Key Takeaways
- Hugging Face introduced Funes on September 3 for searchable history across Claude Code, Codex, pi, and Hermes.
- Retrieval returns source passages with session and turn provenance, rather than only a compressed summary.
- The published binary list currently names Linux and Apple Silicon macOS; it does not list a native Windows binary.
- Local use, agent integration, and publishing are separate choices; inspect exactly what an integration installs and what a push includes.
Funes is an open-source memory layer that lets coding agents retrieve the original text of earlier sessions, including the reasoning behind a project decision. It works locally by default and can optionally publish its memory as a Hugging Face dataset you control.
The important setup decision is whether you want local retrieval, an installed integration that indexes future work, or synchronized history. Those choices have different effects. Sharing a memory is a data-publication action, and a secret scanner does not decide whether an otherwise ordinary conversation is appropriate to share.
Hero: 20 Jay Street in Brooklyn, photographed in March 2018. Hugging Face listed Suite 620 in this building in its 2022 NAIRR submission; archive location context, not the Funes interface. Photo by Jim.henderson, source, CC BY-SA 4.0. Cropped and resized by ToolSurge; derivative retains the same license. Location context: Hugging Face's 2022 submission.
The missing information is often why a choice was made
A repository records code changes well, but the rejected approach or a failed investigation may exist only in an agent transcript. Starting another session can mean repeating work because the conclusion survived while its evidence did not.
Hugging Face’s introduction describes Funes as a retrieval layer over those traces. It indexes sessions into a common structure, combines keyword and vector retrieval, and returns passages with provenance. A companion retrieval command can open the complete turn around a hit.
The practical value is inspectability. An answer about an old decision can point back to the conversation that produced it. That lets you distinguish an actual project decision from an agent’s suggestion that was later rejected.
Our context-engine guide covers why relevant context matters for coding work. Funes addresses a particular source of that context: your existing session history, retained as searchable evidence rather than rewritten into a single permanent rule.
Inspect a public example before indexing your own history
The project provides a public development-memory dataset and documents a one-question ask workflow. It retrieves passages and hands them to a coding agent for a grounded response without installing an ongoing agent integration.
This is a useful first evaluation because it separates the retrieval experience from the decision to index your private sessions. Ask a question whose answer can be checked against the returned passages, then inspect the surrounding turn. A credible answer should expose its evidence instead of asking you to trust the memory system’s confidence.
Our suggested test includes a question the dataset should answer and another it probably cannot. A system that admits an unsupported answer is more useful than one that invents continuity. This is a proposed test plan, not a claim that we installed Funes or measured its quality on private session logs.
Be precise about “nothing installed.” The ask mode avoids installing the persistent integration; you still need the relevant executable and coding-agent access to run the command. A workflow description should not be read as browser-only access to a service.
Check the supported platform before copying an installer
The README lists prebuilt binaries for Linux x86-64, Linux ARM64, and Apple Silicon macOS. It also documents building from source with Rust and a protobuf compiler. The current list does not include a native Windows binary.
If you work on Windows, do not interpret a generic “single binary” description as verified native Windows support. Check the project’s current release artifacts and platform instructions for the environment you actually use. This guide does not claim that an untested compatibility layer will behave identically to a listed platform.
The README says its installer verifies a tagged release checksum and version. It also notes that a checksum from the same download location detects corruption or mismatch but does not independently authenticate that location. That is a useful distinction when reviewing how a new tool enters a work environment.
Start with a platform and agent combination the documentation explicitly supports. Resolve the basic executable and access requirements before connecting a large archive, so installation problems do not become confused with indexing or retrieval quality.
Adding an agent changes persistent behavior
The integration guide describes funes add as more than exposing a search command. It can build an initial index, register read tools, install ongoing indexing automation, and perform a first publish when a shared memory is bound.
The same guide documents agent-specific details. For Codex, hooks require a review, and session-boundary publishing has a stated version requirement. Do not assume that each supported agent uses identical files or lifecycle events simply because the top-level command has the same shape.
For a local-only setup, make that intent explicit. The documentation says a token-present setup may offer to create a shared memory even when none was named. Review the proposed destination before accepting an integration that could upload future session history.
The removal command reverses the integration while preserving stored memory, original transcripts, caches, and any remote dataset. That is useful for trying the tool, but “remove the integration” should not be described as deleting every copy of the data.
A private dataset still needs deliberate content selection
Funes-created datasets are private by default, according to the README. An existing dataset retains its current visibility. The publishing guide says a normal push sends local chunks the remote does not yet have; an explicit session selection can narrow that publication.
That means the scope should be decided before the command runs. A session may contain useful engineering rationale alongside client names, commercial plans, file paths, or unrelated personal details. Not all sensitive information looks like an API key, so credential scanning does not replace a decision about the intended audience.
Our recommendation is to begin with a small, reviewed collection. Confirm the destination owner, visibility, and reader permissions. Inspect the resulting dataset after publication and verify the expected sessions rather than assuming that a successful upload proves the selection was correct.
This is the same distinction discussed in our MCP versus CLI guide: exposing a capability through a convenient interface does not decide when using that capability is appropriate.
Read the scanner’s limits, including local behavior
The project documents credential redaction during indexing and a separate publishing scan. Its detailed publishing guide says local indexing can continue without TruffleHog, with a warning that index-time redaction is disabled. Publishing requires the scanner and refuses to proceed unscanned.
The detailed guide also explains partial publication: blocks with detected secrets are withheld, while unrelated clean rows can still upload with a warning. This is more precise than treating every warning as an all-or-nothing failure. Read the result and inspect pending rows before reporting a memory fully synchronized.
The security policy warns that an uploaded credential can remain in remote history even after later content changes. It also treats passages from someone else’s memory as untrusted input because they can contain instructions aimed at the reading agent.
Our operational conclusion is to separate remembered evidence from current authority. An old session can explain what happened, but its text should not silently override today’s instructions, permissions, or corrected facts.
What happens next
Evaluate retrieval first, then the local integration, then sharing if you need it. Choose a known past decision and verify that the system returns the relevant original context, including any later correction. A plausible recollection of an outdated decision is still an outdated answer.
Measure whether the tool reduces repeated investigation while keeping provenance easy to inspect. The launch reports encouraging results on a two-task handoff comparison, but that small vendor benchmark is not a general cost guarantee for your projects.
Funes makes session history easier to carry between agents and machines. Its strongest benefit is that the next agent can inspect the evidence behind a decision. Keep the publication scope and the distinction between historical text and current instructions equally explicit.
Quick poll
Which part of earlier agent work do you lose most often?
Our take: a useful memory should expose the original evidence and its later corrections.
FAQ
Is Funes a hosted memory subscription? It is an open-source tool with local memory by default. Optional sharing uses a Hugging Face dataset owned by the user or organization.
Is there a documented native Windows binary? The current README’s prebuilt list names Linux and Apple Silicon macOS. It does not list native Windows.
Does removing Funes delete my history? The documented removal command reverses integration but preserves local memory, transcripts, caches, and remote datasets.
Does the secret scanner make every session safe to share? No. Credential detection is not a review of all confidential information, and published history requires separate remediation if sensitive material escapes.