Read-only MCP bridge for alethech — verifiable, Ed25519-signed agent memory over stdio.
Verifiable agent continuity protocol — local-first, zero-LLM, zero-blockchain. The art of un-concealing transmission integrity.
Copyright (c) 2026 AliceLabs LLC.
Listed in TeleAI-UAGI/Awesome-Agent-Memory (Emerging projects) after a maintainer audit of the claims against the code.
Now in the official MCP Registry: io.github.eddyflores100-lang/alethech — the read-only alethech-mcp bridge, discoverable by any registry-aware MCP client.
If alethech is useful to you, a ★ star is how other people — and their agents — find it.
From Greek ἀλήθεια (aletheia, "truth as un-concealment") + τέχνη (techne, "art, craft"). The art of revealing that a memory was not modified after being signed.
This is the reference implementation of the protocol specified in docs/implementacion-nucleo-minimo.md (rev 2 + rev 3 identity layer).
alethech provides cryptographically verifiable, portable memory continuity for AI agents. It signs memory commits with Ed25519, links them in a hash-linked DAG, rotates keys without losing identity, and can seal a verified history into one encrypted .aleth file for transfer between compatible runtimes and devices.
What this repo IS:
.aleth, scrypt + AES-256-GCM)python -m alethech.mcp_memory, or alethech-mcp after pip install alethech) exposing verified memory context and verification tools — credentials and paths stay configuration, never tool argumentsinit, commit, evidence, verify, export, import, migrate, key rotate, key revoke)alethechWhat this repo is NOT:
memex project (Python/ChromaDB memory server)cryptography and click — no mem0ai, no chromadb, no ollamaThe legacy memex codebase (167 commits, AliceLabs Proprietary License) is preserved in a separate repository: eddyflores100-lang/memex-legacy. It is not part of this repo and not installed by pip install alethech.
This memory set forms part of a cryptographically verifiable history associated with a determined identity, whose commits can be independently verified with respect to their integrity, cryptographic authorship, and provenance relations.
When a reference checkpoint exists, it can additionally be verified that the presented history continues from that checkpoint.
The protocol does NOT prove that the agent's claims are true — only that they were signed by the identity that claims them. The truth being un-concealed is the truth about transmission integrity, not about content.
Released version 0.9.1 — portable encrypted memory (.aleth v2 with ALETH002 recovery across Python, TypeScript, and Rust) and chat capture into portable memory are live. CI runs the Python suite on 3.10–3.13 plus cross-language conformance and .aleth interoperability across Python, Rust, and TypeScript. No LLM, no required cloud, no blockchain, no consensus.
pip install alethech
For development:
git clone https://github.com/eddyflores100-lang/alethech.git
cd alethech
pip install -e ".[dev]"
alethech init # generate identity + genesis commit
alethech commit --content <json-file> # create signed MemoryCommit
alethech evidence --tool <name> # create signed EvidenceCommit
--input <file> --output <file>
alethech verify # verify the whole store, offline
alethech export --output <dir> # portable package
alethech import --input <dir> # import external memory
alethech key rotate # rotate operational key
alethech key revoke --key-id <id> # revoke a key
alethech migrate --to v0.2 # migrate identity layer
Use the Alethech toolbar icon to capture the loaded conversation, review it, and
create an encrypted .aleth with a new local identity and recovery code. Carry
that file to another device, chat or IDE. The extension imports it and inserts
selected context into an empty chat editor only on request; it never sends.
For any text-capable client, export context.txt. MCP clients can use the local
read-only memory connector. A single offline alethech.html also opens/creates
files without installing an extension or registering an account.
See the complete capture and transfer guide and
IDE/MCP setup. Capture requires only activeTab and
scripting, with no global host or storage permission. Rendered chat capture
cannot retrieve a provider's hidden memories or unloaded conversation history.
.aleth)Alethech 0.9 development adds a single encrypted file designed for drag-and-drop transfer:
from alethech import Alethech
agent = Alethech.initialize("./working-store")
agent.commit({"fact": "portable memory"})
agent.seal("memory.aleth", "your-passphrase")
# Plugin-style path: dropped file -> unlock -> verify -> neutral context
context = Alethech.drop_context("memory.aleth", "your-passphrase")
The .aleth container uses scrypt + AES-256-GCM. Its authenticated payload can be opened byte-exactly by the Python, Rust, and TypeScript implementations in CI. The portable file may carry the encrypted operational signing key so history can continue on another device, but it excludes root.key and recovery.key.
See docs/ALETH_CONTAINER_SPEC.md and docs/ADAPTER_CONTRACT.md.
.aleth container is encrypted.alethech comes from:
So alethech = "the art of un-concealing". The protocol un-conceals:
It does NOT un-conceal whether the content is true — that's the agent's responsibility, not the protocol's.
python -m pytest tests/
The Python test suite covers:
alethech/ # this repo — cryptographic protocol only
├── alethech/ # source: crypto, objects, store, verify, cli, canonical
│ └── integrations/ # langchain + memex hooks
├── alethech-rs/ # Rust SDK (31 tests, cross-validation)
├── alethech-ts/ # TypeScript SDK (15 tests, Web Crypto API)
├── tests/ # Python behavioral, adversarial, mutation and conformance tests
├── conformance/ # 15 adversarial conformance vectors
├── docs/ # protocol specification
├── examples/ # basic_usage.py
├── INTEGRATION.md # how to integrate with memex via MemexAlethechHook
├── CHANGELOG.md # version history
├── SECURITY.md # threat model + vulnerability policy
├── CONTRIBUTING.md # dev setup + PR process
├── CODE_OF_CONDUCT.md # Contributor Covenant
├── CITATION.cff # academic citation
├── LICENSE # MIT
├── README.md # this file
└── pyproject.toml # alethech 0.9.1, deps: cryptography + click only
The protocol is implemented in three independent languages:
| Language | Tests | Dependencies |
|---|---|---|
| Python | CI suite | cryptography + click |
| Rust | 31 | ed25519-dalek, sha2, serde |
| TypeScript | 15 | 0 (Web Crypto API only) |
All three use the same NIST SHA-256 test vectors, RFC 4648 base32 vectors, and RFC 8785 JCS conformance vectors. The cross-language claim is backed by an executable harness:
python conformance/cross_language_check.py
This runs all three implementations against the same shared fixtures in conformance/ and asserts byte-exact agreement on canonical bytes for accepted fixtures. The default run is fail-closed: exit 0 = all three ran and agree, 1 = disagreement, 2 = an implementation/runtime is unavailable. CI builds the Rust helper and executes the three-runtime harness. See conformance/CROSS_LANGUAGE.md for the contract and how to add a 4th implementation.
MIT.
eddyflores100-lang/memex-legacy — Legacy Memex codebase (167 commits, AliceLabs Proprietary License). Python/ChromaDB memory system with MCP integration. Preserved for historical reference. NOT installed by pip install alethech.Copyright (c) 2026 AliceLabs LLC. MIT License.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx alethechMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-eddyflores100-lang-alethech": {
"command": "uvx",
"args": [
"alethech"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencealethechpypialethech works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.