Skip to main content
Glama

Vox MCP

Multi-model AI gateway for MCP clients.

Why

MCP clients like Claude Code, Claude Desktop, and Cursor are locked to their host model. Vox gives them access to every other model — Gemini, GPT, Grok, DeepSeek, Kimi, or your local Ollama — through a single chat tool.

The design is deliberately minimal: prompts go to providers unmodified, responses come back unmodified. No system prompt injection. No response formatting. No behavioral directives. The only value Vox adds is routing and conversation memory — everything else is pure passthrough.

Related MCP server: 1mcpserver

What it does

Send a prompt, optionally attach files or images, pick a model (or let the agent pick), and get back the model's raw response. Conversation threads persist in memory via continuation_id for multi-turn exchanges across any provider — start a thread with Gemini, continue it with GPT. Threads are shadow-persisted to disk as JSONL for durability and can be exported as Markdown.

3 tools:

Tool

Description

chat

Send prompts to any configured AI model with optional file/image context

listmodels

Show available models, aliases, and capabilities

dump_threads

Export conversation threads as JSON or Markdown

10 providers:

Provider

Environment variable

Built-in preference or route

Google Gemini

GEMINI_API_KEY

gemini-3.8-flash; gemini-3.1-pro-preview for extended reasoning

OpenAI

OPENAI_API_KEY

gpt-6-astra

Anthropic

ANTHROPIC_API_KEY

claude-opus-5-5, then claude-fable-5-1

xAI

XAI_API_KEY

grok-4.6

DeepSeek

DEEPSEEK_API_KEY

deepseek-flash (V4.1 Flash)

Moonshot (Kimi)

MOONSHOT_API_KEY

kimi-k3

OpenRouter

OPENROUTER_API_KEY

Explicit OpenRouter model ID or curated alias

Cloudflare AI Gateway

CLOUDFLARE_API_TOKEN + CLOUDFLARE_ACCOUNT_ID

cloudflare/<provider>/<model>

Vercel AI Gateway

VERCEL_AI_GATEWAY_API_KEY or AI_GATEWAY_API_KEY

vercel/<provider>/<model>

Custom

CUSTOM_API_URL

Ollama, vLLM, LM Studio, etc.

These are preferences within each provider. With auto, the calling agent chooses an available model; if Vox must choose, its existing provider priority applies. An explicit model or configured default takes precedence. GPT-6 Sol/Luna, Grok 4.7, Claude Fable 5.1, Sonnet 5, and Haiku 4.5 remain selectable. Claude 3 Opus's pinned snapshot is preserved for accounts with access.

See model selections and verification sources for provider preferences, exact API IDs, and reasoning behavior.

Quick start

Published package

With uv installed, add Vox to your MCP client's configuration. For example, to use OpenAI:

{
  "mcpServers": {
    "vox-mcp": {
      "command": "uvx",
      "args": ["vox-mcp"],
      "env": {
        "OPENAI_API_KEY": "your-key-here"
      }
    }
  }
}

Use the environment variable for your preferred provider from the table above. Only one provider is required. Connect the server, then ask your agent to call listmodels to see the models available with your configuration.

For an exact release, use "args": ["vox-mcp@0.8.0"]. To refresh a cached installation, run uvx --refresh vox-mcp config show, then reconnect the MCP server. A version pinned in your client configuration must be updated there as well.

Source checkout

git clone https://github.com/linxule/vox-mcp.git
cd vox-mcp
cp .env.example .env
# Edit .env — add at least one API key
uv sync
uv run python server.py

MCP client configuration

Vox runs as a stdio MCP server. Each client needs to know how to launch it. The following examples use a source checkout; the published-package configuration above avoids cloning the repository. Replace /path/to/vox-mcp with the absolute path to your cloned repo.

Claude Code (CLI)

claude mcp add vox-mcp \
  -e GEMINI_API_KEY=your-key-here \
  -- uv run --directory /path/to/vox-mcp python server.py

Or add to .mcp.json in your project root:

{
  "mcpServers": {
    "vox-mcp": {
      "command": "uv",
      "args": ["run", "--directory", "/path/to/vox-mcp", "python", "server.py"],
      "env": {
        "GEMINI_API_KEY": "your-key-here"
      }
    }
  }
}

Claude Desktop

Add to claude_desktop_config.json:

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

{
  "mcpServers": {
    "vox-mcp": {
      "command": "uv",
      "args": ["run", "--directory", "/path/to/vox-mcp", "python", "server.py"],
      "env": {
        "GEMINI_API_KEY": "your-key-here"
      }
    }
  }
}

Cursor

Add to .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):

{
  "mcpServers": {
    "vox-mcp": {
      "command": "uv",
      "args": ["run", "--directory", "/path/to/vox-mcp", "python", "server.py"],
      "env": {
        "GEMINI_API_KEY": "your-key-here"
      }
    }
  }
}

Windsurf

Add to ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "vox-mcp": {
      "command": "uv",
      "args": ["run", "--directory", "/path/to/vox-mcp", "python", "server.py"],
      "env": {
        "GEMINI_API_KEY": "your-key-here"
      }
    }
  }
}

Any MCP client

The canonical stdio configuration:

{
  "mcpServers": {
    "vox-mcp": {
      "command": "uv",
      "args": ["run", "--directory", "/path/to/vox-mcp", "python", "server.py"],
      "env": {
        "GEMINI_API_KEY": "your-key-here"
      }
    }
  }
}

Tips:

  • Paths must be absolute

  • You only need one API key to start — add more providers later via .env

  • The .env file in the vox-mcp directory is loaded automatically, so API keys can go there instead of in the client config

  • Use VOX_FORCE_ENV_OVERRIDE=true in .env if client-passed env vars conflict with your .env values

Configuration

Set these values in your MCP client's Vox env object. For a source checkout, you can instead copy .env.example to .env:

  • API keys — at least one provider key is required

  • DEFAULT_MODEL — overrides the saved model preference; auto asks the agent to choose

  • VOX_CONFIG_PATH — optional settings file path (default: ~/.vox/config.json)

  • Model restrictions — GOOGLE_ALLOWED_MODELS, OPENAI_ALLOWED_MODELS, etc.

  • CONVERSATION_TIMEOUT_HOURS — thread TTL (default: 24h)

  • MAX_CONVERSATION_TURNS — thread length limit (default: 100)

See .env.example for the full reference.

Set your default model

Available since 0.8.0. You or your agent can save a default without editing MCP client configuration. For example, choose GPT-6 Astra:

uvx vox-mcp config set-default gpt-6-astra
uvx vox-mcp config show

Replace gpt-6-astra with any available model ID, such as kimi-k3, grok-4.6, claude-opus-5-5, claude-fable-5-1, deepseek-flash, or gemini-3.8-flash. To remove the saved preference, run uvx vox-mcp config reset-default.

For a source checkout, use uv run vox-mcp config .... Preferences are stored in ~/.vox/config.json; set VOX_CONFIG_PATH to use another file. This file contains model preferences, not API keys. Commands make no model requests and do not need provider credentials. Use listmodels in your connected MCP client to choose an available ID or alias. Explicit gateway routes such as vercel/google/gemini-3.1-pro-preview can also be saved. IDs are preserved exactly; saving a default does not verify your account's access to that model.

Restart or reconnect Vox after changing settings. config show prints the saved default, effective default, and its source for the command's launch environment. The running MCP client's environment may differ; listmodels reports the default that its server actually loaded.

Selection order is: explicit chat.model, the previous model for a continued thread, DEFAULT_MODEL from the server environment, the saved default, then auto. A saved default therefore changes new conversations; it does not switch existing threads. To override saved preferences for one MCP client, add "DEFAULT_MODEL": "your-model-id" to the Vox server's env object. Existing source checkout .env settings also retain their environment precedence. The automatically loaded .env belongs to the Vox installation, not the current directory; use the settings command or MCP client environment for uvx installations.

With auto, the agent is asked to select a model for each call. If a caller passes model: "auto", Vox uses its built-in provider priority and preferences; this is not a live comparison of all providers. Explicit model selections always remain available. An agent with terminal access can do this for you:

Use Vox listmodels to check that GPT-6 Astra is available. Save it as my Vox default with the config command, check whether DEFAULT_MODEL overrides it, and tell me how to reconnect Vox.

An agent with only Vox's three MCP tools can select a model for each call, but cannot persist a preference; saving settings requires terminal or file access.

Cloudflare and Vercel AI Gateway

Use an explicit gateway prefix in chat.model. Vox removes only that first prefix before sending the request and keeps it in conversation memory. A missing gateway configuration or disallowed model fails without falling through to OpenRouter or a native provider. Bare model names keep their existing routing behavior.

Cloudflare

CLOUDFLARE_API_TOKEN=your-cloudflare-token
CLOUDFLARE_ACCOUNT_ID=your-account-id
CLOUDFLARE_GATEWAY_ID=default
CLOUDFLARE_MODELS=openai/gpt-5.5
{"prompt": "Explain quorum consensus.", "model": "cloudflare/openai/gpt-5.5"}

Vox uses the Cloudflare account REST API at https://api.cloudflare.com/client/v4/accounts/<account>/ai/v1, authenticates with a bearer token, and sets cf-aig-gateway-id (default unless configured). The token needs Workers AI Read permission; an AI Gateway-only token is not sufficient. Third-party models use Cloudflare Unified Billing. Workers AI model IDs retain their @cf/ prefix, for example cloudflare/@cf/moonshotai/kimi-k2.6. Legacy /compat, provider-key forwarding, and dynamic/ routes are not supported by this adapter.

Vercel

VERCEL_AI_GATEWAY_API_KEY=your-vercel-gateway-key
VERCEL_MODELS=anthropic/claude-sonnet-4.6
{"prompt": "Explain quorum consensus.", "model": "vercel/anthropic/claude-sonnet-4.6"}

Vox uses Vercel's OpenAI-compatible API at https://ai-gateway.vercel.sh/v1. AI_GATEWAY_API_KEY is also accepted; VERCEL_AI_GATEWAY_API_KEY takes precedence when both are set.

Catalogs and limits

CLOUDFLARE_MODELS and VERCEL_MODELS are optional comma-separated upstream IDs for listmodels and agent discovery. They do not restrict access. Explicit gateway model IDs work without a catalog, including with the default DEFAULT_MODEL=auto; the caller must supply the gateway model. Use CLOUDFLARE_ALLOWED_MODELS or VERCEL_ALLOWED_MODELS to restrict access. Both upstream IDs and fully prefixed Vox routes are accepted in catalogs and allowlists. Use the exact model ID published by the gateway; native-provider and gateway IDs can differ.

Gateway requests currently support text only. Vox does not infer vision or thinking controls from a model name; explicit gateway thinking_mode requests are rejected before inference. Its 32,768-token context and 4,096-token output budgets are conservative local estimates, not advertised upstream limits; these numbers are not sent as generation parameters. Omitted temperature and reasoning settings use upstream defaults. No catalog or model availability request is made at startup. The adapters are covered by mocked HTTP tests; live inference requires a configured account and has not been exercised as part of the release checks.

Development

Dependencies are maintained in pyproject.toml and uv.lock; Dependabot updates the lock through its uv integration while respecting the supported version ranges. Changing those ranges requires a deliberate compatibility review. CI checks the lockfile, runs the offline test suite on Python 3.10 and 3.13, and audits locked packages with pip-audit. The supported SDK lines are MCP 1.x, OpenAI 2.x, and Anthropic 0.x. MCP SDK 2 requires a separate server API migration; provider major upgrades are kept separate from dependency maintenance.

uv sync
uv run python -c "import server"   # smoke test
uv run pytest                       # run tests

See CONTRIBUTING.md for code style, project structure, and how to add providers.

License

Apache 2.0 — see LICENSE and NOTICE.

Derived from pal-mcp-server by Beehive Innovations.

Available Tools

3 tools
chatA
Read-only

Multi-model AI gateway. Routes prompts to external AI models (Gemini, OpenAI, Anthropic, DeepSeek, Moonshot, xAI, OpenRouter, custom endpoints) with conversation memory. Supports file context embedding, images, and multi-turn threads via continuation_id.

ParametersJSON Schema
NameRequiredDescriptionDefault
modelYesCurrently in auto model selection mode. If no model is provided, you may use the `listmodels` tool to review options and select an appropriate match. The server validates model availability and returns errors for unknown models. Top models: gemini-3.8-flash (score 100, 1.0M ctx, thinking, code-gen); gemini-2.5-pro (score 100, 1.0M ctx, thinking, code-gen); gemini-3.1-pro-preview (score 100, 1.0M ctx, thinking, code-gen); gemini-2.5-flash (score 81, 1.0M ctx, thinking).
imagesNoImage paths (absolute) or base64 strings for optional visual context.
promptYesYour question or task for the external model. Prefer passing code and large content via absolute_file_paths rather than inlining it here.
temperatureNoOptional sampling temperature. If omitted, the model's own default is used (recommended; some reasoning models reject or degrade on a fabricated value). Range is provider-dependent (commonly 0–2); values are clamped per model.
thinking_modeNoOptional reasoning depth: minimal, low, medium, high, or max. Omit to use the provider default.
continuation_idNoUnique thread continuation ID for multi-turn conversations. Works across different tools. Reuse the last continuation_id you were given to preserve full conversation context, files, and history across turns. Threads are held in memory and expire after inactivity.
absolute_file_pathsNoFull, absolute file paths to relevant code in order to share with the external model. Accepts both files and directories (directories are expanded recursively). Content is read and embedded into the prompt context.

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, so the safety profile is covered; the description adds real behavioral context beyond that, namely that it is a multi-provider gateway with conversation memory, file-context embedding, image support, and multi-turn threads. It omits any mention of cost, rate limits, or per-provider failure behavior, so it falls short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tight sentences, front-loaded with the core identity ('Multi-model AI gateway') followed by routing scope and the capabilities that matter for invocation. No sentence is wasted or redundant with the schema.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 7-parameter, multi-provider routing tool with no output schema, the description covers the essential mental model: what it routes to, that memory/threads exist, and that files and images can be attached. It leaves unaddressed what happens on provider failure or how responses are shaped, but the readOnly annotation and rich schema compensate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so every parameter is already documented in detail, which sets the baseline at 3. The description adds only high-level framing ('file context embedding, images, and multi-turn threads via continuation_id') without new syntax or format detail beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource ('Routes prompts to external AI models') and enumerates the providers, so an agent immediately knows this is a completion/routing tool rather than a listing tool. It does not explicitly name the siblings (listmodels, dump_threads) to contrast itself against them, which keeps it at a 4 rather than a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by 'Multi-model AI gateway' and the routing sentence, but there is no explicit statement of when to use chat versus listmodels (which the schema, not the description, suggests for model discovery) or when a thread should be continued versus started fresh. The agent must infer the workflow.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

dump_threadsA
Read-only

Export conversation threads as JSON or Markdown. Threads persist to disk and can be cold-reloaded after memory expiry. Use thread_ids to filter specific threads, format to choose output.

ParametersJSON Schema
NameRequiredDescriptionDefault
formatNoOutput format: 'markdown' (clean export with YAML frontmatter, written to disk) or 'json' (raw thread data, inline).markdown
thread_idsNoFilter to specific thread UUIDs. Omit for all active threads.

TDQS

A3.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The annotation already declares readOnlyHint=true, so the description only needs to add extra behavioral nuance. It does mention thread persistence and cold-reload, which is useful context beyond the annotation, but it does not clarify whether the export writes files to disk (only the schema does for markdown) or describe any side effects. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, with the primary purpose front-loaded. The second sentence is a bit of a run-on ('Use thread_ids to filter specific threads, format to choose output') but is still concise and informative. No wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple two-parameter tool with no required fields and no output schema, the description plus schema covers the main usage: exporting threads with optional filtering and format selection. The persistence/cold-reload note adds valuable context. Could mention the default behavior (all threads) but that is already in the schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with both parameters (format and thread_ids) already documented in detail. The description merely echoes 'Use thread_ids to filter specific threads, format to choose output' without adding new semantic information. Baseline 3 applies since schema carries the load.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description starts with a specific verb and resource: 'Export conversation threads as JSON or Markdown.' It clearly identifies the tool's function and distinguishes it from sibling tools like chat and listmodels, which involve interaction and model listing respectively.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides implicit usage context: 'Threads persist to disk and can be cold-reloaded after memory expiry' suggests using this tool for backup or recovery after memory loss. It does not explicitly name alternatives or exclusions, but the context is clear enough for an agent to infer when this tool is appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

listmodelsA
Read-only

Shows which AI model providers are configured, available model names, their aliases and capabilities.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, so the safe-read nature is covered. The description adds useful context about what information is returned (providers, names, aliases, capabilities), but it does not disclose additional behavioral traits such as pagination or formatting.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, concise sentence that front-loads the verb 'Shows' and packs all relevant information about the tool's output without unnecessary words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is simple with no parameters and no output schema, but the description sufficiently covers its purpose and the categories of data it returns. It could be slightly more complete by mentioning that no arguments are required, but that is implicit in the empty input schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters, so there is nothing for the description to elaborate. The baseline score of 4 applies, as no parameter information is needed.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb 'Shows' and clearly defines the resource: configured AI model providers, available model names, aliases, and capabilities. This clearly distinguishes it from sibling tools like chat and dump_threads.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage—you'd use this tool when you need to see configured models—but it does not provide explicit guidance on when to use it versus alternatives like chat or dump_threads. There is no direct comparison or exclusion.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev0.8.0
    • Changedchat2 fields changed
      • changedInput schema / properties / model / description
        Previous value: -"Currently in auto model selection mode. If no model is provided, you may use the `listmodels` tool to review options and select an appropriate match. The server validates model availability and returns errors for unknown models. Top models: gemini-2.5-pro (score 100, 1.0M ctx, thinking, code-gen); gemini-3.1-pro-preview (score 100, 1.0M ctx, thinking, code-gen); gemini-2.5-flash (score 81, 1.0M ctx, thinking); gemini-2.0-flash (score 66, 1.0M ctx); gemini-2.0-flash-lite (score 56, 1.0M ctx)."New value: +"Currently in auto model selection mode. If no model is provided, you may use the `listmodels` tool to review options and select an appropriate match. The server validates model availability and returns errors for unknown models. Top models: gemini-3.8-flash (score 100, 1.0M ctx, thinking, code-gen); gemini-2.5-pro (score 100, 1.0M ctx, thinking, code-gen); gemini-3.1-pro-preview (score 100, 1.0M ctx, thinking, code-gen); gemini-2.5-flash (score 81, 1.0M ctx, thinking)."
      • changedInput schema / properties / thinking_mode / description
        Previous value: -"Reasoning depth: minimal, low, medium, high, or max."New value: +"Optional reasoning depth: minimal, low, medium, high, or max. Omit to use the provider default."
  2. 3 tool updatesv0.5.0
    • First observedchat
    • First observeddump_threads
    • First observedlistmodels

TDQS

A3.9/5.0

Scored across 3 tools

Disambiguation5/5

chat, dump_threads, and listmodels have clearly distinct purposes: sending prompts, exporting conversation threads, and listing available models. There is no overlap or ambiguity in which tool to use for each task.

Naming Consistency3/5

The set mixes naming conventions: 'chat' is a single lowercase word, 'dump_threads' uses snake_case verb_noun, and 'listmodels' is a concatenated lowercase noun phrase. While still readable, the pattern is inconsistent.

Tool Count4/5

Three tools is lean but reasonable for a focused multi-model gateway covering chat, export, and model discovery. It could benefit from one or two additional thread-management tools, but nothing feels excessive.

Completeness3/5

Core operations are present: chatting, exporting threads, and listing models. However, obvious lifecycle operations like deleting or clearing threads are missing, and there is no way to list threads independently of exporting them.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    F
    maintenance
    Enables AI assistants to intelligently select and switch between different AI models (OpenAI, Anthropic, etc.) within the same conversation based on task requirements. Provides a unified interface for accessing multiple AI providers through a single MCP tool.
    1
    21 npm
    MIT