Default development version: KIP 2.0 β normative draft. The repository root contains the current protocol and tooling. KIP v1.0-RC11 is frozen for historical reference and migration; changing the default does not upgrade existing deployments or declare the 2.0 protocol stable.
- The scope is frozen. A new contract enters the draft only together with engine evidence; corrections, simplifications and new evidence do not need that gate (Specification Status).
- Names are stable; revisions are digests. There is one memory package,
kip://profiles/cognitive-memory@2.0.0, one general domain package,kip://domains/general@1.0.0, one standard projection policy,kip:memory-default, one standard strength policy,kip:strength-half-life-30d, and schema IDsurn:kip:2.0:schema:*. A draft revision is identified by its content digest; earlier draft packages are not retained. - Both reference engines pass the whole engine suite β 431 cases in 26 fixtures, none pending. The suite manifest records the verified engine revision.
- No learning result is claimed. Engine runs, bounded models and structural tests are separate evidence from measured Brain behavior, which stays
not_rununtil a Brain evaluation measures it.
What the latest revision changed, and how it was validated, is in the revision record.
- Agent integration: Memory Interface and the Agent memory card.
- Protocol implementation: Specification, syntax reference, and conformance checks.
- Running a Brain: Anda Brain, a memory service that serves the Memory Interface; see Implementations.
- Developer tools: TypeScript language toolkit (
@ldclabs/kip-lang) and VS Code extension, both targeting KIP 2.0. - Existing v1 users: frozen archive, deployment migration, and repository path changes.
The archived MCP server and Skill implement v1 interfaces; native v2 integration starts with the current Interface and wire contracts above.
An interactive version β pan, zoom, relationship tracing, five guided views β is a self-contained file: download it and open it in a browser.
A memory that cannot separate what was said from what is true will eventually lie to its owner with total confidence. KIP 2.0 refuses to collapse three questions:
Meaning what can be represented at all
Belief what the Brain currently accepts
Authority who may read, write, project, or elevate
So a stored Proposition is truth-neutral. An Assertion carries one actor's stance toward it, with mode, confidence, validity and evidence. Belief is not a stored field but an Epistemic Projection computed at read time over the eligible assertions:
Proposition exists β Proposition is true β Brain accepts Proposition
Change never rewrites the past. Three kinds of change keep three different histories:
- The world changed. One new Assertion from the time of the change. Temporal succession closes the actor's older value at that point, so a formerly true claim is ended rather than declared wrong, and historical queries still answer with it. Two inferences never succeed one another.
- A claim was wrong. A new Assertion supersedes the old one, which stays on record.
- The Brain misrecorded it. Recording repair invalidates the wrong extraction; the source bytes and everyone's stance stay as they were.
Time is stated as honestly as it is known: asserted_at is when a claim was made, not when it was recorded; a claim with no stated start began no later than that; and a coarse date is a time bound, not an invented instant. A preference is an ordinary claim that changes within its kind β there is no Preference type. Where claims of one slot still conflict, the standard memory policy kip:memory-default resolves them the same way on every engine: context specificity first, then first-person testimony, then recency.
Evidence, provenance and schema get the same treatment: Evidence and Activity are first-class elements rather than metadata bags, and schema lives in versioned, digest-pinned packages. A Brain that meets a relation the Profile lacks drafts it into the Space's draft vocabulary with DEFINE, which only adds; promoting a draft onto an installed symbol is a Schema migration that only a Principal holding manage_schema performs. Retrieval composes with belief in one query through the Search Pattern: search finds candidates, and BELIEF decides what is accepted.
A memory that only answers when asked is half a memory. The other half is what the Brain does when nobody is talking to it β and it must not be a cron job. KIP 2.0 gives that half four mechanisms, none of which decides policy on the Brain's behalf:
| Mechanism | What it is |
|---|---|
Watch |
Durable attention state. A declared condition under which a change β or the absence of one β deserves attention. Armed watches are evaluated against committed Change Envelopes: a delta watch fires on a matching committed change; a silence watch fires once due_at has passed and the evaluator has consumed the change stream through that deadline without a match β the clock alone proves nothing. Proactivity becomes a state differential rather than a blind schedule. A fired Watch grants nothing: it creates attention, never an action, and reaches the business Agent through the Memory Interface's attention recall. |
action_gate |
An Activity class recording what the gate decided β act, ask, defer, or silence β with the inputs it weighed. Restraint is the hardest thing to justify after the fact, so deliberate silence is written down like any other outcome. |
LIST DEPENDENTS |
Bounded reverse traversal of provenance. Revise a root and the cognition compiled from it β insights, preference summaries, skills, the self-model β becomes discoverable in one operation instead of quietly stale. Β§57.5 makes the rule explicit: a revised root must not auto-retract its dependents, and must leave them reviewable. Whether one survives is a review decision, not a protocol rule. |
PURGE PAYLOAD |
Destroy an Evidence element's observed bytes while keeping the record: its digest, class, observation time, source, and the citations that depend on it. Data minimization that costs no provenance β corroboration and independence counting keep working on the surviving digest. Distinct from element purge, which destroys the record itself. |
Supporting state lives in the Cognitive Memory Profile: WorkingState is the consolidated resume digest stamped with its basis_seq, so a Brain wakes from compiled state plus a delta rather than re-reading scrollback; computed dependency validity makes a revised root visible at the next read; and MnemonicState.utility holds the admission bet β how useful this memory is expected to be β kept deliberately separate from salience, from memory_strength, and from epistemic confidence. Strength itself is computed at read time from a base, an anchor and a pinned decay policy; nothing sweeps it, and reading never reinforces it.
Everything above makes the system watch the world better. The consequence channel is how the world watches back.
Outcome Evidence records what actually happened after a decision, action, or trialed procedure β written by instrumentation (telemetry, verifiers, test harnesses, human review), never by the actor whose action it grades. An actor's own account is agent_statement, citable as context only; the separation is a conformance invariant, enforced as auditability β engine origin always records who wrote what, and Governance can restrict who may write outcomes β because an open protocol can make self-grading visible even where it cannot make it impossible.
Each outcome carries a task family that selects candidate consequences. Sharing the family establishes neither attribution nor baseline membership: under the optional Validated Learning companion, TrialRecord explicitly freezes comparable baseline attempts and outcomes. Treatment observations link through the instrument's outcome_observation Activity to an attempt and the action_gate decision that applied the exact Skill revision. Its DecisionRecord distinguishes retrieval from actual use, and grading counts independent attempts assigned before execution. A SkillRevision must name its task family before trial; a pattern that nothing could prove wrong is not procedural memory. On the channel sits the Skill lifecycle:
proposed β trialed β adopted β revoked
Lifecycle changes commit with a validated immutable EvaluationRecord on a lifecycle_verdict Activity and a guarded update (Validated Learning Β§7). Auditors replay exact inputs against the immutable TrialRecord; a Skill's current_trial only selects it, and its GradingState is a computed view. Without the companion, Skills stay unproven candidates β useful, recallable, never promoted. Only trialed β adopted promotes through a comparative verdict, and revocation is never harder than adoption. Same-state monitoring may retain standing under authorized policy without claiming new improvement; policy withdrawal may have zero outcomes. Imported Skills enter proposed without local grades and remain recallable as unproven candidates. Revoked Skills must enter a new trial before adoption can recur.
KIP does not define an admission threshold, an interruption policy, a salience algorithm, a consolidation schedule, or a skill compiler. It defines where those decisions put their inputs and their receipts. A protocol that hardcoded one utility function would stop being a protocol β and every deployment would fork it.
The policy layer is a separate, replaceable component:
- Brain 2.0 β the reference design: Formation (what deserves to outlive this turn), Recall (what from the past should change what I do next), and Maintenance (the sleep-time metabolism that consolidates, compiles skills, reviews contradictions, and metabolizes memory strength).
$self/$systemβ the single-agent variant, a thin delta layered on the Brain policies above: a waking mind that experiences, and a sleeping mind that integrates.- Experience Learning Architecture β the loop the Brain implements, and how to evaluate whether it actually learned anything rather than merely stored more.
The seam matters in both directions. Because policy is out of the protocol, two Brains with different admission utilities can share one Cognitive Nexus; and because the signals are in the protocol, either Brain's decisions remain auditable by the other.
If memory is what makes an agent valuable, the natural move is to make it impossible to leave with. KIP takes the opposite position: cognition exports as a signed, inspectable Cognitive Capsule, and import is a destination-governed transaction β a capsule's signature proves origin and integrity, never truth, trust, or authority. Imported skills stay non-executable until the destination elevates them; a source's $self never becomes the destination's.
This repository defines the protocol and its tooling; it does not contain a production engine or Brain. Each implementation's own repository is the authority on what it supports β this table claims nothing beyond the evidence it links.
| Component | What it is | Evidence here |
|---|---|---|
anda_cognitive_nexus |
Rust KIP 2.0 engine (Cognitive Nexus) on AndaDB | Passes all 431 engine-suite cases (manifest) |
@ldclabs/kip-do |
Independent TypeScript KIP 2.0 engine on SQLite Cloudflare Durable Objects | Passes all 431 engine-suite cases (manifest) |
anda_kip |
Rust parser, request/response types and model-facing function definitions; ships this repository's syntax card, Profile and Brain role cards for model prompts | β |
| Anda Brain | Self-hosted memory service: Formation / Recall / Maintenance agents on the Rust engine, serving the Memory Interface at memory_basic, with a harness adapter for the Interface and reliability vectors |
A historical evidence record of an earlier revision; no current harness run is recorded |
| Anda Brain Worker | A compact Brain on kip-do for Cloudflare Workers, also serving memory_basic |
β |
@ldclabs/kip-lang, vscode-kip |
This repository's TypeScript toolkit (lexer, parser, formatter, diagnostics, lowering, canonical JSON, MemorySession) and VS Code extension |
Their own test suites; they execute no KIP |
| Document | Description |
|---|---|
| π Memory Interface | Five Agent intents, processing receipts, scoped and attention recall, and composable levels (δΈζ) |
| π Agent memory card | The small everyday Interface; direct KIP role cards live alongside it (δΈζ) |
| π Specification 2.0 | The normative draft (δΈζ) |
| π§© Cognitive Memory Profile 2.0 | Experience, Skill, Commitment, Watch, WorkingState, and the rest (δΈζ) |
| π Validated Learning | Optional companion: revisions, attempts, trials, evaluations and validated Skill standing (δΈζ) |
| βοΈ Brain Runtime | Optional companion: durable attention, leases, dispatch and receiver fencing (δΈζ) |
| π¦ Capsule Specification 2.0 | Specification Β§37βΒ§41 and Β§95: the portable, verifiable memory artifact (δΈζ) |
| π§ Optional Profiles & Migration | Specification Β§100, Β§101, Β§103 and Appendix I: Historical, High-Assurance, and KIP 1.x migration (δΈζ) |
| π Invariant Registry | The 49 Core and 49 Profile invariants in one list, each with the section that establishes it and the vectors that pin it (δΈζ) |
| π Architecture 2.0 | Design rationale behind the Specification (δΈζ) |
| π Syntax Reference 2.0 | LLM-facing KQL / KML / META card (δΈζ) |
| π§ Brain 2.0 | Formation / Recall / Maintenance (δΈζ) |
| π Brain evaluation | Separate protocol, reliability and behavioral-learning release gates (δΈζ) |
π€ $self / βοΈ $system |
Single-agent prompt pair, a delta over Brain 2.0 ($system) |
| π€ Grammars & Schemas | Normative EBNF, plus the wire schemas |
| π§ͺ Conformance | 431 executable engine cases, 344 parent vectors, 30 cognitive, 20 Memory Interface and 17 reliability scenarios, and executable contract models |
| π¬ Formal Verification | Alloy, TLA+ and Python models, including world-time succession, and what they proved (δΈζ) |
| π Migration from 1.x | What changes, and what legacy meaning must not be invented (δΈζ) |
| π Revision records | The latest revision's checklist and validation; earlier: reliability, review |
| π Design Notes | Ten pre-consolidation rationale documents, frozen 2026-09-02 |
Chinese *_CN.md mirrors track the English sources. The English sources are normative; a mirror is not an alternative semantic contract.
Project terminology lives in CONTEXT.md; essays remain in post/.
| Path | Contents |
|---|---|
Root *.md |
The Specification, companions, invariant registry, architecture and syntax card |
grammar/, schemas/, profiles/ |
Normative EBNF, wire and artifact schemas, the memory package, the general domain package and the standard policies |
brain/ |
Reference Brain policies, role cards, optional companions and the evaluation protocol |
conformance/ |
Engine suite, vectors, fixtures, reference models, adapter runners and digest tooling |
formal/ |
Bounded Alloy, TLA+ and Python models with their reports |
packages/ |
@ldclabs/kip-lang and the VS Code extension (the pnpm workspace) |
migration/, post/, diagrams/ |
Migration guidance, essays and visuals; not normative |
design/, v1/ |
Frozen pre-consolidation notes and the frozen KIP 1.x archive |
The usual checks, from the repository root:
pnpm install --frozen-lockfile
pnpm --filter @ldclabs/kip-lang test # language, examples, schemas and contract tests
node conformance/update-digests.mjs # schema locks and artifact digests
bash formal/run.sh # bounded models (exit 3 means prerequisites were missing)AGENTS.md records the contribution rules, and conformance/README.md explains how to run the suites against an engine or a Brain.
KIP 2.0 is a protocol for durable cognition: new information may change what a Brain does next without requiring the Brain to falsify what happened before.
Copyright Β© 2026 LDC Labs. Licensed under the MIT License.