M1K3

Private memory, documents, voice and a local LLM for your coding agents, served on-device by the M1K3 Mac app. 18 tools over a token-protected loopback HTTP server. Source-available.

ドキュメント

Your agent already knows the web. M1K3 is the one that knows you. It runs on your Mac — your documents, your memories, a local brain, a voice — and it answers over MCP at http://127.0.0.1:4242/mcp while the app is open. Three commands put it in front of Claude Code, Codex, Cursor, VS Code or Zed.

$ brew trust round-tower/tap && brew install --cask round-tower/tap/m1k3
$ m1k3 login
$ m1k3 connect claude

The first line is Homebrew: version 6 asks you to trust a third-party tap before it will install from one, and the cask then installs the nightly Developer ID build of M1K3 and symlinks m1k3 — the small command-line client that ships inside the app bundle — onto your PATH.

The second line hands m1k3 the server's access token. Every request to M1K3's MCP server has to carry it; a request without it is turned away with a 401. Copy it from the app (next section), run m1k3 login and paste. It reads the token with echo off, or down a pipe (pbpaste | m1k3 login), never from the command line where your shell history would keep it. When the app is running it checks the token before saving it, and it keeps it in your login keychain.

The third line writes the MCP entry for your agent, token included, as an Authorization: Bearer header. Swap claude for codex, cursor, vscode or zed; add --print to see the config without touching a file.

One switch, once

The MCP server is off by default, and it lives inside the app: open M1K3, then Settings ▸ Privacy ▸ MCP server, and switch it on. The same pane shows the access token, masked, with Copy (for m1k3 login) and New Token…. A new token disconnects every agent until you run m1k3 login and m1k3 connect again. The pane also has a picker for all five agents with the snippet, token filled in, and a Copy button, if you would rather click than type.

Without Homebrew

Download the signed, notarized M1K3.dmg from GitHub Releases and drag it to Applications. Then either use the picker in Settings ▸ Privacy ▸ MCP server, or run the same command from inside the bundle:

$ /Applications/M1K3.app/Contents/Helpers/m1k3 login
$ /Applications/M1K3.app/Contents/Helpers/m1k3 connect claude

M1K3 needs an Apple Silicon Mac on macOS 26. It does not need an account.

Per agent

Five clients, and they genuinely differ — so connect does the safe thing for each and tells you which it did. These are the snippets m1k3 connect <client> --print produces, with your token where these show m1k3_…:

ClientWhat connect doesWhere it lands
Claude CodeRuns the command for youClaude Code's own registry
CursorEdits the file for you~/.cursor/mcp.json
VS CodeEdits the file for you~/Library/Application Support/Code/User/mcp.json
CodexPrints it to paste~/.codex/config.toml
ZedPrints it to paste~/.config/zed/settings.json

the two it edits keep every other server in the file, and get one.bak beside them the first time

Claude Code

$ claude mcp add --transport http -s user m1k3 http://127.0.0.1:4242/mcp --header "Authorization: Bearer m1k3_…"

-s user registers it once for every project, which is the point of a resident. If an m1k3 entry is already there, connect removes it and adds it again, so an entry from before the token gets the header.

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "m1k3": {
      "url": "http://127.0.0.1:4242/mcp",
      "headers": { "Authorization": "Bearer m1k3_…" }
    }
  }
}

VS Code — ~/Library/Application Support/Code/User/mcp.json

{
  "servers": {
    "m1k3": {
      "type": "http",
      "url": "http://127.0.0.1:4242/mcp",
      "headers": { "Authorization": "Bearer m1k3_…" }
    }
  }
}

Codex — ~/.codex/config.toml

[mcp_servers.m1k3]
url = "http://127.0.0.1:4242/mcp"
http_headers = { "Authorization" = "Bearer m1k3_…" }

Zed — ~/.config/zed/settings.json

"context_servers": {
  "m1k3": {
    "url": "http://127.0.0.1:4242/mcp",
    "headers": { "Authorization": "Bearer m1k3_…" }
  }
}

Zed's settings schema has moved more than once — check the shape against your Zed version. That, and Codex's TOML living in a file full of your own settings, is why those two print rather than write.

Tell your agent it's there

A connected server your agent never thinks to call is a wasted server. m1k3 agent-notes --write folds this block into the project's AGENTS.md — or CLAUDE.md, or any path you name. It is marker-fenced, so running it again replaces the block instead of stacking copies:

<!-- m1k3:begin -->
## M1K3 is the resident

M1K3 is a local, private assistant running on this Mac, reachable over MCP. It
holds the user's own documents and memories — so before you search the web, ask
it: \`ask_m1k3\` for a grounded answer, \`search_knowledge\` for the sources behind
one. Persist a durable fact with \`remember\` and it is there next session too.
\`speak\` narrates aloud, which is often kinder than a wall of text.

M1K3 can be down — a "disconnected" MCP server just means the app is closed.
Never block on it; carry on without it.
<!-- m1k3:end -->

Four lines an agent will actually obey beat a paragraph it skims. Run m1k3 agent-notes with no arguments to print it instead.

What your agent gets

Eighteen tools. The short version: it can ask a local brain, search your own documents, keep and recall facts across sessions, speak and listen, and put something on your todo list without ever taking it off.

ToolWhat it does
ask_m1k3Ask M1K3's local brain a question, grounded in your documents and memories
get_answer / list_jobsCollect a long ask by job id; list the jobs queued and finished
search_knowledgeSearch M1K3's stored knowledge — documents, calls, notes; hybrid (vector + full-text) retrieval
list_documentsList indexed items with ids, kinds, and titles
get_documentFetch the text of one indexed item by id
rememberStore text in M1K3's memory, searchable in every future conversation
recall_memoryRecall atomic facts from the temporal memory graph
related_memoryBest-matching fact, plus one step out to its linked or superseded neighbours
forget_memoryPermanently forget a fact — the consent primitive, the counterpart to remember
memory_statsHow many live facts M1K3 currently remembers
speak / stop_speakingSpeak text aloud through M1K3's voice (and animate the avatar); stop immediately
listenListen on the mic and return the transcript when the speaker pauses
list_todosRead the user's todo list — what is open, what is proposed and not yet accepted
propose_todoPropose a todo, stamped with your client's name. Only the user can accept it
get_statusActive brain tier, voice status, and busy flags
open_linkOpen a URL in M1K3's review panel, beside the conversation

The consent gates are deliberate and asymmetric: an agent can remember and it can forget_memory, but it can only ever propose a todo — accepting, completing and dismissing stay with the person.

What it will not do

  • It will not answer another machine. The listener is pinned to 127.0.0.1 at the socket, never an interface address, so nothing on your network can reach it.
  • It will not answer a web page. Requests whose Host header is not a loopback address are refused, and an Origin that is not a loopback page is refused too — the standard defence against a site using your browser to reach a server on your own machine.
  • It will not run while M1K3 is closed. The server is part of the app. A "disconnected" MCP server almost always means the app is not open — which is why the resident block above tells your agent never to block on it. The m1k3 command opens the app itself and waits for the port.
  • It will not answer without its token. Every request has to carry the access token as an Authorization: Bearer header; one without it gets a 401 before it reaches a session. The token keeps out stray scripts that find the port open, and stops a caller without it from knocking your agent off. It is not a defence against malware running as you, which can read any client's config file. The per-tool switches in Settings (listening, deleting memories, opening links) cover that for every caller.
  • It will not write your config from the App Store build (TestFlight today). That copy of m1k3 is sandboxed, so it can neither read ~/.cursor/mcp.json nor run claude for you. There, connect prints the config and says so. The Developer ID build — the DMG and the Homebrew cask — does the write.
  • It will not serve two agents at once. One MCP client at a time, in this version: a second client connecting ends the first one's session.
  • It will not send your documents or memories anywhere. Retrieval, embeddings, inference and voice run on the Mac. M1K3's documented network crossings are unchanged by connecting an agent: a one-time model download you opt into, web search (on by default, one switch in Settings to turn it off), and updates.

Frequently asked questions

Does the M1K3 app need to be running?

Yes, and the server has to be switched on. The MCP server lives inside the app, serves at http://127.0.0.1:4242/mcp only while M1K3 is open, and is off by default — turn it on once in Settings, Privacy, MCP server. A server your agent reports as disconnected almost always means the app is closed. The m1k3 command opens the app for you and waits up to twenty seconds for the port to answer.

Which agents can m1k3 connect for me?

Five, in two ways. For Claude Code it runs that client’s own registration command; for Cursor and VS Code it edits the one JSON file, keeping every other server in it and leaving a.bak copy beside it the first time. For Codex and Zed it prints the snippet for you to paste, because rewriting an editor’s whole settings file on a hunch is the wrong thing for a tool to do.

Is it safe to leave the MCP server on?

It binds to 127.0.0.1 and nothing else, so no other machine can reach it, and it refuses any request whose Host header is not a loopback address or whose Origin is anything but a loopback page — the defence against a web page being tricked into calling it. It also wants its access token on every request, so a stray script that finds the port open gets a 401. The token is not a defence against malware running as you, which can read any client’s config file; the per-tool switches for listening, deleting memories and opening links cover that. Leave it on while you are working, and treat it the way you treat a shell.

What reaches the cloud when my agent uses M1K3?

Not your documents or memories: retrieval, embeddings, inference and voice all run on your Mac. The honest caveats: whatever your agent reads through M1K3 becomes part of that agent’s own context, and a cloud-hosted agent sends its context wherever its conversations go. Local server, client’s rules. And M1K3’s own network crossings are unchanged — a one-time model download you opt into, web search (on by default, so a question M1K3 looks up sends that search to the web; one switch in Settings turns it off), and updates.

What does it cost?

Nothing. M1K3 is free for humans — no account, no subscription, no telemetry. The source is public under the Functional Source License (FSL-1.1-ALv2). Organisations that want one shared brain served to many people on their own hardware have a separate licence, M1K3 for Teams.