Memory for Warp’s agent, in notes you own
Open Warp on another machine and some of yesterday is already there. Your global rules sync through Warp Drive, whose docs say "All objects stored in Warp Drive sync immediately as they’re updated", and your conversations are stored in Warp’s cloud unless you turn that setting off. What the agent concluded is another matter, because outside one preview it writes nothing down by itself. The rules are the ones you write, and a rule Warp suggests is saved only when you click it. Agent Memory, the part that "extracts durable facts, learnings, and outcomes from the transcript and writes them as memories", "is in research preview and is enabled per team for design partners", and Warp’s pricing page lists it for Enterprise only. For everyone else, what the agent decided on Tuesday is kept only inside Tuesday’s conversation.
Only in Agent Memory, a waitlisted research preview for Enterprise teams; otherwise Warp syncs your global rules and stores your conversations in its cloud by default, and what the agent decided stays inside those conversations. To keep its decisions where you read and correct them next to your notes, and where assistants that do not run in Warp reach them too, connect Warp to Pando and have its agent write them into your outline.
Set it up
- In Pando, open Agents and API keys in Settings, give a new agent a handle, and choose Create the agent. Copy its key, which begins with pf_ and is shown once.
- Add {"mcpServers": {"pando": {"url": "https://pando.ink/mcp", "headers": {"Authorization": "Bearer <key>"}}}} to ~/.warp/.mcp.json, with your key in place of <key>. If the file already lists servers, add the pando entry beside them.
Warp speaks Streamable HTTP and sends custom headers, so the address and the header are the whole connection. On Windows the file is %USERPROFILE%\.warp\.mcp.json. Pando’s key screen also shows a config that runs npx pando-mcp; for Warp, use the entry above instead. One key serves every machine you put the entry on.
Then give Warp one more global rule, which syncs through Warp Drive with the others: recall from Pando before assuming, and keep decisions and their reasons there.
Why a key, and not a sign-in
Warp’s app can sign in to an MCP server through the browser. The stable release asks to be sent back to warp://mcp/oauth2callback, and a build from its open-source repository to warposs://. Pando refuses either address when Warp registers, because it accepts a return address only on https, or on http at the machine’s own loopback address, such as 127.0.0.1 or localhost. That is the MCP specification’s own rule: "All redirect URIs MUST be either localhost or use HTTPS." Leave the header out and Warp starts that sign-in by itself, since "Starting a server without existing credentials automatically opens a browser-based authentication flow", and Pando refuses it. A key in a header needs no return address, and Warp’s docs say the form without one is not supported for its cloud agents either: "A raw url MCP config that requires OAuth and has no Authorization header isn’t supported for cloud agents".
In the Warp Agent CLI
The CLI "reads MCP servers from its global config file only", in the same mcpServers format as the app, so put the same entry, with the header, in that file. Its browser sign-in returns to http://127.0.0.1 on a random port, and Pando accepts any port there, but that sign-in has not been run against Pando yet. Approved that way on Pando’s consent page, it starts with your whole outline, to read and write or to read only.
What it reaches
- An agent made with both boxes ticked, as they are by default, reads and writes your whole outline and remembers in a new bullet under Home named after its handle.
- To hold it to one branch, open that branch, open Agents and API keys in Settings, tap the agent’s row under Your agents, and press Let it reach only “…”, the bullet you are in, where the quotes hold that bullet’s words. It then reads and writes that bullet and everything under it, remembers there, and reaches nothing else in your outline. A CLI that signed in is held the same way, even one you approved to read only.
- Untick “Let it read and write this outline” and “Give it a bullet of its own to remember in” before Create the agent, and it reaches nothing until you give it a bullet the same way. Its row says so meanwhile.
- A bullet you protect refuses every change from it. A lock stops changes, not reading.
- To take the key back, open Agents and API keys, find it under Keys, where each row says revoke, and tap it. It will not work again.
What each place is for
- Global rules, for how you want Warp’s agent to work, synced through Warp Drive. Warp may suggest one from how you use it, and a suggestion is saved only when you click it.
- Cloud conversations, to go back to what was said. The Free plan keeps 30; Build, Max and Business keep them without a limit.
- Agent Memory, if your Enterprise team is let into the preview, for facts Warp extracts from each finished conversation and shares across the agent harnesses it supports, Claude Code and Codex among them.
- A branch of your outline, for decisions and their reasons that you want to read, correct and share yourself, and that any agent you allow reaches, whether it runs in Warp or not.
When Warp’s own is enough
If your team is in the Agent Memory preview and every agent you use is one of the harnesses it supports, Warp already writes down what each conversation settled and shares it among them, and you do not need Pando for this. Nor do you if your global rules and the conversations themselves are all you want to carry: Warp Drive and its cloud already do that. The outline earns its place when you want the agent’s decisions written down where you read and correct them yourself, next to the rest of your notes and on your phone, or when an assistant that does not run in Warp, such as ChatGPT or the Claude apps, needs them.
What it costs
Nothing, for 1,000 bullets, with every feature included and no payment card. On Warp’s side, MCP is on every plan, Free included. The Free plan has no bundled AI usage for the Warp Agent, and since 21 May 2026 you can bring your own API key on every plan.
Deeper
Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this