← Pando

Memory for Kiro’s IDE and CLI that your other agents can read

Kiro and Pando, for memory between sessions.

Whether Kiro remembers depends on which Kiro you open. Its MCP docs name four surfaces, the IDE, the CLI, Kiro Web and Mobile, and Crew is a separate Kiro agent. Read on 23 September 2026, its docs describe a memory for Kiro Web and for Crew, and none for the IDE. Kiro Web, which comes only with the Pro, Pro+, Pro Max and Power plans, keeps one by itself: "Memory is maintained automatically, so there's nothing to turn on and nothing to add manually." Crew keeps its own on the machine it runs on, and a new remote host gets it when you sync your local state there. The CLI comes closest of the rest, with a knowledge base that "persists across chat sessions", experimental and off until you enable it. What it holds is the files and folders you add to its index, so it finds what your documents say, not what you and Kiro decided last week and why.

Kiro Web and the separate Crew agent do, and Kiro Web comes only with the paid plans; the IDE keeps no memory its docs describe, and the CLI only an experimental knowledge base of files you index, on the machine it runs on. Connect Kiro to Pando and have it write decisions into your outline, which every session and machine reaches, and so does every other agent you allow to read it.

Set it up

  1. Add {"mcpServers": {"pando": {"url": "https://pando.ink/mcp", "oauthScopes": ["pyflow.read", "pyflow.write"]}}} to ~/.kiro/settings/mcp.json, which the IDE and the CLI both read, in every workspace.
  2. In the IDE, check that the MCP support setting is on (Settings, search for MCP) and save the file; in the CLI, start kiro-cli chat. Kiro opens Pando in your browser, where you approve the sign-in.

A workspace can have its own .kiro/settings/mcp.json as well, and when both files exist Kiro merges them, the workspace’s settings taking precedence. The CLI needs the file too, because kiro-cli mcp add has no --url flag. In a kiro-cli chat, /mcp shows whether pando is connected, and /mcp auth pando opens the sign-in again. If the sign-in does not finish, connect with a key instead, as further down.

Kiro’s docs promise a short sign-in: "Most servers use Dynamic Client Registration (DCR) and need no extra configuration - just connect, and Kiro opens the authorization page." Pando offers that registration. Keep the oauthScopes line all the same. Without it Kiro asks for its default scopes, openid, email, profile and offline_access, none of them pyflow.write, so Pando’s consent page opens on Read your outline only. With pyflow.read and pyflow.write it opens on Read and write your outline. Either way you can switch on the page itself.

Remote servers work in the IDE, the CLI and Kiro Web; Mobile is the one Kiro surface without them. On a second machine, add the entry there as well, because Configuration Sync will not carry it. Uploading settings/mcp.json "sends those servers to Kiro Web sandbox MCP server settings, not to the IDE as cloud-managed MCP servers", and what it loads into new local IDE and CLI sessions is your "cloud Steering files, custom agents, Skills, Powers, and Hooks", no MCP servers among them.

What you approve in Pando

Kiro opens Pando, where you sign in first if you are not signed in already, and then its consent page, which offers two levels, “Read and write your outline” or “Read your outline only”. Either way Kiro starts with your whole outline. A box underneath, ticked by default, gives it a bullet under Home to remember in, named after whatever Kiro calls itself when it registers. Untick it and it remembers nowhere until you assign a bullet under Agents and API keys. The token Kiro gets has no expiry and no refresh token, and works until you revoke it there. A bullet you protect refuses every change Kiro tries, and a lock stops changes, not reading.

One branch only, or a key instead

A Kiro that signed in can be held to one branch without a key: open that branch, open Agents and API keys in Settings, tap its row under Your agents, and press Let it reach only “…”, the bullet you are in. It then reads and writes that bullet and everything under it, remembers there, and reaches nothing else in your outline, even if you approved it read only. The button is not offered at Home or on a branch somebody lent you. To connect with a key from the start instead:

{"mcpServers": {"pando": {"url": "https://pando.ink/mcp", "headers": {"Authorization": "Bearer ${PANDO_KEY}"}}}}

What each place is for

When Kiro’s own memory is enough

If you work in Kiro Web on a paid plan, it keeps a memory for you with nothing to turn on, and for work that stays in Kiro Web that may be all you need. If Crew is your agent, its memory already carries preferences and learned corrections from one session to the next. If you want the CLI to search your own documents, its knowledge base does that. And if Kiro is your only agent and you are content to keep the decisions in a steering file you write yourself, that may be enough, and on a plan with Kiro Web, Configuration Sync can load the global ones into new sessions on your other machine. The outline earns its place when another agent has to read what Kiro decided, or you do on your phone: Claude Code, Codex and Cursor connect to the same address, and what Kiro writes there is what they read next.

What it costs

Nothing, for 1,000 bullets, with every feature included and no payment card.

Deeper

Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this