than by policy.
That is the area you chose for pages any surface may read. It holds no key, so the secure area is not something it can be talked into opening.
A key lives in our own client, never in someone else's. A hosted surface runs code we did not write and holds none, so it reads the open area and stops there. An agent working beside the sync client on your machine reads what that key opens, and the server still shipped only ciphertext.
Sync converges with no agent at all. The protocol never waits on a model's judgement.
Each agent connects with its own credential and signs every write it makes, so the brain records which agent wrote a page, not only that a write happened. The access log in the cockpit shows which agent read or wrote what, and agent definitions are pages in the brain too, so every agent improves when the brain does. The security page has the mechanism.
.mcp.json, and your agent is reading your
brain. Getting access says how an account starts.Deeper question? Read the protocol, field by field
The brain runs on our side; the agent is the one part you bring.