Skip to content

Authentication

Remem uses a bearer credential for protected API operations. Configure it with REMEM_SERVER_API_KEY; production mode refuses to start without one.

Set the key in .env before starting Compose:

Terminal window
REMEM_SERVER_API_KEY=$(openssl rand -hex 32)

Then every protected request includes:

Terminal window
curl http://localhost:4545/api/v1/memories \
-H "Authorization: Bearer $REMEM_SERVER_API_KEY"

The X-API-Key header is also accepted when a client cannot send a bearer header.

The remem-mcp stdio bridge uses REMEM_MCP_API_KEY or its --api-key flag. Keep the value equal to the server key and set REMEM_MCP_URL to the server’s /mcp endpoint when it is not running on the default address.

GET /api/v1/health, GET /api/v1/ready, and GET /api/v1/openapi.json are available for health checks and API discovery. Keep all other endpoints behind the server credential and your normal network boundary.