Connect
On your own machine, let the client launchmirage mcp. It starts the server if needed and sends your token.
- Claude Code
- Cursor
- VS Code
- Codex
- Claude Code
- Cursor
- VS Code
- Codex
Auth
The endpoint takes the same bearer token as the HTTP API.mirage mcp reads it from MIRAGE_TOKEN or ~/.mirage/auth_token. The server does not offer OAuth sign-in, so a client must send the header.
Tools
Their inputs are listed under Call a tool.
read, ls, grep and glob are marked read-only. A session is offered the ones its profile leaves it: shell needs a command the allow list installs, ls and grep those commands, write and edit a mount the session may write. A tool it is not offered is not found.
VFS calls and explain
Add?calls=all to the URL, or --all-calls to mirage mcp, to also list each of the 24 VFS calls as a tool named vfs_<call> (vfs_read, vfs_is_dir), with the same arguments. Each answers the route’s JSON as text; a failed one answers {detail, errno, refusal} with isError set. shell and every vfs_<call> then take explain: true, which answers what the call would do and runs nothing; see Explain.
Sessions
Calls run in the workspace’s default session. To use another, add?session_id=<id> to the URL, or -s <id> to mirage mcp. The session’s profile applies as it does to a shell line: a path hidden from cat is hidden from read. Command rules apply only to shell, ls and grep.