Skip to main content

MCP Tools

Currently includes 43 tools, grouped by function as follows.

Source data: tools.json


Tool Overview​

Authentication & Login​

Others​

Environment Management​

NoSQL Database​

Data Models​

PostgreSQL Database​

PostgreSQL Cloud Storage​

MySQL Database​

Cloud Functions​

Static Hosting​

Cloud Storage​

Templates & Files​

Search & Knowledge Base​

CloudRun​

Gateway​

App Authentication​

Permissions​

Logs​

AI Agent​

Cloud API​

Message Push​


Hosted MCP Configuration​

Environment Variable Configuration​

Using hosted MCP requires configuring the following environment variables:

Environment VariableDescriptionHow to Obtain
TENCENTCLOUD_SECRETIDTencent Cloud SecretIdGet Tencent Cloud API Key
TENCENTCLOUD_SECRETKEYTencent Cloud SecretKeyGet Tencent Cloud API Key
TENCENTCLOUD_SESSIONTOKENOptional, Tencent Cloud temporary key TokenOnly needed when using temporary keys, can be obtained via STS Service
CLOUDBASE_ENV_IDCloudBase Environment IDGet CloudBase Environment ID

Detailed Specs​

auth​

CloudBase (Tencent Cloud Development) development stage login and environment binding. After logging in, you can access cloud resources; an environment (env) is an isolation unit for cloud functions, databases, static hosting and other resources. After binding the environment, other MCP tools can operate on that environment. Supports: query status, initiate login, API Key login, bind environment (set_env), logout. auth(status) returns credential_scope (account=account-level / single_env=environment-level API Key) and the current region; environment-level API Keys can only see the bound envId, not being able to query other regions' environments is a permission boundary, not that the environment doesn't exist. Optional site/region/lang parameters: site=site (domestic/intl), region=region, lang=output language (zh/en).

Parameters​

ParameterTypeRequiredDescription
actionstringAction: status=query status, start_auth=initiate login, login_by_api_key=API Key login, set_env=bind environment (pass envId), logout=logout. Allowed values: "status", "start_auth", "set_env", "logout", "get_temp_credentials", "login_by_api_key"
authModestringAuthentication mode: device=device code authorization, web=browser callback authorization. Allowed values: "device", "web"
oauthEndpointstringAdvanced optional: Custom device-code login endpoint. When configured, oauthCustom defaults to true
clientIdstringAdvanced optional: Custom device-code login client_id, uses default value if not provided
oauthCustombooleanAdvanced optional: Custom endpoint return format switch. Defaults to false when endpoint not configured; defaults to true when endpoint is configured. Endpoints using the standard {code,result} wrapper format (e.g. the international site tcb-api.tencentcloud.com) should explicitly pass false
sitestringSite: domestic=China site, intl=international site. When the environment is provisioned on the Tencent Cloud international site, login (start_auth/login_by_api_key) must explicitly pass intl, otherwise the China-site flow is used and international-site environments are invisible. An explicitly passed value takes precedence over the TCB_SITE environment variable / the region mapping table / project config, and affects the login endpoint, the authorization page and the API Key exchange gateway. Allowed values: "domestic", "intl"
envIdstringEnvironment ID (CloudBase environment unique identifier), after binding the tool will operate on this environment. Required when action=set_env
regionstringRegion (e.g. ap-shanghai / ap-guangzhou / ap-singapore). Used for region→site inference and API Key exchange gateway selection; an explicit site takes precedence
langstringOutput language: zh=Chinese (default), en=English. Overrides the instance-level language (createCloudBaseMcpServer lang option / TCB_LANG / project.json). Allowed values: "zh", "en"
apiKeystringCloudBase API Key, required when action=login_by_api_key
apiKeyEnvIdstringCloudBase environment ID (EnvId), required when action=login_by_api_key, used to specify the environment the API Key belongs to
confirmstringConfirm operation when action=logout, pass yes. Allowed values: const "yes"
revealbooleanOptional when action=get_temp_credentials. true=return plaintext temporary credentials; defaults to false returning masked results only

queryEnv​

Query CloudBase environment related information, supports querying the environment list, details of a specific environment, security domains, resource usage, and monitoring metrics. (Former names: envQuery, listEnvs, getEnvInfo, getEnvAuthDomains) When action=list, it filters/lists per DescribeEnvs semantics, returning standard fields EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, and supports trimming these fields via the fields whitelist; aliasExact=true filters by exact alias match to avoid mistaking environments with similar prefixes as candidates; even when envId is passed, action=list only returns the summary, not full resource details or expiry. Account-level login can pass region (ap-shanghai/ap-guangzhou/ap-singapore) to query corresponding regions, aligned with CLI tcb env list -r <region>; environment-level credentials (API Key / hosted authorization token) can only see the bound envId, returning credential_scope=single_env; in that case region is not applied and is truthfully reported in ignored_params (AppliedFilters.region is null) — do not misjudge this as the environment not existing or region filtering being broken. To query the detailed information of a known EnvId environment (including resource fields and billing info), use action=info with the target envId. action=info supplements BillingInfo (e.g. ExpireTime, PayMode, IsAutoRenew) when available.

📊 action=usage aligns with tcb env usage/info: passes through Manager SDK describeEnvAccountCircle + describeCreditsUsageDetail, returning billing cycle and resource credit usage by module (FLEXDB/SCF/COS etc.). envId required; type optionally filters modules; when startDate/endDate are not passed, the current billing cycle is used automatically.

📈 action=metrics aligns with CloudBase DescribeCurveData (manager.monitor.describeCurveData, not Cloud Monitor GetMonitorData): queries environment/gateway QPS, cloud function invocations and errors, database CPU/memory/disk, CloudRun CPU/QPS time series. envId and metricName required; startTime/endTime format YYYY-MM-DD HH:mm:ss, must be passed as a pair, defaults to last 24 hours when omitted; period only supports 300/3600/86400. When GatewayTraceEnvQPS is called without resourceID, environment-level all|:|all|:|all|:|all is auto-filled; CloudRun Tke* metrics must pass service name as resourceID. Do not use callCloudApi to guess monitoring Actions.

🔍 action=info also derives three fields for backend selection:

  • EnvInfo.RuntimeMode: 'postgresql' or 'nosql', indicating the recommended default backend for new services (postgresql when PG is enabled, otherwise nosql).
  • EnvInfo.RuntimeBackends: three booleans \{postgresql, nosql, mysql\} describing which backends currently coexist in the environment.
  • EnvInfo.RuntimeModeHints: API/tool/skill hints for each backend.

🌐 action=info also projects gateway route Enable status without overwriting StaticStorages[].StaticDomain (cloud API nominal domain): StaticStorages[].staticDomainRouteEnabled and EnvInfo.staticDomainRouteEnabled (same source as queryHosting websiteConfig). false means the default static domain root route is disabled (access returns GATEWAY_ROUTE_DISABLED), do not treat the nominal domain as a reachable URL.

AI must check these three items before writing business/permission/storage code: In PG mode, new services should use app.rdb() + RLS (managePgDatabase action=execute to run CREATE POLICY) + pgstore; existing NoSQL collections / old storage / managePermissions(resourceType="noSqlDatabase") remain valid in PG environments. What is truly inapplicable is MySQL: when RuntimeBackends.mysql === false, manageMysqlDatabase / queryMysqlDatabase / relational-database-mcp-cloudbase skill should not be used.

Parameters​

ParameterTypeRequiredDescription
actionstringyesQuery type: list=environment list/summary filter (filters per DescribeEnvs semantics, supports filtering by envId/region, returns EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, no expiry), info=detailed info of the specified environment (envId required, returns resource fields and billing info), domains=security domain list, usage=environment resource usage (envId required, aligned with tcb env usage/info), metrics=environment monitoring time series (envId and metricName required, aligned with CloudBase DescribeCurveData). Allowed values: "list", "info", "domains", "usage", "metrics"
aliasstringFilter by environment alias. Optional when action=list
aliasExactbooleanFilter by exact environment alias. Optional when action=list; used with alias
envIdstringEnvironment ID. Optional when action=list (only filters per DescribeEnvs semantics, still returns the summary); required when action=info / action=usage / action=metrics; optional when action=domains (queries the currently bound environment when omitted, or that environment's security domains when provided).
regionstringQuery region. Only effective when action=list. Account-level credentials pass this value through to DescribeEnvs (X-TC-Region), e.g. ap-singapore. Equivalent CLI: tcb env list -r <region> --json. Environment-level credentials (API Key / hosted authorization token) are single-environment scoped and this parameter is ignored: the result is always the bound environment, the response has AppliedFilters.region = null, query_region takes that environment's own Region, and ignored_params explains why it was ignored — do not conclude from this that the region has no environments. ⚠️ ap-singapore belongs to both the China site and the international site; when no site is explicitly specified it is treated as the international site (site=intl): if you have logged in to both sites, passing this region silently queries the international-site account, so call auth(site="domestic") or set TCB_SITE=domestic first to pin the site. Allowed values: "ap-shanghai", "ap-guangzhou", "ap-singapore"
limitintegerMax number of results. Optional when action=list
offsetintegerPagination offset. Optional when action=list
fieldsarray of stringReturn field whitelist. Only supports EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault. Optional when action=list
typearray of stringUsage module filter. Only effective when action=usage; queries all modules when omitted. Available values aligned with tcb CLI: FLEXDB, TDSQL, SCF, EKS, COS, AI, HOSTING, Auth, APIInvocation, HTTPInvocation, VM, Workflow, Other.
startDatestringUsage start date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with endDate. Uses current billing cycle when omitted.
endDatestringUsage end date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with startDate. Uses current billing cycle when omitted.
needUsageDetailsbooleanWhether to return daily usage details. Only effective when action=usage; defaults to true.
metricNamestringMonitoring metric name. Only effective and required when action=metrics. GatewayTraceEnvQPS/EnvQPSAll=environment and gateway QPS; FunctionInvocation/FunctionError/FunctionTimeout/FunctionThrottle=cloud function invocations, errors, timeouts, throttling; DbRead/DbWrite/DbSizepkg=document database reads, writes, and capacity; MysqlCpuUsageRate/MysqlMemoryUse/MysqlStorageUsage=SQL database CPU/memory/disk; TkeCpuUsedService/TkeQPSService/TkeHttpErrorService=CloudRun CPU/QPS/errors. Allowed values: "GatewayTraceEnvQPS", "EnvQPSAll", "FunctionInvocation", "FunctionError", "FunctionTimeout", "FunctionThrottle", "FunctionDuration", "FunctionConcurrentExecutions", "DbRead", "DbWrite", "DbSizepkg", "MysqlCpuUsageRate", "MysqlMemoryUse", "MysqlStorageUsage", "MysqlQps", "MysqlSlowQueries", "MysqlDbConnections", "TkeCpuUsedService", "TkeMemUsedService", "TkeQPSService", "TkeHttpErrorService", "TkeInvokeNumService"
startTimestringMonitoring start time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with endTime. Defaults to last 24 hours when omitted. End time must be at least five minutes after start time.
endTimestringMonitoring end time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with startTime. Defaults to last 24 hours when omitted.
periodnumberStatistics period (seconds). Only effective when action=metrics; only supports 300, 3600, 86400. Auto-selected by backend based on time range when omitted. Time range ≤1 day cannot use 86400; >3 days cannot use 300. Allowed values: 300, 3600, 86400
resourceIDstringResource ID. Only effective when action=metrics. Cloud functions pass function name, document database passes collection name, CloudRun must pass service name; GatewayTraceEnvQPS auto-fills environment-level all|:|all|:|all|:|all when omitted.
subresourceIDstringSub-resource ID. Only effective when action=metrics; pass version name when querying CloudRun version monitoring.

envQuery​

Query CloudBase environment related information, supports querying environment list, current environment information, security domains, resource usage, and monitoring metrics. (Original tool names: listEnvs/getEnvInfo/getEnvAuthDomains/getWebsiteConfig, these names can still be used for compatibility with old AI rules) When action=list, standard return fields are EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, and supports filtering these fields via fields whitelist; aliasExact=true will filter by exact alias match to avoid mistaking environments with similar prefixes as candidates; even if envId is passed, action=list only returns summary, not complete resource details or expiry. Account-level login can pass region (ap-shanghai/ap-guangzhou/ap-singapore) to query corresponding regions, aligned with CLI tcb env list -r <region>; environment-level credentials (API Key / hosted authorization token) can only see the bound envId, returning credential_scope=single_env; in that case region is not applied and is truthfully reported in ignored_params (AppliedFilters.region is null) — do not misjudge this as the environment not existing or region filtering being broken. To query detailed information of a known environment, use action=info. action=info will supplement BillingInfo (such as ExpireTime, PayMode, IsAutoRenew and other billing fields) when available.

📊 action=usage aligns with tcb env usage/info: passes through Manager SDK describeEnvAccountCircle + describeCreditsUsageDetail, returning billing cycle and resource credit usage by module (FLEXDB/SCF/COS etc.). envId required; type optionally filters modules; when startDate/endDate are not passed, the current billing cycle is used automatically.

📈 action=metrics aligns with CloudBase DescribeCurveData (manager.monitor.describeCurveData, not Cloud Monitor GetMonitorData): queries environment/gateway QPS, cloud function invocations and errors, database CPU/memory/disk, CloudRun CPU/QPS time series. envId and metricName required; startTime/endTime format YYYY-MM-DD HH:mm:ss, must be passed as a pair, defaults to last 24 hours when omitted; period only supports 300/3600/86400. When GatewayTraceEnvQPS is called without resourceID, environment-level all|:|all|:|all|:|all is auto-filled; CloudRun Tke* metrics must pass service name as resourceID. Do not use callCloudApi to guess monitoring Actions.

🔍 action=info also derives three fields for backend selection:

  • EnvInfo.RuntimeMode: 'postgresql' or 'nosql', indicates the recommended default backend for new services (postgresql when PG is enabled, otherwise nosql).
  • EnvInfo.RuntimeBackends: {postgresql, nosql, mysql} three booleans describing the actual coexisting backends of the current environment.
  • EnvInfo.RuntimeModeHints: API/tool/skill hints corresponding to each backend.

🌐 action=info also projects gateway route Enable status without overwriting StaticStorages[].StaticDomain (cloud API nominal domain): StaticStorages[].staticDomainRouteEnabled and EnvInfo.staticDomainRouteEnabled (same source as queryHosting websiteConfig). false means the default static domain root route is disabled (access returns GATEWAY_ROUTE_DISABLED), do not treat the nominal domain as a reachable URL.

AI must check these three items before writing business/permission/storage code: In PG mode, new services should use app.rdb() + RLS (managePgDatabase action=execute to run CREATE POLICY) + pgstore; existing NoSQL collections / old storage / managePermissions(resourceType="noSqlDatabase") remain valid in PG environments. What is truly inapplicable is MySQL: when RuntimeBackends.mysql === false, manageMysqlDatabase / queryMysqlDatabase / relational-database-tool skill should not be used.

⚠️ DEPRECATED: This tool name is deprecated and is an old word-order alias for queryEnv. Input parameters and actions are completely identical. Please call queryEnv directly; this alias will be removed in the next version.

Parameters​

ParameterTypeRequiredDescription
actionstringYesQuery type: list=environment list/summary filtering (filters per DescribeEnvs semantics, supports filtering by envId/region, returns EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, does not support expiry), info=specified environment detailed information (envId required, returns resource fields and billing info), domains=security domain list, usage=environment resource usage (envId required, aligned with tcb env usage/info), metrics=environment monitoring time series (envId and metricName required, aligned with CloudBase DescribeCurveData). Allowed values: "list", "info", "domains", "usage", "metrics"
aliasstringFilter by environment alias. Optional when action=list
aliasExactbooleanFilter by exact environment alias match. Optional when action=list; used together with alias
envIdstringEnvironment ID. Optional when action=list (only filters per DescribeEnvs semantics, still returns summary); required when action=info / action=usage / action=metrics; optional when action=domains (queries the currently bound environment when omitted, or that environment's security domains when provided).
regionstringQuery region. Only effective when action=list. Account-level credentials pass this value through to DescribeEnvs (X-TC-Region), e.g. ap-singapore. Equivalent CLI: tcb env list -r <region> --json. Environment-level credentials (API Key / hosted authorization token) are single-environment scoped and this parameter is ignored: the result is always the bound environment, the response has AppliedFilters.region = null, query_region takes that environment's own Region, and ignored_params explains why it was ignored — do not conclude from this that the region has no environments. ⚠️ ap-singapore belongs to both the China site and the international site; when no site is explicitly specified it is treated as the international site (site=intl): if you have logged in to both sites, passing this region silently queries the international-site account, so call auth(site="domestic") or set TCB_SITE=domestic first to pin the site. Allowed values: "ap-shanghai", "ap-guangzhou", "ap-singapore"
limitintegerMaximum number of results to return. Optional when action=list
offsetintegerPagination offset. Optional when action=list
fieldsarray of stringReturn field whitelist. Only supports EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault. Optional when action=list
typearray of stringUsage module filter. Only effective when action=usage; queries all modules when omitted. Available values aligned with tcb CLI: FLEXDB, TDSQL, SCF, EKS, COS, AI, HOSTING, Auth, APIInvocation, HTTPInvocation, VM, Workflow, Other.
startDatestringUsage start date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with endDate. Uses current billing cycle when omitted.
endDatestringUsage end date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with startDate. Uses current billing cycle when omitted.
needUsageDetailsbooleanWhether to return daily usage details. Only effective when action=usage; defaults to true.
metricNamestringMonitoring metric name. Only effective and required when action=metrics. GatewayTraceEnvQPS/EnvQPSAll=environment and gateway QPS; FunctionInvocation/FunctionError/FunctionTimeout/FunctionThrottle=cloud function invocations, errors, timeouts, throttling; DbRead/DbWrite/DbSizepkg=document database reads, writes, and capacity; MysqlCpuUsageRate/MysqlMemoryUse/MysqlStorageUsage=SQL database CPU/memory/disk; TkeCpuUsedService/TkeQPSService/TkeHttpErrorService=CloudRun CPU/QPS/errors. Allowed values: "GatewayTraceEnvQPS", "EnvQPSAll", "FunctionInvocation", "FunctionError", "FunctionTimeout", "FunctionThrottle", "FunctionDuration", "FunctionConcurrentExecutions", "DbRead", "DbWrite", "DbSizepkg", "MysqlCpuUsageRate", "MysqlMemoryUse", "MysqlStorageUsage", "MysqlQps", "MysqlSlowQueries", "MysqlDbConnections", "TkeCpuUsedService", "TkeMemUsedService", "TkeQPSService", "TkeHttpErrorService", "TkeInvokeNumService"
startTimestringMonitoring start time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with endTime. Defaults to last 24 hours when omitted. End time must be at least five minutes after start time.
endTimestringMonitoring end time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with startTime. Defaults to last 24 hours when omitted.
periodnumberStatistics period (seconds). Only effective when action=metrics; only supports 300, 3600, 86400. Auto-selected by backend based on time range when omitted. Time range ≤1 day cannot use 86400; >3 days cannot use 300. Allowed values: 300, 3600, 86400
resourceIDstringResource ID. Only effective when action=metrics. Cloud functions pass function name, document database passes collection name, CloudRun must pass service name; GatewayTraceEnvQPS auto-fills environment-level all|:|all|:|all|:|all when omitted.
subresourceIDstringSub-resource ID. Only effective when action=metrics; pass version name when querying CloudRun version monitoring.

envDomainManagement​

Manage CloudBase environment security domains, supports add and delete operations. (Original tool names: createEnvDomain/deleteEnvDomain, these names can still be used for compatibility with old AI rules) When browser Web applications need to directly access CloudBase resources from local Vite / dev server or custom domains, first use envQuery(action=domains) to check if the actual browser origin's host:port is already in the whitelist, then add based on that actual value.

Parameters​

ParameterTypeRequiredDescription
actionstringYesOperation type: create=add domain, delete=delete domain. Allowed values: "create", "delete"
domainsarray of stringYesSecurity domain array

manageEnv​

Manage CloudBase environments, supports: listPackages=query available plan list, create=create a new environment (requires confirmation), modifyPlan=change plan (scale up/down, requires confirmation), renew=renew environment (requires confirmation).

⚠️ All fee-incurring operations (create/modifyPlan/renew) must show a configuration summary and wait for the user to confirm via confirm="yes" before execution.

Parameters​

ParameterTypeRequiredDescription
actionstringyesOperation type: listPackages=query available plans, create=create environment, modifyPlan=change plan, renew=renew. Allowed values: "listPackages", "create", "modifyPlan", "renew"
aliasstringEnvironment alias (required when action=create). Requirements: lowercase letters/numbers/hyphens, cannot start or end with a hyphen, max 20 characters
packageIdstringPlan ID (required when action=create/modifyPlan). Options include baas_personal (Personal), baas_pf_standard (Standard), baas_pf_enterprise (Enterprise)
resourcesarray of stringEnabled resource types (optional when action=create). Available values: storage, function (cloud function), postgresql; defaults to all three when omitted. CreateEnv requires a non-empty Resources field; MCP always sends it. flexdb (document database) is no longer included: newly created environments do not create a NoSQL instance, and its availability is determined by EnvInfo.RuntimeBackends returned by queryEnv(action="info")
durationintegerPurchase or renewal duration (months), optional when action=create/renew, default 1
regionstringCreation region (only effective when action=create). Passed through with X-TC-Region semantics and determines where the new environment lives; equivalent CLI: tcb env create --region ap-shanghai. When omitted, the current session region is used (cloudBaseOptions.region → TCB_REGION → project config / rc binding → site default region: ap-shanghai for the China site, ap-singapore for the international site). Note: region is not written into the CreateEnv request body but takes effect through the request-level region context — consistent with the callCloudApi rule "do not put Region into params". ⚠️ ap-singapore belongs to both the China site and the international site; when no site is explicitly specified it is treated as the international site (site=intl). To create in that region on the China site, call auth(site="domestic") or set TCB_SITE=domestic first. Allowed values: "ap-shanghai", "ap-guangzhou", "ap-singapore"
envIdstringEnvironment ID (required when action=modifyPlan/renew)
confirmstringConfirmation. All paid operations (create/modifyPlan/renew) must pass "yes". Allowed values: const "yes"

readNoSqlDatabaseStructure​

Read NoSQL database collection and index structure, supports listing collections, viewing collection details, listing indexes, and checking if an index exists.

Parameters​

ParameterTypeRequiredDescription
actionstringYeslistCollections: List collection list
describeCollection: Describe collection details (returns index summary)
checkCollection: Check if collection exists
listIndexes: List indexes of specified collection
checkIndex: Check if specified index exists. Allowed values: "listCollections", "describeCollection", "checkCollection", "listIndexes", "checkIndex"
limitnumberReturn count limit (optional for listCollections operation)
offsetnumberOffset (optional for listCollections operation)
collectionNamestringCollection name (required for describeCollection, listIndexes, checkIndex operations)
indexNamestringIndex name (required for checkIndex operation)

writeNoSqlDatabaseStructure​

Modify NoSQL database structure, supports creating/deleting collections, and adding/deleting indexes via updateCollection's updateOptions.CreateIndexes / updateOptions.DropIndexes.

Parameters​

ParameterTypeRequiredDescription
actionstringYescreateCollection: Create collection
updateCollection: Update collection configuration; pass updateOptions.CreateIndexes to add indexes, pass updateOptions.DropIndexes to delete indexes
deleteCollection: Delete collection. Allowed values: "createCollection", "updateCollection", "deleteCollection"
collectionNamestringYesCollection name
updateOptionsobjectUpdate options (used for updateCollection). CreateIndexes for adding indexes, DropIndexes for deleting indexes.
updateOptions.CreateIndexesarray of objectList of indexes to add
updateOptions.CreateIndexes[].IndexNamestringYesIndex name to create
updateOptions.CreateIndexes[].MgoKeySchemaobjectYesField and constraint configuration for index to be created
updateOptions.CreateIndexes[].MgoKeySchema.MgoIsUniquebooleanYesWhether unique index
updateOptions.CreateIndexes[].MgoKeySchema.MgoIndexKeysarray of objectYesIndex field list, supports single field or compound indexes
updateOptions.CreateIndexes[].MgoKeySchema.MgoIndexKeys[].NamestringYesIndex field name
updateOptions.CreateIndexes[].MgoKeySchema.MgoIndexKeys[].DirectionstringYesIndex direction, typically 1 for ascending, -1 for descending
updateOptions.DropIndexesarray of objectList of indexes to delete
updateOptions.DropIndexes[].IndexNamestringYesIndex name to delete

readNoSqlDatabaseContent​

Query and get NoSQL database data records

Parameters​

ParameterTypeRequiredDescription
collectionNamestringYesCollection name
instanceIdstringOptional: Explicitly specify database instance ID; will be automatically resolved and cached if not provided
queryobject | stringQuery conditions (object or string, object recommended)
projectionobject | stringReturn field projection (object or string, object recommended)
sortarray of object | stringSort conditions, only supports array [{"key":"createdAt","direction":-1}] or corresponding JSON string.
limitnumberReturn count limit
offsetnumberNumber of records to skip

writeNoSqlDatabaseContent​

Modify NoSQL database data records. Can be understood using MongoDB updateOne/updateMany mental model: partial updates must use update operators like $set/$inc/$push; if you directly pass a plain object like { field: value }, the underlying layer treats it as replacement content, risking overwriting the entire document. When updating a field in a nested object, you must use dot notation path (e.g., { "$set": { "address.city": "shenzhen" } }); if written as { "$set": { "address": { "city": "shenzhen" } } }, the entire address object will be replaced and other sibling fields will be lost. If role/profile documents in a collection are read on the frontend via db.collection(...).doc(uid), ensure the document _id is that uid; do not use query={"uid":"..."} + upsert=true to update users / profiles, otherwise it often generates a different _id, causing subsequent doc(uid) reads to miss.

Parameters​

ParameterTypeRequiredDescription
actionstringYesinsert: Insert data (add document)
update: Update data
delete: Delete data. Allowed values: "insert", "update", "delete"
collectionNamestringYesCollection name
instanceIdstringOptional: Explicitly specify database instance ID; will be automatically resolved and cached if not provided
documentsarray of objectArray of document objects to insert, each document is an object (required for insert operation)
queryobject | stringQuery conditions (object or string, object recommended) (required for update/delete operations)
updateobject | stringUpdate content (object or string, object recommended) (required for update operation). Pass MgoUpdate using MongoDB update semantics: for partial updates use $set/$inc/$unset/$push operators, e.g., { "$set": { "status": "pending" } }; do not directly pass { "status": "pending" }, otherwise the entire document may be replaced. When updating nested fields, use dot notation path, e.g., { "$set": { "address.city": "shenzhen" } }, do not write { "$set": { "address": { "city": "shenzhen" } } } (will replace entire address object).
isMultibooleanWhether to update multiple records (optional for update/delete operations)
upsertbooleanWhether to insert if not exists (optional for update operation)

queryPgDatabase​

Query CloudBase PostgreSQL databases. Supports getting the current PG context, listing schema-qualified database objects, reading lightweight metadata, inspecting a single object structure, and executing read-only SQL.

Parameters​

ParameterTypeRequiredDescription
actionstringyesOperation type: context=get current PostgreSQL context; objects=list schema-qualified database objects; metadata=get lightweight table metadata; schema=inspect a single schema-qualified object structure; sql=execute read-only SQL. Allowed values: "context", "objects", "metadata", "schema", "sql"
sqlstringRead-only SQL used when action=sql
objectNamestringSchema-qualified PostgreSQL object name used when action=schema, e.g. public.users
schemastringOptional schema filter, used for action=objects or action=metadata
limitintegerOptional cap on summary rows for objects, metadata, or SQL results. Default 20, max 200

managePgDatabase​

Manage CloudBase PostgreSQL: execute confirmed write SQL, SQL risk preflight, and migration management. Schema changes such as CREATE/ALTER/DROP MUST use applyMigration (explicit migrationVersion; before success, it automatically writes or validates the local cloudbase/migrations/<version>_<name>.sql file, consistent with the CLI tcb db pg migration). Do not default to execute. execute is mainly for DML and operational SQL like GRANT/RLS.

Parameters​

ParameterTypeRequiredDescription
actionstringyesOperation type: execute=execute confirmed write SQL (DML/GRANT/RLS; schema DDL is rejected by default, requires allowDdlViaExecute=true); dryRun=only analyze SQL risk without executing; planMigration=preview migration plan (requires migrationName + migrationVersion + sql; optional includeAll=true allows out-of-order, aligned with CLI --include-all); applyMigration=apply migration, preferred for CREATE/ALTER schema (requires migrationName + migrationVersion + sql + confirm=true; optional includeAll; if the local SQL is missing it is automatically written to cloudbase/migrations/, if content mismatches it fails closed with LOCAL_MIGRATION_FILE_MISMATCH; before returning success it polls DescribeTaskResult (default max 10 minutes, adjustable via taskPollTimeoutMs / waitForTask) and verifies the migrationVersion has landed in remote history; on timeout returns MIGRATION_TASK_TIMEOUT, must first describeMigrationTask then listMigrations, do NOT immediately re-push the same version; if not applied returns success=false with errorCode=MIGRATION_NOT_APPLIED); listMigrations=query the applied Migration list (supports limit/offset paging); migrationDetail=view a single Migration detail (requires migrationVersion); describeMigrationTask=query the Push async task status by TaskId (DescribeTaskResult: Status/Phase/Reason; requires taskId; used for waitForTask=false / MIGRATION_TASK_TIMEOUT / failure diagnosis, listMigrations cannot see Reason); fetchMigration=pull SQL from remote history and write to local cloudbase/migrations/ (aligned with CLI tcb db pg migration fetch; optional migrationVersion pulls a single entry, omitted pulls all; force=true overwrites existing files, default skips); rollbackMigration=roll back the latest N Migrations (requires lastN + confirm=true); repairMigration=repair Migration history (requires migrationVersion + migrationName + repairStatus + repairReason). Allowed values: "execute", "dryRun", "planMigration", "applyMigration", "listMigrations", "migrationDetail", "describeMigrationTask", "fetchMigration", "rollbackMigration", "repairMigration"
sqlstringSQL statement used by action=execute, dryRun, planMigration, applyMigration, or repairMigration(applied)
confirmbooleanMust be explicitly set to true before executing any write SQL
envIdstringOptional CloudBase environment ID; uses the current MCP environment when omitted
instanceIdstringOptional PostgreSQL logical instance identifier, default cloudbase-pg
defaultSchemastringOptional default schema, default public
rolestringOptional PostgreSQL role, passed to Manager SDK executePGSql; e.g. pass postgres when managing policies
objectNamestringOptional object name, currently only used for non-migration scenarios. For migration operations use migrationName / migrationVersion / lastN
migrationNamestringRequired for plan/apply/repair: migration name, starts with a lowercase letter, only lowercase letters, digits, and underscores allowed
migrationVersionstring14-digit timestamp YYYYMMDDHHMMSS. Required for plan/apply/detail/repair; optional for fetchMigration (pass to pull that entry only, omit to pull all remote history); must not be silently generated server-side, to avoid diverging from local cloudbase/migrations/<version>_<name>.sql. applyMigration is not incremental: always pass the complete SQL; when a run ends in a failed final state and listMigrations has not recorded it, the version number is not consumed — just resend the full SQL under a new migrationVersion (the same name with a different version does not conflict)
rollbackSqlstringOptional for plan/apply: rollback SQL statement
lastNintegerRequired for rollback: roll back the latest N applied Migrations, positive integer
limitintegerOptional for list: max number of results, 1-500, default 100
offsetintegerOptional for list: pagination offset, default 0
lockTimeoutMsintegerOptional for apply: max time to acquire the database lock (ms), default 5000
statementTimeoutMsintegerOptional for apply: max execution time per SQL statement (ms), default 300000
taskPollTimeoutMsintegerOptional for apply: max wait for polling DescribeTaskResult (ms). Default 600000 (aligned with CLI tcb db pg migration up 10-minute wait). Range 5000-600000. On timeout, first describeMigrationTask(taskId) then listMigrations, do NOT immediately re-push the same version
waitForTaskbooleanOptional for apply, default true. When false, Push returns the TaskId immediately (errorCode=MIGRATION_TASK_PENDING) and the caller polls the task final state with describeMigrationTask, then confirms persistence with listMigrations; suitable for MCP host tool calls with short timeout. Default true waits synchronously for the task final state
taskIdstringRequired for describeMigrationTask: the TaskId returned by PushPGUserMigrations / applyMigration. Used for a one-shot DescribeTaskResult (Status/Phase/Reason) query, no polling
repairStatusstringRequired for repair: applied=mark as applied (can backfill Query), reverted=delete history record. Allowed values: "applied", "reverted"
repairReasonstringRequired for repair: repair reason
forcebooleanOptional for fetchMigration, default false. true=overwrite an existing local SQL file with the same name (aligned with CLI tcb db pg migration fetch --force); false=skip existing files. Used to realign Git checksums from remote history
includeAllbooleanOptional for planMigration / applyMigration, default false. true=allow out-of-order (version lower than remote LatestVersion) Preview/Push, aligned with CLI tcb db pg migration up --include-all; only use when intentionally backfilling history/out-of-order migrations, otherwise choose a larger migrationVersion
allowDdlViaExecutebooleanOptional, default false. Only set true when deliberately bypassing migration history to allow schema DDL via execute; normal CREATE/ALTER schema must use applyMigration

queryPgStorage​

Query cloud storage capabilities in the CloudBase PostgreSQL environment. Returns bucket/config capability summaries, object info query plans, and upload implementation plans based on HTTP API or SDK; does not read local files and does not output large numbers of signed URLs by default.

Parameters​

ParameterTypeRequiredDescription
actionstringyesOperation type: buckets/config=query storage capability summary; createBucket=generate bucket creation plan (SQL/HTTP API/CLI); uploadPlan=generate HTTP API/SDK upload plan; objectInfo=generate object metadata query plan; signUpload/signDownload=explicit one-time signed URL request placeholders. Allowed values: "buckets", "config", "uploadPlan", "objectInfo", "signUpload", "signDownload", "createBucket"
bucketstringCloud storage bucket name
objectKeystringSingle object key
objectKeysarray of stringMultiple object keys, used for object metadata query planning
objectsarray of objectMetadata of objects to upload. File byte content is not passed through MCP
expiresInintegerSigned URL validity period in seconds, range 60 to 86400

queryMysqlDatabase​

Query CloudBase MySQL database information. Supports read-only SQL execution, MySQL provisioning result lookup, MySQL task status lookup, and current instance context discovery.

Parameters​

ParameterTypeRequiredDescription
actionstringYesrunQuery=execute read-only SQL; describeCreateResult=query CreateMySQL result; describeTaskStatus=query MySQL task status; getInstanceInfo=get current SQL instance context; describeInstance=alias of getInstanceInfo. Allowed values: "runQuery", "describeCreateResult", "describeTaskStatus", "getInstanceInfo", "describeInstance", "getConnectionInfo"
sqlstringRead-only SQL used by action=runQuery
requestobjectOfficial request payload used by describeCreateResult/describeTaskStatus
dbInstanceobjectOptional SQL database instance context for runQuery
dbInstance.instanceIdstring
dbInstance.schemastring

manageMysqlDatabase​

Manage CloudBase MySQL database resources. Supports MySQL provisioning, MySQL destruction, write SQL/DDL execution, and schema initialization. IMPORTANT: MySQL must be provisioned first (action=provisionMySQL with confirm=true) before any runStatement or initializeSchema call. If MySQL is not yet provisioned, the tool will return MYSQL_NOT_CREATED with a nextAction to provision first.

Parameters​

ParameterTypeRequiredDescription
actionstringYesprovisionMySQL=create MySQL instance; destroyMySQL=destroy MySQL instance; runStatement=execute write SQL or DDL; initializeSchema=run ordered schema initialization statements. Allowed values: "provisionMySQL", "destroyMySQL", "runStatement", "initializeSchema"
confirmbooleanExplicit confirmation required for action=provisionMySQL or action=destroyMySQL
sqlstringSQL statement used by action=runStatement
requestobjectOfficial request payload used by action=provisionMySQL or action=destroyMySQL
statementsarray of stringOrdered schema initialization SQL statements used by action=initializeSchema
requireReadybooleanWhether initializeSchema should block until MySQL is confirmed ready. Defaults to true.
statusContextobjectOptional provisioning status requests used to confirm readiness before initializeSchema
statusContext.createResultRequestobject
statusContext.taskStatusRequestobject
dbInstanceobjectOptional SQL database instance context for runStatement/initializeSchema
dbInstance.instanceIdstring
dbInstance.schemastring

manageDataModel​

Data model query tool, supports querying and listing data models (read-only operations). Use the action parameter to distinguish operation types: list=get model list (without Schema, optional names parameter for filtering), get=query single model details (with Schema field list, format, relationships, etc., requires name parameter), docs=generate SDK usage documentation (requires name parameter)

Parameters​

ParameterTypeRequiredDescription
actionstringYesOperation type: get=query single model (with Schema field list, format, relationships, requires name parameter), list=get model list (without Schema, optional names parameter for filtering), docs=generate SDK usage documentation (requires name parameter). Allowed values: "get", "list", "docs"
namestringData model name to query. When action='get' or action='docs', this parameter is required and must provide an existing data model name. Available model names can be obtained via action='list' operation
namesarray of stringModel name array (optional for list operation, for filtering)

modifyDataModel​

Create or update data model based on Mermaid classDiagram. Supports creating new models and updating existing model structures. Built-in async task monitoring, automatically polls until completion or timeout.

Parameters​

ParameterTypeRequiredDescription
mermaidDiagramstringYesMermaid classDiagram code describing the data model structure.
actionstringOperation type: create=create new model. Allowed values: "create"; Default: "create"
publishbooleanWhether to publish the model immediately. Default: false
dbInstanceTypestringDatabase instance type. Default: "MYSQL"
Example
classDiagram
class Student {
name: string <<Name>>
age: number = 18 <<Age>>
gender: x-enum = "Male" <<Gender>>
classId: string <<Class ID>>
identityId: string <<Identity ID>>
course: Course[] <<Courses>>
required() ["name"]
unique() ["name"]
enum_gender() ["Male", "Female"]
display_field() "name"
}
class Class {
className: string <<Class Name>>
display_field() "className"
}
class Course {
name: string <<Course Name>>
students: Student[] <<Students>>
display_field() "name"
}
class Identity {
number: string <<ID Number>>
display_field() "number"
}

%% Relationships
Student "1" --> "1" Identity : studentId
Student "n" --> "1" Class : student2class
Student "n" --> "m" Course : course
Student "n" <-- "m" Course : students
%% Class naming
note for Student "Student Model"
note for Class "Class Model"
note for Course "Course Model"
note for Identity "Identity Model"

queryFunctions​

Unified read-only entry for the functions domain. Query function list, function details, logs, layers, triggers, and code download URLs via self-explanatory action names.

Parameters​

ParameterTypeRequiredDescription
actionstringYesRead-only operation type, e.g., listFunctions, getFunctionDetail, listFunctionLogs. Allowed values: "listFunctions", "getFunctionDetail", "listFunctionLogs", "getFunctionLogDetail", "listFunctionLayers", "listLayers", "listLayerVersions", "getLayerVersionDetail", "listFunctionTriggers", "getFunctionDownloadUrl", "getFunctionDeployStatus"
functionNamestringFunction name. Required for function-related actions
limitnumberPagination count. Optional for list-type actions
offsetnumberPagination offset. Optional for list-type actions
codeSecretstringCode protection secret
startTimestringLog query start time
endTimestringLog query end time
requestIdstringLog requestId. Required when getting log details
qualifierstringFunction version, optional for log queries
runtimestringRuntime filter for layer queries
searchKeystringLayer name search keyword
layerNamestringLayer name. Required for layer-related actions
layerVersionnumberLayer version number. Required when getting layer version details

manageFunctions​

Unified write entry for the functions domain. Supports function creation, code updates, config updates, function invocation, cron timer triggers, layer bindings, incremental deployment, and deletion. Image deployment (Runtime=CustomImage): push the image via zip→COS→CloudApp custom build→TCR first (this stage uses bare Tencent Cloud APIs, not covered by this tool), then use createFunction with func.runtime="CustomImage" and imageConfig to create an HTTP function from the TCR image; subsequent iterations use updateFunctionCode + imageConfig to swap image tags. Dangerous operations require explicit confirm=true.

Parameters​

ParameterTypeRequiredDescription
actionstringYesWrite operation type, e.g., createFunction, invokeFunction, attachLayer. Allowed values: "createFunction", "updateFunctionCode", "updateFunctionConfig", "invokeFunction", "deleteFunction", "createFunctionTrigger", "deleteFunctionTrigger", "createLayerVersion", "deleteLayerVersion", "attachLayer", "detachLayer", "updateFunctionLayers", "incrementalDeployFunction"
funcobjectFunction configuration for createFunction operation
func.namestringYesFunction name
func.typestringFunction type. Allowed values: "Event", "HTTP"
func.protocolTypestringHTTP cloud function protocol type. Allowed values: "HTTP", "WS"
func.protocolParamsobject
func.protocolParams.wsParamsobject
func.protocolParams.wsParams.idleTimeOutnumberWebSocket idle timeout (seconds)
func.instanceConcurrencyConfigobject
func.instanceConcurrencyConfig.dynamicEnabledboolean
func.instanceConcurrencyConfig.maxConcurrencynumber
func.timeoutnumberFunction timeout
func.envVariablesobjectEnvironment variables
func.vpcobjectVPC configuration
func.vpc.vpcIdstringYes
func.vpc.subnetIdstringYes
func.runtimestringRuntime environment. Event functions support multiple runtimes:
Nodejs: Nodejs24.11(Beta), Nodejs22.21(Beta), Nodejs20.19, Nodejs18.15, Nodejs16.13
Python: Python3.11, Python3.10, Python3.9, Python3.7
Php: Php8.0, Php7.4
Java: Java11
Golang: Golang1
Image deployment (create HTTP function from TCR image) use "CustomImage", also provide imageConfig; no functionRootPath/zipFile needed.
Recommended runtimes:
Node.js: Nodejs20.19
Python: Python3.11
PHP: Php7.4
Java: Java11
Go: Golang1
func.imageConfigobjectImage deployment configuration (only used when runtime=CustomImage). Used for stage B of zip→COS→CloudApp custom build→TCR→SCF: creating an HTTP function from a TCR image. Once imageConfig is passed, the function is treated as image-deployed and requires no local code packaging, scf_bootstrap, or Handler.
func.imageConfig.imageTypestringImage registry type: enterprise (Enterprise TCR) or personal (Personal TCR). Defaults to enterprise when omitted. Allowed values: "enterprise", "personal"
func.imageConfig.imageUristringYesFull image address (must include tag), format {domain}/{namespace}/{image}:{tag}, e.g., ccr.ccs.tencentyun.com/your-ns/demo-app:demo-app-001. Do not use :latest.
func.imageConfig.registryIdstringTCR instance ID, e.g., tcr-xxxxxxxx. Required when imageType=enterprise.
func.imageConfig.commandstringOverride image ENTRYPOINT. Uses Dockerfile default if not provided, e.g., python.
func.imageConfig.argsstringOverride image CMD, space-separated, e.g., -u app.py.
func.imageConfig.entryPointstringImage entry point, generally not needed.
func.imageConfig.imagePortnumberContainer listening port. Web Server functions use 9000 (default), Job-type images use -1.
func.imageConfig.containerImageAcceleratebooleanWhether to enable image acceleration. Recommended for large images to reduce cold start time.
func.triggersarray of objectTrigger configuration array
func.triggers[].namestringYesTrigger name
func.triggers[].typestringYesTrigger type. Allowed values: "timer"
func.triggers[].configstringYesTrigger configuration, timer uses 7-segment cron: second minute hour day month week year
func.handlerstringFunction entry point
func.ignorestring | array of stringIgnored files
func.isWaitInstallbooleanWhether to wait for dependency installation
func.layersarray of objectLayer configuration
func.layers[].namestringYes
func.layers[].versionnumberYes
functionRootPathstringFunction root directory (parent directory absolute path)
forcebooleanWhether to overwrite when createFunction
functionNamestringFunction name. Most actions use this field as unified target
zipFilestringCode package base64 encoding
handlerstringFunction entry point
timeoutnumberTimeout for config update
envVariablesobjectEnvironment variables to merge for config update
vpcunknownVPC info for config update
paramsobjectInvocation parameters for invokeFunction
triggersarray of unknownTrigger list for createFunctionTrigger
triggerNamestringTarget trigger name for deleteFunctionTrigger
layerNamestringLayer name
layerVersionnumberLayer version number
contentPathstringLayer content path, can be directory or ZIP file
base64ContentstringLayer content base64 encoding
runtimesarray of stringList of runtimes the layer applies to
descriptionstringLayer version description
licenseInfostringLayer license information
layersarray of objectTarget layer list for updateFunctionLayers, order is final order
layers[].layerNamestringYesLayer name
layers[].layerVersionnumberYesLayer version number
codeSecretstringCode protection secret for layer binding
imageConfigunknownImage deployment configuration (Runtime=CustomImage). Used with createFunction to create an HTTP function from a TCR image, or with updateFunctionCode to swap image tags only. Requires imageUri (with tag); enterprise TCR also requires registryId. Can also be provided in func.imageConfig; when both are passed, the top-level imageConfig takes precedence.
incrementalFilestringFile path for incrementalDeployFunction incremental deployment
confirmbooleanDangerous operation confirmation switch

queryHosting​

Query read-only information about CloudBase static hosting. Suitable for AI discovery before deciding next steps: action=websiteConfig queries index/error page, routing rules and site domain info; action=status queries hosting service status; action=findFiles finds files by prefix; action=listFiles lists all hosted files; action=domainStatus queries the current status and config of custom domains. This tool has no side effects.

Parameters​

ParameterTypeRequiredDescription
actionstringyesQuery type: websiteConfig=query static hosting website document config and site domain info, status=query static hosting service status, findFiles=find hosted files by prefix, listFiles=list all files in static hosting, domainStatus=query custom domain config and effective status. This tool is strictly read-only and does not modify any resources. Allowed values: "websiteConfig", "status", "findFiles", "listFiles", "domainStatus"
prefixstringFile prefix filter. Only used when action=findFiles, e.g. app/ or assets/logo
markerstringPagination start marker. Only used when action=findFiles, to continue fetching results after the previous page
maxKeysintegerMax file entries returned per call. Only used when action=findFiles
domainsarray of stringCustom domain list to query. Only used when action=domainStatus, e.g. ["www.example.com"]

manageHosting​

Manage change operations for CloudBase static hosting. action=upload uploads local build artifacts to the shared domain (domain format: <envId>-<appId>.tcloudbaseapp.com/<cloudPath>); action=delete deletes hosted files or directories (must confirm=true); action=setWebsiteDocument sets index/error pages and routing rules; action=enableService enables static hosting; action=bindDomain / unbindDomain / updateDomain manage custom domains; action=downloadFile / downloadDirectory download hosted content to local. ⚠️ For new project deployments, prefer manageApps (deploys to an independent subdomain); this tool is for existing legacy projects or as a fallback for manageApps. manageApps and manageHosting use different domains; switching will break old links. If the task only needs to view config, files, or domain status, use queryHosting instead.

Parameters​

ParameterTypeRequiredDescription
actionstringyesManagement type: upload=upload local build artifacts to static hosting, delete=delete hosted files or directories, setWebsiteDocument=set index/error pages and routing rules, enableService=enable static hosting service, bindDomain=bind a custom domain, unbindDomain=unbind a custom domain, updateDomain=update domain cache/anti-leech/IP rules, downloadFile=download a single hosted file locally, downloadDirectory=download a hosted directory locally. Allowed values: "upload", "delete", "setWebsiteDocument", "enableService", "bindDomain", "unbindDomain", "updateDomain", "downloadFile", "downloadDirectory"
localPathstringLocal path. For action=upload, the local file/directory path to upload; for action=downloadFile or downloadDirectory, the local destination path. Absolute paths recommended
cloudPathstringTarget path in static hosting. For action=upload, the hosted path after upload; for action=delete/downloadFile/downloadDirectory, the hosted file or directory path
filesarray of objectMulti-file upload config. Optional when action=upload; when passed, each file is uploaded individually and single localPath/cloudPath is not used
ignoreunionFile patterns to ignore when uploading. Optional when action=upload, e.g. node_modules or ["/*.map", "/.DS_Store"]
isDirbooleanWhether to treat cloudPath as a directory. Only used when action=delete; true=delete directory, false=delete a single file
confirmbooleanConfirmation switch for high-risk operations. Must be explicitly true for action=delete and action=unbindDomain to avoid accidental file deletion or domain unbinding
indexDocumentstringWebsite index document name. Required only when action=setWebsiteDocument, e.g. index.html
errorDocumentstringError page document name. Optional when action=setWebsiteDocument, e.g. 404.html
routingRulesarray of objectWebsite routing rule list. Optional when action=setWebsiteDocument. A common SPA config rewrites 404 to index.html
domainstringCustom domain. Used for action=bindDomain / unbindDomain / updateDomain, e.g. www.example.com
certIdstringCertificate ID. Required only when action=bindDomain
domainIdnumberDomain ID. Required only when action=updateDomain, for precisely updating the specified domain config
domainConfigobjectDomain config. Required only when action=updateDomain; supports cache, Referer, anti-leech, IP rules, and rate limiting

queryStorage​

Query cloud storage information, supports listing directory files, getting file information, getting temporary download links and other read-only operations. Returned file information includes file name, size, modification time, download link, etc.

Parameters​

ParameterTypeRequiredDescription
actionstringYesQuery operation type: list=list all files in directory, info=get detailed information of specified file, url=get temporary download link for file. Allowed values: "list", "info", "url", "read"
cloudPathstringYesCloud file path, e.g., files/data.txt or files/ (directory)
maxAgenumberTemporary link validity period in seconds, range: 1-86400, default: 3600 (1 hour). Default: 3600

manageStorage​

Manage cloud storage files, only for COS/Storage objects, not for static website hosting. Supports uploading files/directories, downloading files/directories, deleting files/directories and other operations. Delete operation requires setting force=true for confirmation to prevent accidental deletion of important files.

Parameters​

ParameterTypeRequiredDescription
actionstringYesManagement operation type: upload=upload file or directory, download=download file or directory, delete=delete file or directory. Allowed values: "upload", "download", "delete"
localPathstringYesLocal file path, absolute path recommended, e.g., /tmp/files/data.txt
cloudPathstringYesCloud file path, e.g., files/data.txt
forcebooleanForce operation switch, recommended to set to true for delete operations to confirm deletion, defaults to false. Default: false
isDirectorybooleanWhether directory operation, true=directory operation, false=file operation, defaults to false. Default: false

downloadTemplate​

Automatically download and deploy CloudBase project templates. ⚠️ MANDATORY FOR NEW PROJECTS ⚠️

CRITICAL: This tool MUST be called FIRST when starting a new project.

Supported templates:

  • react: React + CloudBase full-stack application template
  • vue: Vue + CloudBase full-stack application template
  • miniprogram: WeChat Mini Program + CloudBase template
  • uniapp: UniApp + CloudBase cross-platform application template
  • rules: Only includes AI editor configuration files (includes all mainstream editor configurations such as Cursor, WindSurf, CodeBuddy, etc.), suitable for supplementing AI editor configuration in existing projects

Supported IDE types:

  • all: Download all IDE configurations
  • cursor: Cursor AI editor
  • Other IDE types see list below

Note: If ide parameter is not passed and IDE cannot be detected from environment, an error will be prompted and require passing ide parameter

  • windsurf: WindSurf AI editor
  • codebuddy: CodeBuddy AI editor
  • claude-code: Claude Code AI editor
  • cline: Cline AI editor
  • gemini-cli: Gemini CLI
  • opencode: OpenCode AI editor
  • qwen-code: Tongyi Lingma
  • baidu-comate: Baidu Comate
  • openai-codex-cli: OpenAI Codex CLI
  • augment-code: Augment Code
  • github-copilot: GitHub Copilot
  • roocode: RooCode AI editor
  • tongyi-lingma: Tongyi Lingma
  • trae: Trae AI editor
  • qoder: Qoder AI editor
  • antigravity: Google Antigravity AI editor
  • vscode: Visual Studio Code
  • kiro: Kiro AI editor
  • aider: Aider AI editor

Special notes:

  • rules template will automatically include current MCP version information, which helps with later maintenance and version tracking
  • When downloading rules template, if README.md file already exists in the project, the system will automatically protect the file from being overwritten (unless overwrite=true is set)

Parameters​

ParameterTypeRequiredDescription
templatestringYesTemplate type to download. Allowed values: "react", "vue", "miniprogram", "uniapp", "rules"
idestringYesSpecify the IDE type to download. Allowed values: "all", "cursor", "windsurf", "codebuddy", "claude-code", "cline", "gemini-cli", "opencode", "qwen-code", "baidu-comate", "openai-codex-cli", "augment-code", "github-copilot", "roocode", "tongyi-lingma", "trae", "qoder", "antigravity", "vscode", "kiro", "aider", "iflow-cli"
overwritebooleanWhether to overwrite existing files, defaults to false (no overwrite)

searchKnowledgeBase​

CloudBase knowledge base intelligent retrieval tool, supports fixed skill documents (skill), OpenAPI documents (openapi) and CloudBase official documentation (docs) queries.

It is strongly recommended to always prioritize using fixed skill documents (skill), OpenAPI documents (openapi) or CloudBase official documentation (docs) mode for retrieval, If these fixed modes cannot cover your question, use the CloudBase official documentation (docs) mode.

The response contains the full SKILL.md of that skill plus the address list of every .md file for it in the remote aggregation repo (CNB raw) — SKILL.md, references/, and so on, directly fetchable over HTTP. Relative links outside code fences in the body are also rewritten to absolute addresses; if the skill does not exist in the remote repo, only the inline content is returned, clearly marked, and no dead links are returned.

Fixed skill documents (skill) query currently supports 30 fixed documents, they are: Document name: ai-model-nodejs - Document description: "Use this skill for Node.js backend AI via @cloudbase/node-sdk (>=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration. The only SDK supporting image generation (ai.createImageModel + generateImage). Text via ai.createModel with groups cloudbase, hunyuan-exp, or custom-; model ids (e.g. deepseek-v4-flash, glm-5, kimi-k2.6) go in the model field of generateText/streamText. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web) or Mini Program (use ai-model-wechat)." Document name: ai-model-web - Document description: "Use this skill when a browser/Web app (React, Vue, Next, Nuxt, static sites, SPAs, dashboards, AI chat UI, 页面, 前端, 网页) needs AI models via @cloudbase/js-sdk. Default routing for Web/frontend AI — call directly from the browser, do NOT propose a Node.js proxy. Covers generateText and streamText; models via ai.createModel with groups cloudbase, hunyuan-exp, or custom-, model id in the model field. MUST run two-step preflight before code — see body. NOT for Node.js backend (use ai-model-nodejs), Mini Program (use ai-model-wechat), or image generation (Node SDK only)." Document name: ai-model-wechat - Document description: "Use this skill for WeChat Mini Program AI via wx.cloud.extend.AI (小程序, wx.cloud apps). Covers generateText and streamText with callbacks (onText, onEvent, onFinish); streamText needs a data wrapper, generateText returns the raw response. Models via wx.cloud.extend.AI.createModel with groups hunyuan-exp (小程序成长计划), cloudbase (main managed), or custom-*; model id goes in the data wrapper model field. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web), Node.js backend (use ai-model-nodejs), or image generation (use ai-model-nodejs)." Document name: auth-nodejs-cloudbase - Document description: CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase; not when configuring providers or building client login UI. Document name: auth-tool-cloudbase - Document description: CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow. Document name: auth-web-cloudbase - Document description: CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management. Document name: auth-wechat-miniprogram - Document description: CloudBase WeChat Mini Program native authentication guide. This skill should be used when users need mini program identity handling, OPENID/UNIONID access, or wx.cloud auth behavior in projects where login is native and automatic. Document name: cloud-api-operations - Document description: Operate Tencent Cloud control-plane resources (monitoring/alarms, CLB, CAM roles, COS, MySQL, SCF) via cloud APIs when no dedicated MCP tool covers the task. Use when a task needs control-plane operations beyond CloudBase's own tooling, or when a callCloudApi call failed and needs classifying. Document name: cloud-functions - Document description: CloudBase function runtime guide for building, deploying, and debugging your own Event Functions or HTTP Functions. This skill should be used when users need application runtime code on CloudBase, not when they are merely calling CloudBase official platform APIs. Document name: cloud-storage-web - Document description: Complete guide for CloudBase cloud storage using Web SDK (@cloudbase/js-sdk) - upload, download, temporary URLs, file management, and best practices. Document name: cloudbase-agent - Document description: Build and deploy AI agents with CloudBase Agent SDK (TypeScript & Python). Implements the AG-UI protocol for streaming agent-UI communication. Use when deploying agent servers, using LangGraph/LangChain/CrewAI adapters, building custom adapters, understanding AG-UI protocol events, or building web/mini-program UI clients. Supports both TypeScript (@cloudbase/agent-server) and Python (cloudbase-agent-server via FastAPI). Document name: cloudbase-cli - Document description: CloudBase CLI (tcb, 云开发CLI, Tencent CloudBase命令行) resource management skill. Use when deploying cloud functions, CloudRun, storage, NoSQL/MySQL, static hosting, permissions, CORS/domains via tcb; for CI/CD and batch ops; when the user prefers CLI; or as the first-session fallback when CloudBase MCP tools are not loaded yet (after install/config, before IDE restart). Covers tcb login (device code for Tencent Cloud accounts; --cloudbase-api-key -e for environment API Key without an account; --apiKeyId/--apiKey for CI) and domain commands (fn/hosting/cloudrun/…) as MCP auth/manage parity — do not default to tcb deploy. Document name: cloudbase-code-review - Document description: "Code review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects, call this skill to check for known pitfalls — auth guard misuse, missing database tables, RLS misconfiguration, storage domain setup, and SDK API misuse. Supports automated lint scripts (regex-based) + LLM semantic review." Document name: cloudbase-declarative-deploy - Document description: CloudBase declarative deployment from a cloudbaserc config (声明式部署, 配置式部署, cloudbaserc 部署) through the deployBuild / deployPlan / deployApply MCP tools. Use when deploying database, functions, app, hosting, or gateway resources described in cloudbaserc.json/yaml as a single desired-state config, when a user wants to build static hosting artifacts locally first (deployBuild), or wants a dry-run plan before applying (deployPlan), or when handling multi-environment deploys via mode / envOverrides. Covers build-plan-apply flow (deployBuild local build → deployPlan dry-run → deployApply confirm=true), hosting build-output neutralization, envId resolution priority, only/skip filtering, concurrency, and continueOnError. Prefer deployBuild (when hosting declares a buildCommand) and deployPlan before deployApply; do not confuse with per-resource tcb CLI deploy or single-function deploy. Document name: cloudbase-document-database-in-wechat-miniprogram - Document description: Use CloudBase document database WeChat MiniProgram SDK to query, create, update, and delete data. Supports complex queries, pagination, aggregation, and geolocation queries. Document name: cloudbase-document-database-web-sdk - Document description: Use CloudBase document database Web SDK only for confirmed NoSQL collection work. Query, create, update, and delete document data; if the task mentions PostgreSQL / CloudBase PG / app.rdb(), route to postgresql-development instead. Document name: cloudbase-platform - Document description: CloudBase platform overview and routing guide. This skill should be used when users need high-level capability selection, platform concepts, console navigation, or cross-platform best practices before choosing a more specific implementation skill. Document name: cloudbase-wechat-integration - Document description: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase. Document name: cloudrun-development - Document description: CloudBase Run backend development rules (Function mode/Container mode). Use this skill when deploying backend services that require long connections, multi-language support, custom environments, AI agent development, or migrating existing/GitHub apps that need VPC access to MySQL/PostgreSQL/Redis. Also use when diagnosing CloudRun container deploy failures (deploy_failed, readiness/probe failed, image won't start, docker.io pull loops). For stateless HTTP services, prefer HTTP cloud functions. Document name: data-model-creation - Document description: "[Deprecated] Optional advanced tool for complex data modeling. For simple MySQL table creation, use relational-database-tool directly; for PostgreSQL / CloudBase PG schema work, use postgresql-development. New environments should use PostgreSQL DDL via queryPgDatabase/managePgDatabase — see postgresql-development skill instead." Document name: http-api-cloudbase - Document description: CloudBase official HTTP API client guide. This skill should be used when backends, scripts, or non-SDK clients must call CloudBase platform APIs over raw HTTP instead of using a platform SDK or MCP management tool. Document name: minimal-web-baas-demo - Document description: "Fast path for a minimal CloudBase Web + database demo (最小前后端 / 最小可用 fullstack / Lovable-like BaaS). Defaults to @cloudbase/js-sdk client CRUD (NoSQL app.database / PG app.rdb), MCP-only schema, preview-first, and forbids cloud functions unless secrets, cron/background jobs, or logic that security rules/RLS cannot express. Use for 搭一套 demo、留言板、Todo、Notes、Kanban, or when users say 带云函数+云数据库 but only need CRUD. NOT for production multi-service backends, CloudRun, WeChat Mini Programs, or tasks that truly need server secrets." Document name: miniprogram-development - Document description: WeChat Mini Program development skill for building, debugging, previewing, testing, publishing, and optimizing mini program projects (小程序开发、调试、预览、发布). Covers project structure and config (project.config.json, appid, miniprogramRoot, tabBar, routing/navigation, icon assets), WeChat Developer Tools Nightly workflows (wechatide CLI, WeChat IDE Skills/MCP), miniprogram-ci preview/upload, console/network debugging, message push (消息推送) and customer-service auto-reply (客服消息), mini program SEO / search indexing (小程序搜索优化、页面收录、搜索推广、mpcrawler), and CloudBase integration (wx.cloud, 腾讯云开发, 云开发) when explicitly used. Use when users create, develop, modify, debug, preview, deploy, publish, or promote WeChat Mini Programs. NOT for Web frontend (use web-development), pure backend services (use cloudrun-development / cloud-functions), or UI-design-only tasks (use ui-design). Document name: ops-inspector - Document description: AIOps-style CloudBase inspection skill (v3). Use when users need health checks, log diagnosis, alarm interpretation (CPU alert normal?, peak QPS), metrics via queryEnv(action=metrics), or fault playbooks for 429 / function 404 / ACCESS_TOKEN_INVALID / zero invocations. Triggers on 巡检, 诊断, 告警, 峰值 QPS, 限频, 调用量为 0, troubleshooting. Document name: postgresql-development-cloudbase - Document description: "Use when building, debugging, or evaluating CloudBase PostgreSQL / CloudBase PG / PG mode apps, including Postgres schema setup, queryPgDatabase/managePgDatabase, JS SDK v3 app.rdb() CRUD/RPC, PG HTTP API fallback, RLS-style permissions, username-password auth, and Web CMS/admin CRUD flows backed by CloudBase PG." Document name: relational-database-mcp-cloudbase - Document description: "[Deprecated] This is the required documentation for agents operating on the CloudBase Relational Database through MCP. It defines the canonical SQL management flow with queryMysqlDatabase, manageMysqlDatabase, queryPermissions, and managePermissions, including MySQL provisioning, destroy flow, async status checks, safe query execution, schema initialization, and permission updates. New environments should use PostgreSQL — see postgresql-development skill instead." Document name: relational-database-web-cloudbase - Document description: "[Deprecated] Use when building frontend Web apps that talk to CloudBase Relational Database via @cloudbase/js-sdk – provides the canonical init pattern so you can then use Supabase-style queries from the browser. New environments should use PostgreSQL with app.rdb() — see postgresql-development skill instead." Document name: spec-workflow - Document description: Use when medium-to-large changes need explicit requirements, technical design, and task planning before implementation, especially for multi-module work, unclear acceptance criteria, or architecture-heavy requests. Document name: ui-design - Document description: Use when users need visual direction, interface hierarchy, layout decisions, design specifications, or prototypes before implementing a Web or mini program UI. Document name: web-development - Document description: Use when users need to implement, integrate, debug, build, deploy, or validate a Web frontend after the product direction is already clear, especially for React, Vue, Vite, browser flows, or CloudBase Web integration.

OpenAPI documents (openapi) queries only need mode="openapi" and apiName — do not pass action; action is only used for mode="docs". Currently supports 8 API documents, they are: API name: mysqldb - API description: MySQL RESTful API - 云开发 MySQL 数据库 HTTP API API name: pgdb - API description: PostgreSQL RESTful API (PostgREST) - 云开发 PostgreSQL 数据库 HTTP API,含 exec-pgsql 直连 SQL API name: functions - API description: Cloud Functions API - 云函数 HTTP API API name: auth - API description: Authentication API - 身份认证 HTTP API API name: cloudrun - API description: CloudRun API - 云托管服务 HTTP API API name: storage - API description: Storage API - 云存储 HTTP API API name: nosql - API description: NoSQL RESTful API - 文档型数据库 HTTP API API name: ai_model - API description: AI 大模型接入 API - 统一 AI 模型 HTTP API API name: storage - API description: Storage API - Cloud Storage HTTP API API name: mysqldb - API description: MySQL RESTful API - CloudBase MySQL Database HTTP API API name: auth - API description: Authentication API - Identity Authentication HTTP API API name: cloudrun - API description: CloudRun API - CloudRun Service HTTP API

Parameters​

ParameterTypeRequiredDescription
modestringYesAllowed values: "skill", "openapi", "docs"
skillNamestringSpecify when mode=skill. Skill name. Allowed values: "ai-model-nodejs", "ai-model-web", "ai-model-wechat", "auth-nodejs-cloudbase", "auth-tool-cloudbase", "auth-web-cloudbase", "auth-wechat-miniprogram", "cloud-api-operations", "cloud-functions", "cloud-storage-web", "cloudbase-agent", "cloudbase-cli", "cloudbase-code-review", "cloudbase-declarative-deploy", "cloudbase-document-database-in-wechat-miniprogram", "cloudbase-document-database-web-sdk", "cloudbase-platform", "cloudbase-wechat-integration", "cloudrun-development", "data-model-creation", "http-api-cloudbase", "minimal-web-baas-demo", "miniprogram-development", "ops-inspector", "postgresql-development-cloudbase", "relational-database-mcp-cloudbase", "relational-database-web-cloudbase", "spec-workflow", "ui-design", "web-development"
apiNamestringSpecify when mode=openapi. API name. Allowed values: "mysqldb", "pgdb", "functions", "auth", "cloudrun", "storage", "nosql", "ai_model"
actionstringSpecify when mode=docs. CloudBase documentation operation type: listModules=list all documentation modules, listModuleDocs=get directory structure of specified module, findByName=smart search by name/path/URL, readDoc=read specified documentation Markdown, searchDocs=full-text search official documentation. Allowed values: "listModules", "listModuleDocs", "findByName", "readDoc", "searchDocs"
moduleNamestringSpecify when mode=docs and action=listModuleDocs. Module name.
inputstringSpecify when mode=docs and action=findByName. Supports module name, document title, hierarchy path or URL.
docPathstringSpecify when mode=docs and action=readDoc. Document relative path or full URL.
querystringSpecify when mode=docs and action=searchDocs. Full-text search keywords.
thresholdnumberSpecify when mode=vector. Similarity retrieval threshold. Default: 0.5
idstringSpecify when mode=vector. Knowledge base scope, defaults to cloudbase. cloudbase=CloudBase full knowledge, scf=CloudBase cloud functions knowledge, miniprogram=Mini Program knowledge (excluding CloudBase and cloud functions knowledge). Allowed values: "cloudbase", "scf", "miniprogram"; Default: "cloudbase"
contentstringSpecify when mode=vector. Retrieval content
optionsobjectSpecify when mode=vector. Other options
options.chunkExpandarray of numberSpecify the expansion length for returned document content, e.g., [3,3] means expand 3 before and 3 after. Default: [3,3]
limitnumberSpecify when mode=vector. Specify the value of K for returning Top K most similar results. Default: 5

queryCloudRun​

Query CloudRun service information, supports getting service list, querying service details and getting available template list. Returned service information includes service name, status, access type, configuration details, etc.

Parameters​

ParameterTypeRequiredDescription
actionstringYesQuery operation type: list=get CloudRun service list (supports pagination and filtering), detail=query detailed information of specified service (including configuration, version, access address, etc.), templates=get available project template list (for initializing new projects). Allowed values: "list", "detail", "templates", "getDeployLog", "getProcessLog", "getDeployRecords", "envStatus"
pageSizenumberPage size, controls number of services returned per page. Range: 1-100, default: 10. Adjust based on network performance and display requirements. Default: 10
pageNumnumberPage number, for paginated queries. Starts from 1, default: 1. Use with pageSize for paginated browsing. Default: 1
serverNamestringService name filter condition, supports fuzzy matching. E.g., entering "test" matches "test-service", "my-test-app", etc. Leave empty to query all services
serverTypestringService type filter condition: function=function-type CloudRun (Node.js only, has special development requirements and limitations, suitable for simple API services), container=container-type service (recommended, supports any language and framework like Java/Go/Python/PHP/.NET, suitable for most application scenarios). Allowed values: "function", "container"
detailServerNamestringService name to query detailed information for. Required when action is detail, must be an existing service name. Available service names can be obtained via list operation

manageCloudRun​

Manage CloudRun services, supports in development order: initialize project (can start from template, template list can be queried through queryCloudRun), download service code, run locally (function mode services only), deploy code, delete service. Deployment can configure CPU, memory, instance count, access type and other parameters. Delete operation requires confirmation, it is recommended to set force=true.

Parameters​

ParameterTypeRequiredDescription
actionstringYesCloudRun service management operation type: init=initialize new CloudRun project code from template (creates subdirectory named serverName under targetPath, supports multiple language and framework templates), download=download existing service code from cloud to local for development, run=run function-type CloudRun service locally (for development and debugging, only supports function-type services), deploy=deploy local code to cloud CloudRun service (supports both function-type and container-type), delete=delete specified CloudRun service (irreversible, requires confirmation), createAgent=create function-type Agent (develop AI agents based on function-type CloudRun). Allowed values: "init", "download", "run", "deploy", "delete", "createAgent"
serverNamestringYesCloudRun service name, used to identify and manage services. Naming rules: supports uppercase/lowercase letters, numbers, hyphens and underscores, must start with letter, length 3-45 characters. In init operation used as subdirectory name created under targetPath, in other operations as target service name
targetPathstringLocal code path, must be absolute path. In deploy operation specifies code directory to deploy, in download operation specifies download target directory, in init operation specifies CloudRun service parent directory (will create subdirectory named serverName under this directory). Recommended convention: cloudrun/ directory under project root, e.g., /Users/username/projects/my-project/cloudrun
serverConfigobjectService configuration items, used to set service runtime parameters during deployment. Includes resource specs, access permissions, environment variables and other configuration. Uses default configuration if not provided
serverConfig.OpenAccessTypesarray of stringPublic network access type configuration, controls service access permissions: OA=office network access, PUBLIC=public network access (default, accessible via HTTPS domain), MINIAPP=mini program access, VPC=VPC access (only accessible within same VPC). Can configure multiple types
serverConfig.CpunumberCPU spec configuration, unit is cores. Options: 0.25, 0.5, 1, 2, 4, 8, etc. Note: Memory spec must be 2x CPU spec (e.g., CPU=0.25 then memory=0.5, CPU=1 then memory=2). Affects service performance and billing
serverConfig.MemnumberMemory spec configuration, unit is GB. Options: 0.5, 1, 2, 4, 8, 16, etc. Note: Must be 2x CPU spec. Affects service performance and billing
serverConfig.MinNumnumberMinimum instance count configuration, controls minimum number of running service instances. Setting to 0 enables scale-to-zero (no cost when no requests), setting > 0 always keeps specified number of instances running (ensures fast response but increases cost). Recommended to set to 1 to reduce cold start latency and improve user experience
serverConfig.MaxNumnumberMaximum instance count configuration, controls maximum number of running service instances. When request volume increases, service can scale up to specified number of instances, beyond which new requests will be rejected. Recommended to set based on business peak
serverConfig.PolicyDetailsarray of objectScaling configuration array, used to configure service auto-scaling policies. Can configure multiple scaling policies
serverConfig.PolicyDetails[].PolicyTypestringYesScaling type: cpu=CPU utilization-based scaling, mem=memory utilization-based scaling, cpu/mem=CPU and memory utilization-based scaling. Allowed values: "cpu", "mem", "cpu/mem"
serverConfig.PolicyDetails[].PolicyThresholdnumberYesScaling threshold, unit is percentage. E.g., 60 means trigger scaling when resource utilization reaches 60%
serverConfig.CustomLogsstringCustom log configuration, used to configure service log collection and storage policies
serverConfig.PortnumberService listening port configuration. Function-type services fixed at 3000, container-type services can be customized. Service code must listen on this port to receive requests normally
serverConfig.EnvParamsstringEnvironment variable configuration, JSON string format. Used to pass configuration information to service code, e.g., '{"DATABASE_URL":"mysql://...","NODE_ENV":"production"}'. Sensitive information is recommended to use environment variables rather than hardcoding
serverConfig.DockerfilestringDockerfile filename configuration, only required for container-type services. Specifies the Dockerfile file path for building container images, defaults to Dockerfile in project root
serverConfig.BuildDirstringBuild directory configuration, specifies the directory path for code building. Used when code structure differs from standard, defaults to project root
serverConfig.InternalAccessstringInternal network access switch configuration, controls whether to enable internal network access. true=enable internal network access (can be called directly via CloudBase SDK), false=disable internal network access (public network access only)
serverConfig.InternalDomainstringInternal network domain configuration, used to configure service internal network access domain. Only effective when internal network access is enabled
serverConfig.EntryPointarray of stringDockerfile EntryPoint parameter configuration, only required for container-type services. Specifies entry program array when container starts, e.g., ["node","app.js"]
serverConfig.Cmdarray of stringDockerfile Cmd parameter configuration, only required for container-type services. Specifies default command array when container starts, e.g., ["npm","start"]
templatestringProject template identifier, used to specify template for project initialization. Available template list can be obtained via queryCloudRun templates operation. Common templates: helloworld=Hello World example, nodejs=Node.js project template, python=Python project template, etc. Default: "helloworld"
runOptionsobjectLocal run parameter configuration, only supports function-type CloudRun services. Used to configure local development environment run parameters, does not affect cloud deployment
runOptions.portnumberLocal run port configuration, only effective for function-type services. Specifies the port number for service to listen on locally, default 3000. Ensure port is not occupied by other programs. Default: 3000
runOptions.envParamsobjectAdditional environment variable configuration for local run, used for local development and debugging. Format is key-value pairs, e.g., {"DEBUG":"true","LOG_LEVEL":"debug"}. These variables only take effect when running locally
runOptions.runModestringRun mode: normal=normal function mode, agent=Agent mode (for AI agent development). Allowed values: "normal", "agent"; Default: "normal"
runOptions.agentIdstringAgent ID, used in agent mode to identify specific Agent instance
agentConfigobjectAgent configuration items, only used in createAgent operation
agentConfig.agentNamestringYesAgent name, used to generate BotId
agentConfig.botTagstringBot tag, used to generate BotId, auto-generated if not provided
agentConfig.descriptionstringAgent description information
agentConfig.templatestringAgent template type, defaults to blank (blank template). Default: "blank"
forcebooleanForce operation switch, used to skip confirmation prompts. Defaults to false (requires confirmation), set to true to skip all confirmation steps. Strongly recommended to set to true for delete operations to avoid accidental operations. Default: false
serverTypestringService type configuration: function=function-type CloudRun (Node.js only, has special development requirements and limitations, suitable for simple API services), container=container-type service (recommended, supports any language and framework like Java/Go/Python/PHP/.NET, suitable for most application scenarios). Auto-detected if not provided: 1) existing service type 2) has Dockerfile→container 3) has @cloudbase/aiagent-framework dependency→function 4) otherwise→container. Allowed values: "function", "container"

deployBuild​

Parses cloudbaserc and runs a local build for projects that declare buildCommand in hosting[] (it only executes buildCommand — it does not install dependencies and does not upload). Equivalent to the CLI's tcb app build, but it only handles hosting[] static hosting entries and is unrelated to the cloudbaserc app resource type (cloud build pipeline). Declarative hosting deployment is split into three steps — build → plan → apply — and this tool is the first step: build artifacts locally, then dry-run with deployPlan, and finally upload the artifacts with deployApply. deployApply no longer builds locally implicitly — hosting entries with a build command error out when artifacts are missing and point you here first. Pure static hosting (no buildCommand configured and no detectable framework) is skipped automatically. The build is a purely local operation: it does not resolve an environment, does not require login, and does not need confirm.

  • cwd: Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
  • mode: Environment name; merges the corresponding override config when it matches envOverrides.<mode>

Parameters​

ParameterTypeRequiredDescription
cwdstringProject root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
modestringEnvironment name (e.g. production/staging); merges overrides when it matches envOverrides.<mode>

deployPlan​

Parses cloudbaserc and computes a declarative deployment plan (dry-run — it produces no changes). This is the dry-run counterpart to deployApply: plan computes and deployApply executes the same cloudbaserc. It returns the action classification for each resource: create=new, update=overwrite update, skip=no change / will not run, conflict=conflict detected and must abort, deploy=direct upload overwrite. The plan has already been recomputed with yes into "the actions that will actually happen": when yes=true is not passed, functions that already exist in the cloud are marked skip (keeping update in declaredStatus), which matches what deployApply actually executes, so the dry-run never contradicts the real run. Applicability boundary: this tool is for project-level declarative orchestration (one cloudbaserc for plan/apply); for one-off single-resource direct uploads use manageFunctions/manageHosting/manageApps.

  • cwd: Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
  • mode: Environment name; merges the corresponding override config when it matches envOverrides.<mode>
  • envId: Target environment ID; takes precedence over the envId in cloudbaserc. When omitted, the configured value or the currently bound environment is used
  • only: Compute the plan only for the specified resource types
  • skip: Skip the specified resource types
  • yes: Aligned with deployApply's yes, used to recompute the effective action for functions that already exist. true=dry-run as overwrite update; false (default)=dry-run as conservative skip

Parameters​

ParameterTypeRequiredDescription
cwdstringProject root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
modestringEnvironment name (e.g. production/staging); merges overrides when it matches envOverrides.<mode>
envIdstringTarget environment ID; takes precedence over the envId in cloudbaserc. When omitted, the configured value or the currently bound environment is used
onlyarray of stringCompute the plan only for the specified resource types. Available values: database/functions/app/hosting/gateway
skiparray of stringSkip the specified resource types. Available values: database/functions/app/hosting/gateway
yesbooleanAligned with deployApply's yes, used to recompute the effective action for functions that already exist. true=dry-run as overwrite update; false (default)=dry-run as conservative skip

deployApply​

Parses cloudbaserc and executes a declarative deployment in the order database→functions→app→hosting→gateway. This is the execution counterpart to deployPlan (plan dry-runs / deployApply executes the same cloudbaserc). It is a local-form apply (reads the local cloudbaserc, builds and uploads locally) and is a write operation that changes cloud resources, so it only runs when confirm=true is passed explicitly. Prefer running deployPlan first, then executing once the plan checks out. Applicability boundary: this tool is for project-level declarative orchestration (one cloudbaserc for plan/apply); for one-off single-resource direct uploads use manageFunctions/manageHosting/manageApps.

  • confirm: Must be explicitly passed as true for the deployment to run, otherwise it is rejected outright
  • confirmDestructive: When the database migrations in this run contain destructive statements (DROP/TRUNCATE/DELETE, ALTER…DROP/RENAME), confirmDestructive=true must additionally be passed explicitly on top of confirm; otherwise it is rejected and the matching migrations and statements are listed. Has no effect when there are no destructive migrations
  • cwd: Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
  • mode: Environment name; merges the corresponding override config when it matches envOverrides.<mode>
  • envId: Target environment ID; takes precedence over the envId in cloudbaserc. When omitted, the configured value or the currently bound environment is used
  • only: Deploy only the specified resource types
  • skip: Skip the specified resource types
  • yes: How to handle resources that already exist. true=overwrite and update directly; false (default)=conservatively skip, so existing resources are not overwritten in scenarios where interactive confirmation is impossible (consistent with deployPlan's yes semantics)
  • concurrency: Maximum parallelism within a resource type, default 1 (serial)
  • continueOnError: Continue deploying the remaining resources after one fails (a database failure still aborts forcibly)

Parameters​

ParameterTypeRequiredDescription
confirmbooleanDestructive-operation confirmation switch. Deployment changes cloud resources, so confirm=true must be passed explicitly for it to run
confirmDestructivebooleanDestructive database change confirmation switch. When the pending migrations contain DROP/TRUNCATE/DELETE or ALTER…DROP/RENAME, confirmDestructive=true must additionally be passed explicitly on top of confirm=true; no effect when there are no destructive migrations
cwdstringProject root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
modestringEnvironment name (e.g. production/staging); merges overrides when it matches envOverrides.<mode>
envIdstringTarget environment ID; takes precedence over the envId in cloudbaserc. When omitted, the configured value or the currently bound environment is used
onlyarray of stringDeploy only the specified resource types. Available values: database/functions/app/hosting/gateway
skiparray of stringSkip the specified resource types. Available values: database/functions/app/hosting/gateway
yesbooleanWhether to overwrite and update resources that already exist. true=overwrite; false (default)=conservatively skip existing resources
concurrencyintegerMaximum parallelism within a resource type, default 1 (serial); only applies within a type, cross-type dependency order is unchanged
continueOnErrorbooleanWhether to continue deploying the remaining resources after one fails; a database failure always aborts forcibly

queryGateway​

Unified read-only entry for the gateway domain. Query gateway domains, access entries, and target exposure status via action.

Parameters​

ParameterTypeRequiredDescription
actionstringYesRead-only operation type, e.g., getAccess, listDomains. Allowed values: "getAccess", "listDomains", "listRoutes", "getRoute", "listCustomDomains"
targetTypestringTarget resource type. Currently supports function, extensible in future. Allowed values: "function"
targetNamestringTarget resource name. Required for getAccess
routeIdstringRoute ID. Optional for getRoute

manageGateway​

Unified write entry for the gateway domain. Create target access entries via action, with more general gateway configuration capabilities to follow.

Parameters​

ParameterTypeRequiredDescription
actionstringYesWrite operation type, e.g., createAccess. Allowed values: "createAccess", "createRoute", "updateRoute", "deleteRoute", "bindCustomDomain", "deleteCustomDomain", "deleteAccess", "updatePathAuth"
targetTypestringTarget resource type. Currently supports function, extensible in future. Allowed values: "function"
targetNamestringTarget resource name
pathstringAccess path, defaults to /{targetName}
typestringTarget function's own type (not access form). If the accessed function is Event type (default), pass Event here; only pass HTTP when the accessed function was created as HTTP function. Allowed values: "Event", "HTTP"
authbooleanWhether to enable authentication
routeobjectHTTP route configuration object
route.routeIdstring
route.pathstring
route.serviceTypestring
route.serviceNamestring
route.authboolean
domainstringCustom domain
certificateIdstringCertificate ID
accessNamestringAccess entry name, reserved field

queryAppAuth​

Read-only entry for application-side authentication configuration. Used to query login methods, providers, publishable key, API key, client configuration, and static domain authentication readiness status. If the business needs to accept plain username-style identifiers, first query action=getLoginConfig; if usernamePassword=false, the next step should immediately call manageAppAuth(action=patchLoginStrategy, patch={ usernamePassword: true }), do not directly write email login API.

Parameters​

ParameterTypeRequiredDescription
actionstringYesAllowed values: "getLoginConfig", "listProviders", "getProvider", "getClientConfig", "getPublishableKey", "getStaticDomain", "listApiKeys"
providerIdstringProvider identifier, e.g., email, google
clientIdstringOAuth client_id / DescribeClient Id; uses current environment ID (default client) when omitted
keyTypestringAPI key type filter, optional publish_key or api_key. Allowed values: "publish_key", "api_key"
pageNumberintegerAPI key list page number, starts from 1
pageSizeintegerAPI key list items per page

manageAppAuth​

Write entry for application-side authentication configuration. Used to modify login methods, providers, client configuration, ensure publishable key, and create or delete API keys and custom login keys. If the frontend needs to accept plain username-style identifiers, first execute action=patchLoginStrategy with patch={ usernamePassword: true }, then implement the corresponding frontend login logic.

Parameters​

ParameterTypeRequiredDescription
actionstringYesAllowed values: "patchLoginStrategy", "addProvider", "updateProvider", "deleteProvider", "updateClientConfig", "ensurePublishableKey", "createApiKey", "deleteApiKey", "createCustomLoginKeys"
patchobjectSimplified login strategy patch used by patchLoginStrategy, e.g., { usernamePassword: true }
providerIdstringProvider identifier, e.g., email, google; for addProvider can also be used as custom provider Id
providerTypestringProvider protocol type for addProvider, e.g., OAUTH, OIDC, EMAIL
displayNamestring | objectDisplay name for addProvider, can pass string or multilingual object
clientIdstringClient Id for updateClientConfig; uses current environment ID when omitted
configobjectProvider / client configuration object
keyTypestringAPI key type for createApiKey, defaults to publish_key. Allowed values: "publish_key", "api_key"
keyNamestringAPI key name for createApiKey
expireInintegerValidity period for createApiKey, unit is seconds; 0 means no expiration
keyIdstringAPI key unique identifier for deleteApiKey

queryApps​

Query CloudBase apps and versions deployed via the app deploy feature. Can query the app list/details, version list/details; after deployment, poll build status with getAppVersion by buildId; getBuildLog queries build logs to diagnose failures.

Parameters​

ParameterTypeRequiredDescription
actionstringyesAllowed values: "listApps", "getApp", "listAppVersions", "getAppVersion", "getBuildLog", "getUploadUrl"
serviceNamestringCloudBase app service name. Required for getApp / listAppVersions / getAppVersion / getBuildLog; reuse the same serviceName after redeployment to query version history
searchKeystringFuzzy search keyword by app service name, only used when action=listApps
pageNonumberPagination page number, starting from 1
pageSizenumberPagination size
versionNamestringVersion name. For getAppVersion, can be used alternatively with buildId; prefer passing it when the version number is known
buildIdstringBuild ID. For getAppVersion, can be used alternatively with versionName; after deploy returns a BuildId you can poll status with it directly. Required for getBuildLog
startnumberBuild log offset for paginating subsequent logs. Only used when action=getBuildLog; when omitted, returns from the beginning

manageApps​

Deploy web apps to CloudBase (build frontend and backend, deploy to an independent subdomain). action=getUploadUrl gets a presigned upload URL (used in cloud mode), returns the upload address and cosTimestamp. action=deployApp uploads a source ZIP and triggers the remote build/deploy pipeline:

  1. Remote npm install (can be skipped with installCmd="")
  2. Remote npm run build (can be skipped with buildCmd="")
  3. Remote tcb hosting deploy

Domain format: &lt;serviceName&gt;-&lt;envId&gt;.webapps.tcloudbase.com (each serviceName gets an independent subdomain)

✅ Recommended usage (new projects / web apps that need an independent domain, prefer this tool): On first deployment of a new project, pass framework=static, installCmd="", buildCmd="" to skip remote build, and only run tcb hosting deploy. After deployment you get an independent subdomain with version management.

⚠️ Compatibility notes:

  • If an existing project was previously deployed with manageHosting (domain format: &lt;envId&gt;-&lt;appId&gt;.tcloudbaseapp.com), switching to manageApps produces a brand new URL and old links break. Keep the original deployment method unchanged.
  • To check: call queryHosting to see if hosted files already exist.

Comparison with manageHosting:

  • manageApps (this tool, preferred for new projects): domain &lt;serviceName&gt;-&lt;envId&gt;.webapps.tcloudbase.com, independent subdomain, version management
  • manageHosting (existing projects or fallback): domain &lt;envId&gt;-&lt;appId&gt;.tcloudbaseapp.com/&lt;path&gt;, shared environment domain Both can bind custom domains.

⚠️ If manageApps build fails, first check logs with queryApps(action="getBuildLog"); if still failing, fall back to manageHosting.

Parameters​

ParameterTypeRequiredDescription
actionstringyesAllowed values: "deployApp", "getUploadUrl", "deleteApp", "deleteAppVersion"
serviceNamestringyesCloudBase app service name, reflected in the domain: &lt;serviceName&gt;-&lt;envId&gt;.webapps.tcloudbase.com. For deployApp, reusing an existing serviceName adds a new deployment version and triggers redeployment rather than delete-and-recreate. Use a new name for first deployment
filePathstringAbsolute path to the local project root to upload and deploy. Required for deployApp in local mode; usually the source directory (containing package.json and source), not the dist directory. Specify the build output directory with buildPath. Not needed in cloud mode; use cosTimestamp instead
cosTimestampstringOptional COS timestamp. Passing this value creates the app directly from already-uploaded code, skipping local file upload. First call getUploadUrl to get a presigned URL, upload the ZIP, then pass this timestamp. Required in cloud mode; local mode can also pass it instead of filePath. Use one of the two: filePath (local packaging upload) or cosTimestamp (presigned URL upload)
appPathstringApp online access path (hosting mount path), e.g. /my-web-app. Not a local directory path; CloudApp already has an independent subdomain, defaults to / (root) when omitted
buildPathstringBuild output directory, relative to filePath, e.g. dist or build. ⚠️ When passed, the remote build system cds into this directory before running tcb hosting deploy, so deployCmd automatically uses . (current directory) instead of the directory name to avoid path duplication (e.g. dist/dist). Can be omitted for pure static HTML at the project root, but note deployCmd defaults to dist
frameworkstringFrontend framework type. Options: vue, react, next, nuxt, vite, angular, static. Even when passing static, it still goes through the remote build pipeline. If already built locally, consider manageHosting to upload directly and skip remote build entirely. Allowed values: "vue", "react", "next", "nuxt", "vite", "angular", "static"
nodeJsVersionstringNode.js version used for the build; CloudBase uses its default when omitted
installCmdstringDependency install command, e.g. npm install. Defaults to npm install. If already installed locally or no install needed, pass an empty string '' to skip, but the remote still runs tcb hosting deploy
buildCmdstringBuild command, e.g. npm run build. Defaults to npm run build. If already built locally, pass an empty string '' to skip the build step. To skip the remote pipeline entirely, use manageHosting
deployCmdstringCustom deploy command. Usually not needed; a tcb hosting deploy command is generated by default. With buildPath the remote already cds into that directory and uses . as the source path; without buildPath it defaults to dist
ignorearray of stringFile/directory glob patterns to ignore when uploading, e.g. /node_modules/
versionNamestringHistorical version name to delete, required only when action=deleteAppVersion

queryPermissions​

Unified read-only entry for the permissions domain. Supports querying resource permissions, role list/details, and application user list/details.

Parameters​

ParameterTypeRequiredDescription
actionstringYesAllowed values: "getResourcePermission", "listResourcePermissions", "listRoles", "getRole", "listUsers", "getUser"
resourceTypestringAllowed values: "noSqlDatabase", "sqlDatabase", "function", "storage"
resourceIdstring
resourceIdsarray of string
roleIdstring
roleIdentitystring
roleNamestring
uidstring
usernamestring
pageNonumber
pageSizenumber

managePermissions​

Unified write entry for the permissions domain. Supports modifying resource permissions, role management, member and policy add/remove, and application user CRUD. createUser / updateUser are environment-side application user management capabilities, suitable for test accounts, administrators, or preset users, and should not replace browser-side Web SDK registration forms; frontend username password registration should use auth.signUp(&#123; username, password &#125;), login should use auth.signInWithPassword(&#123; username, password &#125;). Note: The detailed semantics of securityRule depend on resourceType; doc._openid, auth.openid, query condition subset validation, and create / update / delete JSON templates only apply to resourceType="noSqlDatabase" document database security rules. When configuring function or storage, please refer to their respective official security rule documentation, not reuse NoSQL templates.

Parameters​

ParameterTypeRequiredDescription
actionstringYesAllowed values: "updateResourcePermission", "createRole", "updateRole", "deleteRoles", "addRoleMembers", "removeRoleMembers", "addRolePolicies", "removeRolePolicies", "createUser", "updateUser", "deleteUsers", "setPolicy"
resourceTypestringTarget resource type. The specific semantics of securityRule depend on this value; noSqlDatabase uses collection security rules, function and storage also have their own independent security rule semantics, do not apply NoSQL rule syntax. Allowed values: "noSqlDatabase", "sqlDatabase", "function", "storage"
resourceIdstring
permissionstringAllowed values: "READONLY", "PRIVATE", "ADMINWRITE", "ADMINONLY", "CUSTOM"
securityRulestringResource type-specific rule content, detailed semantics depend on resourceType. When resourceType="noSqlDatabase" and permission="CUSTOM", should pass document database security rule JSON (document database rules: https://docs.cloudbase.net/database/security-rules); keys are typically read / create / update / delete, values are expressions. Important: create rule validates written data, document doesn't exist yet at this point, cannot use doc.*; read / update / delete rules can use doc.* to reference existing document fields. Do not misuse doc._openid, auth.openid, query condition subset validation or create / update / delete templates for function, storage or sqlDatabase. For configuring function or storage, please refer to official security rule documentation: cloud functions https://docs.cloudbase.net/cloud-function/security-rules, cloud storage https://docs.cloudbase.net/storage/security-rules. Example: &#123;"read":"auth.uid != null","create":"auth.uid != null && auth.loginType != \"ANONYMOUS\"","update":"auth.uid != null && doc._openid == auth.openid","delete":"auth.uid != null && doc._openid == auth.openid"&#125;
roleIdstring
roleIdsarray of string
roleNamestring
roleIdentitystring
descriptionstring
memberUidsarray of string
policiesarray of object
uidstring
uidsarray of string
usernamestring
passwordstring
userStatusstringAllowed values: "ACTIVE", "BLOCKED"

queryLogs​

Unified read-only entry for the logs domain. Supports checking log service status and searching CLS logs.

Parameters​

ParameterTypeRequiredDescription
actionstringYesAllowed values: "checkLogService", "searchLogs"
queryStringstring
servicestringAllowed values: "tcb", "tcbr"
startTimestring
endTimestring
limitnumber
contextstring
sortstringAllowed values: "asc", "desc"

queryAgents​

Unified read-only entry for the Agent domain. Supports listing, details, and log queries.

Parameters​

ParameterTypeRequiredDescription
actionstringYesAllowed values: "listAgents", "getAgent", "getAgentLogs"
agentIdstring
pageNumbernumber
pageSizenumber
paramsobject

manageAgents​

Unified write entry for the Agent domain. Supports creating, updating, and deleting remote Agents.

Parameters​

ParameterTypeRequiredDescription
actionstringYesAllowed values: "createAgent", "updateAgent", "deleteAgent"
agentIdstring
paramsobject

callCloudApi​

General cloud API calling tool, mainly used for CloudBase / Tencent Cloud management plane and dependent resource related API calls. Read the interface index before calling: https://docs.cloudbase.net/ai/cloudbase-ai-toolkit/api-reference.md (an Action-level index synced daily, including rate limits; check this index first to confirm service/Action/parameters so you never guess an Action name; for products the index does not cover, verify against that product's official API docs). If your goal is to directly integrate auth/functions/cloudrun/storage/mysqldb and other CloudBase business APIs via HTTP protocol, do not prioritize using callCloudApi, instead prioritize checking the corresponding OpenAPI / Swagger. The existing OpenAPI / Swagger capabilities are not a general management plane Action collection; for management plane APIs, please prioritize referring to CloudBase API Overview https://cloud.tencent.com/document/product/876/34809 and CloudBase Dependent Resource API Guide https://cloud.tencent.com/document/product/876/34808. For tcb service, common Action categories are as follows:

Environment Management: CreateEnv, ModifyEnv, DescribeEnvs, DestroyEnv User Management: CreateUser, ModifyUser, DescribeUserList, DeleteUsers Authentication Configuration: EditAuthConfig, DescribeAuthDomains Cloud Functions: DescribeFunctions, CreateFunction, UpdateFunctionCode, DeleteFunction Database: CreateMySQLInstance, DescribeMySQLInstances, DestroyMySQLInstance

When destroying an environment, the common practice is to at least include EnvId and BypassCheck: true; if the environment is already in isolation period, add IsForce: true per documentation.

Parameters​

ParameterTypeRequiredDescription
servicestringYesTencent Cloud product identifier. Values may only come from this field's enum whitelist (57 in total), which determines the request domain https://<service>.tencentcloudapi.com. Values outside the list are rejected — do not invent them; COS is not part of the cloud API system. See the cloud-api-operations skill for the product-to-Action mapping. CloudRun always goes through tcbr. Allowed values: "tcb", "tcbr", "scf", "sts", "cam", "cloudaudit", "tag", "billing", "region", "cvm", "lighthouse", "tke", "cbs", "cfs", "tcr", "cdb", "mariadb", "postgres", "sqlserver", "redis", "mongodb", "cynosdb", "dcdb", "tcaplusdb", "keewidb", "vpc", "clb", "cdn", "ecdn", "dnspod", "privatedns", "domain", "ssl", "teo", "gaap", "kms", "ssm", "waf", "cwp", "tcss", "ckafka", "tdmq", "tdmysql", "apigateway", "monitor", "cls", "apm", "tsf", "tat", "hunyuan", "lkeap", "tts", "trtc", "live", "vod", "sms", "ses"
actionstringYesSpecific Action name, must conform to the corresponding service's official API definition. When unsure, check the official documentation first — do not guess from synonyms or historical names (a wrong guess surfaces as an invalid-action server error that is hard to diagnose). See the cloud-api-operations skill for common Actions.
paramsobjectParameter object corresponding to the Action; key names match the official API definition — check the docs first when unsure. Do not put Region here; use the top-level region for cross-region calls. For CloudBase business APIs prefer searchKnowledgeBase(mode="openapi") rather than this tool. Examples are in the cloud-api-operations skill.
versionstringAPI version (omittable in most cases). Products with only one official version in the whitelist are auto-filled and need not pass it; the following multi-version products must pass it explicitly, otherwise an error listing the available options is returned: tke, mongodb, teo, monitor, vod, sms. Example: service="tcbr", version="2022-02-17", action="CreateCloudRunEnv", params={EnvId:"env-xxx",PackageType:"Standard"}; service="monitor" must explicitly pass "2018-07-24" (the alarm-policy Action family belongs to that version).
regionstringCloud API region (X-TC-Region), e.g. ap-shanghai. Cross-region calls must pass this top-level parameter — do not write it into params. ⚠️ ap-singapore belongs to both the China site and the international site; when no site is specified it is treated as the international site (site=intl): to operate on that region on the China site, call auth(action="start_auth", site="domestic") or set TCB_SITE=domestic first.

queryMessagePush​

Query Mini Program cloud development message push configuration (qbase getappconfig) or all valid message push event constraints (getcallbacksupportlist). There are two push modes: cloud function (default, callback per (msgType, event)) and CloudRun (qbase_open=true, receives all messages in bulk to container path). action=list also returns pushMode (cloudfunction|container), containerConfig, callbacks, and version; in CloudRun mode, callbacks may still exist but are not effective (see note), use ensureCloudFunctionMode to switch back to cloud function mode before callbacks take effect. action=listSupportedEvents returns all valid constraints (grouped by message type). Requires WeChat IDE login session channel (host-injected cloudBaseOptions.requestFn).

Parameters​

ParameterTypeRequiredDescription
appidstringYesMini Program AppID (required, consistent with WeChat Developer Tools; used to select WeChat login session)
envstringOptional: Environment ID; when passed, list only returns subscription entries for that environment
actionstringYeslist: Query current message push configuration list (includes pushMode/containerConfig). listSupportedEvents: Query all valid message push event constraints (grouped by msgType). Allowed values: "list", "listSupportedEvents"

manageMessagePush​

Manage Mini Program cloud development message push configuration (write operations, requires confirm="yes" confirmation). Push modes: cloud function (default, callback per (msgType, event)) vs CloudRun (bulk reception; in CloudRun mode subscribe/unsubscribe/setEnable will be rejected, use ensureCloudFunctionMode first). Implements declarative idempotency based on "read full → merge → full overwrite (with version optimistic lock)". msg_type defaults to "event"; message types use msg_type=text|image|voice|video|miniprogrampage. action=subscribe validates that function_name actually exists in the environment before proceeding. action=ensureCloudFunctionMode disables CloudRun bulk reception; action=ensureContainerMode enables CloudRun (requires qbase_container_path/qbase_env/text_mode); action=setContainerCallback updates CloudRun path/env/text_mode. No write request is sent when the collection has no changes (idempotent no-op). Requires WeChat IDE login session channel.

Parameters​

ParameterTypeRequiredDescription
appidstringYesMini Program AppID (required, consistent with WeChat Developer Tools; used to select WeChat login session)
env_idstringYesEnvironment ID (cloud development environment bound to cloud function subscriptions; also serves as default CloudRun environment when qbase_env is not passed for ensureContainerMode/setContainerCallback)
function_namestringYesCloud function name to receive message push (used by subscribe/unsubscribe/setEnable/ensureCloudFunctionMode; CloudRun-related actions can pass a placeholder)
actionstringYessubscribe: Subscribe to specified cloud function (rejected in CloudRun mode). unsubscribe: Remove matching subscription (rejected in CloudRun mode). setEnable: Enable/disable matching subscription (rejected in CloudRun mode). ensureCloudFunctionMode: Switch to cloud function push mode (disable qbase_open). ensureContainerMode: Switch to CloudRun bulk reception (requires qbase_container_path + text_mode). setContainerCallback: Update CloudRun callback path/env/text_mode. Allowed values: "subscribe", "unsubscribe", "setEnable", "ensureCloudFunctionMode", "ensureContainerMode", "setContainerCallback"
msg_typestringMessage type (defaults to "event"). "event": Event-type entries, used with event_types (subscribe defaults to virtual payment 7 events when omitted). "text"|"image"|"voice"|"video"|"miniprogrampage": Message type entries (event is always empty string), do not pass event_types. Allowed values: "event", "text", "image", "voice", "video", "miniprogrampage"
event_typesarray of stringEvent list to operate on (only used when msg_type="event"; can first query all constraints via queryMessagePush(action=listSupportedEvents)). subscribe defaults to subscribing to virtual payment 7 events when omitted; required for unsubscribe / setEnable when msg_type=event.
enablebooleanRequired for setEnable: true to enable subscription / false to disable subscription
qbase_container_pathstringCloudRun callback path/URL (required for ensureContainerMode; optional update for setContainerCallback)
qbase_envstringCloudRun service environment ID (optional for ensureContainerMode/setContainerCallback; defaults to env_id when omitted)
text_modenumberCloudRun message body encoding: 1=json, 2=xml (required for ensureContainerMode; optional update for setContainerCallback). Allowed values: 1, 2
confirmstringWrite operation confirmation: pass confirm="yes" to confirm execution; returns a pending configuration summary (CONFIRM_REQUIRED) when omitted or other value is passed, review and retry. No confirmation needed when the collection has no changes.