Optional extension trust sheet
Add MemoryEndpoints to LocalEndpoint Connect
Share owner-selected public-safe memory through browser pairing. Installed development Connect 0.2.273 implements it; production qualification remains open.
Current pairing design
Pair in the browser. Never paste a workspace secret.
Local .uai memory remains active and authoritative without MemoryEndpoints. Add hosted sharing only for owner-reviewed public-safe summaries and only after explicit browser approval.
- Development implementation installed
- One-use browser PKCE
- Per-agent credential protected locally
- Production qualification open
- Adds
- Owner-selected public-safe decisions, status, procedures, evidence references, risks, and handoff summaries for approved agents.
- Works without it
- Local
.uaimemory remains active and authoritative. - Pairing
- In Connect, choose Settings → Connect securely in browser. A one-use browser-PKCE flow asks the owner to approve the exact company, workspace, and project once.
- Credential
- After approval, a bound per-agent connector credential is stored in current-user Windows Credential Manager.
- What may leave
- Only summaries the owner has chosen and reviewed as public-safe. Public-safe is an owner decision, not an automatic classification.
- Never paste
- No secret or workspace key is pasted into Connect, LocalEndpoints.com, the setup manifest, prompts, reports, or logs.
- Release truth
- Installed development Connect 0.2.273 implements this client design. No real production round trip or public artifact qualification is claimed; public 0.2.242 remains legacy and unqualified.
- Authority
- Shared memory, public-safe save, and hosted search remain separate owner choices. Installing the manifest alone grants no hosted access or runtime authority.
Four deliberate steps
Connect securely in the browser in four deliberate steps.
The intended and implemented development flow never asks the owner to paste a reusable workspace secret into the app or website.
- 01Add the extension
Save the template as
Download setup filememoryendpoints.com.plugin.json, refresh plugins, and confirm its identity. - 02Use a qualified Connect build
Installed development version 0.2.273 contains the pairing implementation. The public 0.2.242 download is a legacy tester and is not qualified for this flow.
Review public release limits - 03Connect securely in browser
Choose Settings → Connect securely in browser. Connect starts a one-use browser-PKCE request instead of showing a secret-entry field.
- 04Approve exact scope, then verify
Approve the company, workspace, and project once in the browser. Connect receives a bound per-agent connector credential, stores it for the current Windows user, and can then run a redacted connection test.
The setup file selects the extension for local intake. It contains no workspace key or reusable connector credential and cannot complete browser approval by itself.
Evidence, not a badge
Installed development pairing exists; production qualification remains open.
Installed local development version 0.2.273 implements Connect securely in browser, the one-use browser-PKCE client flow, explicit company/workspace/project approval, and local storage for a bound per-agent connector credential. The live service advertises this contract. Neither implementation nor discovery metadata proves a real production round trip, hosted save/search, or a qualified public artifact. Public 0.2.242.0 remains legacy and unqualified.
Historical 0.2.239.0 evidence covered a manual workspace-key UI. That superseded proof is historical only and does not describe current setup.
Development evidence supports
- Installed 0.2.273 browser-pairing implementation
- One-use PKCE and exact approval-scope client contract
- Current-user Credential Manager storage for a bound per-agent connector credential
Still open
- Real production pairing and protected identity readback
- Live hosted save and search
- Publicly downloadable artifact qualification
- Server-side rotation, revocation, and disconnect proof
Stop locally: turn off the memory lanes, disconnect the pairing, and remove the connector credential in Settings. Local removal does not by itself prove server-side revocation.
Keep private material local: do not send credentials, hidden prompts, full files, raw logs, model weights, training data, or private payloads as shared memory.
Setup-file details and technical references
The template includes enabled and userApproved values for accepted local intake. They do not prove a hosted connection, browser approval, or runtime authority. Its installedUtc value is template metadata, not this device's pairing time. No authorization code, secret, workspace key, or connector credential belongs in this file.