cairn

share

Move memories when you mean to

By default, the vault stays on local disk. Export, sync, or a configured backup can copy data to another location.

Git

Export writes a pack. Commit that file. A teammate imports it. Keys that already exist are skipped. There is no merge conflict on the vault itself.

cairn export --out memory/handoff.json
cairn import memory/handoff.json

HTTPS

One machine runs cairn serve. It prints a token. Other machines push and pull with that token. Use this when the vault changes often and you do not want a git commit for every fact.

Plain HTTP is only for localhost. A server on any other address must use TLS 1.2 or newer and a bearer token. Clients check the certificate. Pass --tls-ca when the certificate is not from a public certificate authority.

cairn serve --host 0.0.0.0 --port 8778 --token "$CAIRN_TOKEN" \
  --tls-cert cert.pem --tls-key key.pem
cairn push https://peer:8778 --token "$CAIRN_TOKEN" --tls-ca cert.pem
cairn pull https://peer:8778 --token "$CAIRN_TOKEN" --tls-ca cert.pem

SQLite backups

Since v0.10.0, Cairn can replicate SQLite changes and snapshots to local folders or S3-compatible buckets. Install Litestream 0.5.16 or later and cairn[backup]. Configure one or more destinations, then keep cairn backup replicate running.

cairn backup replicate
cairn backup status
cairn restore --from primary --at 2026-09-29T18:00:00Z

Restore can use the latest backup or the latest retained update at or before a timestamp. Cairn restores only when the live database and its SQLite sidecar files are absent. See the SQLite backup and restore guide for configuration details.

gc only prints a plan until you pass --apply. An export that would cut off the tail of the vault fails instead of writing a short file.