Skip to main content
I keep a second brain so you don’t have to.
New in 1.3.0: Mercury Bots

Soul-driven AI agent

An AI agent with a soul, loyal only to you.

Mercury learns how you work, remembers what matters, and gets things done while you’re away. It runs on your machine, asks before it acts, and works with any model, from your terminal, browser, Telegram, Discord, Slack, or Signal.

curl -fsSL https://mercuryagent.sh/install.sh | sh

Standalone binary, no Node.js needed. Read the script first.

mercury
☿ Mercury 1.3.0 · deepseek-chat · Ask Me mode
tidy CHANGELOG for 1.3.1, push it, and open a PR
git_statusread · no prompt
read_file CHANGELOG.mdread · no prompt
edit_file CHANGELOG.md+14 −2
git_commit "docs: changelog for 1.3.1"
git_push origin docs/changelog-1.3.1 — modifies a remote
Yes — approve once
Always — remember this permission
No — deny
git_pushapproved once
create_pr #214 "docs: changelog for 1.3.1"
Task complete · 6 steps · 38s
Remembered · changelog PRs go on a docs/* branch
MITopen source, self-hosted
Localmemory in SQLite on your disk
0telemetry in the agent
~50built-in tools, permission-gated
10+model providers, auto-fallback

Built on trust

An agent is only useful if you can rely on it.

Most agents are built to impress in a demo. Mercury is built for the day after, when it is running on its own with access to your files, your accounts, and your time.

01 · Control

It asks before it acts.

Reads are free. Anything that writes, runs, pushes, or reaches outside its scope waits for your answer. Approve once, approve for good, or say no. Some commands never run, no matter what mode you pick.

  • Ask Me or Allow All, chosen per session
  • Shell blocklist: sudo, rm -rf /, and its flag-swapped variants
  • Folder-level read/write scopes per channel and per sender role
  • Bots fail closed: a missing permission is a denial, not a pop-up
How permissions work →
clear out the build cache and old logs
list_dir ./buildread · no prompt
run_command rm -rf build/.cache logs/*.old
Yes — approve once
Always — remember this permission
No — deny
run_commandapproved once
now wipe everything under /
Blocked · `rm -rf /` is on the shell blocklist. It never runs, in any mode.

02 · Memory

It remembers what matters.

A Second Brain on your own disk. Mercury pulls out preferences, people, and decisions as you work, resolves contradictions, and consolidates every hour, so tomorrow does not start from zero.

  • SQLite + FTS5 full-text search, stored in ~/.mercury
  • 10 memory types, auto-extraction, conflict resolution
  • /memory to search, pause, or clear it at any time
  • Personality lives in markdown files you own: soul.md, persona.md
Inside the Second Brain →
draft the weekly update for the team
search_memory "weekly update"3 hits
· prefers bullet points, no emoji
· Friday updates go to #eng-leads
· Priya owns the billing migration
Drafted in your usual format: bullets, billing migration first (Priya), ready for #eng-leads.
Updated · billing migration moved to "in review"

03 · Autonomy

It keeps working when you don’t.

One command makes Mercury a background service that starts on boot and restarts itself on a crash. Schedule routines, run a fleet of persistent bots, and hear back on whichever channel you are on.

  • mercury up: system service, crash recovery, boot start
  • Cron schedules, heartbeat checks, proactive notifications
  • Mercury Bots: persistent specialists with their own model and memory
  • Durable job queue: work survives restarts and failures can be replayed
Meet Mercury Bots →
mercury up
service installed · starts on boot
daemon runningpid 48211
07:00 ◷ daily-brief → Telegram
09:00 ✒ release-notes bot → drafted 620 words
09:02 ⚑ fact-checker → 14/14 sourced
11:40 needs you · deploy bot wants shell access it was never granted
Fleet idle · journals clean · 0 in dead-letter queue

04 · Honesty

It tells you the truth about “done”.

Agents love to say “task complete”. Mercury works under a completion contract: a task ends either verified, with a build, typecheck, or test that actually ran, or paused with the blocker named. Mercury never claims success it can’t show.

  • Evidence-gated completion banners in Mercury Code
  • Honest pauses that name the blocker, never a silent stop
  • Daily token budgets with live usage and Token Saver Mode
  • Provider fallback mid-task, so one outage does not end the run
The completion contract →
migrate the settings page to the new form library
edit_file src/settings/Form.tsx+86 −41
run_command npm run typecheck0 errors
run_command npm test settings12 passed
Task complete · 9 steps · 2m 14sverified
and the billing page
edit_file src/billing/Form.tsx+52 −30
Paused · npm test billing fails (2). Not calling this done. Say "continue" to resume.

Three ways to work with it

One agent. Code, chat, or a whole crew.

A senior engineer inside your repo.

A full-screen, repo-aware coding environment. Mercury plans and builds in one AUTO flow, shows every step on a live checklist, and only calls a task done after a build, typecheck, or test actually ran.

  • AUTO mode: plan and build in one flow, one confirmation for big changes
  • Live plan checklist, per-file diffs, and a workspace IDE (/ws)
  • /code agent hands work to a background sub-agent while you keep chatting
  • Stall watchdog, compact-on-pressure, provider fallback mid-task
Explore Mercury Code →
mercury code ~/projects/acme
☿ Mercury Code · AUTO · branch main
refactor the auth module to JWT and add tests
read_file src/auth/handler.tsplan 1/4
create_file src/auth/jwt.ts+64
edit_file src/auth/handler.ts+31 −48
create_file tests/auth.test.ts+112
run_command npm test8 passed
Task complete · 6 steps · 34sverified
3 files changed · /code diff to review · /ws to commit

Mercury Chat (/chat): Talk to it like someone who knows you.

The everyday Mercury: ask, plan, delegate, schedule. It answers from what it remembers about you, works with ~50 built-in tools, and follows you from the terminal to Telegram, Discord, Slack, Signal, or the web.

Mercury Bots (/bots): A small team, not a single chat.

Persistent bots, each with its own persona, model, memory, and permissions. Send one a job and keep talking to Mercury: the bot works in the background and delivers to its own thread. Promote one to fleet lead and it recruits a crew.

Mercury CloudOptional. Pair from the terminal and keep your agent reachable from anywhere, with no port forwarding, reverse proxy, or certificates.

Everywhere you are

Six channels. One memory.

Every channel shares one tool registry, one permission system, and one Second Brain. Start a task in the terminal and check on it from Telegram.

Extend it with 126+ community skills, based on the open Agent Skills spec. Install one with a single command after reading its source.

  • TerminalInk TUI, slash commands, workspace IDE
  • WebLocal dashboard, Kanban, bot cockpit
  • TelegramPinned status card, admin/member roles
  • DiscordSlash commands, streaming edits
  • SlackSocket Mode, no public endpoint
  • SignalEnd-to-end encrypted via signal-cli

Works with

  • Anthropic
  • OpenAI
  • DeepSeek
  • Grok
  • ChatGPT Plus / Pro
  • GitHub Copilot
  • Ollama Local
  • Ollama Cloud
  • Atomic Chat
  • Mercury Cloud

Honest by design

How Mercury compares, including where it doesn’t win.

Checked in September 2026 against each product’s official docs and public repos. Rows where Mercury loses are left in on purpose.

MercuryClaude CodeCodex CLIGemini CLI
Model providersAny provider, API key or OAuth, auto-fallbackAnthropic + third-partyOpenAI onlyGemini only
Scheduled autonomyDaemon + cron + bot routines, 24/7 localCloud routines + desktop tasks——
Persistent agentsBots with persona, memory, permissionsSub-agents + background agents——
Messaging channelsTelegram, Discord, Slack, Signal, WebSlack, Telegram, Discord, iMessage——
Long-term memorySecond Brain (SQLite, auto-extract, conflict resolution)Auto memoryAGENTS.mdGEMINI.md
Token budgetDaily budget + overrides + live stats———
Security modelPermission modes + blocklist + scopesSandboxed execution + promptsOS-level sandboxSandbox profiles
MCP external tools—✓✓✓
IDE surfaceBuilt-in workspace (files, git)VS Code, JetBrains, DesktopVS Code, Cursor, WindsurfIDE integrations
LicenseMITSource-availableApache-2.0Apache-2.0

No MCP yet

Mercury doesn’t speak the Model Context Protocol today. Skills and ~50 built-in tools cover most ground, and MCP is on the roadmap.

No OS-level sandbox

Safety comes from approvals, a blocklist, and folder scopes. The process itself is not sandboxed, so Ask Me is the default for a reason.

Signal skips Windows

The signal-cli bridge runs natively on Linux, and on macOS with Java 17+. Every other channel works on all three operating systems.

Spotted a cell that’s wrong? Open an issue and we’ll fix it.

Questions

Before you hand it the keys.

Is Mercury free?

Yes. Mercury is MIT-licensed open source. You bring the model: an API key, your ChatGPT Plus/Pro or GitHub Copilot subscription through OAuth, or a local Ollama model at zero cost. Mercury Cloud is optional.

Where does my data live?

On your machine, in ~/.mercury. Memory is a local SQLite database you can search, pause, or clear, and the agent ships no telemetry. Prompts go only to the model provider you configure. With Ollama Local, nothing leaves your machine.

Could it do something destructive?

In Ask Me mode, every file write, shell command, push, and scope change waits for your approval. Commands like sudo and rm -rf / are on a blocklist that never executes in any mode. Reads and writes are scoped to the folders you allow, and bots fail closed.

How is it different from Claude Code or Codex?

Those are coding sessions you open and close. Mercury is a personal agent that stays running: it has memory, schedules, persistent bots, and chat channels. It also includes Mercury Code, a full coding environment, for when you need one.

Which platforms does it run on?

macOS, Linux, and Windows, as standalone binaries or through npm (Node.js 20+). It also runs on Android via Termux and on any cloud VM.

Does it support MCP?

Not yet. Mercury uses its own skills, based on the Agent Skills spec with 126+ in the registry, plus ~50 built-in tools. MCP support is on the roadmap.

Up and running in about a minute.

Install, answer the setup wizard, then run mercury up to keep it running for good.

curl -fsSL https://mercuryagent.sh/install.sh | sh

Standalone binary, no Node.js needed. Read the script first.