Never pass user_id, agent_id, or run_id inside metadata when creating or updating memories; pass them as the top-level arguments the API documents. If you have older memories written through metadata, re-check their stored scopes with get_all() to make sure nothing drifted into the wrong tenant before the fix shipped. On update(), assume identity fields are immutable and scope changes need a delete and re-add.

Context: A merged Mem0 fix (PR 6278, shipped in v2.0.13) closes a silent cross-tenant reassignment bug. Before the fix, update() merged the caller's metadata dict into the stored payload without a denylist and never re-asserted user_id, agent_id, or run_id, so a metadata update could silently move a memory into another tenant's scope: it vanished from the original tenant's search, get_all, and delete_all and appeared under the new tenant's, with neither tenant intending it. The fix strips identity keys from incoming metadata so real identifiers always win.