MCP

MCP 专栏

安全连接 AI 智能体:User MCP 用于运营,Developer MCP 用于集成 — 含 profile、confirm、dry-run 与人工审批。

MCP track_package(tracking_number) Tool
RPC tools/list JSON-RPC 2.0
RPC tools/call JSON-RPC 2.0
Documentation

MCP 专栏概览

本指南是开发者中心的 Superroute MCP 专栏,涵盖两个服务端、智能体安全模型,以及来自 UserMcpToolCatalog 的实时工具目录。

什么是 MCP?

模型上下文协议(MCP)是一种开放标准,允许 Claude、Cursor 和 ChatGPT 等 AI 助手与外部工具和服务交互。它使您的 AI 能够在对话中直接执行实际操作,例如追踪包裹。

通过配置 Superroute MCP 服务器,您的 AI 助手无需离开工作流程即可使用物流工具。

两个 MCP 服务

按受众选择正确的服务。不要给无人值守智能体分配带完全权限的 Developer 服务。

服务名 端点 受众 鉴权
superroute https://api.miliexpress.com/mcp 运营 / 客服 / 业务智能体 Bearer + 可选 profile/scopes(未设置时兼容全量)
superroute-developer https://api.miliexpress.com/mcp/developer 集成开发者与编码智能体 优先连接级 Bearer;tool 参数 api_token 将淘汰

快速开始

包裹追踪等公开工具无需认证即可使用。将以下配置添加到您的 MCP 客户端:

JSON
{
  "mcpServers": {
    "mili-express": {
      "type": "url",
      "url": "https://api.miliexpress.com/mcp"
    }
  }
}
试试看! 设置完成后,询问您的 AI 助手:"追踪包裹 SR100012345"

认证访问

要使用需要用户权限的工具,请在配置中添加您的 API Bearer 令牌:

务必把令牌放在 MCP 连接请求头中,切勿写入工具参数或提示词。

JSON
{
  "mcpServers": {
    "mili-express": {
      "type": "url",
      "url": "https://api.miliexpress.com/mcp",
      "headers": {
        "Authorization": "Bearer <your-api-token>",
        "X-MCP-Profile": "ops-readonly"
      }
    }
  }
}

如何获取 API 令牌

使用您的凭据调用登录接口:

Bash
curl -X POST https://api.miliexpress.com/api/v1/user/login \
  -H "Content-Type: application/json" \
  -d '{"email": "you@example.com", "password": "your-password"}'

响应将包含您的访问令牌:

JSON Response
{
  "access_token": "eyJ0eXAiOiJKV1Qi...",
  "token_type": "Bearer",
  "expires_at": "2026-02-20 00:00:00"
}

在 MCP 配置的 Authorization 头中使用 access_token 值。

智能体安全模型

User MCP 面向最小权限智能体。创建 token 时选择 MCP 配置文件(默认运营只读),或通过 header 传递 profile/scopes。

配置文件(X-MCP-Profile)

命名的权限包。无人值守智能体优先 ops-readonly 或 support。

配置 名称 权限范围
ops-readonly 运营只读 orders:read, labels:read, routes:read, drivers:read, analytics:read, address:read, approvals:read
support 客服(客户服务) orders:read, analytics:read, address:read, approvals:read
ops-write 运营写入(订单 + 面单 + 路线) orders:read, orders:write, labels:read, labels:write, routes:read, routes:write, drivers:read, analytics:read, address:read, approvals:read, approvals:write
wms-readonly WMS 只读 wms:read, orders:read
datasets-readonly 数据集只读 datasets:read
alliance-readonly 联盟只读 alliance:read
full 完全访问(全部 MCP 工具)— 不适用于无人值守智能体 *
.mcp.json — 推荐智能体配置
{
  "mcpServers": {
    "mili-express": {
      "type": "url",
      "url": "https://api.miliexpress.com/mcp",
      "headers": {
        "Authorization": "Bearer <ops-readonly-token>",
        "X-MCP-Profile": "ops-readonly"
      }
    }
  }
}

可选请求头

请求头 用途
Authorization: Bearer …API Bearer 令牌(连接级)。
X-MCP-Profile命名配置:ops-readonly、support、ops-write、wms-readonly、datasets-readonly、alliance-readonly、full。
X-MCP-Scopes显式逗号分隔 scopes(覆盖 profile)。
X-MCP-Dry-Run: 1预览写操作且不落库。
X-MCP-Require-Approval: 1将高危写操作入队等待人工批准,而不是立即执行。

高危确认

以下工具在 tools/call 时需要 confirm=true(或使用审批队列):

人工审批队列

无人值守智能体应提议写操作;由人在应用内或通过 MCP 批准。

  1. 智能体:propose_write 或发送 X-MCP-Require-Approval: 1
  2. 人:打开 Web 的 MCP 审批,或 list_pending_approvals
  3. 人:approve_pending_write(confirm=true)或 reject_pending_write

Web 界面路径(需登录): /mcp-approvals

Developer MCP 鉴权

优先在连接上使用 Authorization: Bearer。按工具传 api_token 已弃用,将于 2026-12-31 后硬切断。

可用工具

以下工具目前在 MCP 服务器上可用: 93 个来自服务端目录的实时工具

此表在请求时由 UserMcpToolCatalog 生成,与生产环境认证全量 tools/list 保持同步。

工具 认证 风险 权限 描述
track_package 公开 low — Track a package by its tracking number. Returns delivery status, tracking events timeline, and proof of delivery if available.
otep_tracking 公开 low — Get the unified OTEP (Open Tracking Event Protocol) timeline for a tracking number — self-delivery, third-party and carrier events normalize...
get_capabilities 公开 low — List MCP tools available to the current connection, with risk level, required scopes, and whether confirm=true is needed. Call this first wh...
get_orders 需要 low orders:read List orders with filtering and pagination. Returns order details including status, tracking, and delivery info.
get_order_detail 需要 low orders:read Get full details of a specific order by ID, including address, status, packages, and tracking info.
find_order 需要 low orders:read Fuzzy-find orders across tracking number, external tracking, ref, recipient name, and phone in a single query. Use this instead of get_order...
get_operation_events 需要 low orders:read Get the full audit trail for orders — every status change, who performed it, GPS coordinates, and photos.
create_order 需要 medium orders:write Create a delivery/pickup order. D=delivery (warehouse→customer), P=pickup (customer→warehouse), P2P=peer-to-peer. Returns order ID and track...
cancel_order confirm 需要 high orders:write Cancel an existing order by order ID. Only works for orders not yet delivered.
bulk_create_orders confirm 需要 high orders:write Create up to 100 delivery orders in one call. Returns a per-order success/failure summary; partial failures do not abort the batch unless st...
reroute_to_address confirm 需要 high orders:write Change the delivery address of an order that has not been picked up yet: cancels the original order and recreates it with the new address. R...
update_delivery_instruction 需要 medium orders:write Update only the delivery_instruction field on an existing order (PATCH). Safer than full order rewrite.
update_order_note 需要 medium orders:write Update only the internal note field on an existing order (PATCH).
update_time_window_by_refs 需要 medium orders:write Bulk-update delivery time windows (and optional schedule_date) for orders identified by external refs.
hold_order confirm 需要 high orders:write Put an order on HOLD so it is not dispatched until release_order. HIGH-RISK: requires confirm=true.
release_order confirm 需要 high orders:write Release an order from HOLD back to NEW_ORDER. HIGH-RISK: requires confirm=true.
propose_write 需要 low approvals:read Queue a write/high-risk tool for human approval instead of executing it. Reviewers use list_pending_approvals + approve_pending_write.
list_pending_approvals 需要 low approvals:read List pending MCP write approvals for this business (or mine_only).
approve_pending_write confirm 需要 high approvals:write Approve and execute a pending write proposal. HIGH-RISK: requires confirm=true. Reviewer must have scopes for the underlying tool.
reject_pending_write 需要 medium approvals:write Reject a pending write proposal without executing it.
get_routes 需要 low routes:read List delivery routes with their status, assigned driver, and order count.
get_route_detail 需要 low routes:read Get one route with its stop/order list. Prefer this over get_routes when you already know route_id.
get_drivers 需要 low drivers:read List drivers for the authenticated business (ids, names, capacity defaults). Use driver id with get_driver_routes_today or route tools.
get_driver_routes_today 需要 low routes:read, drivers:read Orders assigned to a driver on a given date (defaults to today). Useful for "what is driver X running today?"
get_build_route_options 需要 low routes:read List routing engines, balance modes, capacity types, and defaults before calling build_route.
build_route confirm 需要 high routes:write Build/optimize a delivery route (POST /api/v3/client/build-route). HIGH-RISK: assigns orders to drivers. Call get_build_route_options first....
order_snapshot 需要 low orders:read One-call order context for support: order detail + operation events + public tracking (when tracking number is known). Pass order_id or trac...
list_exceptions 需要 low orders:read List failed/returned/exception-like orders for a schedule date (default today). Read-only ops triage helper.
get_shipping_methods 需要 low labels:read List available shipping carriers/methods. Returns IDs and names — use the ID for rate/label tools.
get_shipping_rate 需要 low labels:read Get a shipping cost quote. Dry-run — no label created. Returns rate options with pricing and transit time.
create_shipping_label 需要 medium labels:write Book a shipment with a carrier and generate a shipping label with tracking numbers.
quote_and_ship 需要 medium labels:write One-shot: rate across all enabled carriers, pick the best one by strategy, create the shipping label, return tracking number. Saves 3+ tool...
compare_all_carriers 需要 low labels:read Get rate quotes from every enabled carrier for the same shipment, in one call. Returns a sorted comparison (cheapest first) with price + tra...
search_address 需要 low address:read Search and resolve addresses by postal code or free-text query. Returns structured address suggestions.
daily_digest 需要 low analytics:read One-call summary of today's logistics activity: total orders, by status, exceptions (failed/returned), pending pickups. Designed as the firs...
get_orders_summary 需要 low analytics:read Aggregate order metrics over a time window: counts by status, top carriers, on-time rate, exception count. Use period=today|week|month or pa...
get_account_credits 需要 low analytics:read Get the authenticated customer's wallet balance, currency, and recent topup history. Customer (B2C) accounts only — returns an error for cli...
get_warehouses 需要 low wms:read List WMS warehouses available to the authenticated business.
get_inventory 需要 low wms:read Query WMS inventory (POST /api/v1/wms/inventory). Pass filters supported by the inventory API (sku, warehouse_id, etc.).
list_datasets 需要 low datasets:read List custom datasets available to the business.
get_dataset 需要 low datasets:read Get one dataset by id (metadata/columns).
list_dataset_groups 需要 low datasets:read List groups inside a dataset.
search_dataset_records 需要 low datasets:read Search records across groups in a dataset (POST .../search).
list_alliances 需要 low alliance:read List alliances the authenticated business belongs to.
get_alliance 需要 low alliance:read Get one alliance by id.
list_alliance_members 需要 low alliance:read List members of an alliance.
list_accessible_clients 需要 low alliance:read List clients accessible via alliance partnerships.
quote_delivery 需要 low orders:read Get the local delivery price for a shipment before creating the order (POST /api/v1/orders/rate). No order is created.
print_local_label 需要 low orders:read Get the printable label of a local delivery order as a base64 PDF, with its label code and tracking numbers (POST /api/v2/shipping/getShippi...
bulk_create_orders_async confirm 需要 high orders:write Queue a large batch of delivery orders for creation (POST /api/v1/client/batchOrderCreateAsync). Returns an asyncId at once; read the per-or...
get_async_batch_result 需要 low orders:read Read the status and per-order results of a batch queued with bulk_create_orders_async (GET /api/v1/client/async/{id}).
get_shipping_detail confirm 需要 high labels:write Get the carrier shipping detail of a label order: tracking numbers, price and the label (POST /api/v1/labelservice/getShippingDetail). The f...
download_shipping_label confirm 需要 high labels:write Download the label PDF of an order as base64 (POST /api/v1/shipping/getShippingLabel with base64). For a carrier label order whose label was...
cancel_shipping_label confirm 需要 high labels:write Cancel (void) a carrier label with the carrier (POST /api/v1/labelservice/cancelShippingLabel). Pass the order id, or one package tracking n...
submit_shipping_information confirm 需要 high labels:write Submit the shipping information of one or more label orders to their carriers (POST /api/v1/labelservice/submitShippingInformation).
end_of_day confirm 需要 high labels:write Close the day with the carriers: submit the shipping information of every open label order (POST /api/v1/labelservice/endofday).
uniorder_rate 需要 low uniorder:read Quote one shipment across self delivery and, with quote_labels=true, every label carrier service of the account (POST /api/v1/uniorder/rate)...
uniorder_create 需要 medium uniorder:write Create an order at a rate_id from uniorder_rate (POST /api/v1/uniorder). The rate decides the service: a self delivery order, or a label ord...
uniorder_get 需要 low uniorder:read Read one uniorder order in the uniorder shape (GET /api/v1/uniorder/{orderId}).
uniorder_label 需要 low uniorder:read Get the label PDF of a uniorder order, base64 (GET /api/v1/uniorder/{orderId}/label).
uniorder_tracking 需要 low uniorder:read Get the tracking timeline of a uniorder order (GET /api/v1/uniorder/{orderId}/tracking).
uniorder_cancel confirm 需要 high uniorder:write Cancel a uniorder order, self delivery or label (POST /api/v1/uniorder/{orderId}/cancel). A label order voids its carrier label.
uniorder_purchase_label confirm 需要 high uniorder:write Buy the carrier label of a uniorder label order that was kept without one (LABEL_PURCHASE_FAILED), at the service chosen at create or at a n...
uniorder_rate_batch 需要 low uniorder:read Quote up to 20 shipments in one call (POST /api/v1/uniorder/rate/batch). Each shipment takes the uniorder_rate shape plus an optional refere...
uniorder_create_batch confirm 需要 high uniorder:write Create up to 20 orders in one call, each at its own rate_id (POST /api/v1/uniorder/batch). Returns a result per order.
uniorder_rate_batch_async 需要 low uniorder:read Queue up to 500 shipments to quote (POST /api/v1/uniorder/rate/batch-async). Returns a job id; read the quotes with uniorder_job.
uniorder_create_batch_async confirm 需要 high uniorder:write Queue up to 500 orders to create, each at its own rate_id (POST /api/v1/uniorder/batch-async). Returns a job id; read the results with unior...
uniorder_job 需要 low uniorder:read Read a queued uniorder batch and, once done, its results (GET /api/v1/uniorder/jobs/{jobId}).
list_shipping_services 需要 low customer_shipping:read List the shipping services the customer may order (GET /api/v1/customer/shipping-orders/services). Step 1 of a shipping order. Needs a custo...
get_shipping_service_config 需要 low customer_shipping:read Get one shipping service's order form: warehouses, surcharges, packaging, supplies, units and form fields (GET /api/v1/customer/shipping-ord...
estimate_shipping_order 需要 low customer_shipping:read Estimate the price of a shipping order on a service (POST /api/v1/customer/shipping-orders/services/{serviceCode}/estimate-price). No order...
create_shipping_order 需要 medium customer_shipping:write Create a shipping order on a service (POST /api/v1/customer/shipping-orders/services/{serviceCode}/orders). Note the package list field is `...
pay_shipping_order confirm 需要 high customer_shipping:write Pay the full remaining balance of a shipping order from the customer wallet (POST /api/v1/customer/shipping-orders/{id}/pay). A fully paid p...
get_shipping_order 需要 low customer_shipping:read Get one shipping order of the customer (GET /api/v1/customer/shipping-orders/{id}). Needs a customer account token.
list_shipping_orders 需要 low customer_shipping:read List the customer's shipping orders on one service, paginated (GET /api/v1/customer/shipping-orders/services/{serviceCode}/orders). Needs a...
cancel_shipping_order confirm 需要 high customer_shipping:write Cancel a pending or confirmed shipping order of the customer (POST /api/v1/customer/shipping-orders/{id}/cancel). Needs a customer account t...
get_storage_order_config 需要 low storage:read Get what a storage order form needs: warehouses, packaging, supplies, pickup timeframes, units, surcharges and form fields (GET /api/v1/cust...
quote_storage_order 需要 low storage:read Calculate the price of a storage order before creating it (POST /api/v1/customer/storage-orders/calculate-price). Storage order form fields...
create_storage_order 需要 medium storage:write Create a storage order (POST /api/v1/customer/storage-orders). Storage order form fields as returned by get_storage_order_config: warehouse_...
pay_storage_order confirm 需要 high storage:write Pay a storage order from the customer wallet (POST /api/v1/customer/storage-orders/{id}/pay). Needs a customer account token.
get_storage_order 需要 low storage:read Get one storage order of the customer, with can_edit, can_cancel and each package's received flag (GET /api/v1/customer/storage-orders/{id})...
list_storage_orders 需要 low storage:read List the customer's storage orders, paginated (GET /api/v1/customer/storage-orders). Needs a customer account token.
cancel_storage_order confirm 需要 high storage:write Cancel a storage order of the customer while its status allows it (POST /api/v1/customer/storage-orders/{id}/cancel). Needs a customer accou...
list_stored_packages 需要 low storage:read List the customer's stored packages that can be shipped out: received, not stocked out and not held by another ship-out, grouped by storage...
list_shipout_services 需要 low storage:read List the shipping services that ship out from a warehouse (GET /api/v1/customer/shipout-orders/services). pricing_method 1 = priced at once,...
estimate_shipout 需要 low storage:read Estimate the price of a ship-out (POST /api/v1/customer/shipout-orders/services/{serviceCode}/estimate). A manually priced service answers h...
create_shipout 需要 medium storage:write Create a ship-out of stored packages from one warehouse (POST /api/v1/customer/shipout-orders/services/{serviceCode}/orders). The chosen pac...
pay_shipout confirm 需要 high storage:write Pay a priced ship-out from the customer wallet (POST /api/v1/customer/shipout-orders/{id}/pay). Default is the full remaining balance. Needs...
get_shipout 需要 low storage:read Get one ship-out of the customer with paid amount, remaining balance, can_be_paid, can_be_cancelled and its packages (GET /api/v1/customer/s...
list_shipouts 需要 low storage:read List the customer's ship-outs, paginated (GET /api/v1/customer/shipout-orders). Needs a customer account token.
cancel_shipout confirm 需要 high storage:write Cancel a pending or confirmed ship-out and release its stored packages (POST /api/v1/customer/shipout-orders/{id}/cancel). A payment is not...
otep_client_tracking 需要 low orders:read Get the OTEP timeline and details (addresses, dates, proof of delivery, item counts) of one of your own shipments: a parcel tracking number,...
otep_client_locker_storage 需要 low orders:read Get the OTEP timeline (storage profile) and details of one of your locker storage rentals, by rental id. Requires a token.

客户端配置

选择您的 AI 客户端以获取相应的配置说明:

Claude Code

Claude Code 从项目根目录或主目录中的 .mcp.json 文件读取 MCP 配置。

  1. 在项目根目录创建 .mcp.json 文件(或 ~/.claude/.mcp.json 用于全局访问)。
  2. 添加以下配置:
.mcp.json
{
  "mcpServers": {
    "mili-express": {
      "type": "url",
      "url": "https://api.miliexpress.com/mcp"
    }
  }
}

要使用认证工具,请添加 headers 字段:

.mcp.json (带认证)
{
  "mcpServers": {
    "mili-express": {
      "type": "url",
      "url": "https://api.miliexpress.com/mcp",
      "headers": {
        "Authorization": "Bearer <your-api-token>",
        "X-MCP-Profile": "ops-readonly"
      }
    }
  }
}

Cursor

Cursor 通过内置配置支持 MCP 服务器。

  1. 在项目根目录创建 .cursor/mcp.json 文件。
  2. 添加以下配置:
  3. 重启 Cursor 以加载新的 MCP 服务器。
.cursor/mcp.json
{
  "mcpServers": {
    "mili-express": {
      "type": "url",
      "url": "https://api.miliexpress.com/mcp"
    }
  }
}

Windsurf

Windsurf 使用全局 MCP 配置文件。

  1. 编辑 ~/.codeium/windsurf/mcp_config.json(如果不存在则创建)。
  2. 添加以下配置:
~/.codeium/windsurf/mcp_config.json
{
  "mcpServers": {
    "mili-express": {
      "serverUrl": "https://api.miliexpress.com/mcp"
    }
  }
}

ChatGPT

ChatGPT 为 Plus、Pro 和 Team 用户支持 MCP 连接。

  1. 打开 ChatGPT 并进入设置。
  2. 导航到"连接的应用"或"工具"部分。
  3. 添加新的 MCP 服务器,使用上方显示的端点 URL。
ChatGPT 的 MCP 支持可能因您的计划和地区而异。请参阅 OpenAI 文档获取最新说明。

技术细节