An append-only ledger of sourced, dated, confidence-scored claims your agent cites and you audit
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
linkedparticles.org Β· docs.linkedparticles.org Β· PyPI Β· Apache-2.0
Particles is shared memory for humans and AI agents. Each particle is one claim, plus what you need to judge it: who said it, where, when, and how confident they were. Facts, opinions, and memories are all claims, recorded the same way as particles. Particles are not edited or deleted. Particles are superseded, retracted, or disputed in the open. How much to trust it is a perspective applied at query time, never baked into the record.
linkedparticles is the Engine of the Particles reference implementation:
the package you install to actually run a belief store. Give it documents,
pages, chat logs, or an agent's own session notes; get back claim-granularity
beliefs, each carrying calibrated confidence, an uncertainty kind, a resolved
subject, and provenance back to the exact source bytes. Ask a question and the
answer cites the beliefs it was built from. Nothing is ever overwritten, so you
can ask the store what it believed a year ago and why it stopped.
When your agent is wrong, you can see exactly why, and fix it at the source.
The Engine is a library first. The HTTP API, the CLI, the read-only MCP server, and the resident daemon are all surfaces over it.
Python 3.11+. linkedparticles-core, the store-free Client layer, is pulled
in automatically.
Because nothing is overwritten, the store can replay its own history. --as-of
is the assertion-time lens. It answers what did the store believe at T, and
why did it stop, not what was true of the world at T:
There is a clickable version of that belief history on the front door. Step by step: getting started, then as-of time travel.
It can also stand in for the reference memory server, and it plugs into LangChain as a retriever and a tool set. See Claude Code memory, swapping in for the reference memory server, and using from LangChain.
Measured on LongMemEval, the multi-session agent-memory benchmark, with a full-context oracle and a no-memory floor run as controls in the same harness:
| Recall@40 | End-to-end QA | |
|---|---|---|
Particles memory (shipped default, top_k 40) | 0.969 | 0.804 |
| Full-context oracle (baseline, n=148) | β | 0.878 |
| No memory (floor) | β | 0.047 |
Method, per-question-type breakdowns, comparator memories, and the budget-matched arm (including the arms where Particles loses) are on the benchmarks page, with the report JSONs of record beside them.
A memory layer is an input-shaping attack surface: it does not merely hold
data, it shapes what the agent believes and does next, so a poisoned claim is
an instruction on a delay timer. Before this code was opened we ran an
adversarial application-security audit over the whole package: the HTTP, CLI,
and MCP surfaces, the filesystem writers, the egress layer, and the build
pipeline. The verdict, verbatim: GO-WITH-FIXES, with 33 findings (2
High, 7 Medium, 20 Low, 4 Info). The ranked must-fix set merged the following
day; the last open finding closed in v1.128.0.
What that bought, and what it did not:
text(), no string-built SQL, no dynamic ORDER BY.The real answer to the residual is epistemic rather than technical: every
particle carries its provenance, source trust is a read-time lens that
discounts a distrusted source without rewriting anything, and lint / review
turn your rulings on contradictions into a reusable trust policy. The store is
a record of what sources said, weighted by how much you trust them, not an
oracle, so a poisoned source is something you can see, discount, and retract
with the audit trail intact.
The limitations we ask you to read before relying on any of this are in SECURITY.md: the unauthenticated read surface, verbatim storage of whatever you deposit (secrets included), the single-operator trust model, and the MCP write boundary. SECURITY.md is also where to report a vulnerability; please report privately.
Most Retrieval-Augmented Generation systems re-derive knowledge from scratch on every query, operating over raw text chunks without any persistent record of what was learned, how confidently it was held, or where it came from. Particles takes a different approach: rather than retrieving passages, it stores discrete, citable, revisable claims (natural-language sentences paired with structured metadata for confidence, provenance, and uncertainty) so that an agent's knowledge accumulates as an auditable ledger rather than evaporating between sessions. Corpus-entry-level provenance is required at Core, meaning every belief can be traced back to the source that produced it, and the particle store itself is a derived view that can be rebuilt from the corpus by re-running extractors, giving the system both durability and reproducibility.
The Particles standard defines the particle schema, the source-corpus model, the extraction protocol, and a set of operations (deposit, extract, query, lint, review, and reindex) that together form the spine along which an agent's knowledge is built, queried, audited, and revised one belief at a time. A developer working with this loop deposits a source into the append-only corpus, extracts claim-granularity particles with resolved subjects, queries by effective-confidence ranking, lints for contradictions and staleness, and reviews inconsistencies into a reusable trust policy. Because particles carry explicit confidence and provenance, Particles can answer queries that require finding relevant claims about a subject and synthesising them with provenance intact, rather than returning a ranked list of chunks whose epistemic status is opaque.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/particles)<a href="https://allmcps.com/mcp/particles"><img src="https://allmcps.com/api/badge/particles?style=directory" alt="Particles on AllMCPs" /></a>