Context ledger for agent file reads: lossless re-read dedup, token metering, signed read receipts.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
The flight recorder for your agent's context. A persistent, hook-fed ledger of every file version your coding agent was shown β so a compaction can't destroy the working set, a subagent fleet doesn't pay for the same files N times, and you can prove afterward exactly what the model saw.
When Claude Code compacts, roughly two-thirds of a typical context is tool output β mostly file contents β and compaction discards it permanently. The model then flails: re-reading files it half-remembers, or worse, guessing at contents it no longer has (#27242 is the ask, at 80 π).
The flight recorder closes the loop automatically:
Read/Edit/Write included, not just MCP reads), then
writes a ranked working-set manifest. Fast enough to sit on the compaction path β one
real 14 MB transcript swept in 361 ms; measure yours:
node bench/sweep-bench.mjs <transcript.jsonl>.restore_context β re-emits the working set from current disk state,
budget-capped, annotating any file that changed since the model last saw it.Cross-session memory tools (claude-mem and friends) summarize what happened for the next session. This is the complementary, mid-session layer: file-version-exact recovery of what you were just working on.
Fan-outs are where token waste actually lives. Measured across 195 real multi-agent runs:
19.6% of all subagent Read tokens were duplicate reads of identical content by sibling
agents (5.18M of 26.4M tokens) β every sibling starts cold and reads the same CLAUDE.md,
the same spec, the same core modules.
export_pack ranks the archive's cross-session read history for stable hot files and
renders them as one deterministic block for a custom agent-type's system prompt. The
block is a stable prefix, so the whole fleet hits the provider prompt cache on it. On a
real review fan-out this measured 46.55% cheaper than baseline β and the same pack
injected per-task measured 19.6% worse (every sibling cache-writes it), which is why
the tool tells you where to put it. Both numbers were measured externally on one real
corpus, not by a harness in this repo β exact figures, method, and that caveat are in
BENCHMARK.md. Generate the pack once per run and embed it verbatim:
ranking follows live read history, so repeated export_pack calls can differ.
Observability vendors capture what your agent read into mutable trace stores. Nobody signs it or binds it to repo identity β and agent self-reports are not evidence (ask anyone whose agent claimed it "verified" something it never read).
context_receipt issues an HMAC-SHA256-signed attestation: every file/view shown, the
SHA-256 of every content version, the git blob SHA-1 of each version (so any verifier
with a clone can check git cat-file -e <sha1> β was this ever committed?), repo HEAD
at issue time, delivery kinds, token totals, and an explicit coverage statement of
which capture paths it attests (mcp, and transcript-sweep with include_sweep). By
default it signs with the same key file as trust-mcp receipts, so one key verifies a full
evidence chain: what the agent saw + what it did.
The honest scope: a receipt attests what passed through the ledger and sweeps β it
never claims coverage of unmediated paths, and says so in its own coverage.note.
context_stats shows where the session's file-read tokens went β per repo, per file, in
dollars, counted with a real tokenizer.
Reality check, kept from earlier versions because it's true: as an intra-session token saver this measures ~0% on real Claude Code transcripts (+0.4% with the never-lose engine; the native file-state cache already ate the opportunity β full data in BENCHMARK.md). The savings that DO exist are cross-agent (packs, above). Read-path dedup remains because it is provably lossless and never negative β not because it will save you much on its own.
Wire the flight-recorder hooks in ~/.claude/settings.json (npm root -g shows the
install root; on Windows use forward slashes):
sweep-transcript.mjs (PreCompact + SessionEnd) β captures the working set + exact
versions; bumps the dedup epoch on PreCompact; never blocks compaction.inject-manifest.mjs (SessionStart, matcher compact; add resume if wanted) β
injects the recovered working-set manifest.reset-epoch.mjs (SessionStart, no matcher) β keeps read dedup lossless across new
sessions.Without the hooks everything still works β you just lose automatic capture of native-tool activity and post-compaction injection; the ledger then records MCP reads only.
| Tool | What it does |
|---|---|
read_file(path, symbol?, lines?, force_full?) | Lossless read: full / unchanged-marker / diff. Optional single-symbol or lines:"40-90" views. Refuses binary files. |
read_files(paths[], force_full?) | A working set in one call; per-file errors don't fail the batch. |
working_set(limit?) | Heat-ranked table of what the recorder knows this session (+ last 24h), with staleness vs disk. |
restore_context(files?, budget_tokens?) | Re-emit the working set after compaction β manifest top-K by default, budget-capped, change-annotated. |
export_pack(repo?, top?, budget_tokens?, days?) | Deterministic fan-out context pack from cross-session read history, for an agent-type system prompt. |
outline(path) | Cheap structural map of a file (declarations only). |
context_stats() | Token/dollar breakdown of this session's reads. |
context_receipt(artifact, include_sweep?) | Signed, git-bound context receipt with explicit coverage. |
verify_context_receipt(receipt, signature) | Timing-safe, canonicalized verification. |
The archive lives at ~/.lossless-context/archive (override: LOSSLESS_CONTEXT_DIR),
content-addressed, capped at 512 MiB (LOSSLESS_ARCHIVE_BYTES) with LRU eviction; event
logs age out after 30 days (LOSSLESS_EVENTS_DAYS). Nothing ever leaves your machine.
Files matching secret patterns (.env*, keys/certs, .ssh/.aws paths, credentials β
plus your own LOSSLESS_ARCHIVE_EXCLUDE globs) are never stored β the check covers
both the requested path and its resolved real path, so a symlink to a secret doesn't
bypass it. For excluded files only the path, touch counts, and timestamps are recorded
(no content, and no content-derived metadata like hashes or sizes, which could enable
offline confirmation of low-entropy secrets).
The engine only withholds or diffs content it can prove the model still has, bounded by context epochs (the hooks bump the epoch on compaction, so post-compaction reads are always full). A 400-op randomized invariant test asserts the model's reconstructable view equals disk truth after every operation. Anything less provable is sent in full.
v1.3.0 β the flight recorder: persistent content-addressed archive, transcript sweep
working_set / restore_context / export_pack, receipts v2
(git blob SHA-1 + repo HEAD binding, coverage disclosure, sweep attestation). 71 tests
green including the losslessness invariant; over-the-wire smoke covers the full
sweep β inject β restore loop; real-transcript sweep validated (14 MB in 361 ms). MIT.Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/lossless-context-mcp)<a href="https://allmcps.com/mcp/lossless-context-mcp"><img src="https://allmcps.com/api/badge/lossless-context-mcp?style=directory" alt="Lossless Context Mcp on AllMCPs" /></a>