The command line
Needs Solo or TeamUpdated 4 October 2026
mu is memoratu from a terminal. It is a single binary that talks
to https://api.memoratu.com over HTTPS and to nothing else
— the same way the phone apps do, just without a screen.
Before you start
Needs Solo or Team
Installing mu is free and
open to anyone. Using it against your memoratu account needs a paid
plan.
The command line is a paid feature by
design. Signing in mints a CLI token, and the server refuses to mint one
on the free plan — it answers
plan_limit_exceeded and names the plan and the feature
rather than just saying no.
There is no billing yet, so every account today is on the free plan. In practice that makes this a tool for the people building memoratu — and the honest reason to read on is to see exactly how it works, and to have it installed for when that changes.
What you need
- A Mac with Homebrew, for the one-line install. Apple silicon and Intel are both covered.
- Or Linux, on
arm64oramd64— the release carries a tarball for each, with published checksums. - A memoratu account on a paid plan, to sign in.
Install it, step by step
Six commands. Run them in order, in a terminal.
-
Install
muOn a Mac, from our public Homebrew tap:
brew install subbutgs/memoratu/muHomebrew taps the formula, downloads the binary and tells you where it landed — something like
/opt/homebrew/Cellar/mu/0.1.0.On Linux, download the tarball for your architecture from the v0.1.0 release, check it against
checksums.txt, and putmusomewhere on your$PATH. -
Check that it ran
Confirm the version, and which API this install talks to:
mu --versionYou should see the version, the commit it was built from, and the base URL:
mu 0.1.0 (commit 4aef1232, built 2026-10-03T16:50:02Z) API: https://api.memoratu.com -
Sign in
This step needs Solo or Team
This is the only way to get your first token — signing in mints one for you and stores it in your macOS Keychain.
mu auth loginmuasks for your email, then your password. The password is always prompted and is never accepted as a flag, so it never reaches your shell history or a process list.It then prints the token's name, when it expires (90 days by default, and the value it chose is always shown, never silent) and the permissions it was given. It does not print the secret — it has already stored it, so it does not need to show it to you.
The token it creates is deliberately narrow: read on projects, lists and tokens, and read, create, update and complete on todos. It cannot mint or revoke other tokens. If a later command refuses with
permission_denied, it names the exact permission that is missing, and that is the default working as designed.On a free plan this step is where you stop. The server refuses to mint the token and answers
plan_limit_exceeded, naming the plan and the feature. -
Capture your first todo
This is the command that matters. One line, no setup, no choosing a project first:
mu add "call the client back"It lands in
Inbox— the one permanent list every account has.mugenerates the id for you, on your machine, before the server hears about it, and prints both the id and the longer readable identifier.Added to Inbox · call the client back id 3f2b1a9c-7e2d-4b11-9c4a-6a1f2e9d7c3b identifier mem:todo:...:3f2b1a9c-7e2d-4b11-9c4a-6a1f2e9d7c3b -
See what you have
List your todos:
mu todo listCompleted todos are hidden by default — open, cancelled and moved all still show. Add
--allfor every status, or--status donefor finished ones only. If you are counting or auditing rather than checking what needs doing, use--all. -
Tick it off
Pass the id — or just the first few characters of it, git-style:
mu todo done 3f2b1a9cA short unique prefix works anywhere an id is accepted. Fewer than six characters is refused outright, and a prefix matching more than one todo is refused with every candidate listed rather than guessed at.
That is the whole loop: capture, list, complete. Everything below is detail.
The commands
A readable summary. mu help <command> is
always the authority on a flag — it is generated from the command tree
itself, so it cannot fall out of step with the tool.
| Command | What it does |
|---|---|
mu add "<title>" | Quick capture. Lands in Inbox. |
mu todo list | List todos. Hides completed ones unless you pass --all. |
mu todo get <id> | Show one todo in full. |
mu todo done <id> | Mark it complete. |
mu todo reopen <id> | Reopen it. The original completion time is kept, not cleared. |
mu todo rm <id> | Delete a todo. |
mu project add "<name>" | Create a project — the level above lists. |
mu project list | List projects. |
mu project rm <id> | Delete a project and everything inside it. Cannot be undone. |
mu list add "<name>" | Create a list, inside a project or standing alone. |
mu list list | List lists. A * marks Inbox. |
mu list rm <id> | Delete a list. A non-empty one needs --delete-todos or --move-to. |
mu auth login | Sign in and mint this profile’s token. |
mu auth status | Who you are, which account, which permissions. mu whoami is the same command. |
mu auth logout | Revoke this profile’s token on the server, then remove it locally. |
mu token list | This account’s tokens, never a secret. Revoked ones are hidden unless you pass --all. |
mu token create | Mint a token. The secret is shown exactly once. |
mu token revoke <id> | Revoke a token immediately. |
mu help | Every command. mu help <command> for one command’s flags and examples. |
mu exit-codes | Print the exit-code table. |
Deleting things
mu project rm,
mu list rm, mu todo rm and
mu token revoke all take --dry-run, which prints
what would happen and mutates nothing, and --yes, which skips
the confirmation. Given neither a --yes nor a terminal
to ask on, they refuse rather than guess.
mu project rm also shows an
estimate of what will be deleted before it asks, and the actual counts
afterwards — and says so if the two differ.
mu project rm 7c9e6679-7425-40de-944b-e07fc1f90ae7 --dry-runFor scripts and AI agents
An agent driving a terminal is a first-class user of memoratu, by design rather than by accident.
Always use --output json
Every command supports it, and it returns the same shape the server itself does rather than a second vocabulary invented for the CLI.
mu todo list --output jsonBranch on
error.code, never on error.message
— the message is English prose for a person and may be reworded at
any time. The code is the contract.
{"error": {"code": "plan_limit_exceeded", "message": "...", "detail": {"limit": "max_todos_per_list", "current": 50, "allowed": 50}}}detail names what you need in
order to act: which permission is missing, which limit was hit, how long to
back off. A code beginning cli_ means mu itself
refused before any request left your machine, and is never one of the
server’s own codes.
Exit codes
Branch on these rather than on the text
of stderr. mu exit-codes prints the same table from the tool
itself.
| Code | Meaning | Retry? |
|---|---|---|
0 | Success | — |
1 | The server refused it — validation, permission, not found, conflict, plan limit, rate limit, or a bare 500 | Ask error.code. server_error and rate_limited usually yes, with backoff; the rest no |
2 | You used the command wrong. Decided before any network call | No — it will fail identically |
3 | Could not reach the server — DNS, refused, reset, TLS, timeout | Yes, with backoff |
4 | Not authenticated — no token, or the server said so | No — fix the credential first |
Credentials, for something with no keychain
Set MEMORATU_TOKEN to an
already-minted secret. Every command checks it before touching any
keychain, and this is the supported path for CI and for an agent running
where there is no keychain of its own.
export MEMORATU_TOKEN=mem_live_...Use mu token create to get a
secret you can paste somewhere else — that is its whole purpose, and
it prints the secret exactly once.
mu auth login deliberately does not, because it has already
stored the one it minted.
An agent cannot
complete mu auth login by itself. The prompts need a
human-equivalent stdin on a real terminal. If mu exits
4 and you have no token to set, that is the moment to ask a
person — there is no workaround, and that is a deliberate choice
rather than a gap.
Two things to know before you count anything
mu todo listhidesdone, andmu token listhides revoked tokens. Both filters apply identically in--output json— this is not a presentation difference. Pass--allwhen you are auditing rather than deciding what to act on.- Every list command pages.
--limitand--offsetgo in;limit,offsetandtotalcome back alongside the items. No endpoint ever returns an unbounded set.
Profiles, and a second machine
One Mac, several accounts — each kept properly apart.
mu auth login --profile workmu todo list --profile workEach profile gets its own entry in
~/.memoratu/config — the base URL and the output default,
never a secret — and its own Keychain item.
--profile works anywhere on the command line, before or after
the command itself.
Signing in again on the same profile revokes the token that was in that profile’s slot, named by id in the confirmation, and nothing else. A token signed in on another machine, or under a different profile on this one, lives in its own slot and is never touched.
To reuse the same credential on a second
machine, mu auth login --show-secret prints it. To take an
already-minted token instead, --with-token reads one from a
prompt or a pipe:
echo "$MY_TOKEN" | mu auth login --with-tokenWhat is not true yet
Kept in one place on purpose, so it is correctable in one edit when it changes — and so nothing above has to hedge.
- There is no Windows build. The
v0.1.0release carries macOS and Linux binaries, each for both architectures. - On Linux and Windows there is no system keychain. On macOS the token goes into the Keychain. Elsewhere, set
MEMORATU_TOKENin your environment. - Nothing can buy a paid plan today. Billing does not exist, so every account is on the free plan and signing in with
muis refused. The plan gate is real, not theoretical. - There is no web page that creates a token.
mu auth loginis the only way to get a first one. There is also no way to sign up for an account from a browser. - The binary is not signed and not notarised. Homebrew needs neither — it fetches over curl, so nothing attaches a quarantine attribute and the install is clean. That is a property of how brew works, not a claim that this binary has been through Apple’s process.
- The source is not public. The release repository carries compiled binaries and checksums only.
- There are no commands for search, sync, export or sharing. Those endpoints are not on the server yet, so
muhas nothing to call.mu todo copyis in the same position.