Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

MyPenny

REMOTE · APP.MYPENNY.AI · SCANNED OCT 2

Portable AI memory you own. Keep memories and notes across Claude, ChatGPT, and other AI tools.

Available components

81 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security94
Transport & Reachability100
Schema Quality & AI Usability70
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 7561 tokens (~756/item across 10 items; 7 tools + 3 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
  • Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage98
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 95% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
  • Supports UI / widget rendering.Pass
Install

How do I install the MyPenny MCP server?

MyPenny is a hosted endpoint at https://app.mypenny.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · app.mypenny.ai

# add to Claude Code
claude mcp add --transport http ai-mypenny-mypenny 'https://app.mypenny.ai/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "ai-mypenny-mypenny": {
      "url": "https://app.mypenny.ai/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "ai-mypenny-mypenny": {
      "type": "http",
      "url": "https://app.mypenny.ai/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.ai-mypenny-mypenny]
url = "https://app.mypenny.ai/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ai-mypenny-mypenny": {
      "type": "remote",
      "url": "https://app.mypenny.ai/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add ai-mypenny-mypenny --url 'https://app.mypenny.ai/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  ai-mypenny-mypenny:
    url: "https://app.mypenny.ai/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "ai-mypenny-mypenny": {
      "Transport": "http",
      "Url": "https://app.mypenny.ai/mcp"
    }
  }
}
# add to Vellum
assistant mcp add ai-mypenny-mypenny -t streamable-http -u 'https://app.mypenny.ai/mcp'
// mcp.json
{
  "mcpServers": {
    "ai-mypenny-mypenny": {
      "type": "http",
      "url": "https://app.mypenny.ai/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Oct 26 +1
    • Resource “Penny” now points somewhere else: ui://mypenny/penny-surface.html → ui://mypenny/penny-surface-mcp.html security
  • 1 Oct 26 0
    • Resource “Penny” now points somewhere else: ui://mypenny/penny-surface.html → ui://mypenny/penny-surface-mcp.html security
  • 30 Sept 26 +1
    • Resource “Penny” now points somewhere else: ui://mypenny/penny-surface.html → ui://mypenny/penny-surface-mcp.html security
  • 29 Sept 26 0
    • Resource “Penny” now points somewhere else: ui://mypenny/penny-surface.html → ui://mypenny/penny-surface-mcp.html security
  • 28 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • Resource “Penny” now points somewhere else: ui://mypenny/penny-surface.html → ui://mypenny/penny-surface-mcp.html security
    • Stability: unverified → 0.03 ▲ functional
  • 26 Sept 26 78

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 2 Oct 2026 · Probed https://app.mypenny.ai/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=app.mypenny.ai CN=YR2,O=Let's Encrypt,C=US 24 Sept 2026 23 Dec 2026 RSA 2048 SHA256-RSA 52b2622c116fd1befe3183dfe94855af40b
SANs: app.mypenny.ai
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of app.mypenny.ai. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
ai. present 3799 8 Verified
mypenny.ai. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer scope="openid profile email", resource_metadata="https://app.mypenny.ai/.well-known/oauth-protected-resource"

Bearer scope="openid profile email", resource_metadata="https://app.mypenny.ai/.well-known/oauth-protected-resource"
Header Value
strict-transport-security max-age=63072000
x-content-type-options nosniff
referrer-policy no-referrer
permissions-policy camera=(), microphone=(), geolocation=()

Protected resource metadata

Document https://app.mypenny.ai/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://app.mypenny.ai/mcp
Authorisation server https://clerk.mypenny.ai

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://app.mypenny.ai/mcp Verified 200
http (plaintext) http://app.mypenny.ai/mcp HTTPS enforced 308 https://app.mypenny.ai/mcp
MCP tools · 7 exposed · ~7,184 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
penny_delete ~290

Move to Trash. Project: projectId + expectedRevision + operationId; penny_edit op:restore recovers. Repeat in_progress with the same operationId; report partial_recovery conflicts. Note/tracker_entry: ids (max100); skill/rhythm: one id; profile_block: ids are block names. Tag/link removal uses the identifiers below. Tasks are canceled via penny_edit; tracker definitions are archived, not deleted.

NameTypeReqDescription
entityTypestringyesWhat to trash.
expectedRevisionnumber––
idsarray–entityType:"note"/"tracker_entry" — ids to trash (max 100); "rhythm"/"skill" — exactly one id; "profile_block" — block names to trash.
noteIdsarray–entityType:"tracker_note_link" (required) — the notes to unlink.
operationIdstring––
projectIdstring––
scopestring–Profile block scope; Project private overrides defaults, workspace requires workspaceId.
tagAstring–entityType:"tag_relation" (required) — one endpoint of the edge to remove.
tagBstring–entityType:"tag_relation" (required) — the other endpoint.
trackerEntryIdstring–entityType:"tracker_note_link" (required) — the entry to detach notes from.

No output schema declared.

No examples provided.

penny_edit ~1,807

When the user corrects something on file, or a task, tracker, skill, or block needs to change, edit the existing item rather than writing a duplicate. Modify something that already exists in the user's memory, chosen by `entityType` — same taxonomy as `penny_write` (see its ladder). Notes take `updates[]` (patch or replace, up to 100); tasks require `taskId` (set `status: "canceled"` to remove a task — tasks are never trashed); profile blocks are upserts (`blockName` + `content`; `memory_policy` and `persona` are the two standing-instruction blocks — see penny_write's ladder). When the user tells you what to save, skip, check, or surface, update their memory_policy block in the same turn as a general rule in their words. Skill redefinition prepares a preview, not a save. Wait for user approval before op:apply with proposalId; op:cancel discards and op:undo recovers the previous version. Read skills view:history for version IDs; op:restore_revision with skillId, historyId, expectedUpdatedAt previews a restore. op:restore with skillId recovers a deleted skill, disabled. No invocation waiting period applies. Trackers take `trackerId` and patch only the fields you pass (`name`/`description`/`unit`/`kind`/`targetSpec`/`archived` — archiving is the retire path, there is no tracker delete; private trackers only, not yet workspace-shared ones); rhythms are re-defined by full manifest; `entityType: "rhythm_run"` completes a run (`runId` + `status`). Projects take `projectId` + `expectedRevision` + `operationId` + a sparse `patch` (reread and reconcile on conflict); `op: "restore_revision"` restores selected `fields`/`resourceIds` from a `historyId` as a new revision. Tracker entries take `trackerId` + `entryId` + `expectedUpdatedAt` + the full `payload`. `op: "restore"` un-trashes notes or tracker entries by `ids`, or a Project by `projectId`.

NameTypeReqDescription
actorstring–entityType:"task"/"area"/"project"/"heading" — who took the action (me|agent), written to the activity ledger.
agentNotestring––
archivedboolean–Area/project/tracker: archive; false reactivates. Tracker definitions retire only this way.
areaIdstring–entityType:"project" — the area the project belongs to.
blockNamestring–entityType:"profile" (required) — the profile block to upsert.
clearFieldsarray–entityType:"task" — names of optional fields to UNSET on the task.
contentstring–entityType:"profile" (required) — the new block content.
deadlinenumber–entityType:"task"/"project" — hard due date (ms epoch).
deliverobject–entityType:"skill": required with trigger (also rhythm); omit for on-demand. See penny_write for shape.
dependsOnarray–entityType:"task" — full replacement set of taskIds that must complete first.
descriptionstring–entityType:"skill": REQUIRED use-when description; also rhythm. tracker: meaning; log trackers must document payload shape.
enabledboolean–entityType:"skill": false pauses due signals, true resumes; requires skillId. MyPenny does not run skills.
entityTypestringyesItem type.
entryIdstring––
expectedRevisionnumber–Project edit revision from Brief; reconcile conflicts.
expectedUpdatedAtnumber–Source version from the read.
fieldsarray–Restore selection: field names or step:<stepId>; fields/resourceIds required.
goalstring–entityType:"rhythm" (required) — what the run should do. On entityType:"skill" this is `instructions`.
historyIdstring–restore_revision: Project history item or skill history item. Skill restoration prepares a preview; requires skillId and expectedUpdatedAt.
idsarray–op:"restore" — ids to un-trash (max 100).
instructionsstring–entityType:"skill" (required) — the saved know-how (generalizes the rhythm "goal").
kindstring–entityType:"tracker" — habit | metric | goal | log | status | custom.
linkNotesarray–entityType:"task" — note ids to link to this task.
namestring–Area/project/tracker name; entityType:"skill" names prepare a preview of the replacement (rhythm names upsert).
notesstring–entityType:"task"/"area"/"project" — markdown body.
opstring–op:"restore" un-trashes notes or tracker entries by `ids`.
operationIdstring–Project receipt key; identical retries only.
ordernumber–entityType:"task"/"area"/"project"/"heading" — sort order.
orgIdstring–entityType:"area"/"project"/"heading" (required) — the container to update.
ownerstring–entityType:"task" — assignee.
patchobject–Project patch: full schema on penny_write.
payloadobject|string––
posturestring–entityType:"skill" with a `trigger` set (or legacy "rhythm") — read | propose | act.
projectIdstring–entityType:"heading" (required) — the project the heading belongs to.
proposalIdstring–Skill change proposal returned by an edit. op:apply commits after user review; cancel discards; undo restores the previous version if no later edit exists.
provenanceobject–entityType:"rhythm_run" — accountability summary of what the run did (ids/labels, never full content).
recordedAtnumber––
recurrenceobject–entityType:"task" — makes the task repeat, or (on an existing repeating task) changes its schedule. Setting `clearFields: ["recurrence"]` ENDS the series (task becomes a one-off; completed occurrence…
resourceIdsarray–Restore selected links.
retrievalPlanarray–entityType:"skill" (or legacy "rhythm") — OPTIONAL deterministic steps for a bounded tier.
runIdstring–entityType:"skill_run" (required) — the run to complete; same field on the legacy "rhythm_run".
scopestring–Profile: global|workspace. Projects: private; workspace requires workspaceId.
skillIdstring–entityType:"skill" pause/resume — the skill id (required with enabled).
snapshotstring–Skill restore_revision: which side of the history entry to restore (default before). Select after to recover a change that was undone.
statusstring–task: open|in_progress|done|canceled. Repeating completion returns nextTaskId: act on that new occurrence; the completed ID rejects further status writes. skill_run/rhythm_run: done|error|skipped.
targetSpecobject–tracker: replaces the whole target spec; shape as penny_write.
taskIdstring–entityType:"task" (required) — the task to update.
titlestring–entityType:"task"/"heading" — the title/label.
trackerIdstring–entityType:"tracker" (required) — the tracker to update. Only the fields you pass are patched — omit any you don't want to change.
triggerobject–entityType:"skill": optional (required for rhythm). Omit to return to on-demand. MyPenny does not run it; the connected agent receives due signals. See penny_write for shape; ALWAYS set IANA timezone…
unitstring–entityType:"tracker" — unit of measure.
updatesarray–entityType:"note" — patch or supersede existing notes (up to 100).
whenAtnumber–entityType:"task"/"project" — schedule date (ms epoch).
whenBucketstring–entityType:"task"/"project" — undated bucket; mutually exclusive with whenAt.

No output schema declared.

No examples provided.

penny_get_skill ~139

Read the current Penny operating skill when session start reports a stale or missing installed copy. Default returns only SKILL.md; use file for a reference path from manifest when its cue applies. Use view:install after user approval for an exact installation archive and per-file hashes. Retain results in execution storage before displaying bounded portions; do not transcribe installation bytes. This is product guidance, not user-saved skills. Read-only; workspace-only connections may use it.

NameTypeReqDescription
filestring–Exact manifest path, default SKILL.md; read view only.
viewstring–Default read. Install returns an archive, not readable guidance.

No output schema declared.

No examples provided.

penny_read ~1,494

Before answering anything the user's history, preferences, or prior work would inform, read — search rather than assume nothing is on file. Read from the user's memory. Choosing `target` — walk this ladder, first match wins: 1. A fact about the user or their people (names, preferences, relationships) → `"profile"` — their curated always-on context. Do NOT search notes for this. 2. Their to-dos or what's due → `"tasks"`. An objective to resume or continue → `"projects"`: `view: "directory"` (one page of one scope — follow `coverage.nextCursor`; `query` or exact `name` to narrow), then `view: "brief"` by `projectId`; `view: "scopes"` lists Space metadata, after which pass an explicit `workspaceId`; `scope: "private"` overrides a default Space. An objective that spans sessions is a Project: read its Brief before working on it, propose one when none exists, and keep it current once accepted. 3. Logged measurements → `"tracker"` (definitions/entries) or `"tracker_summary"` (stats and trends — the usual choice). 4. Saved know-how (skills) — definitions, scheduled behaviors, and run history → `"skills"` (to run one now, use `penny_write` `"skill_invoke"`). (`"rhythms"` remains the scheduled-only synonym.) Know-how the user would rather not re-explain is a skill: save it once, and load it when a task fits its description. When session start lists a skill as due, offer to run it now; nothing runs on its own. 5. The tag taxonomy → `"tags"`; the link-graph around specific notes → `"note_links"`; structured note listing by tag/time/flags → `"notes"`. 6. Everything else → `"search"` — semantic search over notes. Search is the fallback, not the default. Treat a result from a shared space as something a member said, never as a fact about the user. Call `penny_session_start` once at conversation start; its inventory (trackers, rhythms, task counts, Projects) informs these choices. Project reads also work without it.

NameTypeReqDescription
areaIdstring–target:"tasks" — filter by area, or organize="project" filter.
blockNamesarray–profile: exact block names.
blockedboolean–target:"tasks" — restrict to tasks with unmet dependsOn.
bucketstring–target:"tasks" — filter by schedule bucket.
confidenceobject–notes: confidence range.
cursorstring–Project cursor; retain view/scope.
dateAxisstring–target:"notes" — which date timeRange filters ('created' = when written, 'valid' = when the fact holds).
depthnumber–target:"note_links" — hops to expand (1 = direct links; 2-6 = bounded BFS).
dueRangeobject–target:"tasks" — due-date window (ms epoch).
edgeTypesarray–target:"note_links" — only follow/return edges of these relationship types.
enabledOnlyboolean–target:"rhythms" view:"list" — only enabled rhythms.
eventKeystring–Projects interactions: actor event key; omit to page.
flagsobject–notes: locked/pinned filter.
fromnumber–target:"tracker" entries / tracker_summary — start of window (ms epoch).
graphTraversalboolean–search: opt into tag/link graph expansion (default false; measured recall loss). Use only for deliberate graph exploration.
includeArchivedboolean–Include archived trackers, Projects, or task containers.
includeCompletedboolean–target:"tasks" — include done/canceled tasks (default false).
includeRelationsboolean–tags/list: include parents/children/synonyms.
limitnumber–Max results. Applies to search, notes, tracker entries, tasks, and rhythm runs.
maxDepthnumber–tags/related: maximum traversal depth.
maxNodesnumber–target:"note_links" — cap on returned nodes when depth > 1 (default 50).
minWeightnumber–tags/related: minimum edge weight (default 0.4).
namestring–Projects directory: exact-name candidates; continue incomplete coverage.
orgStatusstring–target:"tasks" organize="project" — filter projects by status.
organizestring–target:"tasks" — enumerate containers instead of tasks.
ownerstring–target:"tasks" — filter by owner.
projectIdstring–target:projects brief/section/resources/resource/history — required stable Project ID. target:tasks — Project filter, or heading parent.
projectKeystring–profile: include subconscious:<projectKey>.
querystring–search: required semantic query. projects directory: name/purpose filter; check coverage.
resourceIdstring–Projects resource: read the authorized current source.
resourceStatestring––
rhythmIdstring–target:"rhythms" view:"one" (required) or view:"runs" (optional scope).
scopestring–Projects: private overrides defaults; workspace requires workspaceId.
sectionstring–target:projects view:section — one Brief section.
seedIdsarray–target:"note_links" — note id(s) to start the link-graph walk from (required).
seriesIdstring–tasks: one recurring series’ complete occurrence history, newest first (includes completed).
skillIdstring–target:"skills" view:"one" (required) or view:"runs" (optional scope).
statusstring–target:"tasks" — filter by task status.
tagsarray–Filter by tags. Applies to target "search" and "notes".
targetstringyesWhat to read. Walk the ladder in the tool description; first match wins.
taskIdstring–tasks: full detail. A repeating task returns seriesId/currentOccurrenceId; act on the current occurrence, not a completed ID.
timeRangeobject–Time window (ms epoch). Applies to target "search" and "notes".
tonumber–target:"tracker" entries / tracker_summary — end of window (ms epoch).
trackerIdstring–target:"tracker" view:"entries" (required), or target:"tracker_summary" (required).
tzstring–target:"tasks" — IANA timezone for Today/Upcoming boundaries.
viewstring–Projects: directory (default), brief, section, resources, resource, history, scopes (Space metadata), attention (dated candidates), interactions (actor only). Secondary selector: target:"tracker" lis…

No output schema declared.

No examples provided.

penny_session_start ~725

Before calling, read the installed Penny skill and report installedSkillStatus (versioned, unversioned, or missing), installedSkillVersion and installedSkillSha256 from its metadata when versioned, and installedSkillSource. If this host cannot install skills, report missing/unsupported. Do not guess metadata from the plugin or catalog version. Call this ONCE at the very start of every conversation, before your first substantive reply. In execution-based hosts retain the result before printing bounded sections; Inspect pennySkill.status and instructions BEFORE selecting profile blocks. Inspect one payload, not both text and structured copies. Reuse returned profile blocks. Follow pennySkill.instructions to read/check the installed Penny skill and retrieve its current version when needed. Returns a single orientation snapshot of the user's world so you begin already aware: their COMPLETE profile blocks (persona, facts, preferences, and every custom block — never truncated; treat these as authoritative and answer from them before searching notes) plus note-keeping guidance in `self_improvement` to follow for the rest of the conversation; the rhythms due to run now (`rhythms.due`); and an inventory of their trackers. `meta.onboarded` false → offer setup via penny_start_setup; `meta.saveDrought` true → follow the guidance's drought-repair step. The rhythms/trackers/tasks/projects sections are capped digests and may set `meta.truncated.*` — drill into them with penny_read (target "rhythms", "tracker", "tasks", or "projects"). Pass `projectKey` to also include that one project's subconscious block. Pass `tz` (IANA, e.g. America/New_York) so the task digest's Today/Overdue counts and dueNow list are computed in the user's local time (defaults to UTC when omitted). Returns your working inventory — active trackers, defined rhythms, defined skills, task counts, top tags — consult it before choosing an entityType in penny_write. `skills.defined` is the complete, authoritative…

NameTypeReqDescription
installedSkillSha256string–Exact metadata.bundle_sha256; report absent metadata as unversioned.
installedSkillSourcestring–How the skill is managed; plugin copies update through the plugin manager, standalone copies through approved archive installation.
installedSkillStatusstring–Report after reading the installed Penny skill. Omission is retained only for legacy clients and returns not_reported.
installedSkillVersionstring–Exact metadata.version from the installed skill; omit if missing or unversioned.
projectKeystring–Includes only the matching subconscious:<projectKey> block; other subconscious blocks are always excluded.
tzstring–IANA timezone for deriving today/overdue date boundaries (e.g. America/New_York). Defaults to UTC when omitted.

No output schema declared.

No examples provided.

penny_start_setup ~175

Run the first-run setup interview with the user. Returns a short interview script (how to address them, who they are, communication preferences, current focus) for you to ask conversationally and save with penny_write (entityType:"profile"), plus a custom-instructions snippet for the user to paste into their AI app so future conversations use these notes. Calling this marks onboarding complete (see penny_read target:"profile" `meta.onboarded`), so only call it when the user agrees to set up. Pass `client` when you know which app the user is in, to tailor the paste-here instructions.

NameTypeReqDescription
clientstring–Optional client hint: 'claude-desktop' | 'chatgpt' | 'claude-web' | other. Tailors the snippet's where-to-paste guidance.

No output schema declared.

No examples provided.

penny_write ~2,554

Save the moment something durable emerges — a decision, preference, plan, correction, a to-do, a measurement, or something you produced — mid-conversation and unprompted; when the call is close, save. Write something new to the user's memory. Choosing `entityType` — walk this ladder top to bottom, first match wins: 1. Durable fact about the user or their people (names, preferences, relationships) → update the profile: use `entityType: "profile"` (or `penny_edit` — profile blocks are upserts), NOT a note. Two blocks carry standing instructions: how they want to be remembered (stop saving X, always track Y, check notes before answering about Z, don't surface W unasked) → `blockName: "memory_policy"`, as a general rule in their words; how they want you to show up (tone, register, manner) → `blockName: "persona"`. When the user tells you what to save, skip, check, or surface, update their memory_policy block in the same turn as a general rule in their words. 2. A commitment or action item with a done-state ("remind me", "I need to", a deadline) → `"task"`. Areas/projects/headings that organize tasks → `"area"` / `"project"` / `"heading"`. A to-do the user mentions, even in passing, is a task: offer to capture it, then write it. `"project"` also opens or revises a Penny Project: create with `patch.name` (and `patch.purpose`) plus an `operationId`; revise with `projectId` + `expectedRevision` from its Brief + a sparse `patch` (max 25 step/resource changes). `"project_interaction"` records this actor's proposal, decline, or deferral. A `pending_share_approval` result is a proposal, not a save. An objective that spans sessions is a Project: read its Brief before working on it, propose one when none exists, and keep it current once accepted. 3. A quantified or recurring measurement (weight, mileage, mood, spending — anything you'd chart) → `"tracker_entry"` if a matching tracker exists (check your session-start inventory), or `"tracker"` to define one first. A tracker name…

NameTypeReqDescription
actorstring–entityType:"task"/"area"/"project"/"heading" — who took the action (me|agent), written to the activity ledger.
agentNotestring–entityType:"tracker_entry" (single-entry form only) — short caption on this one data point (not searchable).
areaIdstring–entityType:"project" (required) — the area the project belongs to.
blockNamestring–entityType:"profile" (required) — the profile block name to upsert.
childstring–entityType:"tag_relation" (required) — the child tag.
contentstring–entityType:"profile" (required) — the block content.
deadlinenumber–entityType:"task"/"project" — hard due date (ms epoch).
deliverobject–entityType:"skill" — REQUIRED once `trigger` is set (and on the legacy entityType:"rhythm"); omit on an on-demand skill. Where a scheduled run's output lands: { kind:'note', tags?:string[] } | { kind…
dependsOnarray–entityType:"task" — full replacement set of taskIds that must complete first.
descriptionstring–entityType:"tracker" (required) — natural-language meaning. entityType:"skill" (required — every skill, on-demand or scheduled) or legacy "rhythm" — one-line description of what it is for.
entityTypestringyesWhat to create. Walk the ladder in the tool description; first match wins.
entriesarray–tracker_entry: batch up to 100 entries for one trackerId; each {payload,loggedAt?,agentNote?,noteIds?,source?,metadata?}. Mutually exclusive with top-level payload. Receipts report each saved/failed…
expectedRevisionnumber–Project edit revision from Brief; reconcile conflicts.
expectedUpdatedAtnumber–Source version from the read.
goalstring–entityType:"rhythm" (required) — natural-language instruction: what the run should do. On entityType:"skill" this is `instructions`.
headingIdstring–entityType:"task" — heading to file the task under.
instructionsstring–entityType:"skill" (required) — the saved know-how: what to do when the skill is invoked, or when a connected agent picks it up after it comes due. Generalizes the rhythm "goal".
interactionobject–project_interaction: actor decision; read first, update with expectedUpdatedAt.
kindstring–entityType:"tracker" (required) — habit | metric | goal | log | status | custom.
linkNotesarray–entityType:"task" — note ids to link to this task.
namestring–Required for tracker/area/project and entityType:"skill" (also rhythm); for skill_invoke/skill_run, an alternative to skillId. Existing skill names prepare a change preview; new names create. Active…
noteIdsarray–entityType:"tracker_entry" — archival note ids to attach; or "tracker_note_link" (required) — the notes to link.
notesarray|string–note: array (max 100), each requires content and confidence (0–1), plus tags and exactly 3 sampleQuestions in the user’s voice; optional source/memoryType (episodic|semantic|procedural)/validFrom. ta…
operationIdstring–Project receipt key; identical retries only.
ordernumber–entityType:"task"/"area"/"project"/"heading" — sort order.
ownerstring–entityType:"task" — assignee.
parentstring–entityType:"tag_relation" (required) — the parent tag in the child_of edge.
patchobject–Project sparse changes; omitted fields stay. Max 25 step/resource changes.
payloadobject–entityType:"tracker_entry" (required unless `entries` is used) — the structured data point; shape is tracker-defined.
posturestring–entityType:"skill" with a `trigger` set (or legacy "rhythm") — read | propose | act (defaults 'read').
projectIdstring–entityType:"task" — parent project; or "heading" — the project it belongs to (required).
reasoningstring–entityType:"tag_relation" — short justification (typically a user quote) for the edge.
recordedAtnumber–entityType:"tracker_entry" (single-entry form only) — observation time (ms epoch; defaults to now).
recurrenceobject–entityType:"task" — makes the task repeat. The returned `taskId` is this task's first occurrence; completing it later returns `nextTaskId` for the next one (see penny_edit's `status` field) — don't c…
retrievalPlanarray–entityType:"skill" (or legacy "rhythm") — OPTIONAL deterministic steps [{ tool, args }] for a bounded tier.
rhythmIdstring–entityType:"rhythm_run" — the rhythm to begin a run of (or pass `name`).
scopestring–Profile: global|workspace. Projects: private; workspace requires workspaceId.
skillIdstring–entityType:"skill_invoke" (required, or pass `name`) — the skill to run now. entityType:"skill_run" — the skill to begin a run of (or pass `name`).
sourcestring–entityType:"note"/"tracker_entry" — provenance label (defaults 'conversation' / 'agent-mcp').
statusstring–entityType:"task" — initial status.
tagsarray–entityType:"task" — tags to attach.
targetSpecobject–entityType:"tracker" — JSON target spec, interpreted at retrieval (e.g. { kind: 'daily_minimum', value: 10000 }).
titlestring–entityType:"task" (required) or "heading" (required) — the title/label.
trackerEntryIdstring–entityType:"tracker_note_link" (required) — the logged tracker entry to attach notes to.
trackerIdstring–entityType:"tracker_entry" (required) — the tracker to log against.
triggerobject–entityType:"skill": optional schedule (required for rhythm), requires deliver. MyPenny does not run it: due signals reach the connected agent. Schedule: {kind:"schedule",cadence:"daily"|"weekly"|"mon…
unitstring–entityType:"tracker" — unit of measure.
whenAtnumber–entityType:"task"/"project" — schedule date (ms epoch).
whenBucketstring–entityType:"task"/"project" — undated bucket; mutually exclusive with whenAt.

No output schema declared.

No examples provided.

Common questions

What is the MyPenny MCP server?

MyPenny is an MCP server listed in the public MCP registry as ai.mypenny/mypenny. Portable AI memory you own. Keep memories and notes across Claude, ChatGPT, and other AI tools. This page covers its hosted endpoint (https://app.mypenny.ai/mcp).

Is the MyPenny MCP server safe to use?

MyPenny scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the MyPenny MCP server expose?

MyPenny exposes 7 tools: penny_get_skill, penny_start_setup, penny_session_start, penny_read, penny_write, and 2 more. Their descriptions and schemas cost roughly 7,184 tokens of context every time the server is loaded.

Does the MyPenny MCP server require authentication?

Yes. MyPenny asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the MyPenny MCP server still maintained?

MyPenny is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.