What Athenode stores
Athenode keeps what you plan and what you configure: your specifications with their questions, answers, implementation plans and statuses, your ToDo cards and your agent setups. It does not keep your code, the changes an AI agent made to it, or which AI coding tool did the work.
In spec-driven development with Athenode, the plan is in your Athenode project, where every member sees it, and the code is in your repository, where your AI agent writes it.
What Athenode keeps in a project
A project is the container for one product or codebase in Athenode, and everything below belongs to one project.
| What | What is kept |
|---|---|
| Specifications | A specification is one described piece of work, with a title, a summary, Markdown content, a status and its own questions and answers. Athenode also keeps its place in the specification tree (the hierarchy of the project's specifications), its blockers and its implementation plan. |
| ToDo cards | A ToDo card is a short note of work to do later: a follow-up, tech debt, a bug or an idea. Athenode keeps its title, description, type, priority and status, whether a person or an agent created it, its open questions with their answers, and its links to specifications. |
| Agent setups | An agent setup is a named bundle of what your AI coding tools work with: skills, agents, rules, MCP servers and setup files. Athenode keeps all of them, including the bundle files of each skill and the settings files that hold your workflow settings. |
| Members | Each member's name and role, and the email address and role of each pending invite. |
| Project tokens | Each token's name, creation date, expiry and creator. |
| Plan | The project's plan and the details of its subscription. |
Athenode also keeps your account: your email address, your name, the date you joined and your choice about marketing emails. Your account describes how to change and delete it.
What Athenode does not keep
Your code stays in your repository. A leaf specification is a specification with no sub-specifications. Leaves are what an AI agent implements. An apply run, in which your AI agent plans and implements each leaf under a specification, happens in your AI tool. From an apply run, Athenode keeps the parts that belong to the plan:
- each specification's status, as it moves from Prepared to Processing to Completed;
- the implementation plan the agent records for a leaf specification before implementing it;
- the questions the agent asked and the answers you gave.
Athenode does not keep the source files, the diff, the list of changed files or the name of the AI tool that did the work.
Take a web shop whose specification "Checkout flow" has the stages "Cart", "Payment" and "Shipping". When your AI agent applies "Payment", the project shows "Payment" as Processing and then as Completed, and its Plan tab holds the implementation plan. The payment code and its commits are in your repository and wherever you push it.
The text of a specification, an implementation plan or a ToDo card is kept as written. If you or your AI agent put a code excerpt, a file path or a configuration value into that text, it is part of the specification or the card and every member of the project can read it.
The settings files of a setup are kept with the setup in Athenode and are not written into your repository. The other parts of the installed setup are written into your repository as files for your AI tools, as Install a setup describes.
Who can see a project's content
A project's specifications, ToDo cards and agent setups are visible to the members of that project. Every member, including a viewer, can read all of them. Roles and permissions lists who can change what.
Two things are narrower. Project tokens are listed to the member who created them and to the owner. The email address of a pending invite is shown to the owner, and other members see Hidden.
Where your project token is kept
A project token is a personal access token that lets the Athenode CLI, and your AI agent through it, act on one project. The web app shows the token once, when you create it, and cannot show it again afterwards.
On your computer, the Athenode CLI stores the token in .athenode/config.json in the local project directory where you ran init. The CLI creates that file readable by your own user account only, and adds .athenode/ to the repository's .gitignore so that the token stays out of version control. The Athenode MCP server can take the token from the ATHENODE_TOKEN environment variable. Project tokens describes creating, replacing and revoking a token.
Secrets of your MCP servers
An MCP server in a setup often needs a credential of yours, such as an access token for another service. A setup holds a reference to it, written as ${VAR}, and the value stays in the environment where your AI tool runs. Athenode never stores the values of the variables you reference.
A value stored under a name that looks like a secret, such as a token, key or password, must be a ${VAR} reference. MCP servers in a setup describes the references and where to set the variables.
What publishing a setup makes public
Publishing a setup to the setup library is the one action that shows project content outside the project. The setup library is the shared catalogue of agent setups that projects have published. A setup is published only when an editor or the owner publishes it and confirms what will be shown.
A published entry shows the following to every signed-in Athenode user and, with public display on, to anyone on the Athenode website without an account:
- the entry's name, description and tags, and the name of its publisher;
- the full content of its agents;
- the full content of its skills, with their bundle files;
- its rules;
- its setup files, including the files under
settings/, published as they are.
MCP server configuration is not shown on the Athenode website. Publishing is refused while an MCP server of the setup holds a value typed in directly, so replace such values with ${VAR} references before you publish.
Every publish turns public display on, and the publisher can turn it off afterwards. After you turn it off, the entry leaves the Athenode website within a day, and search engines may keep a cached copy for longer. An entry stays in the library when the project it came from, or its publisher's account, is deleted. Unpublish an entry first if it should go with them.
Your specifications and ToDo cards are not part of a library entry. Public display of an entry lists what a published entry shows, and Publish a setup describes the review before publishing.