MiOTSAFE
基于 MijiaAPI 的米家设备智能控制代理,提供标准化的 MCP 服务,支持动态设备发现、属性读写和动作调用
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
中文文档 | English
一个基于 mijiaAPI 3.x 的产品化米家 MCP 服务。它不再要求客户端先理解 did、siid/piid/aiid 这些协议细节,而是优先面向“家庭、房间、设备名、场景名”提供更自然的查询和控制能力。
这版解决什么问题
- 面向 AI 客户端:优先暴露稳定、清晰的产品级工具,而不是底层协议字段
- 面向真实家庭场景:先看家庭与房间,再定位设备,再执行控制
- 面向 MCP 标准:工具返回结构化结果,服务状态和登录状态可直接被客户端消费
- 面向扩展:标准能力 schema、profile 驱动控制、资源模型可以继续演进
当前能力
服务与登录
get_service_statusprepare_loginreconnect_serviceclear_saved_loginrefresh_devicesget_tool_catalogping
家庭与设备
get_home_overviewlist_homeslist_devicesget_deviceget_device_statusget_device_capabilities
设备控制
control_by_intentcontrol_deviceturn_on_deviceturn_off_deviceset_brightnessset_color_temperatureset_target_temperatureset_hvac_modeset_fan_speedset_cover_position
场景与耗材
list_scenesexecute_sceneget_consumable_items
MCP 资源
mijia://servicemijia://homesmijia://devicesmijia://scenesmijia://capabilitiesmijia://tooling
安装
建议使用 Python 3.10+。
poetry install
如果你不用 Poetry:
pip install -r requirements.txt
启动
poetry run python mcp_server/mcp_server.py
测试握手:
poetry run python mcp_server/mcp_test.py
登录方式
mijiaAPI 3.x 已移除账号密码登录,只支持二维码登录。
首次需要登录时,服务会:
- 生成浏览器页:
~/.miot-mcp/qr.html - 同时生成二维码图片:
~/.miot-mcp/qr.png - 默认优先用系统浏览器打开
qr.html - 只有浏览器打不开时,才回退到图片查看器或终端二维码
认证信息会保存到:
~/.miot-mcp/auth_data.json
推荐登录主路径
- 调用
prepare_login - 调用
get_service_status - 读取
service.qr.page_path或service.qr.image_path - 完成扫码后调用
reconnect_service或直接refresh_devices
登录相关状态
get_service_status 和 mijia://service 都会返回结构化登录状态,重点字段包括:
service.connectedservice.has_saved_loginservice.qr.open_modeservice.qr.page_pathservice.qr.image_pathservice.qr.login_urlassistant_summarynext_steps.should_scan_qr
环境变量
export MIJIA_ENABLE_QR="tr
67015f774b20OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add miot-mcp --env MIJIA_PASSWORD=${MIJIA_PASSWORD} -- uvx miot-mcp{
"mcpServers": {
"miot-mcp": {
"command": "uvx",
"args": [
"miot-mcp"
],
"env": {
"MIJIA_PASSWORD": "${MIJIA_PASSWORD}"
}
}
}
}Exposed tools (26)
16 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
clear_saved_login | destructive | Clear saved login credentials so the next connection triggers QR login. |
control_by_intent | read | Route a natural-language-like smart-home request to the best product tool. |
control_device | write | Control a device through capability operations like turn_on, set_brightness, set_target_temperature, or run_action. |
execute_scene | write | Execute a scene by friendly name or scene id. |
get_consumable_items | read | Get consumable items globally or for a specific home. |
get_device | read | Resolve one device and return its summary, capabilities, and common state. |
get_device_capabilities | read | Resolve one device and return its standard capability schema for stable client-side routing. |
get_device_status | read | Return the current state and recommended next actions for one device. |
get_home_overview | read | Return a room-first overview of homes and devices for everyday browsing. |
get_service_status | read | Return service status, authentication status, and local file locations. |
get_tool_catalog | read | Return the recommended everyday tools, advanced tools, and workflow. |
list_devices | read | List devices by friendly filters like name, room, home, or model. |
list_homes | read | List all homes and rooms in a user-friendly structure. |
list_scenes | read | List scenes globally or within a specific home. |
ping | read | Test server connectivity. |
prepare_login | destructive | Prepare QR login artifacts and optionally force a fresh QR login flow. |
reconnect_service | read | Reconnect to Mijia cloud, optionally clearing saved login first. |
refresh_devices | read | Refresh homes, devices, and room mappings from Mijia cloud. |
set_brightness | write | Set device brightness. |
set_color_temperature | write | Set device color temperature. |
set_cover_position | write | Set position for any cover-capable device such as a curtain or blind. |
set_fan_speed | write | Set fan speed on any fan-speed-capable device such as a fan, air conditioner, or purifier. |
set_hvac_mode | write | Set mode on a mode-capable device such as an air conditioner, fan, or purifier. |
set_target_temperature | write | Set target temperature on any target-temperature-capable device. |
turn_off_device | read | Turn off a device. |
turn_on_device | read | Turn on a device. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
clear_saved_login, prepare_login
mcp, mijiaAPI, Pillow, qrcode, setuptools
Gates applied: no_behavioural_pass.
67015f774b20full audit observations/trust-audit/mcp-server/javen-yan__miot.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 67015f774b20 | SAFE | B | 89 | first audit |
Questions
What is the MiOT MCP server?
基于 MijiaAPI 的米家设备智能控制代理,提供标准化的 MCP 服务,支持动态设备发现、属性读写和动作调用
What tools does MiOT expose?
26 in total: 16 read-only, 8 that write, and 2 that can delete or overwrite (clear_saved_login, prepare_login). Every one is listed on this page with its risk.
Is MiOT safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does MiOT need?
It reads MIJIA_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MiOT run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as miot-mcp.
How current is this page?
The grade is for one exact copy of the source (67015f774b20), read on 2026-10-07. The repository is watched and re-audited when it changes.