Skip to content

Session history

mmw-agent can store your Claude Code and Codex session history in MMW. It is off until you allow it yourself in a terminal.

On this page you will learn:

  1. how consent works and why a model cannot give it;
  2. what is uploaded and what never leaves your machine;
  3. how the agent resumes after an interruption, the quota on each plan, and how to stop everything.
  1. Open a terminal and run (with the same wheel and endpoint as in your client config):

    Terminal window
    MMW_ENDPOINT=https://mcp.mmwhub.tech \
    uvx --from https://app.mmwhub.tech/downloads/mmw-agent/mmw_agent-0.1.4-py3-none-any.whl mmw-agent consent
  2. The agent shows what it found and explains what will be uploaded:

    MMW found local AI session history:
    claude-code 42 sessions, 18.3 MB on disk
    codex 7 sessions, 2.1 MB on disk
    If you allow it, MMW will upload these sessions and every new one to your MMW memory:
    - user and assistant messages, tool calls, tool results cut to 4 000 chars;
    - model reasoning, token counters and file snapshots are NOT uploaded;
    - secrets (API keys, tokens, passwords) are replaced on this computer before upload;
    - file paths are not sent; you can stop at any time with `mmw-agent revoke`.
    Upload session history to MMW? Type 'yes' to allow:
  3. Type yes (or y). Any other answer is a refusal and nothing is uploaded.

  4. The agent replies “Consent recorded for: claude-code, codex. Sync starts within a minute.”

What to know about consent:

  • Only a person can give it. The command works only in an interactive terminal; run from a script or by a model, the agent refuses. The mmw_sync_status tool the model sees only reads state.
  • It covers the clients found. The receipt lists the clients whose sessions were on disk at consent time. If you start using Codex later, run mmw-agent consent again.
  • It is stored locally in ~/.mmw/agent.json (or the directory from MMW_AGENT_HOME) with mode 0600, and the device is registered on the server with the consent receipt. The server accepts no data from an unregistered device.
  • Sync runs while the agent runs, that is, while the client that launches it is open. For a one-off cycle, use mmw-agent sync.

The agent never uploads session files as they are. Each line is parsed and turned into short events.

UploadedNever uploaded
Your messages and the assistant’s replies (very long messages are trimmed)Model reasoning (thinking blocks)
Tool calls with argumentsSystem and developer prompts
Tool results, up to 4,000 charactersToken counters, UI state
Event timestampsFile snapshots
File paths: a source is identified by a hash of its path

Where the agent looks: ~/.claude/projects/*/*.jsonl (Claude Code) and ~/.codex/sessions/**/*.jsonl (Codex). To discover them it only lists files; contents are read only after consent.

your machine MMW server
──────────── ──────────
session line → event → secret scrubbing → scrubbed again → compressed → stored
(same rules) (Memory Guard)
  1. On your machine. Before upload the agent replaces API keys, tokens, passwords, private keys and connection-string passwords with placeholders like [REDACTED:type:hash]. The rules are the server’s own: a test checks that the agent’s copy of the rules file matches the server’s.
  2. On the server. Every accepted chunk goes through Memory Guard again before it is stored.

The secret itself is stored nowhere — only the rule type and a short hash that shows whether the same secret appeared in two places.

Reliability: resuming after an interruption

Section titled “Reliability: resuming after an interruption”

The session files on your disk are the queue; the agent buffers nothing elsewhere. The server remembers up to which byte it accepted each file (a watermark). Every cycle, the agent asks for that watermark and sends what is missing.

  • Network down or server restarted — the next cycle reads the watermark and continues from it. On errors the pause between attempts grows up to 5 minutes.
  • Server restored from backup — the watermark is lower, and the agent re-sends the difference on its own.
  • Server temporarily low on disk space — it accepts nothing, the agent waits (up to 5 minutes between attempts) and continues later. Nothing is lost.
  • A session still being written — the agent sends only complete lines and picks up the rest next cycle.
PlanHistory volumeDepth
Free25 MB7 days
Starter100 MB30 days
Pro500 MB90 days
Enterprise and organizations20 GBfull history
  • The newest sessions go first, so on a limited plan your recent work is what gets in.
  • Sessions older than the plan’s depth (by file modification time) are skipped; the count is shown as skipped_by_plan_history in mmw_sync_status.
  • Volume is counted on the scrubbed text; on the server it is stored compressed.
  • When the quota is used up, the agent stops uploading and shows: “Plan storage for session history is full. Full history is available on the Enterprise plan.”

Ask your assistant “show the MMW sync status” — it calls mmw_sync_status:

{
"consent": { "granted": true, "clients": ["claude-code", "codex"], "granted_at": "2026-10-05T09:00:00+00:00" },
"device_id": "dev-…",
"last_cycle": {
"state": "ok",
"sources": 49,
"chunks": 12,
"bytes": 3145728,
"local_redactions": 3,
"skipped_by_plan_history": 0,
"history_days": 90
}
}

local_redactions is how many secrets the agent replaced on your machine in that cycle. All states (consent_required, offline, quota_exceeded, server_busy and others) are described in the mmw_sync_status reference.

Terminal window
MMW_API_KEY=mmw_your_key MMW_ENDPOINT=https://mcp.mmwhub.tech \
uvx --from https://app.mmwhub.tech/downloads/mmw-agent/mmw_agent-0.1.4-py3-none-any.whl mmw-agent revoke
  • The local receipt is removed immediately; from the next cycle on, the agent uploads nothing.
  • The agent tells the server the device is no longer registered. If the server is unreachable you see “Local consent removed; server not notified” — uploads are stopped anyway; run the command again later to notify the server.
  • Revoking stops uploads but does not delete what has already been uploaded. For deleting data, see Data and deletion.