--- title: "Strands Agents memory: sessions, memory stores and MCP" description: "Strands Agents persists sessions and adds long-term memory through a MemoryManager. Add timestamped, source-backed recall, and see where AgentCore Gateway fits." canonical: https://past.dev/integrations/strands-agents last-updated: 2026-10-09 --- # Add memory to AWS Strands Agents Source: https://past.dev/integrations/strands-agents Strands Agents memory has two layers. A session manager persists one conversation and the agent's state so it can resume. A MemoryManager attaches memory stores, such as a local test store or Amazon Bedrock Knowledge Bases, and recalls from them through a tool or by injecting results into the prompt. A tool that calls past.dev over HTTP adds timestamped ingestion and recall that returns ranked documents with dates and source excerpts. ## Strands Agents memory scope [Session management](https://strandsagents.com/docs/user-guide/sdk/agents/session-management/) persists conversation history, agent state and conversation manager state. `SnapshotSessionManager` is the recommended Python manager for new single-agent sessions, keyed by `session_id` and backed by a storage such as local files. `FileSessionManager` and `S3SessionManager` remain supported. [Memory](https://strandsagents.com/docs/user-guide/sdk/memory/overview/) carries knowledge across sessions through a `MemoryManager` and its stores. Recall through a tool and injection into the prompt are on by default when a store is attached. Writing memories is opt-in, and extraction can distill facts from the conversation with a model every few turns. Each store can be scoped to its own tenant. - **A session replays one conversation.** It restores history and state for one `session_id`. - **A memory entry is distilled text.** The extractor turns messages into discrete facts. The documentation states no event time or validity period for an entry. - **The store decides the search.** The test store is a local JSON file; the Bedrock Knowledge Base store adds semantic search over a vector store. ## The integration: two tools The `@tool` decorator from `strands` turns a function into a tool. The first paragraph of the docstring becomes the description, and the `Args` section describes each parameter. With `context=True`, a tool reads `invocation_state`, which the documentation recommends for user ids that should stay out of the prompt ([custom tools](https://strandsagents.com/docs/user-guide/sdk/tools/custom-tools/)). ```python import os, requests from strands import Agent, ToolContext, tool BASE = "https://api.past.dev/api/v1" HEADERS = {"Authorization": f"Bearer {os.environ['PAST_API_KEY']}"} @tool(context=True) def remember(text: str, happened_at: str, tool_context: ToolContext) -> str: """Store timestamped source text, readable by the whole project. Args: text: The source text. happened_at: ISO 8601 time the text was written or the event occurred. """ return requests.post(f"{BASE}/ingest", headers=HEADERS, json={ "content": text, "timestamp": happened_at, "identity": tool_context.invocation_state["user_id"], }).text @tool(context=True) def recall(question: str, tool_context: ToolContext) -> str: """Return ranked documents with dates and source excerpts. Args: question: The question to answer from memory. """ return requests.post(f"{BASE}/recall", headers=HEADERS, json={ "query": question, "identity": tool_context.invocation_state["user_id"], }).text agent = Agent( tools=[remember, recall], system_prompt="Call recall before you answer questions about people, decisions or history.", ) agent("What did we decide about the Q4 budget?", user_id="demo-user") ``` > **Identity** > > The application sets the identity. The model never chooses it. Recall returns what the identity in the request may read, so take the identity from the signed-in user in code, and keep it out of every value that the model fills. Recall returns ranked documents with dates and source excerpts. The application decides whether those documents support an answer, contain a disagreement, or are insufficient; HTTP failures are handled separately. ## Or connect the MCP server The Strands `MCPClient` from `strands.tools.mcp` wraps a transport, and `streamablehttp_client` from the `mcp` package connects to a remote server. Passed directly in `Agent(tools=[...])`, the client's connection is managed for you ([MCP tools](https://strandsagents.com/docs/user-guide/sdk/tools/mcp-tools/), [MCP transports](https://strandsagents.com/docs/user-guide/sdk/tools/mcp-transports/)). The project's end-user MCP server then gives the agent `recall`, `answer` and `who_am_i`, plus `remember` while the project's write toggle is on, with no tool code to write. 1. Turn on the project's end-user MCP server on **Build › MCP server** in the console. 2. Mint an access link there, or with the account server's `create_mcp_access_link` tool. The link has the form `https://api.past.dev/mcp//link/`. It is one URL that is one identity, and the server answers it with no sign-in step. 3. Keep the link in a secret store, such as the `PAST_MCP_URL` environment variable that the code below reads. The secret in its path is the credential. ```python import os from mcp.client.streamable_http import streamablehttp_client from strands import Agent from strands.tools.mcp import MCPClient past = MCPClient(lambda: streamablehttp_client(os.environ["PAST_MCP_URL"])) agent = Agent( tools=[past], system_prompt="Call recall before you answer questions about people, decisions or history.", ) agent("What did we decide about the Q4 budget?") ``` Every call through the link runs as its identity, with that identity's audiences. Mint one link per install, so that a revoked link stops one agent only. When the agent serves several people, mint one link per end user, and connect each request with the link of the user who makes it. Never share one link between users. `remember` writes to the identity's own private audience, and only that identity recalls it. Send data that the whole project must recall through the ingest call. The [end-user server documentation](/docs/mcp/serving-your-own-users) describes the tools, the links and revocation. ## Amazon Bedrock AgentCore Gateway [AgentCore Gateway](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway.html) is a managed endpoint that presents APIs, Lambda functions and MCP servers to agents as MCP tools, with its own inbound authorization. Two of its target types reach past.dev. - **MCP server target.** Point the target at an access link. The link carries its own credential, so the target uses no outbound authorization, an option AWS marks as not recommended in general ([MCP server targets](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-target-MCPservers.html)). Every caller of the gateway then acts as the link's identity. - **OpenAPI schema target.** Describe the `ingest` and `recall` operations in an OpenAPI document, and attach an API key credential provider that sends the project key in the `Authorization` header with the `Bearer` prefix. The gateway requires an `operationId` on every operation and does not support `oneOf`, `anyOf` or `allOf` ([OpenAPI targets](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-schema-openapi.html)), so write a reduced document with those two operations from the [API reference](/docs/memory-api/api-reference). The model fills every parameter of such a target, `identity` included, so add a REQUEST interceptor with `passRequestHeaders` on, which replaces `identity` in each tool call with the caller's id from the validated inbound token ([interceptors](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-interceptors-types.html)). The [quickstart](/docs/memory-api/quickstart) shows how to ingest, wait until ingestion completes, and recall. The [benchmarks](/benchmarks) document how recall is measured. [Event time](/glossary/event-time) explains why ingest carries the source's own timestamp. ## Frequently asked questions ### Does Strands Agents have long-term memory? Yes. A MemoryManager attaches memory stores that persist across sessions, recalls from them through a tool or prompt injection, and can extract facts from the conversation when writing is turned on. ### Can AgentCore Gateway expose past.dev to agents? Yes. An MCP server target can point at an access link of the project's end-user MCP server, and an OpenAPI target can describe the ingest and recall operations with an API key credential provider. ## Related - [Memory for Google ADK](https://past.dev/integrations/google-adk) - [Memory for the OpenAI Agents SDK](https://past.dev/integrations/openai-agents-sdk) - [Memory for Agno](https://past.dev/integrations/agno) - [Event time](https://past.dev/glossary/event-time) - [Quickstart](https://past.dev/docs/memory-api/quickstart)