Skip to main content
mirage is a client of the server’s HTTP routes, with the same commands in Python and TypeScript. When its url is on this machine, it starts a server on first use; a remote url is never started.

Install

Quickstart

workspace.yaml is a workspace config.

Exit codes

Run lines, VFS calls and tools

-w names the workspace and -s the session, the default one when absent. --explain prints what a line or a VFS call would do, running nothing; see Explain.

mirage mcp

mirage mcp [CONFIG] [-w ID] [-s SESSION] [--all-calls] serves a session’s MCP tools on stdio; --all-calls adds the VFS calls and explain. mirage rpc takes the same arguments and serves RPC. mirage ssh-proxy ID carries SSH to workspace ID over the server’s HTTPS port, for ssh’s ProxyCommand. With -w, it serves a workspace the server already holds. Otherwise it creates one from CONFIG, from MIRAGE_MCP_CONFIG (MIRAGE_RPC_CONFIG) or MIRAGE_CONFIG, or from a workspace.yaml found walking up from the working directory. It deletes that workspace when the client disconnects, unless the config names a workspace_id.

Workspaces

Asks

Sessions

Jobs

Daemon

The server the CLI starts. It exits 30 seconds after its last workspace is deleted, and logs to ~/.mirage/daemon.log.

Log in

A server in jwt mode, such as a hosted one, needs a login. Point the CLI at it and log in once:
mirage login asks the server where to sign in, opens your browser there, and waits. If you are already signed in, the browser comes straight back. The CLI then keeps the tokens in ~/.mirage/login.json, readable only by you. A machine with no browser can use mirage login --token TOKEN instead, which keeps a token you paste once the server accepts it; --token - reads it from stdin, so it stays out of your shell history.
  • Every command sends the login’s token, ssh-proxy included, but only to the server it was made for. MIRAGE_TOKEN or auth_token wins over it.
  • The CLI refreshes the token when it ends, and asks you to log in again 30 days after you signed in. A running mcp or rpc relay asks for it on every request, so it keeps working past a refresh.
  • A server that publishes no login, such as the one the CLI starts on your machine, needs none, and mirage login says so.

Config

mirage config set|get|unset|list edits ~/.mirage/config.toml. An environment variable wins over the file. Changes apply on the next start. MIRAGE_HOME moves everything under ~/.mirage.