All releases
v0.4.0LatestGitHub release ↗

Mira v0.4.0

The plugins and desktop release. Mira gains a native desktop app, a full

Desktop appMCP serversPlugins & hooksPlugins page (web UI)Amazon BedrockSandboxingEditor integrationsCloud tasksComputer & browser toolsRemote compute environments

The plugins and desktop release. Mira gains a native desktop app, a full MCP server ecosystem, Claude Code-compatible plugins with running hooks, cloud task offloading, computer/browser control, remote compute environments, Amazon Bedrock, editor integrations for Zed and VS Code — plus a completely redesigned Plugins page.

New

Desktop app

  • Native desktop app. apps/desktop is a Tauri 2 app that bundles mira as a sidecar, starts mira serve on 127.0.0.1:8797, and loads the web UI from it. Single instance; the server stops on quit, and a leftover server from a crash is stopped on the next launch.
  • OAuth in the system browser. Sign-in opens in the system browser and returns through a mira://auth-callback deep link — providers refuse OAuth in webviews. The page exchanges the PKCE code it started.
  • Shell environment. The server gets the login shell's environment so PATH and exported keys work when the app is launched from the Dock.
  • scripts/build-desktop.sh builds the UI, mira, stages the sidecar and runs cargo tauri dev|build. See docs/desktop.md for setup.

MCP servers

  • Full MCP manager (mira-mcp). Live connections over stdio, streamable HTTP, and legacy SSE; parallel connect with timeouts; reconnect with backoff; live config changes; OAuth sign-in with stored and refreshed tokens; project server approval and disable; list_changed, roots, resources, prompts, images in results; output caps; stderr to per-server log files.
  • Scope groups. Servers are grouped as Local (this project, only you), Project (.mcp.json, shared with the repo), User (all your projects), or Plugin (bundled by an installed plugin).
  • Tokens. An "Add token" button on the Plugins page and mira mcp set-var NAME (--unset removes it) let you paste values for servers like GitHub that need a ${VAR} — without editing config files. Values are saved in ~/.mira/mcp/variables.json (0600); the server reconnects automatically.
  • Per-tool on/off. A toggle on each tool's row in the detail page, or mira mcp tool enable|disable NAME, persisted in state. Disabled tools are never sent to the model.
  • On-demand tool loading. mira mcp tool-loading all|on-demand|auto (also MIRA_MCP_TOOL_LOADING). In on-demand mode the model gets search_mcp_tools (keyword search with full schemas) and call_mcp_tool instead of every definition upfront. auto switches automatically above 30 enabled tools. Permission rules still apply to the underlying tool.
  • CLI commands. mira mcp add, add-json, list, get, remove, login, logout, enable, disable, approve, reject, set-var, tool enable|disable, tool-loading.
  • TUI commands. /mcp lists and manages servers from the terminal.
  • Sign-in fixes. Sign-in now opens the tab on the click itself (a deferred open was silently pop-up blocked). The desktop app uses openExternal. A banner keeps an "Open sign-in page" link until the server connects. Sign-in times out after 30 s with a clear error.

Plugins & hooks

  • Claude Code-compatible plugin system (mira-plugins). Marketplaces (GitHub, git, directory, URL), install from relative, GitHub, URL and git-subdir sources, enable/disable/uninstall. Plugin components: commands, agents, skills, MCP servers, hooks, LSP servers.
  • Plugin hooks now run, in Claude Code's format. Five hook points:
    • SessionStart / UserPromptSubmit — stdout or additionalContext prepends to the prompt; exit 2 or decision: block stops it.
    • PreToolUse — deny refuses the call with a reason for the model; ask forces an approval prompt; updatedInput rewrites arguments.
    • PostToolUse — additionalContext is appended to the tool result.
    • Stop — block keeps the agent working with the reason as the next message (capped at 8 iterations).
    • Hooks get JSON on stdin with Claude Code's tool names (Bash, Read, Edit, Write, …) so hooks written for Claude Code work unchanged. Matching hooks run in parallel with CLAUDE_PLUGIN_ROOT and CLAUDE_PROJECT_DIR set and a timeout (default 60 s).
    • User hooks go under hooks: in ~/.mira/mira.yaml. Project config hooks are ignored on purpose.
  • Custom slash commands. Plugin commands support $ARGUMENTS and !<shell> context blocks; expanded server-side and in the TUI.
  • Agents in Claude Code format. Comma-separated tools map to Mira names; model aliases fall back to the session model.
  • CLI commands. mira plugin list, browse, info, install, update, uninstall, enable, disable, marketplace add/list/update/remove.
  • TUI commands. /plugin for in-session plugin management.

Plugins page (web UI)

  • Discover tab. Catalog from your marketplaces with category filter chips, favicon-first sorting, author badges, and install from the card. Suggested marketplaces when none are added. In-page detail view with a What's Included breakdown, README, and Information table — no more modal.
  • Installed tab. 2-column card grid with favicon icons, enable/disable toggle, uninstall, component summary.
  • Marketplaces tab. Add by owner/repo, git URL, marketplace.json URL, or local path; update; remove; plugin count pill.
  • MCP servers tab. Grouped by scope, live status badge overlaid on the avatar icon, sign in (OAuth), "Add token" for ${VAR} servers, per-tool on/off switches, tool-loading mode picker, approve/reject project servers, reconnect, enable/disable, add/edit with a form or pasted JSON. In-page detail view with tools, prompts, resources, server info, and log path — no more modal.
  • Slash palette. The / palette groups commands by source — Mira built-ins, then one section per plugin or MCP server with its icon and name. Each row is labelled Command, Skill, or Prompt. MCP prompts show their own names. Typing a plugin's name lists everything it adds.
  • Favicon fixes. Google favicon service is called with the apex domain (e.g. mcp.figma.com → figma.com) so brand logos appear instead of generic globes. Generic hosting domains (GitHub, npm, etc.) are filtered.
  • Live refresh. The page refreshes on extensions_changed push events; changes apply without a page reload.

Amazon Bedrock

  • Native Bedrock provider via the Converse streaming API.
  • Signs with AWS credentials (SigV4, from env or ~/.aws) or a Bedrock API key. The region comes from the base URL, then AWS_REGION, then ~/.aws/config.
  • Lists inference profiles and foundation models. Added as a preset in Settings; no API key required for credential-based auth.

Sandboxing

  • Landlock on Linux. Used when bubblewrap is missing or can't create namespaces (containers, Ubuntu 24.04+ with AppArmor). Confines reads and writes to the repo, system dirs, PATH, temp, and dev caches. Blocks TCP when offline on kernel 6.7+.
  • bwrap probed once at startup instead of failing every command when broken.
  • MIRA_SANDBOX_BACKEND overrides the choice (bwrap, landlock, seatbelt, none). mira doctor shows the active backend.
  • macOS keychain gap closed. The keychain daemons are now blocked so a command can't read saved secrets through git credential-osxkeychain.

Editor integrations

  • mira acp — Mira as an Agent Client Protocol agent over stdio, for Zed and other ACP editors. Each editor thread is a Mira session in the editor's folder; streams text, tool calls and file diffs, asks for permission through the editor, supports modes and cancel. Zed config: {"agent_servers": {"Mira": {"command": "mira", "args": ["acp"]}}}
  • VS Code extension 0.2.0:
    • Approvals from the chat (Allow / Allow for session / Deny, with the diff inline).
    • Auto-starts mira serve; added a Mira: Start Server command.
    • Publish workflow: builds the extension on changes; on a vscode-v* tag it publishes to the Marketplace and Open VSX.

Cloud tasks

  • mira cloud run "<task>" offloads the entire agent session to an E2B sandbox and returns in seconds — the laptop can close.
  • Cloud worker. Clones the repo, branches mira/<task>-<id>, opens a draft PR immediately, runs a headless /goal session, commits and pushes after every iteration while keeping the PR description current, posts a summary comment, and marks the PR ready when the goal is met.
  • CLI. mira cloud run, list, logs, stop with pre-flight checks (GitHub origin, base branch on GitHub, token, E2B environment).
  • Cross-compile helper. scripts/build-linux-mira.sh cross-compiles a Linux x86_64 binary with cargo-zigbuild for E2B upload from macOS (cloud.binary / MIRA_CLOUD_BINARY).

Computer & browser tools

  • Computer use. mira --computer enables screenshot, click, type, key, scroll, cursor_position, left_click_drag. Backends: X11 (xdotool + maim) and macOS (screencapture + CoreGraphics via JXA). HiDPI-safe coordinate mapping; off-screen clicks refused. Desktop input asks even in yolo mode.
  • Browser automation. mira --browser enables Chrome DevTools-based control: text snapshots with element refs, click/type/key/scroll, screenshots, tabs, and evaluate. Runs in a dedicated Chrome profile.
  • Policy integration. Computer(...) and Browser(...) rules, verb or verb:detail patterns with wildcards. "Allow for session" widens to the verb. Subagents never inherit these tools.
  • Screenshots render inline in the web UI.

Remote compute environments

  • Named environments. compute.environments in the global config: backend (e2b or scratch), template, timeout, env vars, and a setup script run once after first upload. local is the user's machine.
  • Live session switching. /remote-env in the TUI, environment chip in the web UI, or --sandbox <env> at startup.
  • Merge-back. Switching remote → local merges changes file by file (git merge-file); conflicts are reported. Full patch kept under ~/.mira/sandbox/.
  • Parking. Environments you leave are parked (E2B paused, scratch kept); coming back re-uploads tracked files only.

Fixed

  • MCP "Sign in" doing nothing — the sign-in page was opened after the request returned, silently hitting the browser's pop-up blocker. Now opens on the click itself.
  • Paste marker freeze — a malformed or unclosed [[paste: marker made the TUI composer's input tokenizer loop forever. Now treated as plain text.
  • Paste chip column counting — with the caret mid-word, its column counted the whole word; paste chips wider than the row split across rows.
  • Tool-output comment highlighter — // comment rendered as /// comment; abc#tag was dimmed as a comment (# only starts a comment at a token boundary).
  • Diff view line-number band — the line-number cell of added/removed rows now carries the row's tint so the band is continuous.
  • Episodic memory flush — FileEpisodicStore::append dropped without flushing; a read right after could miss the entry just saved.
  • Clippy question_mark lint — fixed for Rust 1.98 compatibility.

Docs

  • docs/mcp-and-plugins.md — complete guide covering scopes and approval, OAuth, tokens, per-tool switches, on-demand loading, marketplaces, plugins, hooks, and the GitHub and Figma setups.
  • README — adds Bedrock, editor integrations (VS Code, Zed), command sandbox, missing crates, and a roadmap that matches what has shipped.

Under the hood

  • mira-mcp — MCP manager, OAuth token store, set_variable, per-tool enable/disable, on-demand search_mcp_tools / call_mcp_tool, Landlock.
  • mira-plugins — marketplace fetcher, plugin installer, component loader, custom command expander, hook runner.
  • mira-cloud — cloud worker, launcher, GitHub client, git helper, task store.
  • mira-compute — ComputeBackend trait, LocalBackend, E2bBackend, EnvironmentManager with ComputeSlot, workspace pack/upload/diff.
  • mira-computer — ComputerBackend trait, X11 and macOS backends, mock.
  • mira-browser — Chrome DevTools driver, dedicated profile.
  • mira-ai — native Amazon Bedrock provider (Converse API, SigV4).
  • apps/desktop — Tauri 2 sidecar app, own Cargo workspace.
  • CI: excludes evals/tasks/* (broken by design); Landlock and macOS sandbox-exec tests; fmt, clippy, and the full test suite all green.