MiMo Free APICAUTION
MiMo Free API MCP: 基于官网逆向的高性能 OpenAI / HTTP MCP 代理网关。支持搜索、识图、长文本分段及 SQLite 持久化。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文
基于小米大模型(MiMo)官方网站(aistudio.xiaomimimo.com)逆向构建的高级 OpenAI 兼容网关 + 原生 MCP 插件集成。现已全量适配 MiMo V2.5 全模态 系列,支持 Thinking (思维链) 协议 与 Omni (全模态) 交互。
🏗️ 核心特性 (V2.5 Features)
- V2.5 全模态适配: 深度集成
mimo-v2.5与mimo-v2.5-pro模型,支持原生图像、视频、音频的复杂分析。 - Thinking 协议对齐: 完美支持官方最新的思维链 (Reasoning) 协议。流式输出中自动包含
reasoning_content,真实还原 AI 思考过程。 - 透明升级路由: 保持对 V2 时代的兼容。请求
mimo-v2-omni会自动平滑路由至mimo-v2.5,mimo-v2-pro会路由至mimo-v2.5-pro。 - 环境化 Token 配置: 支持在
.env中通过token环境变量(格式:ph.uid.token)完成一键部署。 - Native MCP Server: 集成最新 MCP 标准。赋予 Claude / Cursor 等客户端原生的 联网搜索 (`search`) 与 视觉分析 (`vision`) 能力。
📊 模型矩阵 (Model Matrix)
[!TIP] 强制开启 Thinking:您可以通过为模型 ID 添加-thinking后缀(如mimo-v2-flash-thinking)强制激活任何模型的思维链模式。
[!WARNING] 工具调用 (Tool Calling) 限制:目前模型原生工具调用(Function Calling)极度不稳定,无法在 Agent(如 AutoGPT、LangChain Agent 等)中可靠使用。建议仅作为对话、视觉分析或通过 MCP 插件在支持的客户端(如 Claude/Cursor)中使用。
🔑 凭证配置 (Credentials)
项目支持通过环境变量或 API Header 传递凭证。
方式 A:一键式 .env 部署 (推荐)
在根目录创建 .env 文件(可参考 .env.example),填入从官网抓取的三段式 Token:
# 格式: ph.uid.token 或 抓包获取的长字符串 token=xxxxxxxx.yyyyyyyy.zzzzzzzz
方式 B:OpenAI Header 传递
直接在 API 调用时使用 Bearer Token:
Authorization: Bearer YOUR_MIMO_TOKEN
📂 本地路径支持 (Local File Access)
如果您在 Docker 环境下运行,由于容器隔离,服务默认无法直接读取宿主机路径。
核心工作流 (Workflow):
- 多模式支持:本项目支持 URL、Base64 数据 以及 本地文件名。
- 挂载映射 (本地文件):若需使用本地文件,请将其存放在宿主机目录中,并在
docker-compose.yml中挂载到容器的 `/a
19cc585661bbOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mimo-free-api-mcp -- npx -y [email protected]
{
"mcpServers": {
"mimo-free-api-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
search | read | Perform a web search using Mimo AI to get the latest information. Returns a summary of findings with citations. |
vision | read | Multi-modal analysis for images, videos, and audio. Supports URLs, Base64 data URIs, or simple Filenames (which are automatically retrieved from the fixed /app/media storage). |
Trust audit
CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
logger.info(`[Token Check] Prompt Length: ${query.length} chars | Estimated Tokens: ${tokens} | Safe Threshold: ${currentMimoConfig.maxSafeTokens}`);logger.info(`[Auth Pool] New token registered: [${ph.substring(0, 8)}...]`);logger.info(`[Heartbeat] Token [${ph.substring(0, 10)}...] is still valid (No Set-Cookie needed).`);logger.warn(`Token [${ph.substring(0, 8)}...] expired and removed from pool.`);API_BASE = "http://127.0.0.1:8001/v1"
streamable-http
const hash = crypto.createHash("md5").update(contextFingerprint).digest("hex");const hash = crypto.createHash("md5").update(contextFingerprint).digest("hex");const md5 = crypto.createHash("md5").update(buffer).digest("hex");const md5 = crypto.createHash("md5").update(Buffer.from(media.base64, "base64")).digest("hex");safeConvId = crypto.createHash("md5").update(rawConvId).digest("hex");print(token, end="", flush=True)
client = OpenAI(api_key=API_KEY, base_url="http://127.0.0.1:8012/v1")
API_BASE = "http://127.0.0.1:8001/v1"
base_url="http://127.0.0.1:8012/v1"
const response = await axios.post('http://127.0.0.1:8001/v1/chat/completions', {axios, better-sqlite3, colors, crc-32, cron, date-fns, eventsource-parser, file-type
scripts/assets/demo.mp4
Gates applied: no_behavioural_pass.
19cc585661bbfull audit observations/trust-audit/mcp-server/fu-jie__mimo-free-api.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 19cc585661bb | CAUTION | C | 77 | first audit |
Questions
What is the MiMo Free API MCP server?
MiMo Free API MCP: 基于官网逆向的高性能 OpenAI / HTTP MCP 代理网关。支持搜索、识图、长文本分段及 SQLite 持久化。
What tools does MiMo Free API expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MiMo Free API safe to connect to an agent?
With care. The audit graded it C (77/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does MiMo Free API need?
No credential environment variables were found in its source, so it appears to need none.
How does MiMo Free API run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as mimo-free-api-mcp at 1.2.1.
How current is this page?
The grade is for one exact copy of the source (19cc585661bb), read on 2026-10-08. The repository is watched and re-audited when it changes.