Found post-deploy, by reading the telemetry it had just rewritten. The token it was written for IS gone — `TOK=[redacted:token]` where a credential used to be. But `<task-notification>` came back as `<ta[redacted:token]>`, across rows, because `sk-` matched INSIDE the word: `sk-` + `notification` is a vendor prefix followed by twelve word characters. TWO PORTING MISTAKES, COMPOUNDED. The live scrubber's pattern begins with `\b`; the migration's inlined copy had no boundary at all, dropped when I ported it to SQL. And `\b` would not have saved it either — in Postgres ARE `\b` is a BACKSPACE, not a word boundary. `\m` (start of word) is the spelling that means what Python's `\b` means. Two things that look interchangeable, are not, and fail in the same direction. The live scrubber was never affected, and the evidence says so cleanly: rows written after the deploy carry `<task-notification>` intact, while migration-rewritten ones are mangled. Only the frozen copy was wrong. THE DAMAGE HERE IS PERMANENT. The UPDATE overwrote the only copy of that text, so those rows cannot be restored. What this fixes is every OTHER install: 0099 has run exactly once, on one instance, and shipping a known evidence-destroying migration in the chain for everyone else would be the worse half of the mistake. The docstring records what it cost rather than tidying it away. The guard pins the property no reader can eyeball — `\m` present, `\b` absent, in both patterns — and is falsified against the shape that shipped. This is the third time this scrubber has eaten evidence it should not have (`--author=`, then `task-notification`), and the pattern is consistent: the redaction half is easy to verify and the SURVIVAL half only fails on inputs I did not think to include. The evidence set is where the work is. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011cPyzNnegXHr5iRMzzy5KJ
Fabled Scribe
A self-hosted work system-of-record for software projects, built to be driven by Claude Code. Notes, tasks, issues, projects, milestones, rules, and stored processes — reachable from Claude via a built-in MCP endpoint and a bundled Claude Code plugin, with a clean web UI for humans. No in-app LLM; Claude is the sole assistant.
Features
Notes and tasks with a Markdown editor, sub-tasks, milestones, issues, and kanban project workspaces. Stored processes, an engineering rulebook system (with an inception step that decides what each project inherits), and semantic search with proactive knowledge-injection into Claude's context. A knowledge graph, per-user/group sharing, and a built-in MCP server (/mcp) plus a bundled Claude Code plugin so Claude can record and recall your work directly.
Quick Start
Prerequisites: Docker and Docker Compose. No GPU or local model needed — Claude is the sole assistant, reached over MCP.
Download docker-compose.quickstart.yml from this repo, then:
# Optional but recommended — set a secret key
export SECRET_KEY=your-random-secret-here
docker compose -f docker-compose.quickstart.yml up -d
Open http://localhost:5000. The first user to register becomes admin. To connect Claude, create an API key under Settings → API Keys and install the Claude Code plugin — see API Keys & MCP.
Development: To build from source, see Development.
Documentation
| Doc | Contents |
|---|---|
| Architecture | Stack, design decisions, data models, key services |
| Configuration | Environment variables, Docker Compose, production setup, security |
| Features | Detailed feature breakdown and keyboard shortcuts |
| Development | Dev workflow, CI/CD, migrations, release process |
| API Keys & MCP | API key management and Fable MCP install guide |
| SSO / OAuth | OIDC setup for Authentik, Keycloak, and other providers |
| API Reference | All REST API endpoints |
License
This project is privately maintained.