One memory for every agent you use.
Nexara Connect is a self-hosted context vault of plain markdown files that your AI agents and your team share, with a scoped grant for every agent.
The problem
Agents forget
Each session starts from zero. You paste the same background again. Decisions made yesterday are gone today.
Every tool has its own memory
Claude knows one thing. ChatGPT knows another. Cursor knows a third. None of them share, and you cannot see or correct what they hold.
Secrets leak into prompts
Keys, contract terms and client details end up pasted into chats. Once an agent has seen them, you have no control over where they go.
How it works
-
Write in markdown
Your context lives as plain .md files in a git repository. Every write is a commit authored by the person or agent that made it.
-
Give each agent a grant
Every agent is its own principal. It gets scoped, revocable grants and a sensitivity ceiling: public, internal, confidential or secret.
-
Connect your tools
One MCP endpoint, a REST API and a git remote. Your agents read the same vault and get only what their grant allows.
-
Review what changes
Writes from read-only agents become proposals that a human approves. Actions are recorded in a hash-chained audit log.
Trust rings
Access widens in rings. The inner rings work today. The outer two are planned.
- You and your devices. Owners see everything, secrets after step-up.
- Your agents. Scoped grants, a ceiling and proposals for review.
- Other people's agents. Planned.
- Public. Planned.
Sealed secret spans are encrypted at rest and redacted for anyone below the secret ceiling.
Connect anything
The same vault, the same grants, whichever client you open.
- Claude Code
- Claude.ai
- ChatGPT
- Codex
- Cursor
- Gemini CLI
- Hermes
- Obsidian
- Any MCP client
- REST API
- git
Built for self-hosting
- One Node container. One volume holds everything.
- Plain files. Your content is a normal git repository you can clone.
- SQLite FTS5 search. Optional local embeddings run inside the container.
- OAuth 2.1. PKCE and dynamic client registration for connectors.
- TOTP sign-in. Step-up for sensitive actions.
- Audit you can verify. A hash-chained, append-only log you can check from the command line.