Coding agent

MiMo Code

Open coding harness with persistent memory and structured multi-agent workflows.

Status
Active
License
MIT with use restrictions
Evidence
Documented + code-verifiable, 14 sources
Product record checked
2026-08-02

At a glance

A multi-provider terminal coding harness with repository tools, persistent project memory, automatic context compaction, primary and delegated agents, bounded workflow orchestration, headless and local web surfaces, MCP, skills, and Git-backed undo. It runs tools on the host: its permission policy and workflow runtime are controls, not an operating-system sandbox.

Good choice if

  • Long-running repository work that benefits from persistent project memory and automatic context reconstruction
  • Multi-provider or local-model workflows using primary agents, subagents, MCP servers, and reusable skills
  • Headless and structured multi-agent workflows with bounded retries, parallel steps, and optional isolated Git worktrees

Check before choosing

  • MiMo Code has no built-in process sandbox; the official security policy describes permissions as a user-experience control and recommends a container or virtual machine for isolation
  • Most tool permissions default to allow, and the headless CLI can skip permission checks entirely, so unattended use needs an independently constrained runtime
  • The workflow control script runs in QuickJS, but Bash and other tools still act on the host; worktrees separate repository files without containing processes, credentials, network access, or external side effects
See 2 more considerations
  • Persistent memory and project instructions can influence later sessions, so durable context and generated workflow assets need review like other repository-controlled instructions
  • Git-backed undo requires a Git repository, excludes ignored files and untracked files larger than 2 MiB, and cannot reverse shell, network, or other external side effects

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-08-02The source establishes the mechanism, not its quality or availability in every mode.
Reusable skills
DocumentedProduct-supported reusable skill packagesSource · checked 2026-08-02Support does not establish portability, package quality, safety, or adoption.
Local models
DocumentedLocal or self-hosted model pathSource · checked 2026-08-02The source establishes the mechanism, not its quality or availability in every mode.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-08-02The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-08-02The source establishes the mechanism, not its quality or availability in every mode.
Browser control
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.
Isolated execution
No built-in supportHost execution; permission rules and workflow scripting are not process isolationSource · checked 2026-08-02The official security policy explicitly states that MiMo Code has no sandbox and recommends a container or virtual machine for isolation.
Undo file changes
DocumentedProduct-supported file or session rollbackSource · checked 2026-08-02The source establishes the mechanism, not its quality or availability in every mode.

Getting started

Install `@mimo-ai/cli`, connect MiMo or another supported provider, review the permission rules, and use a container or virtual machine when execution isolation is required.

Open official documentation

Classification and operating model

Category fit and technical mechanisms are evidence records, not product-quality scores.

Category fit
Qualifies, 4/4 criteria
Operating model
7/7 layers documented
Inspect category criteria and operating mechanismsFirst-party records

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationWorkspace isolationDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible toolsDocumented mechanism, not a performance score.
  • Context & statePersistent stateDocumented mechanism, not a performance score.
  • Lifecycle & recoveryCheckpoint/rewindDocumented mechanism, not a performance score.
  • ObservabilityLogs/transcriptsDocumented mechanism, not a performance score.
  • VerificationTool-assistedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.

Measured and public context

Configuration-specific measurements and source-native activity stay separate from general product capability.

Inspect code audit, measured configurations, and ecosystem signalsContext, not a product score

Public code audit

5/5public artifacts present
Security policy
Present at inspected commit
CI workflow
Present at inspected commit
Automated tests
Present at inspected commit
Evaluation assets
Present at inspected commit
Contributor documentation
Present at inspected commit

The v0.1.9 tree contains 5,189 tracked files, 538 test- or evaluation-like paths, three workflows, security and contributor documentation, and bundled project-owned evaluation fixtures. Those fixtures are development assets rather than an independent, immutable model × harness × environment × budget × attempts result, so no product score is imported. The root use-restrictions file adds conditions beyond the MIT license text.

Inspect commit c045a9891069000b112079bb10bdc8828d75eb6e, checked 2026-08-02

Measured configurations

No benchmark run passes the full metadata admission policy for this harness yet. Missing data is not scored as zero.

Benchmark policy and all runs
Context, not quality

Public ecosystem signals

Source-native observations for exact mapped artifacts and reviewed stable release trains. Different units and populations stay separate, and missing coverage is never treated as zero.

View this harness in Usage
  • Latest stable releasev0.1.9Released 2026-07-24; 9 stable releases in 90 daysOpen release
  • OpenRouter 30d tokens72.67B#23 coding app; 2026-07-03 to 2026-08-01Open app page
  • Homebrew 30d events397Formula: mimo-codeOpen artifact
  • npm last-month downloads114.78KPackage: @mimo-ai/cliOpen artifact
  • Release asset downloads80.78K9 stable releases; 108 matched assetsOpen artifact
  • GitHub stars12.6KFull-source repository; 1.29K forksOpen artifact

Routing, package retrievals, release downloads, editor installs, and repository interest observe different populations. They are never added together and never affect capability evidence, classification, or measured results.

Interpretation rulesSignals checked

First-party evidence

Each capability claim links to the first-party record that supports it.

14 first-party sourcesProduct record checked

Product and interfaces

2 sources
View 1 more source

Execution and control

3 sources
View 2 more sources

Agents, state and recovery

4 sources
View 3 more sources

Automation and extensions

3 sources
View 2 more sources

Releases and public code audit

2 sources
View 1 more source

Ecosystem context

OpenRouter MiMo Code app Discovery and public attribution context only; it does not establish MiMo Code capabilities, quality, safety, or task performance. Observed 2026-08-02.