Commands, package names, and image names on this page come from the open-source project that Mibyan Desktop is built on, and can differ from the Mibyan Desktop installer. For the supported Mibyan install and update path, see Install and update.
What MCP gives you
- Access to external tool ecosystems without writing a native Mibyan tool first
- Local stdio servers and remote HTTP MCP servers in the same config
- Automatic tool discovery and registration at startup
- Utility wrappers for MCP resources and prompts when supported by the server
- Per-server filtering so you can expose only the MCP tools you actually want Mibyan to see
Quick start
- MCP support ships with the standard install — no extra step needed.
-
Add an MCP server to
~/.mibyan/config.yaml:
- Start Mibyan:
- Ask Mibyan to use the MCP-backed capability.
Catalog: one-click install for Nous-approved MCPs
Mibyan ships a curated catalog of MCP servers that has been reviewed and merged. They’re disabled by default — install only what you actually want. You can also ask in chat: “add the Linear MCP”. The agent callsmanage_connections with an mcp: true target and a setup card appears. The
card works the same way in the desktop app (a dialog), the terminal UI
(mibyan --tui, a callout above the composer) and the classic CLI (a panel):
- Fields. If the entry declares setup values, the card shows all of them at once. A plain value is prefilled with its default. A secret is masked. Nothing is saved while you type.
- Connect or Cancel. Cancel skips that one server; other servers in the same request continue.
- Authorization. For an OAuth entry the card shows the authorization link. Mibyan never opens the browser by itself: click Open in browser on the desktop, or press Enter in the terminal. Over SSH the card tells you how to reach the callback port or paste the redirected URL.
- Save. Mibyan saves the server configuration, the tokens and your setup values together, once the server has accepted the new token and the first connection has returned. If the server rejects the token, or you cancel before that point, nothing from the attempt is kept, your earlier configuration and tokens stay as they were, and a failed form reopens with what you typed. A server that is already authorized connects with its saved tokens; Mibyan asks you to authorize again only when they no longer work.
- Tools. Mibyan then lists the server’s tools and registers them. The agent can call them in the same turn. If authorization worked and the tool list failed, the card says “Authorized. Tools unavailable.” and the agent can run discovery again later without asking you to authorize again.
Enter on a row to install (and walk through any required credentials),
enable, disable, or uninstall. Catalog entries are stored under
optional-mcps/ in the mibyan-agent repo — presence in that directory means
Nous approval. There is no community submission tier; entries are added by
merging a PR.
The third-party n8n bridge is no longer available for catalog installation.
Existing installations keep their mcp_servers configuration, credentials,
installed files, and selected tools. They continue to load as configured MCP
servers and appear as custom entries in the picker, where you can still
configure tools or enable and disable them. Catalog reinstall is no longer
available. This change does not migrate existing connections to
n8n’s official MCP server.
Catalog entries can require:
- API key — Mibyan prompts at install time and writes the value to
~/.mibyan/.env. Non-secret values (base URLs) go to the same file. - OAuth (remote MCP) — written as
auth: oauthin your config; the MCP client opens a browser on first connection. - OAuth (third-party provider like Google/GitHub) — Mibyan points you at
mibyan auth <provider>if you haven’t authenticated already.
n8n’s official MCP server
Then8n-official catalog entry connects directly to your n8n Cloud or
self-hosted instance over HTTP with browser OAuth. No local bridge or n8n
API key is required.
- Ask an owner or admin to enable Settings > Instance-level MCP in n8n.
- Open Connect and copy the full Server URL ending in
/mcp-server/http, not the editor URL. Older versions show the endpoint directly on the MCP settings page. - Run
mibyan mcp install n8n-officialand enter that URL when prompted. - Complete browser OAuth. If needed, run
mibyan mcp login n8n-officialor use Authorize on the configured server in Desktop or the dashboard. - Review tools with
mibyan mcp configure n8n-official, then start a new session or use/reload-mcp.
n8n bridge, so existing connections, credentials,
installed files, and tool selections are not replaced.
Tool selection at install time
After credentials are configured, Mibyan probes the MCP server to list every tool it exposes and presents a checklist:- Your prior selection if you’ve installed this entry before (reinstalls preserve what you had — the manifest’s defaults don’t override it)
- The manifest’s
tools.default_enabledif the entry declares one (some catalog entries pre-prune mutating or rarely-useful tools) - Everything if neither applies
cloudflare,
~3,300 OpenAPI endpoint tools) instead declare tools.default_excluded — a
curated block-list of names and glob patterns. Installing one of these skips
the checklist entirely and writes tools.exclude; everything not matched
stays enabled, including tools the server adds later. Edit
mcp_servers.<name>.tools.exclude in config.yaml to re-enable a family.
Submit the checklist with ENTER. Only the checked tools end up in
mcp_servers.<name>.tools.include. If you select everything, no filter is
written (cleanest config shape, identical behavior).
If the probe fails (server unreachable, OAuth not yet completed,
backing service not running), the install still succeeds: the manifest’s
tools.default_enabled is applied directly (if declared), or no filter is
written (if not). Re-run mibyan mcp configure <name> once the server is
reachable to refine.
Trust model
Installing a catalog entry runs whatever the manifest specifies —git clone,
the entry’s bootstrap commands (pip install, npm install, etc.), and
ultimately the MCP server’s own code. Manifests are gated by PR review into
the mibyan-agent repo, so Nous has reviewed each entry before it shipped —
but you should still read the manifest before installing, especially the
source: field’s repository, the install.bootstrap: commands, and any
transport.command: invocation.
Manifests live at
optional-mcps/<name>/manifest.yaml
on GitHub. The picker also prints the manifest’s source: URL at install
time so you can quickly verify the upstream repo. The web dashboard’s MCP
page surfaces the same detail per catalog entry — transport, auth type, the
endpoint URL (HTTP) or command + args (stdio), the git install source/ref and
bootstrap commands, and setup notes — with the source: rendered as a
clickable link, so you can inspect exactly what an entry connects to or runs
before clicking Install.
Manifest version compatibility
Manifests pin amanifest_version. The catalog is forward-compatible: if a
PR adds an entry with a newer manifest_version than your installed Mibyan
understands, the picker will surface a warning (⚠ '<name>' requires a newer Mibyan) for that entry instead of silently hiding it. Run mibyan update
to install the latest Mibyan when you see that.
Runtime ${ENV_VAR} substitution
Inside an entry’s transport.command, transport.args, transport.url,
and headers, ${VAR} placeholders are resolved at server-connect time
from environment variables (which include everything in ~/.mibyan/.env).
This is useful when a catalog entry wants to reference a value the user
configured elsewhere — e.g. ${HOME}/foo or ${MY_PROVIDER_TOKEN}.
Cursor-style context variables are also substituted (case-sensitive):
${userHome} (home directory), ${workspaceFolder} (session workspace
root), ${workspaceFolderBasename}, and ${pathSeparator} / ${/}
(the OS path separator). See the
MCP config reference for details.
Note this is distinct from ${INSTALL_DIR} in catalog manifests, which is
substituted at install-time with the path the catalog cloned the entry’s
repo into.
Entries that need your own OAuth app (no DCR)
Some vendors run their remote MCP behind OAuth but do not offer Dynamic Client Registration — every client must be an app the user pre-registers in the vendor’s developer console. Asana’s V2 server (https://mcp.asana.com/v2/mcp) is the shipped example: the retired V1
https://mcp.asana.com/sse server accepted any client; V2 does not.
Such a manifest declares the credentials under auth.env and pins the
client under auth.oauth, so installing it (CLI picker, web dashboard or
Desktop) prompts for the Client ID / Client secret, stores them in the
profile’s .env, and writes only ${VAR} references to config.yaml:
post_install notes for the exact app type and redirect URL
to register, then run mibyan mcp login <name> and restart (or
/reload-mcp) the session or gateway that should expose the tools. The
dashboard / Desktop Authorize button works too: because the client is
pre-registered with a pinned redirect_port, Mibyan keeps the registered
loopback callback (http://localhost:27890/callback) instead of the
dashboard’s own callback URL — so the browser you approve in must run on the
same machine as the Mibyan process. For a remote host, use mibyan mcp login
over SSH port-forwarding.
Updating tool selection later
Updating the catalog manifest
MCPs are never auto-updated. Re-runmibyan mcp install <name> to refresh
after a Mibyan update if a manifest version changed.
To add an MCP to the catalog, open a PR against
optional-mcps/.
Suggestion metadata (suggest:)
A manifest may declare an optional suggest: block with keywords: and/or
hosts: lists. UI surfaces (currently the Desktop app’s composer) use it to
offer a one-click “Add <server>” pill when your draft mentions one of the
keywords as a completed word, or contains a pasted link whose hostname ends
with one of the host suffixes. It is purely advisory — installs still flow
through the same validated catalog/config paths — and most hosted remote
entries (Atlassian, Sentry, Notion, Stripe, Vercel, Supabase, and friends)
declare it.
GitHub is deliberately not in the catalog: its hosted MCP requires each
client to bring its own OAuth app (generic dynamic client registration is
rejected), and Mibyan’s bundled github/* skills driving the gh CLI are a
more capable integration. On Desktop, GitHub mentions instead offer the
github-auth skill when gh isn’t signed in yet.
Two kinds of MCP servers
Stdio servers
Stdio servers run as local subprocesses and talk over stdin/stdout.- the server is installed locally
- you want low-latency access to local resources
- you are following MCP server docs that show
command,args, andenv
HTTP servers
HTTP MCP servers are remote endpoints Mibyan connects to directly.- the MCP server is hosted elsewhere
- your organization exposes internal MCP endpoints
- you do not want Mibyan spawning a local subprocess for that integration
HTTPS_PROXY / HTTP_PROXY / ALL_PROXY (a socks:// alias is normalized to socks5://), then the OS proxy (Windows registry, macOS system settings), with NO_PROXY hosts — including CIDR ranges and *.example.com patterns — connecting directly.
OAuth-authenticated HTTP servers
Most hosted MCP servers (Cloudflare, Linear, Sentry, Atlassian, Asana, Figma, Stripe, …) require OAuth 2.1 instead of a static bearer token. Setauth: oauth and Mibyan handles discovery, client identification, PKCE, token exchange, refresh, and step-up auth via the MCP Python SDK.
Mibyan identifies itself with a Client ID Metadata Document on servers that support one, and falls back to Dynamic Client Registration on those that don’t. Both are automatic; there is nothing to configure.
~/.mibyan/mcp-tokens/<server>.json with 0o600 perms; subsequent runs reuse them silently until refresh fails.
Refresh tokens are bound to the authorization server that granted them: Mibyan records the discovered issuer alongside the cached tokens and, if a server’s advertised authorization server ever changes (server migration, metadata edit, or hijack), the stored refresh token is dropped instead of being sent to the new issuer. The current access token keeps working until it expires, then a normal re-authorization runs against the new issuer.
The redirect back from the authorization server is checked against RFC 9207: when the server’s metadata advertises authorization_response_iss_parameter_supported, a redirect without a matching iss is rejected. Figma’s authorization server (https://api.figma.com) advertises that support and then omits iss; Mibyan fills the missing value from the discovered issuer for that one issuer and logs a warning, so mibyan mcp login figma completes. A present-but-different iss is still rejected, and no other server gets the exemption.
The authorization server’s metadata document must name the server the resource advertised (RFC 8414 §3.3); a document for a different server is rejected before any registration or login. One shape is accepted without an exact match: a server advertised with a path (https://host/path) whose document, fetched from https://host/.well-known/oauth-authorization-server/path, names the origin https://host as its issuer — Strava’s MCP connector publishes exactly that pair. Only the origin’s operator controls that well-known location, so the document is treated as the advertised server’s own; a document naming another origin or another path, or one reached only through a redirect or a fallback location, still fails with Authorization server metadata issuer mismatch.
Google-hosted servers (Gmail, Calendar). Google only issues a refresh token when the authorization request carries access_type=offline, which MCP discovery never advertises. Mibyan adds it (plus prompt=consent, so a repeat login is re-granted one) whenever the discovered authorization server is accounts.google.com, so the connection persists across restarts and works from mibyan gateway. Other issuers’ requests are untouched.
Remote / headless hosts. When Mibyan runs on a different machine than your browser, the loopback callback can’t reach your laptop. Ways to complete the flow:
- Mibyan Desktop (automatic): when you run the OAuth sign-in from the Desktop app’s MCP setup UI against a remote backend, Desktop hosts the callback listener on your machine and relays the authorization back to the gateway automatically — no tunnel, paste, or proxy needed. Requires both the Desktop app and the backend to be up to date.
- Paste-back (no setup): on an interactive terminal Mibyan prints “Or paste the redirect URL here…” alongside the authorize URL. Open the URL in your browser, approve, copy the full URL the browser ends up on (the redirect will show a connection error — that’s expected), paste it at the prompt. Bare
?code=…&state=…query strings work too. - Device-code login (no callback at all): if the server’s authorization server advertises a device authorization endpoint, run
mibyan mcp login <server> --flow deviceon the machine running Mibyan. It prints a verification URL and a short code; open the URL on any device, enter the code, and Mibyan polls for approval. No browser is launched on the host and no callback listener is needed. Setoauth.flow: deviceon the server to makeloginandreauthuse it by default. Details: Device-code login. - SSH port forward:
ssh -N -L <port>:127.0.0.1:<port> user@hostin a separate terminal, then let the redirect flow normally. - Proxied callback (
redirect_uri): when a public HTTPS endpoint forwards to the host (e.g. a Tailscale Funnel or reverse proxy pointed at the callback port), setoauth.redirect_uriand the browser redirect reaches Mibyan on its own — no tunnel or paste needed:
mcp-oauth-remote-gateway skill walks the agent through completing the flow manually and writing tokens where Mibyan expects them.
Pitfall — WAF rejects 127.0.0.1 redirect URIs. A few providers front their authorization server with a WAF that 403s any authorize request whose query string contains a literal 127.0.0.1 (Reclaim.ai’s AWS API Gateway is a known example — every attempt returns {"message":"Forbidden"} before reaching the OAuth app). Set oauth.redirect_host: localhost to use http://localhost:<port>/callback instead; the callback listener still binds 127.0.0.1 either way.
See OAuth over SSH / Remote Hosts for the full walkthrough, including DCR-less servers (e.g. Slack), pre-registered client_id/client_secret, scope customization, and re-auth via mibyan mcp login <server>.
Pitfall — providers that don’t support automatic registration (Google Drive, Atlassian). Some servers reject the dynamic client registration step (RFC 7591) that bare auth: oauth relies on — Google’s official Drive server (https://drivemcp.googleapis.com/mcp/v1) returns a 400 Bad Request, so no OAuth client is created and no token is acquired. The symptom is subtle: these servers also serve tools/list without auth, so mibyan mcp login can list the tools and look like it worked, but every real tool call later times out. mibyan mcp login now detects this (it checks that a token actually landed on disk) and tells you to supply your own OAuth client. Create one in the provider’s console and add it to config:
mibyan mcp login googledrive — with the pre-registered client, Mibyan skips registration and runs the normal browser authorization flow.
Pitfall — config auto-reload race. When you edit ~/.mibyan/config.yaml from inside a running Mibyan session, the CLI auto-reloads MCP connections with a 30s timeout. That’s not enough for an interactive OAuth flow. Add the entry, then run mibyan mcp login <server> from a fresh terminal — it waits the full 5 minutes for you to complete auth.
Need longer than 5 minutes to approve? Set oauth.timeout on the server entry (seconds). mibyan mcp login, the dashboard and Desktop re-auth all wait oauth.timeout + 15 s (or the entry’s connect_timeout, whichever is longer); a login that still runs out of time reports Connecting to MCP server '<name>' timed out after Ns naming both knobs instead of a blank failure line.
mTLS / client certificates
Remote HTTP MCP servers that require mutual TLS (client-certificate authentication) are supported viaclient_cert / client_key. Mibyan passes the resolved certificate to the underlying HTTP client for the TLS handshake.
client_cert accepts three shapes:
- A single combined PEM path — one file holding both the certificate and the private key:
- A
[cert, key]2-tuple — certificate and key in separate files (equivalent to settingclient_cert+client_key):
- A
[cert, key, password]3-tuple — when the private key is encrypted, the third element is the key passphrase:
client_cert (combined PEM) plus an explicit client_key. Paths support ~ expansion; a missing file raises a clear, server-scoped error rather than an opaque TLS handshake failure.
Per-user identity header
Remote HTTP/SSE MCP servers that key behavior on a caller identity (per-user rate limits, audit trails, multi-tenant routing) can be sent an identity header on every request viaidentity_header:
value_from: staticsends the literalvaluefrom config.yaml.value_from: profilesends the active Mibyan profile name, resolved once at connect time — useful when multiple profiles on one machine talk to the same server and it needs to tell them apart.
headers mapping with the same name (any casing) always wins; the identity header never overrides your own header config. Invalid identity_header blocks are warned about and ignored — they never block the server from connecting. On stdio servers the key is ignored with a warning (stdio transports have no headers).
Basic configuration reference
Mibyan reads MCP config from~/.mibyan/config.yaml under mcp_servers.
Common keys
Minimal stdio example
Recycling memory-heavy stdio servers
Browser-based MCP servers (e.g.@playwright/mcp) keep a full Chromium
resident after their first tool call — hundreds of MB that never get
released. Opt in to automatic recycling and the server is torn down after
the idle/lifetime limit, then restarted transparently the next time one of
its tools is called (its tools stay registered the whole time):
Minimal HTTP example
Built-in presets
For well-known MCP servers,mibyan mcp add accepts a --preset flag that fills in the transport details so you don’t have to look up the command and args. The preset only supplies defaults — anything else (env vars, headers, filtering) you pass on the same command line still wins.
mibyan mcp add my-codex --preset codex is fine); the preset only provides the command/args defaults.
How Mibyan registers MCP tools
Mibyan prefixes MCP tools so they do not collide with built-in names:
In practice, you usually do not need to call the prefixed name manually — Mibyan sees the tool and chooses it during normal reasoning.
Tool-result sanitization and _meta
Two behaviors apply to every MCP tool result before the model sees it:
- Invisible Unicode TAG characters are stripped. Characters in the U+E0000–U+E007F range render as nothing in terminals and chat UIs but are fully visible to the model — a classic prompt-injection smuggling channel for a malicious or compromised server. Mibyan strips them from tool results, resource content, and tool descriptions. Legitimate emoji tag sequences (regional flags like 🏴) are preserved.
- Vendor
_metais surfaced; protocol-reserved keys are not. When a server attaches a_metamapping to a tool result (vendor namespaces likecom.example/handoff), Mibyan passes it through to the model alongside the result content. Keys under protocol-reserved prefixes — amodelcontextprotocolormcplabel followed by another label, e.g.modelcontextprotocol.io/...ortools.mcp.com/...— are dropped, matching the MCP spec’s key-name rules. If nothing model-facing remains, the_metafield is omitted entirely.
MCP utility tools
When supported, Mibyan also registers utility tools around MCP resources and prompts:list_resourcesread_resourcelist_promptsget_prompt
mcp_github_list_resourcesmcp_github_get_prompt
Important
These utility tools are now capability-aware:- Mibyan only registers resource utilities if the MCP session actually supports resource operations
- Mibyan only registers prompt utilities if the MCP session actually supports prompt operations
Per-server filtering
You can control which tools each MCP server contributes to Mibyan, allowing fine-grained management of your tool namespace.Disable a server entirely
enabled: false, Mibyan skips the server completely and does not even attempt a connection.
Whitelist server tools
include/exclude may also be glob patterns (*, ?, [...],
matched case-sensitively): include: ["*_dns_*"] registers every tool whose
name contains _dns_. Plain entries without metacharacters stay exact-match.
Globs are the practical way to filter servers that expose thousands of
auto-generated endpoint tools by product family.
Blacklist server tools
Glob patterns
Both lists accept fnmatch-style globs alongside exact names — essential for huge flat surfaces like Cloudflare’s API MCP (?codemode=false, ~3,300
tools) where excluding product areas one endpoint at a time is impractical:
*, ?, [) match exactly — docs
excludes only the tool named docs, never docs_search.
Precedence rule
If both are present:include wins.
Filter utility tools too
You can also separately disable Mibyan-added utility wrappers:tools.resources: falsedisableslist_resourcesandread_resourcetools.prompts: falsedisableslist_promptsandget_prompt
Full example
What happens if everything is filtered out?
If your config filters out all callable tools and disables or omits all supported utilities, Mibyan does not create an empty runtime MCP toolset for that server. That keeps the tool list clean.Runtime behavior
Discovery time
Mibyan discovers MCP servers at startup and registers their tools into the normal tool registry. Servers are connected at most 4 at a time per discovery pass (startup,/reload-mcp, config
watcher). Every stdio server spawns its own child-process tree, so an unbounded pass with many servers
used to launch them all in the same instant — a CPU/RAM spike and, on multi-profile fleets, a burst of
simultaneous provider calls. Tune it in config.yaml:
Lazy start
A server withlazy: true is registered from the on-disk schema cache instead: its tools appear in the registry immediately, and the process is spawned (or the HTTP endpoint connected) on the first tool call. The cache is written on every live connect, so the first run of a new or changed server is always eager. The banner and the TUI session panel show such a server as lazy with its cached tool count (3 tool(s) (lazy, starts on first use)) — it is a working server, not a failed one — and the startup discovery summary counts it as N lazy, not spawned yet.
Dynamic Tool Discovery
MCP servers can notify Mibyan when their available tools change at runtime by sending anotifications/tools/list_changed notification. When Mibyan receives this notification, it automatically re-fetches the server’s tool list and updates the registry — no manual /reload-mcp required.
This is useful for MCP servers whose capabilities change dynamically (e.g. a server that adds tools when a new database schema is loaded, or removes tools when a service goes offline).
The refresh is lock-protected so rapid-fire notifications from the same server don’t cause overlapping refreshes. Prompt and resource change notifications (prompts/list_changed, resources/list_changed) are received but not yet acted on.
Reloading
If you change MCP config, use:HASS_TOKEN, OAuth…): a session’s tool set is otherwise frozen, so a credential or daemon that appears mid-session is only picked up on /reload-mcp, /new, or context compaction. For runtime tool changes pushed by the server itself, see Dynamic Tool Discovery above.
A running messaging gateway (mibyan gateway run) also watches config.yaml on its own: within about a minute of you removing an mcp_servers entry or setting enabled: false, that server’s connection is torn down; a newly added entry is connected. A server whose first connect failed (an unreachable host, or an OAuth server on a headless box that had no token yet) is retried automatically on its connect cooldown schedule (30 s, doubling up to 10 min) once you fix the cause. No restart or /reload-mcp needed for the edit to take effect.
Expired OAuth tokens in the background. The gateway, /reload-mcp, and the periodic self-probe of a parked server never open a browser — nobody is there to complete the flow. When a refresh token dies, the server parks with a warning in gateway.log and you re-authorize once with mibyan mcp login <server> (or the Desktop/dashboard Authorize button); the parked server picks the new token up on its next probe.
Toolsets
Each configured MCP server also creates a runtime toolset when it contributes at least one registered tool:Security model
Stdio env filtering
For stdio servers, Mibyan does not blindly pass your full shell environment. Only explicitly configuredenv plus a safe baseline are passed through. This reduces accidental secret leakage.
Config-level exposure control
The new filtering support is also a security control:- disable dangerous tools you do not want the model to see
- expose only a minimal whitelist for a sensitive server
- disable resource/prompt wrappers when you do not want that surface exposed
Example use cases
GitHub server with a minimal issue-management surface
Stripe server with dangerous actions removed
Filesystem server for a single project root
Troubleshooting
MCP server not connecting
Check:agent.log names every server that did not register, with the recorded
connect error, so you never have to work out the failing one by elimination:
not attempted (in retry cooldown).
Remote (HTTP) server rejects the connection
mibyan mcp test <name> reports what the server actually answered. When the MCP SDK can only say
Server returned an error response (a 4xx/5xx whose body is not a JSON-RPC error), Mibyan appends
the HTTP status, the URL it requested and the start of the response body:
400/405 on the initialize POST usually means the endpoint
speaks SSE only (set transport: sse) or a proxy in front of it rejects the request; a 401/403
means the token or OAuth grant is wrong; an HTML body means the URL points at a web page, not an MCP
endpoint. mibyan logs --level debug additionally shows the exact endpoint each connect attempt used.
Tools not appearing
Possible causes:- the server failed to connect
- discovery failed
- your filter config excluded the tools
- the utility capability does not exist on that server
- the server is disabled with
enabled: false
Why didn’t resource or prompt utilities appear?
Because Mibyan now only registers those wrappers when both are true:- your config allows them
- the server session actually supports the capability
Parallel Tool Calls
By default, MCP tools run sequentially — one at a time. If your MCP server exposes tools that are safe to run concurrently (e.g. read-only queries, independent API calls), you can opt-in to parallel execution:supports_parallel_tool_calls is true, Mibyan may execute multiple tools from that server at the same time within a single tool-call batch, just like it does for built-in read-only tools (web_search, read_file, etc.).
MCP Sampling Support
MCP servers can request LLM inference from Mibyan via thesampling/createMessage protocol. This allows an MCP server to ask Mibyan to generate text on its behalf — useful for servers that need LLM capabilities but don’t have their own model access.
Sampling is enabled by default for all MCP servers (when the MCP SDK supports it). Configure it per-server under the sampling key:
MCP Elicitation Support
MCP servers can ask the user for structured input mid-tool-call via theelicitation/create protocol (mcp Python SDK ≥ 1.11.0). Mibyan routes form-mode elicitations through its existing approval surface — an interactive prompt in the CLI/TUI, or approval buttons on gateway platforms like Telegram and Slack — so the request reaches you wherever the session lives. URL-mode elicitations (where a server points you at an external URL) are declined as unsupported.
Elicitation is enabled by default per server. Configure it under the elicitation key:
Running Mibyan as an MCP server
In addition to connecting to MCP servers, Mibyan can also be an MCP server. This lets other MCP-capable agents (Claude Code, Cursor, Codex, or any MCP client) use Mibyan’s messaging capabilities — list conversations, read message history, and send messages across all your connected platforms.When to use this
- You want Claude Code, Cursor, or another coding agent to send and read Telegram/Discord/Slack messages through Mibyan
- You want a single MCP server that bridges to all of Mibyan’s connected messaging platforms at once
- You already have a running Mibyan gateway with connected platforms
Quick start
MCP client configuration
Add Mibyan to your MCP client config. For example, in Claude Code’s~/.claude/claude_desktop_config.json:
Available tools
The MCP server exposes 10 tools, matching OpenClaw’s channel bridge surface plus a Mibyan-specific channel browser:Event system
The MCP server includes a live event bridge that polls Mibyan’s session database for new messages. This gives MCP clients near-real-time awareness of incoming conversations:message, approval_requested, approval_resolved
The event queue is in-memory and starts when the bridge connects. Older messages are available through messages_read.
Options
How it works
The MCP server reads conversation data directly from Mibyan’s session store —~/.mibyan/state.db is the primary source, with sessions.json kept only as a legacy fallback. A background thread polls the database for new messages and maintains an in-memory event queue. For sending messages, it uses the same internal send engine (tools/send_message_tool.py) that powers cron delivery and the mibyan send CLI.
The gateway does NOT need to be running for read operations (listing conversations, reading history, polling events). It DOES need to be running for send operations, since the platform adapters need active connections.
Current limits
- The embedded
mibyan mcp serveexposes a stdio-only MCP server today. If you need an HTTP MCP server, run a separate adapter — or, much more commonly, use the MCP client side of Mibyan, which already speaks both stdio and HTTP (url+headersinmcp_servers.yaml/config.yaml; see HTTP servers above). - Event polling at ~200ms intervals via mtime-optimized DB polling (skips work when files are unchanged)
- No
claude/channelpush notification protocol yet - Text-only sends (no media/attachment sending through
messages_send)

