Blog·Learning

Supermemory with TanStack Start: A Server-Side Memory Boundary

Keep memory credentials and authorization in TanStack Start server functions while the client receives only permitted context.

By Shardul Mane·3 min read

Supermemory with TanStack Start: A Server-Side Memory Boundary

For a TanStack Start application, put the memory API call behind a server function. TanStack Query can manage client-side fetching and caching, and Router can coordinate navigation, but neither a browser cache nor a route loader should be mistaken for durable user memory.

The security boundary is the server's authenticated session. Keep provider credentials there, derive the memory scope there, and return only information the current user may see.

Name the actual stack

TanStack is a family of libraries. A guide that says only “add memory to TanStack” leaves important questions unanswered: is the application using Start, a separate backend, or a static React frontend? This example concerns Start's server-function boundary. A Query-only app needs an equivalent endpoint on its existing backend.

The Start server-function guide describes request validation and server execution. Authentication remains application-specific; creating a server function does not automatically authenticate a request.

Keep the provider behind an adapter

This helper accepts an already authenticated principal and a provider adapter. It validates the question, constructs an unambiguous tenant/user scope, and passes only that scope to retrieval. It is framework-independent so it can be tested before being wired into a server function.

import { createHash } from "node:crypto";

type Principal = { tenantId: string; userId: string };
type Retriever = (scope: string, question: string) => Promise<string[]>;

export async function recallForUser(
  principal: Principal | null,
  question: unknown,
  retrieve: Retriever,
): Promise<string[]> {
  if (!principal?.tenantId || !principal.userId) {
    throw new Error("Authentication required");
  }
  if (typeof question !== "string" || !question.trim() || question.length > 2000) {
    throw new Error("Question must contain 1–2000 characters");
  }
  const scope = createHash("sha256")
    .update(JSON.stringify([principal.tenantId, principal.userId]))
    .digest("hex");
  return retrieve(scope, question.trim());
}

This example targets a Node-compatible server runtime. For an edge runtime, use its supported cryptography API and preserve the exact scope encoding across environments. Changing the encoding later changes which records the application can retrieve.

Wire it into a Start server function

Use createServerFn with input validation for the question. In its handler, resolve the principal using your application's session middleware, then call recallForUser with an adapter built from the server-side Supermemory client. The Supermemory SDK guide provides the client setup.

Do not accept tenantId, containerTag, or a provider API key as arbitrary form input. If a server function supports an administrator selecting another user's scope, authorize that action explicitly before constructing the principal passed to this helper.

The adapter should return bounded, permitted evidence, not the entire provider response by default. Preserve source IDs when the UI needs citations, and avoid leaking internal metadata that has no purpose in the page.

Treat client caching as a separate layer

A cached response can outlive the server-side memory that produced it. Include the appropriate user scope in client cache keys, clear user-specific state on sign-out, and invalidate affected queries after correction or deletion. Server authorization must still run on each request that reaches the endpoint.

Do not put private recall results into a shared static page or a cache keyed only by the question text. Two users asking “what did we decide?” can require entirely different answers.

Test the boundary before the UI

The local tests cover missing authentication, invalid questions, stable scope construction, and separation when tenants or users differ. A fake retriever records the exact scope passed by the helper. That makes an identity bug visible without a model call.

Then run the real Start route in the deployment runtime: sign in as two fictional users, request the same question, sign out, correct a fact, and repeat. Verify response headers and client-cache invalidation as well as provider behavior. The helper is not a complete authenticated Start application, and no live route or provider request is claimed as tested here.

For the data lifecycle behind the endpoint, use the multi-tenant memory guide.

Connect memory behind your existing sign-in flow: get a Supermemory API key and keep it in the server environment. Wire the retriever into the authenticated Start route, then test the same question as two different users.

  1. An update to supermemoryWe've discontinued the supermemory company brain and Nova. Everyone who was charged has been refunded, our MCP and plugins continue to run, and we're going all in on the memory engine.
  2. Scaling Conversations: How Adapta Grew Usage Without Losing ContextAdapta added Supermemory as a persistent memory layer so every conversation keeps its context — letting the team scale usage without losing the thread.
  3. How Chatarmin Ditched RAG and Went Memory-Only with SupermemoryChatarmin replaced a heavy RAG pipeline with Supermemory's memory layer — cutting average AI response time from 40s to 12s and token usage by 40–50%.
  4. SMFS: making agentic retrieval 55% cheaper AND more accurateWe launched SMFS.ai (Supermemory Filesystem) a few weeks ago, with a simple bet: We can redesign the filesystem specifically for agents, with special files, structures, and commands that it can use for it's tasks. Today, SMFS is used by hundreds of companies to power their agents.
  5. Introducing Dynamic Dreaming: supermemory now connects the dots, for you.Dreaming is magical. TLDR: We're launching Dynamic Dreaming in supermemory today, which automatically works if you're using supermemory in any way - API, OpenClaw, Hermes agent, etc.
  6. Dear reader, we just made supermemory insanely cheap... the Context CloudWhen I first started building supermemory, I had one goal: To build the best memory system for AI. I would talk to customers, and find out that memory was not the only thing they needed - They were all setting up 7-8 different vendors at the same time.
  7. Introducing @supermemory/tools v2.0.0Today we're releasing v2.0.0. This release unifies the API across all agents sdk integrations from AI SDK to Mastra, makes conversation identity a first-class concept, and ships with memory saving on by default.
  8. Solving the Precision-Recall Tradeoff: Search Result AggregationWhen you're building memory for AI, search is your foundational layer. The way search generally works is straightforward: the user defines a query, and then sets a limit (top-K) on how many search results they want returned. Usually, this is set to 10 or 20.
  9. Stateful Coding Agents with Memory: Build Long-Running Agents (2026)We built a plugin for Claude Code and OpenCode that gives your coding agent persistent memory. It remembers your preferences, learns your codebase, and never loses context mid-conversation. The result is an agent you can run for months without starting over.
  10. OpenClaw Memory Problems: Why It Forgets and How to Fix It (2026)TLDR: Today, we are releasing a new version of our openclaw plugin - https://github.com/supermemoryai/openclaw-supermemory. This post is going to be a bit technical, so bear with me (or bookmark for later!) In this post, I will talk about what we do about OpenClaw memory, and how we fix it.
  11. Clawd / Molt bot's memory SUCKS. We gave it supermemory.I'm the founder of supermemory. Clawd/Molt bot is blowing up right now, with many, many use cases. I set it up, too, and have been using it through telegram. TLDR: just go to https://supermemory.ai/docs/integrations/clawdbot to set up supermemory for your clawd bot.
  12. Catch up with our UNFORGETTABLE Launch WeekOver the last year, one belief has guided almost everything we’ve built at Supermemory AI becomes meaningfully useful only when it remembers. Memory shouldn’t be something developers rebuild from scratch. It shouldn’t be fragile, expensive, or trapped inside a single tool.
  13. Empowering the Next Generation of Founders: Supermemory Startup ProgramIf there’s one thing we’ve learned while building Supermemory, it’s that most startups don’t fail because they didn't build features; they fail when infrastructure slows them down, or they built too slow.
  14. Building code-chunk: AST Aware Code ChunkingAt Supermemory, we're building context engineering infrastructure for AI. A huge part of that is dealing with code: ingesting repos, understanding structure, and making it searchable. The problem is that most code chunking solutions are terrible. We built code-chunk to fix this.
  15. Supermemory raises $3 million with the best memory engine for LLMsToday, I am excited to announce our first funding round to accelerate our mission of building an interoperable, scalable and reliable memory for LLMs and agents. Memory is one of the hardest challenges in AI right now.
  16. Mem0 vs Supermemory: Why Scira SwitchedScira AI moved its production memory layer from Mem0 to Supermemory. This is what failed, what improved, and how the team evaluated the two systems.
  17. Never Record Again: How Montra Uses Supermemory to Rethink Video CreationCampbell Baron, the founder of Montra, has been making videos since he was twelve. By thirteen, he was already doing brand work. Today, he’s betting on a very different future for creators: a world where recording is the exception, and most videos are generated from scratch.
  18. Unified Memory That Works Where You Work: Your Second Brain With SupermemoryHi everyone, I’m Dhravya, the founder of Supermemory. I want to start with a little story behind why this product means so much to me. You can also skip straight to what it is and how it works below.
  19. Supermemory just got faster on PlanetScaleWhat is Supermemory? Supermemory completes the missing part of the LLM puzzle: memory. Just as memory is crucial for human intelligence, it's essential for truly intelligent AI systems.
  20. Faster, smarter, reliable infinite chat: Supermemory IS context engineering.People are obsessed with prompts and prompt engineering. Sure, what you say is important, but what the model knows when you say it is the difference between a stateless text generator and an intelligent AI system. In short, context is the most crucial component.
  21. We solved AI API interoperabilityOne API to rule them all, One spec to find them, One library to bring them all and in the TypeScript, bind them. When we were building the the Infinite Chat API, initially, we only supported the OpenAI format. This was fine, until a lot of our customers started asking, asking for more.
  22. The Wow Factor of Memory - How Flow Used Supermemory To Build Smarter, Stickier ProductsOverview: Flow is a note-taking app built around a bold vision: to create a more personal, context-aware writing experience powered by AI. At the heart of this mission is memory.
  23. The UX and technicalities of awesome MCPsLast month, we launched the Supermemory MCP, mostly to test our own infrastructure and get some initial traction. It blew up. To my absolute surprise, the initial launch itself got half a million impressions (!!!). Then, we launched and got #2 on ProductHunt too.
  24. Architecting a memory engine inspired by the human brainLanguage is at the heart of intelligence, but what truly powers meaningful interaction is memory — the ability to accumulate, recall, and contextualize information over time. Large Language Models (LLMs) have mastered language, but memory remains their Achilles’ heel.