Every way in but in-app goes through the Mirage server, a FastAPI app in Python and a Fastify app in TypeScript that speak the same protocol. It serves HTTP, and SSH on its own port when
ssh_port is set or over HTTP through mirage ssh-proxy; MCP and RPC are HTTP routes, a FUSE folder is mounted by the server itself or by sshfs over its SSH, and the CLI is an HTTP client that starts the server on your machine when it needs one.
What each one exposes
Each way in exposes what its own protocol defines. A dash means the protocol has no such operation.Sessions
Every call acts as one session, with its own working directory and environment, under the profile it was created with. HTTP, MCP and RPC pick the session with?session_id= (or -s on stdio), and the CLI with -s; each SSH login, an sshfs mount among them, gets a fresh session under its key’s profile. Without one, a call runs in the workspace’s default session, under the default profile: the one the config’s profile: names, else the profile called default, else none. A FUSE folder the server mounts is the exception: it belongs to no session, so no profile applies.
Cancel
Each way in stops a running line as its clients do: Ctrl-C in the CLI and SSH,notifications/cancelled in MCP, $/cancelRequest in RPC, and a dropped request or DELETE /v1/jobs/{id} over HTTP. Through the server every line runs as a job, listed by GET /v1/jobs, and a cancelled one ends canceled. To stop everything a session or a workspace is running, whichever way it came in, HTTP and the CLI cancel its lines and kill its background jobs (mirage session cancel, mirage workspace kill).
Auth
The server asks every HTTP request butGET /v1/health for a bearer token; in the default local mode the CLI reads it from ~/.mirage/auth_token for you. See Auth. SSH logins on the SSH port use public keys instead; through mirage ssh-proxy they use the CLI’s token. In jwt mode a token’s sub is an account that reaches only its own workspaces, and an SSH key names its account with mirage-account.