> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs-beta.getzep.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs-beta.getzep.com/_mcp/server.

# Agent memory

> Build agent memory with user Context Graphs, threads, messages, business data, and Context Blocks.

An agent can fail a later task when it cannot retrieve information from previous conversations, user activity, or changes in preferences. Agent memory keeps this user-owned context in a temporal Context Graph.

## User and thread model

A Zep user owns a user Context Graph. Threads group conversations for that user. Messages and user business data become episodes in the graph.

Use:

* `user_id` for context that belongs to one application user.
* `thread_id` for a conversation or workflow that belongs to that user.
* `thread.get_user_context` to retrieve a Context Block for the next model request.

## Implementation path

#### Create a Zep user

Create one Zep user for each application user whose context must persist.

#### Create a thread and add messages

Use a stable `thread_id` for the conversation. Add each user and assistant message after the application receives or produces it.

#### Add user business data

Add activity, preferences, or records with `user_id` when that data belongs to the user.

#### Retrieve user context

Call `thread.get_user_context` before the next model request and place the returned Context Block in the correct provider input. For complex tasks, give the agent tools that search the user graph with the `user_id` pinned. See [Build an Agent with Zep](/build-an-agent-with-zep).

Start with the [Agent memory quickstart](/quick-start-guide). Then read [Memory security best practices](/memory-security) for provider-specific placement rules.

## Boundaries

Agent memory provides context from prior interactions and activity. Agent memory does not guarantee model behavior or authorize an external action. Your application must control tool permissions and action authorization.