The install desk
Connect an agent to your org memory.
AirMemo hosts an MCP (Model Context Protocol) server. Add it to the client you already use, hand it an org API token, and the agent can search your in-force context. Installing is a decision your company makes, so the token comes from an owner or administrator, and nothing is written to a developer's tools without that developer running the snippet.
01 · The endpoint
One endpoint, one token, five tools
The server speaks MCP over Streamable HTTP. It exposes five tools:search_context, get_decisions, get_memo, whoami, and propose_context. Four are reads. The fifth files a draft into the approval flow and cannot publish anything by itself.
Endpoint
https://api.airmemo.com/mcpEvery request carries the org token in the Authorization header. A request with no token, or with an unknown, expired, or revoked one, is rejected with HTTP 401 before any tool runs. The token is sent in the header only; the server stores its hash, never the token itself.
02 · The token
Two scopes, minted in the console
An owner or administrator creates the token in the console (Settings, then API tokens). It is scoped, short-lived, revocable, rate-limited, and every call is logged server-side. Reads need memos:read. Calling propose_context also needs memos:create; a read-only token cannot write.
Keep the token out of files that travel with source. Every client below reads it from its own environment or prompt, and the token page in the console carries the same snippets so the token has an obvious next step.
03 · Add the server
Pick your client
Each block is the client's own configuration, with the token kept in the client's env-var or prompt mechanism. Run or paste it yourself, then restart the client.
Claude Code
one command
claude mcp add --transport http airmemo \
https://api.airmemo.com/mcp \
--header "Authorization: Bearer <org api token, scope memos:read>"Cursor
~/.cursor/mcp.json
{
"mcpServers": {
"airmemo": {
"url": "https://api.airmemo.com/mcp",
"headers": {
"Authorization": "Bearer ${env:AIRMEMO_API_TOKEN}"
}
}
}
}Cursor expands ${env:AIRMEMO_API_TOKEN} from the environment the editor was started with. The console token page also builds a one-click install link for this client.
VS Code (Copilot)
.vscode/mcp.json
{
"inputs": [
{
"type": "promptString",
"id": "airmemo-token",
"description": "AirMemo org API token",
"password": true
}
],
"servers": {
"airmemo": {
"type": "http",
"url": "https://api.airmemo.com/mcp",
"headers": {
"Authorization": "Bearer ${input:airmemo-token}"
}
}
}
}VS Code prompts for the token once and stores it masked. Use the portable .mcp.json shape (mcpServersinstead of servers) when the config needs to travel with the repository.
Codex CLI
~/.codex/config.toml
# ~/.codex/config.toml
[mcp_servers.airmemo]
url = "https://api.airmemo.com/mcp"
bearer_token_env_var = "AIRMEMO_API_TOKEN"codex mcp add airmemo --url https://api.airmemo.com/mcp registers the server; the bearer variable is declared in config.toml.
Gemini CLI
one command
gemini mcp add --transport http \
--header "Authorization: Bearer <org api token>" \
airmemo https://api.airmemo.com/mcpThe same entry in settings.json uses httpUrl with a headers object, so a project can keep the value out of the file.
Any other MCP client
npx add-mcp
npx add-mcp https://api.airmemo.com/mcp \
--name airmemo --bearer-token-env AIRMEMO_API_TOKENThe token stays in the environment; the command line never carries it. Per-vendor config files and the events each adapter wires are in the docs.
04 · The approval
Who says yes, and what changes when they do
The connection is approved where the credential is issued. An owner or administrator mints the token in the console and hands it to the requester; that is the approval, and it binds the token to one organization, so it cannot read another org's context.
For organization-wide delivery the deeper path is the hook: it rides the lifecycle events the client already exposes so memos reach every enrolled agent rather than one client. Enrolling a device lands it pending and consumes no seat until an owner or administrator approves it in the console. Revoking a device frees the seat. The commands are in the docs.
Nothing here installs itself. AirMemo does not write a client's MCP configuration, and the only tool that writes anything, propose_context, files a pending draft that a person approves in the console before it can be delivered.
05 · The one-request path
Handing this to your administrator
At a large company the product of a suggestion is an approval conversation, not an install. The requester kit answers the questions that conversation raises, in the order it raises them, with a source line under each answer: what AirMemo is, what leaves a developer machine, what is stored and for how long, the credential and its limits, what an administrator approves, and the security documents that are public today.
Open the requester kitOr start the conversation at the front desk
Evaluating first, with no procurement step? Open the console, create an org, and mint a token. The free tier is real and needs no conversation.