Self-hosted on hardware you control, across as many projects and as many machines as you like. Not a trial, not a subset and not the kernel with features switched off. This is the whole thing.
Two machines is worth being precise about, because the two halves of that promise cost different things to run. One machine with any number of projects is the static binary and nothing else. Sharing one brain between machines means one of them holds it and runs Postgres and if they are not on the same network you also run a relay. Both are yours, both stay free however many machines you add: the paid line is drawn on a second person, never a second machine. How that is set up.
The installer detects OS and architecture, verifies the checksum and drops the binary at /usr/local/bin/ns-brain. Nothing is written outside that path until you create a brain.
$ curl -fsSL https://brain.fightclub.pro/install.sh | sh # in the project you want it to remember $ cd ~/projects/yours && ns-brain init initialized ./brain/brain.db · SessionStart and UserPromptSubmit hooks wired
Prefer to fetch it yourself: the builds are at /dl/latest/ with SHA256SUMS beside them. Current version latest-version.txt.
The install put three lines in your agent's settings. One runs before your first turn and puts the brief in context. One runs on every prompt and injects whatever the store matches. One runs at the end and logs what the session did. None of them depend on the model deciding to look, which is the whole point: what depends on being remembered will eventually not be remembered.
# the project's own .claude/settings.json, written by ns-brain init SessionStart $ ns-brain wakeup # the brief, before turn one UserPromptSubmit $ ns-brain hook-recall # what this prompt matches Stop $ ns-brain hook-stop # log the session
The same shape for Codex, Cursor and Gemini with init --agent codex,cursor,gemini. Everything else the agent does with the brain is an ordinary shell command: recall before it searches files, remember when something becomes durably true.
An agent reaches the brain one of two ways and they answer different questions. Hooks answer whether the agent arrived knowing what the project knows. MCP answers whether the agent can reach the brain at all, because it is the only door for a client with no shell. Both run the same code against the same store. Pick by what the client can do, not by preference.
Both are set per project, in different files: the hooks in the project's settings, MCP by claude mcp add in that directory. So one project can run on hooks, the next on MCP and a third on both and nothing is decided for your whole machine unless you add the MCP server at user scope. Claude Code, Codex, Cursor and Gemini can run hooks: use them and stop there. The Claude app, a hosted agent or an IDE that runs no hooks cannot: give it MCP and accept that reading is now the model's decision. A client that can do both may run both, as long as the hooks stay. Click here to see the full comparison.
# hooks: the agent has a shell $ ns-brain init # MCP on this machine: the client launches it $ claude mcp add brain -s local \ -e BRAIN_HOME=$PWD/brain -e BRAIN_PROJECT=yours \ -- ns-brain mcp # MCP from another machine or an agent with no shell $ ns-brain mcp --http 127.0.0.1:7801 --token "$TOKEN"
Your next session opens knowing that, along with the time of day, the branch you are on, how many commits you are behind and any standing rule you have recorded. The brief runs on a hook, so nothing depends on the model remembering to look.
$ ns-brain remember --type infra \ --title "TLS terminates at nginx on 8443, not at the app" \ --body "the app listens on 127.0.0.1:8080 and never sees a cert" remembered #1 [global/infra] TLS terminates at nginx on 8443 $ ns-brain recall "certificates" #1 [global/infra] (score 1.612) TLS terminates at nginx on 8443 the app listens on 127.0.0.1:8080 and never sees a cert
A brain installed into a project that is six months old starts empty while the history sits on disk as session transcripts. ns-brain bootstrap finds them, matching on name so old paths and other machines come too and lists them oldest first with the rules for what to take out.
There is no automatic extractor and there will not be one. A regex pass over transcripts fills a fresh brain with confident noise, which is worse than leaving it empty. We watched a competitor's auto-learner do exactly that: two thirds of its store was function renames and generic advice, all filed at the widest scope and the machinery was excellent. Contents decide whether anybody reads the output.
If you work on one machine, the CLI is the better tool and you can stop reading here. If you have two, the brain lives on one box and every other machine is enrolled against it. The CLI on each of them talks to that one store, so the session hooks keep firing and every command works. That is in the free edition, because the commercial line is a second person and never a second machine.
An agent with no shell reaches the same brain over MCP, as in section 03 and only when it decides to look.
# on the box that holds the brain $ ns-brain hive serve # on each machine you work from $ ns-brain hive login --server https://brain.example.com # says what it will send, asks, then attaches this project # an agent with no shell $ ns-brain mcp --http 127.0.0.1:7801 --token "$TOKEN"
Not on the same network? axon enrols a machine through a relay with a key of its own. The setup page has the rest.
| In Mind | |
|---|---|
| Ranking, decay tiers, supersession, provenance | full strength |
| Every command, every flag | yes |
| MCP server, stdio and HTTP, every command as a tool | yes |
| SessionStart, UserPromptSubmit and Stop hooks | yes |
| Web UI in the binary: read, scope tree, forget | yes |
| One store for many projects, or a file each | yes |
| Per-project opt-out from cross-project search | yes |
| Tasks, measures, the user model, published lessons | yes |
| Full export and import, no lock-in | yes |
| Projects and machines | unlimited |
| A second person on the same brain | Hive |
| Roles, attribution, org axioms | Hive |
| Encryption at rest | Hive |
Encryption is missing on purpose. One developer self-hosting their own data has no second party to be protected from and a key hierarchy nobody needs is a way to lose a brain permanently. The store is mode 600, gitignored and refuses to write text that looks like a credential unless you override it. Full-disk encryption is the right layer for the rest.
The source is not public and no licence has been chosen. Mind ships as a binary and nothing here describes it as open source, because it is not and pretending otherwise would be the first thing a reader could catch us on.
What you can verify without the source: the binary needs nothing installed alongside it, makes one network call on its own (a daily GET of brain.fightclub.pro/latest-version.txt, sending nothing but the request, off with NS_BRAIN_NO_UPDATE_CHECK=1), writes one SQLite file inside your project at mode 600 and hands you every byte of it back with ns-brain export. Point strace or Little Snitch at it if you want that checked rather than believed.
Free for one developer, self-hosted, for as long as you want it.
$ curl -fsSL https://brain.fightclub.pro/install.sh | sh $ cd ~/projects/yours && ns-brain init