项目文件夹

0
Igor Ilic c0d18c80e2 SDK-601 fix(mcp): Guard SSE transport on main (backport #4994) (#5010)
## Description

Backport of #4994 (SDK-601, authored by @NMZivkovic, merged to `dev`
today) to `main`, so the release branch gets the MCP transport-security
fix without pulling in the rest of dev.

Linear: [SDK-601](https://linear.app/cognee/issue/SDK-601) · related
security report: SDK-605.

What lands (same as #4994):
- **SSE transport gets the Host/Origin (DNS-rebinding) guard.** FastMCP
only wires the guard into the streamable-http app; `create_sse_app()`
silently drops the options, so SSE ran unguarded while the startup log
claimed protection. The guard middleware is now mounted explicitly for
SSE with the same allow-lists, and the loopback default asks for
`"auto"` instead of falling through to FastMCP's unguarded default.
- **`--path` is actually applied** to `http_app()` (the banner used to
advertise a URL that 404'd).
- **Dead code dropped**: the unregistered legacy tool block, its
helpers, `strip_vectors`, and the vendored `codingagents` module —
verified equally unreachable on `main` (only
`remember`/`recall`/`forget`/status are registered through
`ToolRegistry`; the deleted functions carried no registration).
- **Real version in `serverInfo`** (`FastMCP("Cognee", version=…)` from
package metadata) and the transport-security test suite.
- cognee-mcp 0.5.6, `requires-python <3.14` cap, lock regen;
docker-compose e2e moved to streamable HTTP.

## Backport notes

Cherry-pick of the #4994 merge commit onto `main` (`-m 1`). Conflicts
came from dev-only cosmetic refactors (import ordering, `Optional` → `|
None`, `logger.error` → `logger.exception`) entangled with the fix;
resolved by re-expressing the PR's changes on `main`'s base text, so
**no other dev changes ride along** — the residual delta vs dev's
post-PR files is exactly main's pre-existing style.

## Test plan

- cognee-mcp hardening suite (includes the new transport-security tests,
same in-process method as the security report's repro): **53 passed**
against the branch's own lock.
- `uv lock --check` clean in cognee-mcp (pyproject 0.5.6 + regenerated
lock are the exact pair from dev).
- Verified `HostOriginGuardMiddleware` exists in the pinned fastmcp
3.4.6 — no dependency bump needed.
- All changed files compile; ruff (main's 0.15.11 pin) check + format
clean; main's pre-commit hooks passed on commit.
- Full-repo grep: zero remaining references to the deleted
modules/helpers.
2026-09-09 18:07:02 +02:00
2026-02-16 15:43:27 +01:00
2025-01-10 19:37:50 +01:00
2025-05-30 23:13:04 +02:00
2025-01-10 19:37:50 +01:00
2024-03-30 11:57:07 +01:00
2026-09-09 15:35:46 +02:00

Cognee Logo

Cognee - The Open-Source AI Memory Platform for Agents

Demo . Docs . Learn More · Join Discord · Join r/AIMemory . Community Plugins & Add-ons

GitHub forks GitHub stars GitHub commits GitHub tag Downloads License Contributors Sponsor

topoteretes%2Fcognee | Trendshift

Cognee is the open-source AI memory platform that gives AI agents persistent long-term memory across sessions. Ingest data in any format, build a self-hosted knowledge graph, and let every agent recall, connect, and act with full context

🌐 This README is also available in:
Deutsch | Español | Français | 日本語 | 한국어 | Português | Русский | 中文

Cognee Demo

📄 Read the research paper: Optimizing the Interface Between Knowledge Graphs and LLMs for Complex Reasoning — Markovic et al., 2025

When to use Cognee

  • Build a Company Brain. Bring documentation, conversations, tickets, code, and agent work into shared memory. Help your team and agents connect a decision to the discussion and implementation behind it. Explore Company Brain.
  • Give agents memory across runs. Retain project context, past decisions, fixes, and learned rules. Distill useful session lessons into durable knowledge that another session can retrieve. Connect your agent.
  • Ground agents in your domain. Structure memory around the entities and relationships your application needs, with custom data models and ontologies. Explore ontologies.

Choose your starting point

I want to… Start here
See a memory graph without an API key Bundled demo
Build with text, code, and session memory Python quickstart
Give an existing agent memory Plugins and MCP
Run Cognee on my infrastructure Deployment options
Use a managed service Cognee Cloud

Quickstart

Requires Python 3.10–3.14.

You can install Cognee with pip, uv, or your preferred Python package manager.

uv pip install cognee

Try it without an API key

cognee-cli demo

Step 2: Configure the LLM

import os
os.environ["LLM_API_KEY"] = "YOUR OPENAI_API_KEY"

Alternatively, create a .env file using our template.

The default uses OpenAI for language models and embeddings. Processing and generated answers make provider calls. See installation, other providers, or local Ollama models for other setups.

import cognee
import asyncio


async def main():
    # Store permanently in the knowledge graph (runs add + cognify + improve)
    await cognee.remember("Cognee turns documents into AI memory.")

    # Store in session memory (fast cache, syncs to graph in background)
    await cognee.remember("User prefers detailed explanations.", session_id="chat_1")

    # Query with auto-routing (picks best search strategy automatically)
    results = await cognee.recall("What does Cognee do?")
    for result in results:
        print(result)

    # Query session memory first, fall through to graph if needed
    results = await cognee.recall("What does the user prefer?", session_id="chat_1")
    for result in results:
        print(result)

    # Delete when done
    await cognee.forget(dataset="main_dataset")


if __name__ == '__main__':
    asyncio.run(main())

How Cognee works

Cognee builds connected memory from different sources. Text becomes entities, relationships, and searchable chunks; code becomes a graph of symbols and dependencies. Session distillation curates accepted lessons into permanent memory.

Text, code, and session guidance follow their ingestion paths into persistent Cognee memory

At query time, retrieval selects relevant graph, vector, or code context. Your application can inspect the retrieved evidence and use it to answer a question or continue an agent task.

Recall retrieves a document fact, a code symbol, and a learned release rule for an agent's next task

Operation What it does Learn more
remember Store content or code in permanent memory, or in a session when a session ID is supplied. Store memory
recall Retrieve context and answers, using automatic routing or a chosen search strategy. Query memory
improve Enrich memory, apply feedback, and bridge session knowledge into the graph. Improve memory
forget Remove a specific item or dataset. Delete memory

Explore the architecture and session lifecycle.

Connect your agent

Install the Claude Code plugin:

claude plugin marketplace add topoteretes/cognee-integrations
claude plugin install cognee-memory@cognee

or Codex plugin

Make sure to enable hooks:

# ~/.codex/config.toml
[features]
hooks = true
codex plugin marketplace add topoteretes/cognee-integrations --ref main
codex plugin add cognee@cognee

Follow the plugin setup guide to configure local or remote memory.

Interface Start here
Claude Code memory plugin Install and configure the plugin
OpenClaw memory plugin Install @cognee/cognee-openclaw
Cursor, Cline, and other MCP clients Cognee MCP guide and server README
Python applications Python API reference
TypeScript applications TypeScript SDK
Rust applications Cognee-RS
Applications using HTTP REST API reference

Browse the integrations repository for agent frameworks, plugins, and source connectors. Each guide describes its setup and memory capture behavior.

To inspect a local installation in the UI:

cognee-cli -ui

The UI launcher requires Node.js/npm; Docker is needed for its MCP service. See local UI setup.

Explore examples

Deploy Cognee

For a local API demo using a prebuilt image, follow the minimal Docker Compose guide. It includes a persistent-volume configuration and explains the single-user demo settings.

To run the API, UI, and MCP server from a source checkout, clone this repository, enter its directory, copy .env.template to .env, and configure your providers. Then run:

docker compose --profile ui --profile mcp up

The default ports are API 8000, UI 3000, and MCP 8001. For deployment beyond a local demo, configure authentication, persistent storage, and compatible backends using the permissions guide and deployment templates. Cognee Cloud provides the managed option.

Run the Whole Memory Layer on Postgres

Graph memory traditionally means operating a stack — a graph database for relationships, a vector database for embeddings, Redis for sessions, and a relational database for metadata — all deployed, secured, and paid for before an agent remembers anything. In cognee 1.0 you can run the entire memory layer on a single Postgres instance.

⚠️ Warning: Using Postgres as a graph store is currently a released as a demo feature. The production ready feature is available as a licenced product. Use it to demo keeping relational metadata, PGVector, and graph working together

Benchmarks and research

The BEAM evaluation measures conversational memory using synthetic long-context conversations and an LLM judge. The reported runs use Cognee's memory components with benchmark-specific data formatting, prompts, and retrieval configuration.

BEAM context Reported score (0–1) Scope
100K tokens 0.79 Fixed hybrid retrieval; four evaluation rounds over 20 questions from one held-out conversation.
10M tokens 0.67 Exploratory result; question-type routing selected and scored on the same question set, averaged over five rounds.

The two settings use different conversations, ingestion models, and retrieval-selection procedures. Read the methodology, models, limitations, and reproduction instructions before comparing these scores with other systems. The report also documents the remaining reproduction gap for the distributed 10M ingestion.

For the research behind Cognee's graph/LLM interface, see Optimizing the Interface Between Knowledge Graphs and LLMs for Complex Reasoning (Markovic et al., 2025).

Latest News

Watch Demo

  • Cognee comes with better incremental load
  • Cognee now supports ingestion of multiple repositories at once
  • Cognee now has better memory usage
  • Cognee now has better conflict resolution
  • Cognee now has ability to call external relational stores
  • Cognee can now ingest from relational databases at scale

Community & Support

Contributing

We welcome contributions from the community! Your input helps make Cognee better for everyone. See CONTRIBUTING.md to get started.

Code of Conduct

We're committed to fostering an inclusive and respectful community. Read our Code of Conduct for guidelines.

Research & Citation

We recently published a research paper on optimizing knowledge graphs for LLM reasoning:

@misc{markovic2025optimizinginterfaceknowledgegraphs,
      title={Optimizing the Interface Between Knowledge Graphs and LLMs for Complex Reasoning},
      author={Vasilije Markovic and Lazar Obradovic and Laszlo Hajdu and Jovan Pavlovic},
      year={2025},
      eprint={2505.24478},
      archivePrefix={arXiv},
      primaryClass={cs.AI},
      url={https://arxiv.org/abs/2505.24478},
}