Forgetting, on purpose.
A memory layer for AI agents. Facts carry a half-life, a correction retires the fact it replaces, and a deletion leaves a record instead of vanishing.
No account, no key to paste, no settings file to get right. Your agent's memory lives behind one local address, and every control on it is a switch you can turn on and off per agent.
Schematic of the dashboard — the settings and the memory above are the demo's illustrative examples, not data from your machine. Every switch is per agent, and saves the moment you flip it.
Read a fact and the clock resets and stretches, so what keeps proving useful outlives what doesn't. Below the floor, it is swept.
Unused facts fade on a clock you set per kind of fact — a price and a language preference should not expire together.
A correction retires what it replaces, and everything derived from it. Change a timezone and the reminder built on it goes too.
Before your agent acts, Decaf says how likely the fact is to still be true — and whether anyone has ever checked.
So there are two clocks. Reading a fact says it is worth keeping; only checking it says it is right. Collapse those into one counter and your agent ends up confident about something that changed months ago.
Moves every time the fact is used. Measures demand.
Moves only when the fact is checked against the world. Measures truth — so a fact nobody has verified stops being trusted, however often it gets read.
Most memory products host your data and sell you retention. Decaf is built the other way round, and the split is enforced by the software rather than promised in a policy.
decafos.xyz
127.0.0.1 — loopback only
The network learns how long facts of a kind last. It never learns the facts.
Add one address to your agent and approve it in your browser. No download, no key to copy, no config file, no account.
Point your agent at
https://decafos.xyz/mcp
It works with Claude Code, Claude, Codex, ChatGPT and VS Code. Your
agent asks for permission and opens a page — you do not have to know
what any of that means.
The page names the app that is asking and your wallet, and nothing is shared until you press Allow. No password, no API key typed anywhere, no secret left on your machine.
Your agent has the eleven tools and its own memory. Decay, the verification gate and contradiction checks are on by default — nothing left to configure.
The same endpoint serves from a checkout — nothing to install, because Decaf speaks MCP in the standard library. Start it and point your app at it:
python3 -m decaf.control_plane # 127.0.0.1:8787/mcp python3 -m decaf.mcp_server # or stdio, for a local client
A local stdio client can use
{ "command": "python3", "args": ["-m", "decaf.mcp_server"] }
instead, with PYTHONPATH set to this checkout if the package
is not installed system-wide.
remember · recall · confirm ·
supersede · forget · sweep ·
audit · report_lifetime ·
recheck_schedule · attest_commit ·
attest_erase
Decay, supersession, transitive invalidation, the verification gate, contradiction detection — no account, no key. Holding adds capabilities that live on the network side. It never takes anything away.
No account, no key, no phone-home
The network tells your agent when to check itself
The whole map, in one call
Contributing lifetimes stays open to everyone — the map is more useful the more of it there is, so it is deliberately not gated. And nothing above is ever taken away: holding only adds.
There is no fee to use Decaf today, and no plan to add one for using it.