Skip to content

Team Memory

JanYork edited this page Sep 29, 2026 · 5 revisions

Self-hosted team memory

简体中文 · What’s new

Available in v0.19.3. Personal use remains local and does not require an account or server. Only explicitly bound team spaces are shared.

Start a team

Follow the deployment guide. Deploy behind HTTPS, initialize the owner, and keep the generated administrator.key private. Sign in with that personal key and create a space. Administrators can provision a member and select initial space roles in one transaction, then privately deliver the one-time displayed personal key. Unselected spaces remain inaccessible. Email invitations are single-use, expire, and require the invited verified email address; configure a supported identity provider before using them.

Email verification-code, Feishu and GitHub sign-in are optional deployment configuration. Their actual external-provider login flows were not included in the v0.19.3 acceptance run. Never put a key in a URL or public configuration. Instance admission tokens and personal keys are different credentials; a shared instance token does not grant a user identity or space permissions.

Connect an Agent

lwc login --server https://memory.example.com --key-stdin
lwc space join SPACE_ID --server https://memory.example.com
lwc space configure SPACE_ID --interval-ms 2000 --automatic true

Supply the personal key to the first command’s standard input separately; do not paste subsequent commands into its input. join starts automatic sync by default. The interval is configurable from 250 to 300000 ms. Install the supplied current-user sync service when synchronization must survive logout or process exit; see the deployment guide for each operating system.

Core knowledge, sources, citations/relations, temporal memory and history, discussions, plans, to-dos, detached draft intent and terminal work audit travel through the server to other authorized local replicas. Plugin-owned runtime state, credentials and machine-local execution bindings are not shared. A reader can use lwc cloud --server ORIGIN --space SPACE_ID ... without joining or creating a local memory database.

Read, share and manage

Choose an authorized space after signing in. Search knowledge, open a page, follow knowledge links, or copy its page link. Shared links contain no credential and still require recipient access. Opening a link never grants permissions. The console supports English and Simplified Chinese while preserving stored content.

Space roles and resource/action policies constrain user, device and Agent permissions. Local writes use signed cached policy; the server independently checks current policy and the actual submitted changes. Revocation blocks subsequent server access, but cannot remotely erase data already downloaded.

Conflict and recovery

LWC automatically merges compatible changes. Semantic conflicts preserve both candidates and signal the external Agent through a Hook or the next CLI/MCP interaction. The Agent must inspect and resolve the conflict promptly; the program does not embed an Agent, invoke an LLM or launch one. If no external Agent is running, semantic resolution waits safely with the evidence retained.

Memory recovery appends an audited compensating change instead of overwriting history. Server backup requires stopping the service. Disaster restore writes a new directory and uses current authorization data so old grants are not silently revived. See the protocol, access and recovery contract, and acceptance evidence.

Core schema is 20; server control schema is 6. Back up before upgrade and do not open migrated databases with an older binary.

LWC Wiki

English · 简体中文


Start here · 开始使用

Core capabilities · 核心能力

Practical guides · 实战指南

Capability configuration · 能力配置

Technical design · 技术设计

Operations · 运行与维护

Reference · 参考资料

Contributing · 参与贡献


Repository · Releases

Clone this wiki locally