MCP Tools
Currently includes 43 tools, grouped by function as follows.
Source data: tools.json
Tool Overview
Authentication & Login
Others
Environment Management
NoSQL Database
readNoSqlDatabaseStructurewriteNoSqlDatabaseStructurereadNoSqlDatabaseContentwriteNoSqlDatabaseContent
Data Models
PostgreSQL Database
PostgreSQL Cloud Storage
MySQL Database
Cloud Functions
Static Hosting
Cloud Storage
Templates & Files
Search & Knowledge Base
CloudRun
Gateway
App Authentication
Permissions
Logs
AI Agent
Cloud API
Message Push
Hosted MCP Configuration
Environment Variable Configuration
Using hosted MCP requires configuring the following environment variables:
| Environment Variable | Description | How to Obtain |
|---|---|---|
TENCENTCLOUD_SECRETID | Tencent Cloud SecretId | Get Tencent Cloud API Key |
TENCENTCLOUD_SECRETKEY | Tencent Cloud SecretKey | Get Tencent Cloud API Key |
TENCENTCLOUD_SESSIONTOKEN | Optional, Tencent Cloud temporary key Token | Only needed when using temporary keys, can be obtained via STS Service |
CLOUDBASE_ENV_ID | CloudBase Environment ID | Get CloudBase Environment ID |
Detailed Specs
auth
CloudBase (Tencent Cloud Development) development stage login and environment binding. After logging in, you can access cloud resources; an environment (env) is an isolation unit for cloud functions, databases, static hosting and other resources. After binding the environment, other MCP tools can operate on that environment. Supports: query status, initiate login, API Key login, bind environment (set_env), logout. auth(status) returns credential_scope (account=account-level / single_env=environment-level API Key) and the current region; environment-level API Keys can only see the bound envId, not being able to query other regions' environments is a permission boundary, not that the environment doesn't exist. Optional site/region/lang parameters: site=site (domestic/intl), region=region, lang=output language (zh/en).
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Action: status=query status, start_auth=initiate login, login_by_api_key=API Key login, set_env=bind environment (pass envId), logout=logout. Allowed values: "status", "start_auth", "set_env", "logout", "get_temp_credentials", "login_by_api_key" | |
authMode | string | Authentication mode: device=device code authorization, web=browser callback authorization. Allowed values: "device", "web" | |
oauthEndpoint | string | Advanced optional: Custom device-code login endpoint. When configured, oauthCustom defaults to true | |
clientId | string | Advanced optional: Custom device-code login client_id, uses default value if not provided | |
oauthCustom | boolean | Advanced optional: Custom endpoint return format switch. Defaults to false when endpoint not configured; defaults to true when endpoint is configured. Endpoints using the standard {code,result} wrapper format (e.g. the international site tcb-api.tencentcloud.com) should explicitly pass false | |
site | string | Site: domestic=China site, intl=international site. When the environment is provisioned on the Tencent Cloud international site, login (start_auth/login_by_api_key) must explicitly pass intl, otherwise the China-site flow is used and international-site environments are invisible. An explicitly passed value takes precedence over the TCB_SITE environment variable / the region mapping table / project config, and affects the login endpoint, the authorization page and the API Key exchange gateway. Allowed values: "domestic", "intl" | |
envId | string | Environment ID (CloudBase environment unique identifier), after binding the tool will operate on this environment. Required when action=set_env | |
region | string | Region (e.g. ap-shanghai / ap-guangzhou / ap-singapore). Used for region→site inference and API Key exchange gateway selection; an explicit site takes precedence | |
lang | string | Output language: zh=Chinese (default), en=English. Overrides the instance-level language (createCloudBaseMcpServer lang option / TCB_LANG / project.json). Allowed values: "zh", "en" | |
apiKey | string | CloudBase API Key, required when action=login_by_api_key | |
apiKeyEnvId | string | CloudBase environment ID (EnvId), required when action=login_by_api_key, used to specify the environment the API Key belongs to | |
confirm | string | Confirm operation when action=logout, pass yes. Allowed values: const "yes" | |
reveal | boolean | Optional when action=get_temp_credentials. true=return plaintext temporary credentials; defaults to false returning masked results only |
queryEnv
Query CloudBase environment related information, supports querying the environment list, details of a specific environment, security domains, resource usage, and monitoring metrics. (Former names: envQuery, listEnvs, getEnvInfo, getEnvAuthDomains) When action=list, it filters/lists per DescribeEnvs semantics, returning standard fields EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, and supports trimming these fields via the fields whitelist; aliasExact=true filters by exact alias match to avoid mistaking environments with similar prefixes as candidates; even when envId is passed, action=list only returns the summary, not full resource details or expiry. Account-level login can pass region (ap-shanghai/ap-guangzhou/ap-singapore) to query corresponding regions, aligned with CLI tcb env list -r <region>; environment-level credentials (API Key / hosted authorization token) can only see the bound envId, returning credential_scope=single_env; in that case region is not applied and is truthfully reported in ignored_params (AppliedFilters.region is null) — do not misjudge this as the environment not existing or region filtering being broken. To query the detailed information of a known EnvId environment (including resource fields and billing info), use action=info with the target envId. action=info supplements BillingInfo (e.g. ExpireTime, PayMode, IsAutoRenew) when available.
📊 action=usage aligns with tcb env usage/info: passes through Manager SDK describeEnvAccountCircle + describeCreditsUsageDetail, returning billing cycle and resource credit usage by module (FLEXDB/SCF/COS etc.). envId required; type optionally filters modules; when startDate/endDate are not passed, the current billing cycle is used automatically.
📈 action=metrics aligns with CloudBase DescribeCurveData (manager.monitor.describeCurveData, not Cloud Monitor GetMonitorData): queries environment/gateway QPS, cloud function invocations and errors, database CPU/memory/disk, CloudRun CPU/QPS time series. envId and metricName required; startTime/endTime format YYYY-MM-DD HH:mm:ss, must be passed as a pair, defaults to last 24 hours when omitted; period only supports 300/3600/86400. When GatewayTraceEnvQPS is called without resourceID, environment-level all|:|all|:|all|:|all is auto-filled; CloudRun Tke* metrics must pass service name as resourceID. Do not use callCloudApi to guess monitoring Actions.
🔍 action=info also derives three fields for backend selection:
EnvInfo.RuntimeMode: 'postgresql' or 'nosql', indicating the recommended default backend for new services (postgresql when PG is enabled, otherwise nosql).EnvInfo.RuntimeBackends: three booleans\{postgresql, nosql, mysql\}describing which backends currently coexist in the environment.EnvInfo.RuntimeModeHints: API/tool/skill hints for each backend.
🌐 action=info also projects gateway route Enable status without overwriting StaticStorages[].StaticDomain (cloud API nominal domain): StaticStorages[].staticDomainRouteEnabled and EnvInfo.staticDomainRouteEnabled (same source as queryHosting websiteConfig). false means the default static domain root route is disabled (access returns GATEWAY_ROUTE_DISABLED), do not treat the nominal domain as a reachable URL.
AI must check these three items before writing business/permission/storage code: In PG mode, new services should use app.rdb() + RLS (managePgDatabase action=execute to run CREATE POLICY) + pgstore; existing NoSQL collections / old storage / managePermissions(resourceType="noSqlDatabase") remain valid in PG environments. What is truly inapplicable is MySQL: when RuntimeBackends.mysql === false, manageMysqlDatabase / queryMysqlDatabase / relational-database-mcp-cloudbase skill should not be used.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Query type: list=environment list/summary filter (filters per DescribeEnvs semantics, supports filtering by envId/region, returns EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, no expiry), info=detailed info of the specified environment (envId required, returns resource fields and billing info), domains=security domain list, usage=environment resource usage (envId required, aligned with tcb env usage/info), metrics=environment monitoring time series (envId and metricName required, aligned with CloudBase DescribeCurveData). Allowed values: "list", "info", "domains", "usage", "metrics" |
alias | string | Filter by environment alias. Optional when action=list | |
aliasExact | boolean | Filter by exact environment alias. Optional when action=list; used with alias | |
envId | string | Environment ID. Optional when action=list (only filters per DescribeEnvs semantics, still returns the summary); required when action=info / action=usage / action=metrics; optional when action=domains (queries the currently bound environment when omitted, or that environment's security domains when provided). | |
region | string | Query region. Only effective when action=list. Account-level credentials pass this value through to DescribeEnvs (X-TC-Region), e.g. ap-singapore. Equivalent CLI: tcb env list -r <region> --json. Environment-level credentials (API Key / hosted authorization token) are single-environment scoped and this parameter is ignored: the result is always the bound environment, the response has AppliedFilters.region = null, query_region takes that environment's own Region, and ignored_params explains why it was ignored — do not conclude from this that the region has no environments. ⚠️ ap-singapore belongs to both the China site and the international site; when no site is explicitly specified it is treated as the international site (site=intl): if you have logged in to both sites, passing this region silently queries the international-site account, so call auth(site="domestic") or set TCB_SITE=domestic first to pin the site. Allowed values: "ap-shanghai", "ap-guangzhou", "ap-singapore" | |
limit | integer | Max number of results. Optional when action=list | |
offset | integer | Pagination offset. Optional when action=list | |
fields | array of string | Return field whitelist. Only supports EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault. Optional when action=list | |
type | array of string | Usage module filter. Only effective when action=usage; queries all modules when omitted. Available values aligned with tcb CLI: FLEXDB, TDSQL, SCF, EKS, COS, AI, HOSTING, Auth, APIInvocation, HTTPInvocation, VM, Workflow, Other. | |
startDate | string | Usage start date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with endDate. Uses current billing cycle when omitted. | |
endDate | string | Usage end date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with startDate. Uses current billing cycle when omitted. | |
needUsageDetails | boolean | Whether to return daily usage details. Only effective when action=usage; defaults to true. | |
metricName | string | Monitoring metric name. Only effective and required when action=metrics. GatewayTraceEnvQPS/EnvQPSAll=environment and gateway QPS; FunctionInvocation/FunctionError/FunctionTimeout/FunctionThrottle=cloud function invocations, errors, timeouts, throttling; DbRead/DbWrite/DbSizepkg=document database reads, writes, and capacity; MysqlCpuUsageRate/MysqlMemoryUse/MysqlStorageUsage=SQL database CPU/memory/disk; TkeCpuUsedService/TkeQPSService/TkeHttpErrorService=CloudRun CPU/QPS/errors. Allowed values: "GatewayTraceEnvQPS", "EnvQPSAll", "FunctionInvocation", "FunctionError", "FunctionTimeout", "FunctionThrottle", "FunctionDuration", "FunctionConcurrentExecutions", "DbRead", "DbWrite", "DbSizepkg", "MysqlCpuUsageRate", "MysqlMemoryUse", "MysqlStorageUsage", "MysqlQps", "MysqlSlowQueries", "MysqlDbConnections", "TkeCpuUsedService", "TkeMemUsedService", "TkeQPSService", "TkeHttpErrorService", "TkeInvokeNumService" | |
startTime | string | Monitoring start time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with endTime. Defaults to last 24 hours when omitted. End time must be at least five minutes after start time. | |
endTime | string | Monitoring end time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with startTime. Defaults to last 24 hours when omitted. | |
period | number | Statistics period (seconds). Only effective when action=metrics; only supports 300, 3600, 86400. Auto-selected by backend based on time range when omitted. Time range ≤1 day cannot use 86400; >3 days cannot use 300. Allowed values: 300, 3600, 86400 | |
resourceID | string | Resource ID. Only effective when action=metrics. Cloud functions pass function name, document database passes collection name, CloudRun must pass service name; GatewayTraceEnvQPS auto-fills environment-level all|:|all|:|all|:|all when omitted. | |
subresourceID | string | Sub-resource ID. Only effective when action=metrics; pass version name when querying CloudRun version monitoring. |
envQuery
Query CloudBase environment related information, supports querying environment list, current environment information, security domains, resource usage, and monitoring metrics. (Original tool names: listEnvs/getEnvInfo/getEnvAuthDomains/getWebsiteConfig, these names can still be used for compatibility with old AI rules) When action=list, standard return fields are EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, and supports filtering these fields via fields whitelist; aliasExact=true will filter by exact alias match to avoid mistaking environments with similar prefixes as candidates; even if envId is passed, action=list only returns summary, not complete resource details or expiry. Account-level login can pass region (ap-shanghai/ap-guangzhou/ap-singapore) to query corresponding regions, aligned with CLI tcb env list -r <region>; environment-level credentials (API Key / hosted authorization token) can only see the bound envId, returning credential_scope=single_env; in that case region is not applied and is truthfully reported in ignored_params (AppliedFilters.region is null) — do not misjudge this as the environment not existing or region filtering being broken. To query detailed information of a known environment, use action=info. action=info will supplement BillingInfo (such as ExpireTime, PayMode, IsAutoRenew and other billing fields) when available.
📊 action=usage aligns with tcb env usage/info: passes through Manager SDK describeEnvAccountCircle + describeCreditsUsageDetail, returning billing cycle and resource credit usage by module (FLEXDB/SCF/COS etc.). envId required; type optionally filters modules; when startDate/endDate are not passed, the current billing cycle is used automatically.
📈 action=metrics aligns with CloudBase DescribeCurveData (manager.monitor.describeCurveData, not Cloud Monitor GetMonitorData): queries environment/gateway QPS, cloud function invocations and errors, database CPU/memory/disk, CloudRun CPU/QPS time series. envId and metricName required; startTime/endTime format YYYY-MM-DD HH:mm:ss, must be passed as a pair, defaults to last 24 hours when omitted; period only supports 300/3600/86400. When GatewayTraceEnvQPS is called without resourceID, environment-level all|:|all|:|all|:|all is auto-filled; CloudRun Tke* metrics must pass service name as resourceID. Do not use callCloudApi to guess monitoring Actions.
🔍 action=info also derives three fields for backend selection:
EnvInfo.RuntimeMode: 'postgresql' or 'nosql', indicates the recommended default backend for new services (postgresql when PG is enabled, otherwise nosql).EnvInfo.RuntimeBackends:{postgresql, nosql, mysql}three booleans describing the actual coexisting backends of the current environment.EnvInfo.RuntimeModeHints: API/tool/skill hints corresponding to each backend.
🌐 action=info also projects gateway route Enable status without overwriting StaticStorages[].StaticDomain (cloud API nominal domain): StaticStorages[].staticDomainRouteEnabled and EnvInfo.staticDomainRouteEnabled (same source as queryHosting websiteConfig). false means the default static domain root route is disabled (access returns GATEWAY_ROUTE_DISABLED), do not treat the nominal domain as a reachable URL.
AI must check these three items before writing business/permission/storage code: In PG mode, new services should use app.rdb() + RLS (managePgDatabase action=execute to run CREATE POLICY) + pgstore; existing NoSQL collections / old storage / managePermissions(resourceType="noSqlDatabase") remain valid in PG environments. What is truly inapplicable is MySQL: when RuntimeBackends.mysql === false, manageMysqlDatabase / queryMysqlDatabase / relational-database-tool skill should not be used.
⚠️ DEPRECATED: This tool name is deprecated and is an old word-order alias for queryEnv. Input parameters and actions are completely identical. Please call queryEnv directly; this alias will be removed in the next version.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Query type: list=environment list/summary filtering (filters per DescribeEnvs semantics, supports filtering by envId/region, returns EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault, does not support expiry), info=specified environment detailed information (envId required, returns resource fields and billing info), domains=security domain list, usage=environment resource usage (envId required, aligned with tcb env usage/info), metrics=environment monitoring time series (envId and metricName required, aligned with CloudBase DescribeCurveData). Allowed values: "list", "info", "domains", "usage", "metrics" |
alias | string | Filter by environment alias. Optional when action=list | |
aliasExact | boolean | Filter by exact environment alias match. Optional when action=list; used together with alias | |
envId | string | Environment ID. Optional when action=list (only filters per DescribeEnvs semantics, still returns summary); required when action=info / action=usage / action=metrics; optional when action=domains (queries the currently bound environment when omitted, or that environment's security domains when provided). | |
region | string | Query region. Only effective when action=list. Account-level credentials pass this value through to DescribeEnvs (X-TC-Region), e.g. ap-singapore. Equivalent CLI: tcb env list -r <region> --json. Environment-level credentials (API Key / hosted authorization token) are single-environment scoped and this parameter is ignored: the result is always the bound environment, the response has AppliedFilters.region = null, query_region takes that environment's own Region, and ignored_params explains why it was ignored — do not conclude from this that the region has no environments. ⚠️ ap-singapore belongs to both the China site and the international site; when no site is explicitly specified it is treated as the international site (site=intl): if you have logged in to both sites, passing this region silently queries the international-site account, so call auth(site="domestic") or set TCB_SITE=domestic first to pin the site. Allowed values: "ap-shanghai", "ap-guangzhou", "ap-singapore" | |
limit | integer | Maximum number of results to return. Optional when action=list | |
offset | integer | Pagination offset. Optional when action=list | |
fields | array of string | Return field whitelist. Only supports EnvId, Alias, Status, EnvType, Region, PackageId, PackageName, IsDefault. Optional when action=list | |
type | array of string | Usage module filter. Only effective when action=usage; queries all modules when omitted. Available values aligned with tcb CLI: FLEXDB, TDSQL, SCF, EKS, COS, AI, HOSTING, Auth, APIInvocation, HTTPInvocation, VM, Workflow, Other. | |
startDate | string | Usage start date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with endDate. Uses current billing cycle when omitted. | |
endDate | string | Usage end date (YYYY-MM-DD). Only effective when action=usage; passed as a pair with startDate. Uses current billing cycle when omitted. | |
needUsageDetails | boolean | Whether to return daily usage details. Only effective when action=usage; defaults to true. | |
metricName | string | Monitoring metric name. Only effective and required when action=metrics. GatewayTraceEnvQPS/EnvQPSAll=environment and gateway QPS; FunctionInvocation/FunctionError/FunctionTimeout/FunctionThrottle=cloud function invocations, errors, timeouts, throttling; DbRead/DbWrite/DbSizepkg=document database reads, writes, and capacity; MysqlCpuUsageRate/MysqlMemoryUse/MysqlStorageUsage=SQL database CPU/memory/disk; TkeCpuUsedService/TkeQPSService/TkeHttpErrorService=CloudRun CPU/QPS/errors. Allowed values: "GatewayTraceEnvQPS", "EnvQPSAll", "FunctionInvocation", "FunctionError", "FunctionTimeout", "FunctionThrottle", "FunctionDuration", "FunctionConcurrentExecutions", "DbRead", "DbWrite", "DbSizepkg", "MysqlCpuUsageRate", "MysqlMemoryUse", "MysqlStorageUsage", "MysqlQps", "MysqlSlowQueries", "MysqlDbConnections", "TkeCpuUsedService", "TkeMemUsedService", "TkeQPSService", "TkeHttpErrorService", "TkeInvokeNumService" | |
startTime | string | Monitoring start time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with endTime. Defaults to last 24 hours when omitted. End time must be at least five minutes after start time. | |
endTime | string | Monitoring end time (YYYY-MM-DD HH:mm:ss). Only effective when action=metrics; passed as a pair with startTime. Defaults to last 24 hours when omitted. | |
period | number | Statistics period (seconds). Only effective when action=metrics; only supports 300, 3600, 86400. Auto-selected by backend based on time range when omitted. Time range ≤1 day cannot use 86400; >3 days cannot use 300. Allowed values: 300, 3600, 86400 | |
resourceID | string | Resource ID. Only effective when action=metrics. Cloud functions pass function name, document database passes collection name, CloudRun must pass service name; GatewayTraceEnvQPS auto-fills environment-level all|:|all|:|all|:|all when omitted. | |
subresourceID | string | Sub-resource ID. Only effective when action=metrics; pass version name when querying CloudRun version monitoring. |
envDomainManagement
Manage CloudBase environment security domains, supports add and delete operations. (Original tool names: createEnvDomain/deleteEnvDomain, these names can still be used for compatibility with old AI rules) When browser Web applications need to directly access CloudBase resources from local Vite / dev server or custom domains, first use envQuery(action=domains) to check if the actual browser origin's host:port is already in the whitelist, then add based on that actual value.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Operation type: create=add domain, delete=delete domain. Allowed values: "create", "delete" |
domains | array of string | Yes | Security domain array |
manageEnv
Manage CloudBase environments, supports: listPackages=query available plan list, create=create a new environment (requires confirmation), modifyPlan=change plan (scale up/down, requires confirmation), renew=renew environment (requires confirmation).
⚠️ All fee-incurring operations (create/modifyPlan/renew) must show a configuration summary and wait for the user to confirm via confirm="yes" before execution.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Operation type: listPackages=query available plans, create=create environment, modifyPlan=change plan, renew=renew. Allowed values: "listPackages", "create", "modifyPlan", "renew" |
alias | string | Environment alias (required when action=create). Requirements: lowercase letters/numbers/hyphens, cannot start or end with a hyphen, max 20 characters | |
packageId | string | Plan ID (required when action=create/modifyPlan). Options include baas_personal (Personal), baas_pf_standard (Standard), baas_pf_enterprise (Enterprise) | |
resources | array of string | Enabled resource types (optional when action=create). Available values: storage, function (cloud function), postgresql; defaults to all three when omitted. CreateEnv requires a non-empty Resources field; MCP always sends it. flexdb (document database) is no longer included: newly created environments do not create a NoSQL instance, and its availability is determined by EnvInfo.RuntimeBackends returned by queryEnv(action="info") | |
duration | integer | Purchase or renewal duration (months), optional when action=create/renew, default 1 | |
region | string | Creation region (only effective when action=create). Passed through with X-TC-Region semantics and determines where the new environment lives; equivalent CLI: tcb env create --region ap-shanghai. When omitted, the current session region is used (cloudBaseOptions.region → TCB_REGION → project config / rc binding → site default region: ap-shanghai for the China site, ap-singapore for the international site). Note: region is not written into the CreateEnv request body but takes effect through the request-level region context — consistent with the callCloudApi rule "do not put Region into params". ⚠️ ap-singapore belongs to both the China site and the international site; when no site is explicitly specified it is treated as the international site (site=intl). To create in that region on the China site, call auth(site="domestic") or set TCB_SITE=domestic first. Allowed values: "ap-shanghai", "ap-guangzhou", "ap-singapore" | |
envId | string | Environment ID (required when action=modifyPlan/renew) | |
confirm | string | Confirmation. All paid operations (create/modifyPlan/renew) must pass "yes". Allowed values: const "yes" |
readNoSqlDatabaseStructure
Read NoSQL database collection and index structure, supports listing collections, viewing collection details, listing indexes, and checking if an index exists.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | listCollections: List collection list describeCollection: Describe collection details (returns index summary) checkCollection: Check if collection exists listIndexes: List indexes of specified collection checkIndex: Check if specified index exists. Allowed values: "listCollections", "describeCollection", "checkCollection", "listIndexes", "checkIndex" |
limit | number | Return count limit (optional for listCollections operation) | |
offset | number | Offset (optional for listCollections operation) | |
collectionName | string | Collection name (required for describeCollection, listIndexes, checkIndex operations) | |
indexName | string | Index name (required for checkIndex operation) |
writeNoSqlDatabaseStructure
Modify NoSQL database structure, supports creating/deleting collections, and adding/deleting indexes via updateCollection's updateOptions.CreateIndexes / updateOptions.DropIndexes.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | createCollection: Create collection updateCollection: Update collection configuration; pass updateOptions.CreateIndexes to add indexes, pass updateOptions.DropIndexes to delete indexes deleteCollection: Delete collection. Allowed values: "createCollection", "updateCollection", "deleteCollection" |
collectionName | string | Yes | Collection name |
updateOptions | object | Update options (used for updateCollection). CreateIndexes for adding indexes, DropIndexes for deleting indexes. | |
updateOptions.CreateIndexes | array of object | List of indexes to add | |
updateOptions.CreateIndexes[].IndexName | string | Yes | Index name to create |
updateOptions.CreateIndexes[].MgoKeySchema | object | Yes | Field and constraint configuration for index to be created |
updateOptions.CreateIndexes[].MgoKeySchema.MgoIsUnique | boolean | Yes | Whether unique index |
updateOptions.CreateIndexes[].MgoKeySchema.MgoIndexKeys | array of object | Yes | Index field list, supports single field or compound indexes |
updateOptions.CreateIndexes[].MgoKeySchema.MgoIndexKeys[].Name | string | Yes | Index field name |
updateOptions.CreateIndexes[].MgoKeySchema.MgoIndexKeys[].Direction | string | Yes | Index direction, typically 1 for ascending, -1 for descending |
updateOptions.DropIndexes | array of object | List of indexes to delete | |
updateOptions.DropIndexes[].IndexName | string | Yes | Index name to delete |
readNoSqlDatabaseContent
Query and get NoSQL database data records
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
collectionName | string | Yes | Collection name |
instanceId | string | Optional: Explicitly specify database instance ID; will be automatically resolved and cached if not provided | |
query | object | string | Query conditions (object or string, object recommended) | |
projection | object | string | Return field projection (object or string, object recommended) | |
sort | array of object | string | Sort conditions, only supports array [{"key":"createdAt","direction":-1}] or corresponding JSON string. | |
limit | number | Return count limit | |
offset | number | Number of records to skip |
writeNoSqlDatabaseContent
Modify NoSQL database data records. Can be understood using MongoDB updateOne/updateMany mental model: partial updates must use update operators like $set/$inc/$push; if you directly pass a plain object like { field: value }, the underlying layer treats it as replacement content, risking overwriting the entire document. When updating a field in a nested object, you must use dot notation path (e.g., { "$set": { "address.city": "shenzhen" } }); if written as { "$set": { "address": { "city": "shenzhen" } } }, the entire address object will be replaced and other sibling fields will be lost. If role/profile documents in a collection are read on the frontend via db.collection(...).doc(uid), ensure the document _id is that uid; do not use query={"uid":"..."} + upsert=true to update users / profiles, otherwise it often generates a different _id, causing subsequent doc(uid) reads to miss.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | insert: Insert data (add document) update: Update data delete: Delete data. Allowed values: "insert", "update", "delete" |
collectionName | string | Yes | Collection name |
instanceId | string | Optional: Explicitly specify database instance ID; will be automatically resolved and cached if not provided | |
documents | array of object | Array of document objects to insert, each document is an object (required for insert operation) | |
query | object | string | Query conditions (object or string, object recommended) (required for update/delete operations) | |
update | object | string | Update content (object or string, object recommended) (required for update operation). Pass MgoUpdate using MongoDB update semantics: for partial updates use $set/$inc/$unset/$push operators, e.g., { "$set": { "status": "pending" } }; do not directly pass { "status": "pending" }, otherwise the entire document may be replaced. When updating nested fields, use dot notation path, e.g., { "$set": { "address.city": "shenzhen" } }, do not write { "$set": { "address": { "city": "shenzhen" } } } (will replace entire address object). | |
isMulti | boolean | Whether to update multiple records (optional for update/delete operations) | |
upsert | boolean | Whether to insert if not exists (optional for update operation) |
queryPgDatabase
Query CloudBase PostgreSQL databases. Supports getting the current PG context, listing schema-qualified database objects, reading lightweight metadata, inspecting a single object structure, and executing read-only SQL.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Operation type: context=get current PostgreSQL context; objects=list schema-qualified database objects; metadata=get lightweight table metadata; schema=inspect a single schema-qualified object structure; sql=execute read-only SQL. Allowed values: "context", "objects", "metadata", "schema", "sql" |
sql | string | Read-only SQL used when action=sql | |
objectName | string | Schema-qualified PostgreSQL object name used when action=schema, e.g. public.users | |
schema | string | Optional schema filter, used for action=objects or action=metadata | |
limit | integer | Optional cap on summary rows for objects, metadata, or SQL results. Default 20, max 200 |
managePgDatabase
Manage CloudBase PostgreSQL: execute confirmed write SQL, SQL risk preflight, and migration management. Schema changes such as CREATE/ALTER/DROP MUST use applyMigration (explicit migrationVersion; before success, it automatically writes or validates the local cloudbase/migrations/<version>_<name>.sql file, consistent with the CLI tcb db pg migration). Do not default to execute. execute is mainly for DML and operational SQL like GRANT/RLS.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Operation type: execute=execute confirmed write SQL (DML/GRANT/RLS; schema DDL is rejected by default, requires allowDdlViaExecute=true); dryRun=only analyze SQL risk without executing; planMigration=preview migration plan (requires migrationName + migrationVersion + sql; optional includeAll=true allows out-of-order, aligned with CLI --include-all); applyMigration=apply migration, preferred for CREATE/ALTER schema (requires migrationName + migrationVersion + sql + confirm=true; optional includeAll; if the local SQL is missing it is automatically written to cloudbase/migrations/, if content mismatches it fails closed with LOCAL_MIGRATION_FILE_MISMATCH; before returning success it polls DescribeTaskResult (default max 10 minutes, adjustable via taskPollTimeoutMs / waitForTask) and verifies the migrationVersion has landed in remote history; on timeout returns MIGRATION_TASK_TIMEOUT, must first describeMigrationTask then listMigrations, do NOT immediately re-push the same version; if not applied returns success=false with errorCode=MIGRATION_NOT_APPLIED); listMigrations=query the applied Migration list (supports limit/offset paging); migrationDetail=view a single Migration detail (requires migrationVersion); describeMigrationTask=query the Push async task status by TaskId (DescribeTaskResult: Status/Phase/Reason; requires taskId; used for waitForTask=false / MIGRATION_TASK_TIMEOUT / failure diagnosis, listMigrations cannot see Reason); fetchMigration=pull SQL from remote history and write to local cloudbase/migrations/ (aligned with CLI tcb db pg migration fetch; optional migrationVersion pulls a single entry, omitted pulls all; force=true overwrites existing files, default skips); rollbackMigration=roll back the latest N Migrations (requires lastN + confirm=true); repairMigration=repair Migration history (requires migrationVersion + migrationName + repairStatus + repairReason). Allowed values: "execute", "dryRun", "planMigration", "applyMigration", "listMigrations", "migrationDetail", "describeMigrationTask", "fetchMigration", "rollbackMigration", "repairMigration" |
sql | string | SQL statement used by action=execute, dryRun, planMigration, applyMigration, or repairMigration(applied) | |
confirm | boolean | Must be explicitly set to true before executing any write SQL | |
envId | string | Optional CloudBase environment ID; uses the current MCP environment when omitted | |
instanceId | string | Optional PostgreSQL logical instance identifier, default cloudbase-pg | |
defaultSchema | string | Optional default schema, default public | |
role | string | Optional PostgreSQL role, passed to Manager SDK executePGSql; e.g. pass postgres when managing policies | |
objectName | string | Optional object name, currently only used for non-migration scenarios. For migration operations use migrationName / migrationVersion / lastN | |
migrationName | string | Required for plan/apply/repair: migration name, starts with a lowercase letter, only lowercase letters, digits, and underscores allowed | |
migrationVersion | string | 14-digit timestamp YYYYMMDDHHMMSS. Required for plan/apply/detail/repair; optional for fetchMigration (pass to pull that entry only, omit to pull all remote history); must not be silently generated server-side, to avoid diverging from local cloudbase/migrations/<version>_<name>.sql. applyMigration is not incremental: always pass the complete SQL; when a run ends in a failed final state and listMigrations has not recorded it, the version number is not consumed — just resend the full SQL under a new migrationVersion (the same name with a different version does not conflict) | |
rollbackSql | string | Optional for plan/apply: rollback SQL statement | |
lastN | integer | Required for rollback: roll back the latest N applied Migrations, positive integer | |
limit | integer | Optional for list: max number of results, 1-500, default 100 | |
offset | integer | Optional for list: pagination offset, default 0 | |
lockTimeoutMs | integer | Optional for apply: max time to acquire the database lock (ms), default 5000 | |
statementTimeoutMs | integer | Optional for apply: max execution time per SQL statement (ms), default 300000 | |
taskPollTimeoutMs | integer | Optional for apply: max wait for polling DescribeTaskResult (ms). Default 600000 (aligned with CLI tcb db pg migration up 10-minute wait). Range 5000-600000. On timeout, first describeMigrationTask(taskId) then listMigrations, do NOT immediately re-push the same version | |
waitForTask | boolean | Optional for apply, default true. When false, Push returns the TaskId immediately (errorCode=MIGRATION_TASK_PENDING) and the caller polls the task final state with describeMigrationTask, then confirms persistence with listMigrations; suitable for MCP host tool calls with short timeout. Default true waits synchronously for the task final state | |
taskId | string | Required for describeMigrationTask: the TaskId returned by PushPGUserMigrations / applyMigration. Used for a one-shot DescribeTaskResult (Status/Phase/Reason) query, no polling | |
repairStatus | string | Required for repair: applied=mark as applied (can backfill Query), reverted=delete history record. Allowed values: "applied", "reverted" | |
repairReason | string | Required for repair: repair reason | |
force | boolean | Optional for fetchMigration, default false. true=overwrite an existing local SQL file with the same name (aligned with CLI tcb db pg migration fetch --force); false=skip existing files. Used to realign Git checksums from remote history | |
includeAll | boolean | Optional for planMigration / applyMigration, default false. true=allow out-of-order (version lower than remote LatestVersion) Preview/Push, aligned with CLI tcb db pg migration up --include-all; only use when intentionally backfilling history/out-of-order migrations, otherwise choose a larger migrationVersion | |
allowDdlViaExecute | boolean | Optional, default false. Only set true when deliberately bypassing migration history to allow schema DDL via execute; normal CREATE/ALTER schema must use applyMigration |
queryPgStorage
Query cloud storage capabilities in the CloudBase PostgreSQL environment. Returns bucket/config capability summaries, object info query plans, and upload implementation plans based on HTTP API or SDK; does not read local files and does not output large numbers of signed URLs by default.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Operation type: buckets/config=query storage capability summary; createBucket=generate bucket creation plan (SQL/HTTP API/CLI); uploadPlan=generate HTTP API/SDK upload plan; objectInfo=generate object metadata query plan; signUpload/signDownload=explicit one-time signed URL request placeholders. Allowed values: "buckets", "config", "uploadPlan", "objectInfo", "signUpload", "signDownload", "createBucket" |
bucket | string | Cloud storage bucket name | |
objectKey | string | Single object key | |
objectKeys | array of string | Multiple object keys, used for object metadata query planning | |
objects | array of object | Metadata of objects to upload. File byte content is not passed through MCP | |
expiresIn | integer | Signed URL validity period in seconds, range 60 to 86400 |
queryMysqlDatabase
Query CloudBase MySQL database information. Supports read-only SQL execution, MySQL provisioning result lookup, MySQL task status lookup, and current instance context discovery.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | runQuery=execute read-only SQL; describeCreateResult=query CreateMySQL result; describeTaskStatus=query MySQL task status; getInstanceInfo=get current SQL instance context; describeInstance=alias of getInstanceInfo. Allowed values: "runQuery", "describeCreateResult", "describeTaskStatus", "getInstanceInfo", "describeInstance", "getConnectionInfo" |
sql | string | Read-only SQL used by action=runQuery | |
request | object | Official request payload used by describeCreateResult/describeTaskStatus | |
dbInstance | object | Optional SQL database instance context for runQuery | |
dbInstance.instanceId | string | ||
dbInstance.schema | string |
manageMysqlDatabase
Manage CloudBase MySQL database resources. Supports MySQL provisioning, MySQL destruction, write SQL/DDL execution, and schema initialization. IMPORTANT: MySQL must be provisioned first (action=provisionMySQL with confirm=true) before any runStatement or initializeSchema call. If MySQL is not yet provisioned, the tool will return MYSQL_NOT_CREATED with a nextAction to provision first.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | provisionMySQL=create MySQL instance; destroyMySQL=destroy MySQL instance; runStatement=execute write SQL or DDL; initializeSchema=run ordered schema initialization statements. Allowed values: "provisionMySQL", "destroyMySQL", "runStatement", "initializeSchema" |
confirm | boolean | Explicit confirmation required for action=provisionMySQL or action=destroyMySQL | |
sql | string | SQL statement used by action=runStatement | |
request | object | Official request payload used by action=provisionMySQL or action=destroyMySQL | |
statements | array of string | Ordered schema initialization SQL statements used by action=initializeSchema | |
requireReady | boolean | Whether initializeSchema should block until MySQL is confirmed ready. Defaults to true. | |
statusContext | object | Optional provisioning status requests used to confirm readiness before initializeSchema | |
statusContext.createResultRequest | object | ||
statusContext.taskStatusRequest | object | ||
dbInstance | object | Optional SQL database instance context for runStatement/initializeSchema | |
dbInstance.instanceId | string | ||
dbInstance.schema | string |
manageDataModel
Data model query tool, supports querying and listing data models (read-only operations). Use the action parameter to distinguish operation types: list=get model list (without Schema, optional names parameter for filtering), get=query single model details (with Schema field list, format, relationships, etc., requires name parameter), docs=generate SDK usage documentation (requires name parameter)
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Operation type: get=query single model (with Schema field list, format, relationships, requires name parameter), list=get model list (without Schema, optional names parameter for filtering), docs=generate SDK usage documentation (requires name parameter). Allowed values: "get", "list", "docs" |
name | string | Data model name to query. When action='get' or action='docs', this parameter is required and must provide an existing data model name. Available model names can be obtained via action='list' operation | |
names | array of string | Model name array (optional for list operation, for filtering) |
modifyDataModel
Create or update data model based on Mermaid classDiagram. Supports creating new models and updating existing model structures. Built-in async task monitoring, automatically polls until completion or timeout.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
mermaidDiagram | string | Yes | Mermaid classDiagram code describing the data model structure. |
action | string | Operation type: create=create new model. Allowed values: "create"; Default: "create" | |
publish | boolean | Whether to publish the model immediately. Default: false | |
dbInstanceType | string | Database instance type. Default: "MYSQL" |
Example
classDiagram
class Student {
name: string <<Name>>
age: number = 18 <<Age>>
gender: x-enum = "Male" <<Gender>>
classId: string <<Class ID>>
identityId: string <<Identity ID>>
course: Course[] <<Courses>>
required() ["name"]
unique() ["name"]
enum_gender() ["Male", "Female"]
display_field() "name"
}
class Class {
className: string <<Class Name>>
display_field() "className"
}
class Course {
name: string <<Course Name>>
students: Student[] <<Students>>
display_field() "name"
}
class Identity {
number: string <<ID Number>>
display_field() "number"
}
%% Relationships
Student "1" --> "1" Identity : studentId
Student "n" --> "1" Class : student2class
Student "n" --> "m" Course : course
Student "n" <-- "m" Course : students
%% Class naming
note for Student "Student Model"
note for Class "Class Model"
note for Course "Course Model"
note for Identity "Identity Model"
queryFunctions
Unified read-only entry for the functions domain. Query function list, function details, logs, layers, triggers, and code download URLs via self-explanatory action names.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Read-only operation type, e.g., listFunctions, getFunctionDetail, listFunctionLogs. Allowed values: "listFunctions", "getFunctionDetail", "listFunctionLogs", "getFunctionLogDetail", "listFunctionLayers", "listLayers", "listLayerVersions", "getLayerVersionDetail", "listFunctionTriggers", "getFunctionDownloadUrl", "getFunctionDeployStatus" |
functionName | string | Function name. Required for function-related actions | |
limit | number | Pagination count. Optional for list-type actions | |
offset | number | Pagination offset. Optional for list-type actions | |
codeSecret | string | Code protection secret | |
startTime | string | Log query start time | |
endTime | string | Log query end time | |
requestId | string | Log requestId. Required when getting log details | |
qualifier | string | Function version, optional for log queries | |
runtime | string | Runtime filter for layer queries | |
searchKey | string | Layer name search keyword | |
layerName | string | Layer name. Required for layer-related actions | |
layerVersion | number | Layer version number. Required when getting layer version details |
manageFunctions
Unified write entry for the functions domain. Supports function creation, code updates, config updates, function invocation, cron timer triggers, layer bindings, incremental deployment, and deletion. Image deployment (Runtime=CustomImage): push the image via zip→COS→CloudApp custom build→TCR first (this stage uses bare Tencent Cloud APIs, not covered by this tool), then use createFunction with func.runtime="CustomImage" and imageConfig to create an HTTP function from the TCR image; subsequent iterations use updateFunctionCode + imageConfig to swap image tags. Dangerous operations require explicit confirm=true.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Write operation type, e.g., createFunction, invokeFunction, attachLayer. Allowed values: "createFunction", "updateFunctionCode", "updateFunctionConfig", "invokeFunction", "deleteFunction", "createFunctionTrigger", "deleteFunctionTrigger", "createLayerVersion", "deleteLayerVersion", "attachLayer", "detachLayer", "updateFunctionLayers", "incrementalDeployFunction" |
func | object | Function configuration for createFunction operation | |
func.name | string | Yes | Function name |
func.type | string | Function type. Allowed values: "Event", "HTTP" | |
func.protocolType | string | HTTP cloud function protocol type. Allowed values: "HTTP", "WS" | |
func.protocolParams | object | ||
func.protocolParams.wsParams | object | ||
func.protocolParams.wsParams.idleTimeOut | number | WebSocket idle timeout (seconds) | |
func.instanceConcurrencyConfig | object | ||
func.instanceConcurrencyConfig.dynamicEnabled | boolean | ||
func.instanceConcurrencyConfig.maxConcurrency | number | ||
func.timeout | number | Function timeout | |
func.envVariables | object | Environment variables | |
func.vpc | object | VPC configuration | |
func.vpc.vpcId | string | Yes | |
func.vpc.subnetId | string | Yes | |
func.runtime | string | Runtime environment. Event functions support multiple runtimes: Nodejs: Nodejs24.11(Beta), Nodejs22.21(Beta), Nodejs20.19, Nodejs18.15, Nodejs16.13 Python: Python3.11, Python3.10, Python3.9, Python3.7 Php: Php8.0, Php7.4 Java: Java11 Golang: Golang1 Image deployment (create HTTP function from TCR image) use "CustomImage", also provide imageConfig; no functionRootPath/zipFile needed. Recommended runtimes: Node.js: Nodejs20.19 Python: Python3.11 PHP: Php7.4 Java: Java11 Go: Golang1 | |
func.imageConfig | object | Image deployment configuration (only used when runtime=CustomImage). Used for stage B of zip→COS→CloudApp custom build→TCR→SCF: creating an HTTP function from a TCR image. Once imageConfig is passed, the function is treated as image-deployed and requires no local code packaging, scf_bootstrap, or Handler. | |
func.imageConfig.imageType | string | Image registry type: enterprise (Enterprise TCR) or personal (Personal TCR). Defaults to enterprise when omitted. Allowed values: "enterprise", "personal" | |
func.imageConfig.imageUri | string | Yes | Full image address (must include tag), format {domain}/{namespace}/{image}:{tag}, e.g., ccr.ccs.tencentyun.com/your-ns/demo-app:demo-app-001. Do not use :latest. |
func.imageConfig.registryId | string | TCR instance ID, e.g., tcr-xxxxxxxx. Required when imageType=enterprise. | |
func.imageConfig.command | string | Override image ENTRYPOINT. Uses Dockerfile default if not provided, e.g., python. | |
func.imageConfig.args | string | Override image CMD, space-separated, e.g., -u app.py. | |
func.imageConfig.entryPoint | string | Image entry point, generally not needed. | |
func.imageConfig.imagePort | number | Container listening port. Web Server functions use 9000 (default), Job-type images use -1. | |
func.imageConfig.containerImageAccelerate | boolean | Whether to enable image acceleration. Recommended for large images to reduce cold start time. | |
func.triggers | array of object | Trigger configuration array | |
func.triggers[].name | string | Yes | Trigger name |
func.triggers[].type | string | Yes | Trigger type. Allowed values: "timer" |
func.triggers[].config | string | Yes | Trigger configuration, timer uses 7-segment cron: second minute hour day month week year |
func.handler | string | Function entry point | |
func.ignore | string | array of string | Ignored files | |
func.isWaitInstall | boolean | Whether to wait for dependency installation | |
func.layers | array of object | Layer configuration | |
func.layers[].name | string | Yes | |
func.layers[].version | number | Yes | |
functionRootPath | string | Function root directory (parent directory absolute path) | |
force | boolean | Whether to overwrite when createFunction | |
functionName | string | Function name. Most actions use this field as unified target | |
zipFile | string | Code package base64 encoding | |
handler | string | Function entry point | |
timeout | number | Timeout for config update | |
envVariables | object | Environment variables to merge for config update | |
vpc | unknown | VPC info for config update | |
params | object | Invocation parameters for invokeFunction | |
triggers | array of unknown | Trigger list for createFunctionTrigger | |
triggerName | string | Target trigger name for deleteFunctionTrigger | |
layerName | string | Layer name | |
layerVersion | number | Layer version number | |
contentPath | string | Layer content path, can be directory or ZIP file | |
base64Content | string | Layer content base64 encoding | |
runtimes | array of string | List of runtimes the layer applies to | |
description | string | Layer version description | |
licenseInfo | string | Layer license information | |
layers | array of object | Target layer list for updateFunctionLayers, order is final order | |
layers[].layerName | string | Yes | Layer name |
layers[].layerVersion | number | Yes | Layer version number |
codeSecret | string | Code protection secret for layer binding | |
imageConfig | unknown | Image deployment configuration (Runtime=CustomImage). Used with createFunction to create an HTTP function from a TCR image, or with updateFunctionCode to swap image tags only. Requires imageUri (with tag); enterprise TCR also requires registryId. Can also be provided in func.imageConfig; when both are passed, the top-level imageConfig takes precedence. | |
incrementalFile | string | File path for incrementalDeployFunction incremental deployment | |
confirm | boolean | Dangerous operation confirmation switch |
queryHosting
Query read-only information about CloudBase static hosting. Suitable for AI discovery before deciding next steps: action=websiteConfig queries index/error page, routing rules and site domain info; action=status queries hosting service status; action=findFiles finds files by prefix; action=listFiles lists all hosted files; action=domainStatus queries the current status and config of custom domains. This tool has no side effects.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Query type: websiteConfig=query static hosting website document config and site domain info, status=query static hosting service status, findFiles=find hosted files by prefix, listFiles=list all files in static hosting, domainStatus=query custom domain config and effective status. This tool is strictly read-only and does not modify any resources. Allowed values: "websiteConfig", "status", "findFiles", "listFiles", "domainStatus" |
prefix | string | File prefix filter. Only used when action=findFiles, e.g. app/ or assets/logo | |
marker | string | Pagination start marker. Only used when action=findFiles, to continue fetching results after the previous page | |
maxKeys | integer | Max file entries returned per call. Only used when action=findFiles | |
domains | array of string | Custom domain list to query. Only used when action=domainStatus, e.g. ["www.example.com"] |
manageHosting
Manage change operations for CloudBase static hosting. action=upload uploads local build artifacts to the shared domain (domain format: <envId>-<appId>.tcloudbaseapp.com/<cloudPath>); action=delete deletes hosted files or directories (must confirm=true); action=setWebsiteDocument sets index/error pages and routing rules; action=enableService enables static hosting; action=bindDomain / unbindDomain / updateDomain manage custom domains; action=downloadFile / downloadDirectory download hosted content to local. ⚠️ For new project deployments, prefer manageApps (deploys to an independent subdomain); this tool is for existing legacy projects or as a fallback for manageApps. manageApps and manageHosting use different domains; switching will break old links. If the task only needs to view config, files, or domain status, use queryHosting instead.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Management type: upload=upload local build artifacts to static hosting, delete=delete hosted files or directories, setWebsiteDocument=set index/error pages and routing rules, enableService=enable static hosting service, bindDomain=bind a custom domain, unbindDomain=unbind a custom domain, updateDomain=update domain cache/anti-leech/IP rules, downloadFile=download a single hosted file locally, downloadDirectory=download a hosted directory locally. Allowed values: "upload", "delete", "setWebsiteDocument", "enableService", "bindDomain", "unbindDomain", "updateDomain", "downloadFile", "downloadDirectory" |
localPath | string | Local path. For action=upload, the local file/directory path to upload; for action=downloadFile or downloadDirectory, the local destination path. Absolute paths recommended | |
cloudPath | string | Target path in static hosting. For action=upload, the hosted path after upload; for action=delete/downloadFile/downloadDirectory, the hosted file or directory path | |
files | array of object | Multi-file upload config. Optional when action=upload; when passed, each file is uploaded individually and single localPath/cloudPath is not used | |
ignore | union | File patterns to ignore when uploading. Optional when action=upload, e.g. node_modules or ["/*.map", "/.DS_Store"] | |
isDir | boolean | Whether to treat cloudPath as a directory. Only used when action=delete; true=delete directory, false=delete a single file | |
confirm | boolean | Confirmation switch for high-risk operations. Must be explicitly true for action=delete and action=unbindDomain to avoid accidental file deletion or domain unbinding | |
indexDocument | string | Website index document name. Required only when action=setWebsiteDocument, e.g. index.html | |
errorDocument | string | Error page document name. Optional when action=setWebsiteDocument, e.g. 404.html | |
routingRules | array of object | Website routing rule list. Optional when action=setWebsiteDocument. A common SPA config rewrites 404 to index.html | |
domain | string | Custom domain. Used for action=bindDomain / unbindDomain / updateDomain, e.g. www.example.com | |
certId | string | Certificate ID. Required only when action=bindDomain | |
domainId | number | Domain ID. Required only when action=updateDomain, for precisely updating the specified domain config | |
domainConfig | object | Domain config. Required only when action=updateDomain; supports cache, Referer, anti-leech, IP rules, and rate limiting |
queryStorage
Query cloud storage information, supports listing directory files, getting file information, getting temporary download links and other read-only operations. Returned file information includes file name, size, modification time, download link, etc.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Query operation type: list=list all files in directory, info=get detailed information of specified file, url=get temporary download link for file. Allowed values: "list", "info", "url", "read" |
cloudPath | string | Yes | Cloud file path, e.g., files/data.txt or files/ (directory) |
maxAge | number | Temporary link validity period in seconds, range: 1-86400, default: 3600 (1 hour). Default: 3600 |
manageStorage
Manage cloud storage files, only for COS/Storage objects, not for static website hosting. Supports uploading files/directories, downloading files/directories, deleting files/directories and other operations. Delete operation requires setting force=true for confirmation to prevent accidental deletion of important files.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Management operation type: upload=upload file or directory, download=download file or directory, delete=delete file or directory. Allowed values: "upload", "download", "delete" |
localPath | string | Yes | Local file path, absolute path recommended, e.g., /tmp/files/data.txt |
cloudPath | string | Yes | Cloud file path, e.g., files/data.txt |
force | boolean | Force operation switch, recommended to set to true for delete operations to confirm deletion, defaults to false. Default: false | |
isDirectory | boolean | Whether directory operation, true=directory operation, false=file operation, defaults to false. Default: false |
downloadTemplate
Automatically download and deploy CloudBase project templates. ⚠️ MANDATORY FOR NEW PROJECTS ⚠️
CRITICAL: This tool MUST be called FIRST when starting a new project.
Supported templates:
- react: React + CloudBase full-stack application template
- vue: Vue + CloudBase full-stack application template
- miniprogram: WeChat Mini Program + CloudBase template
- uniapp: UniApp + CloudBase cross-platform application template
- rules: Only includes AI editor configuration files (includes all mainstream editor configurations such as Cursor, WindSurf, CodeBuddy, etc.), suitable for supplementing AI editor configuration in existing projects
Supported IDE types:
- all: Download all IDE configurations
- cursor: Cursor AI editor
- Other IDE types see list below
Note: If ide parameter is not passed and IDE cannot be detected from environment, an error will be prompted and require passing ide parameter
- windsurf: WindSurf AI editor
- codebuddy: CodeBuddy AI editor
- claude-code: Claude Code AI editor
- cline: Cline AI editor
- gemini-cli: Gemini CLI
- opencode: OpenCode AI editor
- qwen-code: Tongyi Lingma
- baidu-comate: Baidu Comate
- openai-codex-cli: OpenAI Codex CLI
- augment-code: Augment Code
- github-copilot: GitHub Copilot
- roocode: RooCode AI editor
- tongyi-lingma: Tongyi Lingma
- trae: Trae AI editor
- qoder: Qoder AI editor
- antigravity: Google Antigravity AI editor
- vscode: Visual Studio Code
- kiro: Kiro AI editor
- aider: Aider AI editor
Special notes:
- rules template will automatically include current MCP version information, which helps with later maintenance and version tracking
- When downloading rules template, if README.md file already exists in the project, the system will automatically protect the file from being overwritten (unless overwrite=true is set)
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
template | string | Yes | Template type to download. Allowed values: "react", "vue", "miniprogram", "uniapp", "rules" |
ide | string | Yes | Specify the IDE type to download. Allowed values: "all", "cursor", "windsurf", "codebuddy", "claude-code", "cline", "gemini-cli", "opencode", "qwen-code", "baidu-comate", "openai-codex-cli", "augment-code", "github-copilot", "roocode", "tongyi-lingma", "trae", "qoder", "antigravity", "vscode", "kiro", "aider", "iflow-cli" |
overwrite | boolean | Whether to overwrite existing files, defaults to false (no overwrite) |
searchKnowledgeBase
CloudBase knowledge base intelligent retrieval tool, supports fixed skill documents (skill), OpenAPI documents (openapi) and CloudBase official documentation (docs) queries.
It is strongly recommended to always prioritize using fixed skill documents (skill), OpenAPI documents (openapi) or CloudBase official documentation (docs) mode for retrieval, If these fixed modes cannot cover your question, use the CloudBase official documentation (docs) mode.
The response contains the full SKILL.md of that skill plus the address list of every .md file for it in the remote aggregation repo (CNB raw) — SKILL.md, references/, and so on, directly fetchable over HTTP. Relative links outside code fences in the body are also rewritten to absolute addresses; if the skill does not exist in the remote repo, only the inline content is returned, clearly marked, and no dead links are returned.
Fixed skill documents (skill) query currently supports 30 fixed documents, they are:
Document name: ai-model-nodejs - Document description: "Use this skill for Node.js backend AI via @cloudbase/node-sdk (>=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration. The only SDK supporting image generation (ai.createImageModel + generateImage). Text via ai.createModel with groups cloudbase, hunyuan-exp, or custom-; model ids (e.g. deepseek-v4-flash, glm-5, kimi-k2.6) go in the model field of generateText/streamText. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web) or Mini Program (use ai-model-wechat)."
Document name: ai-model-web - Document description: "Use this skill when a browser/Web app (React, Vue, Next, Nuxt, static sites, SPAs, dashboards, AI chat UI, 页面, 前端, 网页) needs AI models via @cloudbase/js-sdk. Default routing for Web/frontend AI — call directly from the browser, do NOT propose a Node.js proxy. Covers generateText and streamText; models via ai.createModel with groups cloudbase, hunyuan-exp, or custom-, model id in the model field. MUST run two-step preflight before code — see body. NOT for Node.js backend (use ai-model-nodejs), Mini Program (use ai-model-wechat), or image generation (Node SDK only)."
Document name: ai-model-wechat - Document description: "Use this skill for WeChat Mini Program AI via wx.cloud.extend.AI (小程序, wx.cloud apps). Covers generateText and streamText with callbacks (onText, onEvent, onFinish); streamText needs a data wrapper, generateText returns the raw response. Models via wx.cloud.extend.AI.createModel with groups hunyuan-exp (小程序成长计划), cloudbase (main managed), or custom-*; model id goes in the data wrapper model field. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web), Node.js backend (use ai-model-nodejs), or image generation (use ai-model-nodejs)."
Document name: auth-nodejs-cloudbase - Document description: CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase; not when configuring providers or building client login UI.
Document name: auth-tool-cloudbase - Document description: CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.
Document name: auth-web-cloudbase - Document description: CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management.
Document name: auth-wechat-miniprogram - Document description: CloudBase WeChat Mini Program native authentication guide. This skill should be used when users need mini program identity handling, OPENID/UNIONID access, or wx.cloud auth behavior in projects where login is native and automatic.
Document name: cloud-api-operations - Document description: Operate Tencent Cloud control-plane resources (monitoring/alarms, CLB, CAM roles, COS, MySQL, SCF) via cloud APIs when no dedicated MCP tool covers the task. Use when a task needs control-plane operations beyond CloudBase's own tooling, or when a callCloudApi call failed and needs classifying.
Document name: cloud-functions - Document description: CloudBase function runtime guide for building, deploying, and debugging your own Event Functions or HTTP Functions. This skill should be used when users need application runtime code on CloudBase, not when they are merely calling CloudBase official platform APIs.
Document name: cloud-storage-web - Document description: Complete guide for CloudBase cloud storage using Web SDK (@cloudbase/js-sdk) - upload, download, temporary URLs, file management, and best practices.
Document name: cloudbase-agent - Document description: Build and deploy AI agents with CloudBase Agent SDK (TypeScript & Python). Implements the AG-UI protocol for streaming agent-UI communication. Use when deploying agent servers, using LangGraph/LangChain/CrewAI adapters, building custom adapters, understanding AG-UI protocol events, or building web/mini-program UI clients. Supports both TypeScript (@cloudbase/agent-server) and Python (cloudbase-agent-server via FastAPI).
Document name: cloudbase-cli - Document description: CloudBase CLI (tcb, 云开发CLI, Tencent CloudBase命令行) resource management skill. Use when deploying cloud functions, CloudRun, storage, NoSQL/MySQL, static hosting, permissions, CORS/domains via tcb; for CI/CD and batch ops; when the user prefers CLI; or as the first-session fallback when CloudBase MCP tools are not loaded yet (after install/config, before IDE restart). Covers tcb login (device code for Tencent Cloud accounts; --cloudbase-api-key -e for environment API Key without an account; --apiKeyId/--apiKey for CI) and domain commands (fn/hosting/cloudrun/…) as MCP auth/manage parity — do not default to tcb deploy.
Document name: cloudbase-code-review - Document description: "Code review and validation for CloudBase projects. After writing code for Web / miniprogram / CloudRun / cloud-function projects, call this skill to check for known pitfalls — auth guard misuse, missing database tables, RLS misconfiguration, storage domain setup, and SDK API misuse. Supports automated lint scripts (regex-based) + LLM semantic review."
Document name: cloudbase-declarative-deploy - Document description: CloudBase declarative deployment from a cloudbaserc config (声明式部署, 配置式部署, cloudbaserc 部署) through the deployBuild / deployPlan / deployApply MCP tools. Use when deploying database, functions, app, hosting, or gateway resources described in cloudbaserc.json/yaml as a single desired-state config, when a user wants to build static hosting artifacts locally first (deployBuild), or wants a dry-run plan before applying (deployPlan), or when handling multi-environment deploys via mode / envOverrides. Covers build-plan-apply flow (deployBuild local build → deployPlan dry-run → deployApply confirm=true), hosting build-output neutralization, envId resolution priority, only/skip filtering, concurrency, and continueOnError. Prefer deployBuild (when hosting declares a buildCommand) and deployPlan before deployApply; do not confuse with per-resource tcb CLI deploy or single-function deploy.
Document name: cloudbase-document-database-in-wechat-miniprogram - Document description: Use CloudBase document database WeChat MiniProgram SDK to query, create, update, and delete data. Supports complex queries, pagination, aggregation, and geolocation queries.
Document name: cloudbase-document-database-web-sdk - Document description: Use CloudBase document database Web SDK only for confirmed NoSQL collection work. Query, create, update, and delete document data; if the task mentions PostgreSQL / CloudBase PG / app.rdb(), route to postgresql-development instead.
Document name: cloudbase-platform - Document description: CloudBase platform overview and routing guide. This skill should be used when users need high-level capability selection, platform concepts, console navigation, or cross-platform best practices before choosing a more specific implementation skill.
Document name: cloudbase-wechat-integration - Document description: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.
Document name: cloudrun-development - Document description: CloudBase Run backend development rules (Function mode/Container mode). Use this skill when deploying backend services that require long connections, multi-language support, custom environments, AI agent development, or migrating existing/GitHub apps that need VPC access to MySQL/PostgreSQL/Redis. Also use when diagnosing CloudRun container deploy failures (deploy_failed, readiness/probe failed, image won't start, docker.io pull loops). For stateless HTTP services, prefer HTTP cloud functions.
Document name: data-model-creation - Document description: "[Deprecated] Optional advanced tool for complex data modeling. For simple MySQL table creation, use relational-database-tool directly; for PostgreSQL / CloudBase PG schema work, use postgresql-development. New environments should use PostgreSQL DDL via queryPgDatabase/managePgDatabase — see postgresql-development skill instead."
Document name: http-api-cloudbase - Document description: CloudBase official HTTP API client guide. This skill should be used when backends, scripts, or non-SDK clients must call CloudBase platform APIs over raw HTTP instead of using a platform SDK or MCP management tool.
Document name: minimal-web-baas-demo - Document description: "Fast path for a minimal CloudBase Web + database demo (最小前后端 / 最小可用 fullstack / Lovable-like BaaS). Defaults to @cloudbase/js-sdk client CRUD (NoSQL app.database / PG app.rdb), MCP-only schema, preview-first, and forbids cloud functions unless secrets, cron/background jobs, or logic that security rules/RLS cannot express. Use for 搭一套 demo、留言板、Todo、Notes、Kanban, or when users say 带云函数+云数据库 but only need CRUD. NOT for production multi-service backends, CloudRun, WeChat Mini Programs, or tasks that truly need server secrets."
Document name: miniprogram-development - Document description: WeChat Mini Program development skill for building, debugging, previewing, testing, publishing, and optimizing mini program projects (小程序开发、调试、预览、发布). Covers project structure and config (project.config.json, appid, miniprogramRoot, tabBar, routing/navigation, icon assets), WeChat Developer Tools Nightly workflows (wechatide CLI, WeChat IDE Skills/MCP), miniprogram-ci preview/upload, console/network debugging, message push (消息推送) and customer-service auto-reply (客服消息), mini program SEO / search indexing (小程序搜索优化、页面收录、搜索推广、mpcrawler), and CloudBase integration (wx.cloud, 腾讯云开发, 云开发) when explicitly used. Use when users create, develop, modify, debug, preview, deploy, publish, or promote WeChat Mini Programs. NOT for Web frontend (use web-development), pure backend services (use cloudrun-development / cloud-functions), or UI-design-only tasks (use ui-design).
Document name: ops-inspector - Document description: AIOps-style CloudBase inspection skill (v3). Use when users need health checks, log diagnosis, alarm interpretation (CPU alert normal?, peak QPS), metrics via queryEnv(action=metrics), or fault playbooks for 429 / function 404 / ACCESS_TOKEN_INVALID / zero invocations. Triggers on 巡检, 诊断, 告警, 峰值 QPS, 限频, 调用量为 0, troubleshooting.
Document name: postgresql-development-cloudbase - Document description: "Use when building, debugging, or evaluating CloudBase PostgreSQL / CloudBase PG / PG mode apps, including Postgres schema setup, queryPgDatabase/managePgDatabase, JS SDK v3 app.rdb() CRUD/RPC, PG HTTP API fallback, RLS-style permissions, username-password auth, and Web CMS/admin CRUD flows backed by CloudBase PG."
Document name: relational-database-mcp-cloudbase - Document description: "[Deprecated] This is the required documentation for agents operating on the CloudBase Relational Database through MCP. It defines the canonical SQL management flow with queryMysqlDatabase, manageMysqlDatabase, queryPermissions, and managePermissions, including MySQL provisioning, destroy flow, async status checks, safe query execution, schema initialization, and permission updates. New environments should use PostgreSQL — see postgresql-development skill instead."
Document name: relational-database-web-cloudbase - Document description: "[Deprecated] Use when building frontend Web apps that talk to CloudBase Relational Database via @cloudbase/js-sdk – provides the canonical init pattern so you can then use Supabase-style queries from the browser. New environments should use PostgreSQL with app.rdb() — see postgresql-development skill instead."
Document name: spec-workflow - Document description: Use when medium-to-large changes need explicit requirements, technical design, and task planning before implementation, especially for multi-module work, unclear acceptance criteria, or architecture-heavy requests.
Document name: ui-design - Document description: Use when users need visual direction, interface hierarchy, layout decisions, design specifications, or prototypes before implementing a Web or mini program UI.
Document name: web-development - Document description: Use when users need to implement, integrate, debug, build, deploy, or validate a Web frontend after the product direction is already clear, especially for React, Vue, Vite, browser flows, or CloudBase Web integration.
OpenAPI documents (openapi) queries only need mode="openapi" and apiName — do not pass action; action is only used for mode="docs". Currently supports 8 API documents, they are: API name: mysqldb - API description: MySQL RESTful API - 云开发 MySQL 数据库 HTTP API API name: pgdb - API description: PostgreSQL RESTful API (PostgREST) - 云开发 PostgreSQL 数据库 HTTP API,含 exec-pgsql 直连 SQL API name: functions - API description: Cloud Functions API - 云函数 HTTP API API name: auth - API description: Authentication API - 身份认证 HTTP API API name: cloudrun - API description: CloudRun API - 云托管服务 HTTP API API name: storage - API description: Storage API - 云存储 HTTP API API name: nosql - API description: NoSQL RESTful API - 文档型数据库 HTTP API API name: ai_model - API description: AI 大模型接入 API - 统一 AI 模型 HTTP API API name: storage - API description: Storage API - Cloud Storage HTTP API API name: mysqldb - API description: MySQL RESTful API - CloudBase MySQL Database HTTP API API name: auth - API description: Authentication API - Identity Authentication HTTP API API name: cloudrun - API description: CloudRun API - CloudRun Service HTTP API
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
mode | string | Yes | Allowed values: "skill", "openapi", "docs" |
skillName | string | Specify when mode=skill. Skill name. Allowed values: "ai-model-nodejs", "ai-model-web", "ai-model-wechat", "auth-nodejs-cloudbase", "auth-tool-cloudbase", "auth-web-cloudbase", "auth-wechat-miniprogram", "cloud-api-operations", "cloud-functions", "cloud-storage-web", "cloudbase-agent", "cloudbase-cli", "cloudbase-code-review", "cloudbase-declarative-deploy", "cloudbase-document-database-in-wechat-miniprogram", "cloudbase-document-database-web-sdk", "cloudbase-platform", "cloudbase-wechat-integration", "cloudrun-development", "data-model-creation", "http-api-cloudbase", "minimal-web-baas-demo", "miniprogram-development", "ops-inspector", "postgresql-development-cloudbase", "relational-database-mcp-cloudbase", "relational-database-web-cloudbase", "spec-workflow", "ui-design", "web-development" | |
apiName | string | Specify when mode=openapi. API name. Allowed values: "mysqldb", "pgdb", "functions", "auth", "cloudrun", "storage", "nosql", "ai_model" | |
action | string | Specify when mode=docs. CloudBase documentation operation type: listModules=list all documentation modules, listModuleDocs=get directory structure of specified module, findByName=smart search by name/path/URL, readDoc=read specified documentation Markdown, searchDocs=full-text search official documentation. Allowed values: "listModules", "listModuleDocs", "findByName", "readDoc", "searchDocs" | |
moduleName | string | Specify when mode=docs and action=listModuleDocs. Module name. | |
input | string | Specify when mode=docs and action=findByName. Supports module name, document title, hierarchy path or URL. | |
docPath | string | Specify when mode=docs and action=readDoc. Document relative path or full URL. | |
query | string | Specify when mode=docs and action=searchDocs. Full-text search keywords. | |
threshold | number | Specify when mode=vector. Similarity retrieval threshold. Default: 0.5 | |
id | string | Specify when mode=vector. Knowledge base scope, defaults to cloudbase. cloudbase=CloudBase full knowledge, scf=CloudBase cloud functions knowledge, miniprogram=Mini Program knowledge (excluding CloudBase and cloud functions knowledge). Allowed values: "cloudbase", "scf", "miniprogram"; Default: "cloudbase" | |
content | string | Specify when mode=vector. Retrieval content | |
options | object | Specify when mode=vector. Other options | |
options.chunkExpand | array of number | Specify the expansion length for returned document content, e.g., [3,3] means expand 3 before and 3 after. Default: [3,3] | |
limit | number | Specify when mode=vector. Specify the value of K for returning Top K most similar results. Default: 5 |
queryCloudRun
Query CloudRun service information, supports getting service list, querying service details and getting available template list. Returned service information includes service name, status, access type, configuration details, etc.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Query operation type: list=get CloudRun service list (supports pagination and filtering), detail=query detailed information of specified service (including configuration, version, access address, etc.), templates=get available project template list (for initializing new projects). Allowed values: "list", "detail", "templates", "getDeployLog", "getProcessLog", "getDeployRecords", "envStatus" |
pageSize | number | Page size, controls number of services returned per page. Range: 1-100, default: 10. Adjust based on network performance and display requirements. Default: 10 | |
pageNum | number | Page number, for paginated queries. Starts from 1, default: 1. Use with pageSize for paginated browsing. Default: 1 | |
serverName | string | Service name filter condition, supports fuzzy matching. E.g., entering "test" matches "test-service", "my-test-app", etc. Leave empty to query all services | |
serverType | string | Service type filter condition: function=function-type CloudRun (Node.js only, has special development requirements and limitations, suitable for simple API services), container=container-type service (recommended, supports any language and framework like Java/Go/Python/PHP/.NET, suitable for most application scenarios). Allowed values: "function", "container" | |
detailServerName | string | Service name to query detailed information for. Required when action is detail, must be an existing service name. Available service names can be obtained via list operation |
manageCloudRun
Manage CloudRun services, supports in development order: initialize project (can start from template, template list can be queried through queryCloudRun), download service code, run locally (function mode services only), deploy code, delete service. Deployment can configure CPU, memory, instance count, access type and other parameters. Delete operation requires confirmation, it is recommended to set force=true.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | CloudRun service management operation type: init=initialize new CloudRun project code from template (creates subdirectory named serverName under targetPath, supports multiple language and framework templates), download=download existing service code from cloud to local for development, run=run function-type CloudRun service locally (for development and debugging, only supports function-type services), deploy=deploy local code to cloud CloudRun service (supports both function-type and container-type), delete=delete specified CloudRun service (irreversible, requires confirmation), createAgent=create function-type Agent (develop AI agents based on function-type CloudRun). Allowed values: "init", "download", "run", "deploy", "delete", "createAgent" |
serverName | string | Yes | CloudRun service name, used to identify and manage services. Naming rules: supports uppercase/lowercase letters, numbers, hyphens and underscores, must start with letter, length 3-45 characters. In init operation used as subdirectory name created under targetPath, in other operations as target service name |
targetPath | string | Local code path, must be absolute path. In deploy operation specifies code directory to deploy, in download operation specifies download target directory, in init operation specifies CloudRun service parent directory (will create subdirectory named serverName under this directory). Recommended convention: cloudrun/ directory under project root, e.g., /Users/username/projects/my-project/cloudrun | |
serverConfig | object | Service configuration items, used to set service runtime parameters during deployment. Includes resource specs, access permissions, environment variables and other configuration. Uses default configuration if not provided | |
serverConfig.OpenAccessTypes | array of string | Public network access type configuration, controls service access permissions: OA=office network access, PUBLIC=public network access (default, accessible via HTTPS domain), MINIAPP=mini program access, VPC=VPC access (only accessible within same VPC). Can configure multiple types | |
serverConfig.Cpu | number | CPU spec configuration, unit is cores. Options: 0.25, 0.5, 1, 2, 4, 8, etc. Note: Memory spec must be 2x CPU spec (e.g., CPU=0.25 then memory=0.5, CPU=1 then memory=2). Affects service performance and billing | |
serverConfig.Mem | number | Memory spec configuration, unit is GB. Options: 0.5, 1, 2, 4, 8, 16, etc. Note: Must be 2x CPU spec. Affects service performance and billing | |
serverConfig.MinNum | number | Minimum instance count configuration, controls minimum number of running service instances. Setting to 0 enables scale-to-zero (no cost when no requests), setting > 0 always keeps specified number of instances running (ensures fast response but increases cost). Recommended to set to 1 to reduce cold start latency and improve user experience | |
serverConfig.MaxNum | number | Maximum instance count configuration, controls maximum number of running service instances. When request volume increases, service can scale up to specified number of instances, beyond which new requests will be rejected. Recommended to set based on business peak | |
serverConfig.PolicyDetails | array of object | Scaling configuration array, used to configure service auto-scaling policies. Can configure multiple scaling policies | |
serverConfig.PolicyDetails[].PolicyType | string | Yes | Scaling type: cpu=CPU utilization-based scaling, mem=memory utilization-based scaling, cpu/mem=CPU and memory utilization-based scaling. Allowed values: "cpu", "mem", "cpu/mem" |
serverConfig.PolicyDetails[].PolicyThreshold | number | Yes | Scaling threshold, unit is percentage. E.g., 60 means trigger scaling when resource utilization reaches 60% |
serverConfig.CustomLogs | string | Custom log configuration, used to configure service log collection and storage policies | |
serverConfig.Port | number | Service listening port configuration. Function-type services fixed at 3000, container-type services can be customized. Service code must listen on this port to receive requests normally | |
serverConfig.EnvParams | string | Environment variable configuration, JSON string format. Used to pass configuration information to service code, e.g., '{"DATABASE_URL":"mysql://...","NODE_ENV":"production"}'. Sensitive information is recommended to use environment variables rather than hardcoding | |
serverConfig.Dockerfile | string | Dockerfile filename configuration, only required for container-type services. Specifies the Dockerfile file path for building container images, defaults to Dockerfile in project root | |
serverConfig.BuildDir | string | Build directory configuration, specifies the directory path for code building. Used when code structure differs from standard, defaults to project root | |
serverConfig.InternalAccess | string | Internal network access switch configuration, controls whether to enable internal network access. true=enable internal network access (can be called directly via CloudBase SDK), false=disable internal network access (public network access only) | |
serverConfig.InternalDomain | string | Internal network domain configuration, used to configure service internal network access domain. Only effective when internal network access is enabled | |
serverConfig.EntryPoint | array of string | Dockerfile EntryPoint parameter configuration, only required for container-type services. Specifies entry program array when container starts, e.g., ["node","app.js"] | |
serverConfig.Cmd | array of string | Dockerfile Cmd parameter configuration, only required for container-type services. Specifies default command array when container starts, e.g., ["npm","start"] | |
template | string | Project template identifier, used to specify template for project initialization. Available template list can be obtained via queryCloudRun templates operation. Common templates: helloworld=Hello World example, nodejs=Node.js project template, python=Python project template, etc. Default: "helloworld" | |
runOptions | object | Local run parameter configuration, only supports function-type CloudRun services. Used to configure local development environment run parameters, does not affect cloud deployment | |
runOptions.port | number | Local run port configuration, only effective for function-type services. Specifies the port number for service to listen on locally, default 3000. Ensure port is not occupied by other programs. Default: 3000 | |
runOptions.envParams | object | Additional environment variable configuration for local run, used for local development and debugging. Format is key-value pairs, e.g., {"DEBUG":"true","LOG_LEVEL":"debug"}. These variables only take effect when running locally | |
runOptions.runMode | string | Run mode: normal=normal function mode, agent=Agent mode (for AI agent development). Allowed values: "normal", "agent"; Default: "normal" | |
runOptions.agentId | string | Agent ID, used in agent mode to identify specific Agent instance | |
agentConfig | object | Agent configuration items, only used in createAgent operation | |
agentConfig.agentName | string | Yes | Agent name, used to generate BotId |
agentConfig.botTag | string | Bot tag, used to generate BotId, auto-generated if not provided | |
agentConfig.description | string | Agent description information | |
agentConfig.template | string | Agent template type, defaults to blank (blank template). Default: "blank" | |
force | boolean | Force operation switch, used to skip confirmation prompts. Defaults to false (requires confirmation), set to true to skip all confirmation steps. Strongly recommended to set to true for delete operations to avoid accidental operations. Default: false | |
serverType | string | Service type configuration: function=function-type CloudRun (Node.js only, has special development requirements and limitations, suitable for simple API services), container=container-type service (recommended, supports any language and framework like Java/Go/Python/PHP/.NET, suitable for most application scenarios). Auto-detected if not provided: 1) existing service type 2) has Dockerfile→container 3) has @cloudbase/aiagent-framework dependency→function 4) otherwise→container. Allowed values: "function", "container" |
deployBuild
Parses cloudbaserc and runs a local build for projects that declare buildCommand in hosting[] (it only executes buildCommand — it does not install dependencies and does not upload). Equivalent to the CLI's tcb app build, but it only handles hosting[] static hosting entries and is unrelated to the cloudbaserc app resource type (cloud build pipeline). Declarative hosting deployment is split into three steps — build → plan → apply — and this tool is the first step: build artifacts locally, then dry-run with deployPlan, and finally upload the artifacts with deployApply. deployApply no longer builds locally implicitly — hosting entries with a build command error out when artifacts are missing and point you here first. Pure static hosting (no buildCommand configured and no detectable framework) is skipped automatically. The build is a purely local operation: it does not resolve an environment, does not require login, and does not need confirm.
- cwd: Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
- mode: Environment name; merges the corresponding override config when it matches
envOverrides.<mode>
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
cwd | string | Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory | |
mode | string | Environment name (e.g. production/staging); merges overrides when it matches envOverrides.<mode> |
deployPlan
Parses cloudbaserc and computes a declarative deployment plan (dry-run — it produces no changes). This is the dry-run counterpart to deployApply: plan computes and deployApply executes the same cloudbaserc. It returns the action classification for each resource: create=new, update=overwrite update, skip=no change / will not run, conflict=conflict detected and must abort, deploy=direct upload overwrite. The plan has already been recomputed with yes into "the actions that will actually happen": when yes=true is not passed, functions that already exist in the cloud are marked skip (keeping update in declaredStatus), which matches what deployApply actually executes, so the dry-run never contradicts the real run.
Applicability boundary: this tool is for project-level declarative orchestration (one cloudbaserc for plan/apply); for one-off single-resource direct uploads use manageFunctions/manageHosting/manageApps.
- cwd: Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
- mode: Environment name; merges the corresponding override config when it matches
envOverrides.<mode> - envId: Target environment ID; takes precedence over the
envIdin cloudbaserc. When omitted, the configured value or the currently bound environment is used - only: Compute the plan only for the specified resource types
- skip: Skip the specified resource types
- yes: Aligned with deployApply's
yes, used to recompute the effective action for functions that already exist. true=dry-run as overwrite update; false (default)=dry-run as conservative skip
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
cwd | string | Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory | |
mode | string | Environment name (e.g. production/staging); merges overrides when it matches envOverrides.<mode> | |
envId | string | Target environment ID; takes precedence over the envId in cloudbaserc. When omitted, the configured value or the currently bound environment is used | |
only | array of string | Compute the plan only for the specified resource types. Available values: database/functions/app/hosting/gateway | |
skip | array of string | Skip the specified resource types. Available values: database/functions/app/hosting/gateway | |
yes | boolean | Aligned with deployApply's yes, used to recompute the effective action for functions that already exist. true=dry-run as overwrite update; false (default)=dry-run as conservative skip |
deployApply
Parses cloudbaserc and executes a declarative deployment in the order database→functions→app→hosting→gateway. This is the execution counterpart to deployPlan (plan dry-runs / deployApply executes the same cloudbaserc). It is a local-form apply (reads the local cloudbaserc, builds and uploads locally) and is a write operation that changes cloud resources, so it only runs when confirm=true is passed explicitly. Prefer running deployPlan first, then executing once the plan checks out.
Applicability boundary: this tool is for project-level declarative orchestration (one cloudbaserc for plan/apply); for one-off single-resource direct uploads use manageFunctions/manageHosting/manageApps.
- confirm: Must be explicitly passed as true for the deployment to run, otherwise it is rejected outright
- confirmDestructive: When the database migrations in this run contain destructive statements (DROP/TRUNCATE/DELETE, ALTER…DROP/RENAME),
confirmDestructive=truemust additionally be passed explicitly on top ofconfirm; otherwise it is rejected and the matching migrations and statements are listed. Has no effect when there are no destructive migrations - cwd: Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory
- mode: Environment name; merges the corresponding override config when it matches
envOverrides.<mode> - envId: Target environment ID; takes precedence over the
envIdin cloudbaserc. When omitted, the configured value or the currently bound environment is used - only: Deploy only the specified resource types
- skip: Skip the specified resource types
- yes: How to handle resources that already exist. true=overwrite and update directly; false (default)=conservatively skip, so existing resources are not overwritten in scenarios where interactive confirmation is impossible (consistent with deployPlan's
yessemantics) - concurrency: Maximum parallelism within a resource type, default 1 (serial)
- continueOnError: Continue deploying the remaining resources after one fails (a database failure still aborts forcibly)
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
confirm | boolean | Destructive-operation confirmation switch. Deployment changes cloud resources, so confirm=true must be passed explicitly for it to run | |
confirmDestructive | boolean | Destructive database change confirmation switch. When the pending migrations contain DROP/TRUNCATE/DELETE or ALTER…DROP/RENAME, confirmDestructive=true must additionally be passed explicitly on top of confirm=true; no effect when there are no destructive migrations | |
cwd | string | Project root directory; cloudbaserc is searched downward from here. Defaults to the current working directory | |
mode | string | Environment name (e.g. production/staging); merges overrides when it matches envOverrides.<mode> | |
envId | string | Target environment ID; takes precedence over the envId in cloudbaserc. When omitted, the configured value or the currently bound environment is used | |
only | array of string | Deploy only the specified resource types. Available values: database/functions/app/hosting/gateway | |
skip | array of string | Skip the specified resource types. Available values: database/functions/app/hosting/gateway | |
yes | boolean | Whether to overwrite and update resources that already exist. true=overwrite; false (default)=conservatively skip existing resources | |
concurrency | integer | Maximum parallelism within a resource type, default 1 (serial); only applies within a type, cross-type dependency order is unchanged | |
continueOnError | boolean | Whether to continue deploying the remaining resources after one fails; a database failure always aborts forcibly |
queryGateway
Unified read-only entry for the gateway domain. Query gateway domains, access entries, and target exposure status via action.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Read-only operation type, e.g., getAccess, listDomains. Allowed values: "getAccess", "listDomains", "listRoutes", "getRoute", "listCustomDomains" |
targetType | string | Target resource type. Currently supports function, extensible in future. Allowed values: "function" | |
targetName | string | Target resource name. Required for getAccess | |
routeId | string | Route ID. Optional for getRoute |
manageGateway
Unified write entry for the gateway domain. Create target access entries via action, with more general gateway configuration capabilities to follow.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Write operation type, e.g., createAccess. Allowed values: "createAccess", "createRoute", "updateRoute", "deleteRoute", "bindCustomDomain", "deleteCustomDomain", "deleteAccess", "updatePathAuth" |
targetType | string | Target resource type. Currently supports function, extensible in future. Allowed values: "function" | |
targetName | string | Target resource name | |
path | string | Access path, defaults to /{targetName} | |
type | string | Target function's own type (not access form). If the accessed function is Event type (default), pass Event here; only pass HTTP when the accessed function was created as HTTP function. Allowed values: "Event", "HTTP" | |
auth | boolean | Whether to enable authentication | |
route | object | HTTP route configuration object | |
route.routeId | string | ||
route.path | string | ||
route.serviceType | string | ||
route.serviceName | string | ||
route.auth | boolean | ||
domain | string | Custom domain | |
certificateId | string | Certificate ID | |
accessName | string | Access entry name, reserved field |
queryAppAuth
Read-only entry for application-side authentication configuration. Used to query login methods, providers, publishable key, API key, client configuration, and static domain authentication readiness status. If the business needs to accept plain username-style identifiers, first query action=getLoginConfig; if usernamePassword=false, the next step should immediately call manageAppAuth(action=patchLoginStrategy, patch={ usernamePassword: true }), do not directly write email login API.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Allowed values: "getLoginConfig", "listProviders", "getProvider", "getClientConfig", "getPublishableKey", "getStaticDomain", "listApiKeys" |
providerId | string | Provider identifier, e.g., email, google | |
clientId | string | OAuth client_id / DescribeClient Id; uses current environment ID (default client) when omitted | |
keyType | string | API key type filter, optional publish_key or api_key. Allowed values: "publish_key", "api_key" | |
pageNumber | integer | API key list page number, starts from 1 | |
pageSize | integer | API key list items per page |
manageAppAuth
Write entry for application-side authentication configuration. Used to modify login methods, providers, client configuration, ensure publishable key, and create or delete API keys and custom login keys. If the frontend needs to accept plain username-style identifiers, first execute action=patchLoginStrategy with patch={ usernamePassword: true }, then implement the corresponding frontend login logic.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Allowed values: "patchLoginStrategy", "addProvider", "updateProvider", "deleteProvider", "updateClientConfig", "ensurePublishableKey", "createApiKey", "deleteApiKey", "createCustomLoginKeys" |
patch | object | Simplified login strategy patch used by patchLoginStrategy, e.g., { usernamePassword: true } | |
providerId | string | Provider identifier, e.g., email, google; for addProvider can also be used as custom provider Id | |
providerType | string | Provider protocol type for addProvider, e.g., OAUTH, OIDC, EMAIL | |
displayName | string | object | Display name for addProvider, can pass string or multilingual object | |
clientId | string | Client Id for updateClientConfig; uses current environment ID when omitted | |
config | object | Provider / client configuration object | |
keyType | string | API key type for createApiKey, defaults to publish_key. Allowed values: "publish_key", "api_key" | |
keyName | string | API key name for createApiKey | |
expireIn | integer | Validity period for createApiKey, unit is seconds; 0 means no expiration | |
keyId | string | API key unique identifier for deleteApiKey |
queryApps
Query CloudBase apps and versions deployed via the app deploy feature. Can query the app list/details, version list/details; after deployment, poll build status with getAppVersion by buildId; getBuildLog queries build logs to diagnose failures.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Allowed values: "listApps", "getApp", "listAppVersions", "getAppVersion", "getBuildLog", "getUploadUrl" |
serviceName | string | CloudBase app service name. Required for getApp / listAppVersions / getAppVersion / getBuildLog; reuse the same serviceName after redeployment to query version history | |
searchKey | string | Fuzzy search keyword by app service name, only used when action=listApps | |
pageNo | number | Pagination page number, starting from 1 | |
pageSize | number | Pagination size | |
versionName | string | Version name. For getAppVersion, can be used alternatively with buildId; prefer passing it when the version number is known | |
buildId | string | Build ID. For getAppVersion, can be used alternatively with versionName; after deploy returns a BuildId you can poll status with it directly. Required for getBuildLog | |
start | number | Build log offset for paginating subsequent logs. Only used when action=getBuildLog; when omitted, returns from the beginning |
manageApps
Deploy web apps to CloudBase (build frontend and backend, deploy to an independent subdomain). action=getUploadUrl gets a presigned upload URL (used in cloud mode), returns the upload address and cosTimestamp. action=deployApp uploads a source ZIP and triggers the remote build/deploy pipeline:
- Remote npm install (can be skipped with installCmd="")
- Remote npm run build (can be skipped with buildCmd="")
- Remote tcb hosting deploy
Domain format: <serviceName>-<envId>.webapps.tcloudbase.com (each serviceName gets an independent subdomain)
✅ Recommended usage (new projects / web apps that need an independent domain, prefer this tool): On first deployment of a new project, pass framework=static, installCmd="", buildCmd="" to skip remote build, and only run tcb hosting deploy. After deployment you get an independent subdomain with version management.
⚠️ Compatibility notes:
- If an existing project was previously deployed with manageHosting (domain format:
<envId>-<appId>.tcloudbaseapp.com), switching to manageApps produces a brand new URL and old links break. Keep the original deployment method unchanged. - To check: call queryHosting to see if hosted files already exist.
Comparison with manageHosting:
- manageApps (this tool, preferred for new projects): domain
<serviceName>-<envId>.webapps.tcloudbase.com, independent subdomain, version management - manageHosting (existing projects or fallback): domain
<envId>-<appId>.tcloudbaseapp.com/<path>, shared environment domain Both can bind custom domains.
⚠️ If manageApps build fails, first check logs with queryApps(action="getBuildLog"); if still failing, fall back to manageHosting.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | yes | Allowed values: "deployApp", "getUploadUrl", "deleteApp", "deleteAppVersion" |
serviceName | string | yes | CloudBase app service name, reflected in the domain: <serviceName>-<envId>.webapps.tcloudbase.com. For deployApp, reusing an existing serviceName adds a new deployment version and triggers redeployment rather than delete-and-recreate. Use a new name for first deployment |
filePath | string | Absolute path to the local project root to upload and deploy. Required for deployApp in local mode; usually the source directory (containing package.json and source), not the dist directory. Specify the build output directory with buildPath. Not needed in cloud mode; use cosTimestamp instead | |
cosTimestamp | string | Optional COS timestamp. Passing this value creates the app directly from already-uploaded code, skipping local file upload. First call getUploadUrl to get a presigned URL, upload the ZIP, then pass this timestamp. Required in cloud mode; local mode can also pass it instead of filePath. Use one of the two: filePath (local packaging upload) or cosTimestamp (presigned URL upload) | |
appPath | string | App online access path (hosting mount path), e.g. /my-web-app. Not a local directory path; CloudApp already has an independent subdomain, defaults to / (root) when omitted | |
buildPath | string | Build output directory, relative to filePath, e.g. dist or build. ⚠️ When passed, the remote build system cds into this directory before running tcb hosting deploy, so deployCmd automatically uses . (current directory) instead of the directory name to avoid path duplication (e.g. dist/dist). Can be omitted for pure static HTML at the project root, but note deployCmd defaults to dist | |
framework | string | Frontend framework type. Options: vue, react, next, nuxt, vite, angular, static. Even when passing static, it still goes through the remote build pipeline. If already built locally, consider manageHosting to upload directly and skip remote build entirely. Allowed values: "vue", "react", "next", "nuxt", "vite", "angular", "static" | |
nodeJsVersion | string | Node.js version used for the build; CloudBase uses its default when omitted | |
installCmd | string | Dependency install command, e.g. npm install. Defaults to npm install. If already installed locally or no install needed, pass an empty string '' to skip, but the remote still runs tcb hosting deploy | |
buildCmd | string | Build command, e.g. npm run build. Defaults to npm run build. If already built locally, pass an empty string '' to skip the build step. To skip the remote pipeline entirely, use manageHosting | |
deployCmd | string | Custom deploy command. Usually not needed; a tcb hosting deploy command is generated by default. With buildPath the remote already cds into that directory and uses . as the source path; without buildPath it defaults to dist | |
ignore | array of string | File/directory glob patterns to ignore when uploading, e.g. /node_modules/ | |
versionName | string | Historical version name to delete, required only when action=deleteAppVersion |
queryPermissions
Unified read-only entry for the permissions domain. Supports querying resource permissions, role list/details, and application user list/details.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Allowed values: "getResourcePermission", "listResourcePermissions", "listRoles", "getRole", "listUsers", "getUser" |
resourceType | string | Allowed values: "noSqlDatabase", "sqlDatabase", "function", "storage" | |
resourceId | string | ||
resourceIds | array of string | ||
roleId | string | ||
roleIdentity | string | ||
roleName | string | ||
uid | string | ||
username | string | ||
pageNo | number | ||
pageSize | number |
managePermissions
Unified write entry for the permissions domain. Supports modifying resource permissions, role management, member and policy add/remove, and application user CRUD. createUser / updateUser are environment-side application user management capabilities, suitable for test accounts, administrators, or preset users, and should not replace browser-side Web SDK registration forms; frontend username password registration should use auth.signUp({ username, password }), login should use auth.signInWithPassword({ username, password }). Note: The detailed semantics of securityRule depend on resourceType; doc._openid, auth.openid, query condition subset validation, and create / update / delete JSON templates only apply to resourceType="noSqlDatabase" document database security rules. When configuring function or storage, please refer to their respective official security rule documentation, not reuse NoSQL templates.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Allowed values: "updateResourcePermission", "createRole", "updateRole", "deleteRoles", "addRoleMembers", "removeRoleMembers", "addRolePolicies", "removeRolePolicies", "createUser", "updateUser", "deleteUsers", "setPolicy" |
resourceType | string | Target resource type. The specific semantics of securityRule depend on this value; noSqlDatabase uses collection security rules, function and storage also have their own independent security rule semantics, do not apply NoSQL rule syntax. Allowed values: "noSqlDatabase", "sqlDatabase", "function", "storage" | |
resourceId | string | ||
permission | string | Allowed values: "READONLY", "PRIVATE", "ADMINWRITE", "ADMINONLY", "CUSTOM" | |
securityRule | string | Resource type-specific rule content, detailed semantics depend on resourceType. When resourceType="noSqlDatabase" and permission="CUSTOM", should pass document database security rule JSON (document database rules: https://docs.cloudbase.net/database/security-rules); keys are typically read / create / update / delete, values are expressions. Important: create rule validates written data, document doesn't exist yet at this point, cannot use doc.*; read / update / delete rules can use doc.* to reference existing document fields. Do not misuse doc._openid, auth.openid, query condition subset validation or create / update / delete templates for function, storage or sqlDatabase. For configuring function or storage, please refer to official security rule documentation: cloud functions https://docs.cloudbase.net/cloud-function/security-rules, cloud storage https://docs.cloudbase.net/storage/security-rules. Example: {"read":"auth.uid != null","create":"auth.uid != null && auth.loginType != \"ANONYMOUS\"","update":"auth.uid != null && doc._openid == auth.openid","delete":"auth.uid != null && doc._openid == auth.openid"} | |
roleId | string | ||
roleIds | array of string | ||
roleName | string | ||
roleIdentity | string | ||
description | string | ||
memberUids | array of string | ||
policies | array of object | ||
uid | string | ||
uids | array of string | ||
username | string | ||
password | string | ||
userStatus | string | Allowed values: "ACTIVE", "BLOCKED" |
queryLogs
Unified read-only entry for the logs domain. Supports checking log service status and searching CLS logs.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Allowed values: "checkLogService", "searchLogs" |
queryString | string | ||
service | string | Allowed values: "tcb", "tcbr" | |
startTime | string | ||
endTime | string | ||
limit | number | ||
context | string | ||
sort | string | Allowed values: "asc", "desc" |
queryAgents
Unified read-only entry for the Agent domain. Supports listing, details, and log queries.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Allowed values: "listAgents", "getAgent", "getAgentLogs" |
agentId | string | ||
pageNumber | number | ||
pageSize | number | ||
params | object |
manageAgents
Unified write entry for the Agent domain. Supports creating, updating, and deleting remote Agents.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Allowed values: "createAgent", "updateAgent", "deleteAgent" |
agentId | string | ||
params | object |
callCloudApi
General cloud API calling tool, mainly used for CloudBase / Tencent Cloud management plane and dependent resource related API calls. Read the interface index before calling: https://docs.cloudbase.net/ai/cloudbase-ai-toolkit/api-reference.md (an Action-level index synced daily, including rate limits; check this index first to confirm service/Action/parameters so you never guess an Action name; for products the index does not cover, verify against that product's official API docs). If your goal is to directly integrate auth/functions/cloudrun/storage/mysqldb and other CloudBase business APIs via HTTP protocol, do not prioritize using callCloudApi, instead prioritize checking the corresponding OpenAPI / Swagger. The existing OpenAPI / Swagger capabilities are not a general management plane Action collection; for management plane APIs, please prioritize referring to CloudBase API Overview https://cloud.tencent.com/document/product/876/34809 and CloudBase Dependent Resource API Guide https://cloud.tencent.com/document/product/876/34808. For tcb service, common Action categories are as follows:
Environment Management: CreateEnv, ModifyEnv, DescribeEnvs, DestroyEnv
User Management: CreateUser, ModifyUser, DescribeUserList, DeleteUsers
Authentication Configuration: EditAuthConfig, DescribeAuthDomains
Cloud Functions: DescribeFunctions, CreateFunction, UpdateFunctionCode, DeleteFunction
Database: CreateMySQLInstance, DescribeMySQLInstances, DestroyMySQLInstance
When destroying an environment, the common practice is to at least include EnvId and BypassCheck: true; if the environment is already in isolation period, add IsForce: true per documentation.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
service | string | Yes | Tencent Cloud product identifier. Values may only come from this field's enum whitelist (57 in total), which determines the request domain https://<service>.tencentcloudapi.com. Values outside the list are rejected — do not invent them; COS is not part of the cloud API system. See the cloud-api-operations skill for the product-to-Action mapping. CloudRun always goes through tcbr. Allowed values: "tcb", "tcbr", "scf", "sts", "cam", "cloudaudit", "tag", "billing", "region", "cvm", "lighthouse", "tke", "cbs", "cfs", "tcr", "cdb", "mariadb", "postgres", "sqlserver", "redis", "mongodb", "cynosdb", "dcdb", "tcaplusdb", "keewidb", "vpc", "clb", "cdn", "ecdn", "dnspod", "privatedns", "domain", "ssl", "teo", "gaap", "kms", "ssm", "waf", "cwp", "tcss", "ckafka", "tdmq", "tdmysql", "apigateway", "monitor", "cls", "apm", "tsf", "tat", "hunyuan", "lkeap", "tts", "trtc", "live", "vod", "sms", "ses" |
action | string | Yes | Specific Action name, must conform to the corresponding service's official API definition. When unsure, check the official documentation first — do not guess from synonyms or historical names (a wrong guess surfaces as an invalid-action server error that is hard to diagnose). See the cloud-api-operations skill for common Actions. |
params | object | Parameter object corresponding to the Action; key names match the official API definition — check the docs first when unsure. Do not put Region here; use the top-level region for cross-region calls. For CloudBase business APIs prefer searchKnowledgeBase(mode="openapi") rather than this tool. Examples are in the cloud-api-operations skill. | |
version | string | API version (omittable in most cases). Products with only one official version in the whitelist are auto-filled and need not pass it; the following multi-version products must pass it explicitly, otherwise an error listing the available options is returned: tke, mongodb, teo, monitor, vod, sms. Example: service="tcbr", version="2022-02-17", action="CreateCloudRunEnv", params={EnvId:"env-xxx",PackageType:"Standard"}; service="monitor" must explicitly pass "2018-07-24" (the alarm-policy Action family belongs to that version). | |
region | string | Cloud API region (X-TC-Region), e.g. ap-shanghai. Cross-region calls must pass this top-level parameter — do not write it into params. ⚠️ ap-singapore belongs to both the China site and the international site; when no site is specified it is treated as the international site (site=intl): to operate on that region on the China site, call auth(action="start_auth", site="domestic") or set TCB_SITE=domestic first. |
queryMessagePush
Query Mini Program cloud development message push configuration (qbase getappconfig) or all valid message push event constraints (getcallbacksupportlist). There are two push modes: cloud function (default, callback per (msgType, event)) and CloudRun (qbase_open=true, receives all messages in bulk to container path). action=list also returns pushMode (cloudfunction|container), containerConfig, callbacks, and version; in CloudRun mode, callbacks may still exist but are not effective (see note), use ensureCloudFunctionMode to switch back to cloud function mode before callbacks take effect. action=listSupportedEvents returns all valid constraints (grouped by message type). Requires WeChat IDE login session channel (host-injected cloudBaseOptions.requestFn).
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
appid | string | Yes | Mini Program AppID (required, consistent with WeChat Developer Tools; used to select WeChat login session) |
env | string | Optional: Environment ID; when passed, list only returns subscription entries for that environment | |
action | string | Yes | list: Query current message push configuration list (includes pushMode/containerConfig). listSupportedEvents: Query all valid message push event constraints (grouped by msgType). Allowed values: "list", "listSupportedEvents" |
manageMessagePush
Manage Mini Program cloud development message push configuration (write operations, requires confirm="yes" confirmation). Push modes: cloud function (default, callback per (msgType, event)) vs CloudRun (bulk reception; in CloudRun mode subscribe/unsubscribe/setEnable will be rejected, use ensureCloudFunctionMode first). Implements declarative idempotency based on "read full → merge → full overwrite (with version optimistic lock)". msg_type defaults to "event"; message types use msg_type=text|image|voice|video|miniprogrampage. action=subscribe validates that function_name actually exists in the environment before proceeding. action=ensureCloudFunctionMode disables CloudRun bulk reception; action=ensureContainerMode enables CloudRun (requires qbase_container_path/qbase_env/text_mode); action=setContainerCallback updates CloudRun path/env/text_mode. No write request is sent when the collection has no changes (idempotent no-op). Requires WeChat IDE login session channel.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
appid | string | Yes | Mini Program AppID (required, consistent with WeChat Developer Tools; used to select WeChat login session) |
env_id | string | Yes | Environment ID (cloud development environment bound to cloud function subscriptions; also serves as default CloudRun environment when qbase_env is not passed for ensureContainerMode/setContainerCallback) |
function_name | string | Yes | Cloud function name to receive message push (used by subscribe/unsubscribe/setEnable/ensureCloudFunctionMode; CloudRun-related actions can pass a placeholder) |
action | string | Yes | subscribe: Subscribe to specified cloud function (rejected in CloudRun mode). unsubscribe: Remove matching subscription (rejected in CloudRun mode). setEnable: Enable/disable matching subscription (rejected in CloudRun mode). ensureCloudFunctionMode: Switch to cloud function push mode (disable qbase_open). ensureContainerMode: Switch to CloudRun bulk reception (requires qbase_container_path + text_mode). setContainerCallback: Update CloudRun callback path/env/text_mode. Allowed values: "subscribe", "unsubscribe", "setEnable", "ensureCloudFunctionMode", "ensureContainerMode", "setContainerCallback" |
msg_type | string | Message type (defaults to "event"). "event": Event-type entries, used with event_types (subscribe defaults to virtual payment 7 events when omitted). "text"|"image"|"voice"|"video"|"miniprogrampage": Message type entries (event is always empty string), do not pass event_types. Allowed values: "event", "text", "image", "voice", "video", "miniprogrampage" | |
event_types | array of string | Event list to operate on (only used when msg_type="event"; can first query all constraints via queryMessagePush(action=listSupportedEvents)). subscribe defaults to subscribing to virtual payment 7 events when omitted; required for unsubscribe / setEnable when msg_type=event. | |
enable | boolean | Required for setEnable: true to enable subscription / false to disable subscription | |
qbase_container_path | string | CloudRun callback path/URL (required for ensureContainerMode; optional update for setContainerCallback) | |
qbase_env | string | CloudRun service environment ID (optional for ensureContainerMode/setContainerCallback; defaults to env_id when omitted) | |
text_mode | number | CloudRun message body encoding: 1=json, 2=xml (required for ensureContainerMode; optional update for setContainerCallback). Allowed values: 1, 2 | |
confirm | string | Write operation confirmation: pass confirm="yes" to confirm execution; returns a pending configuration summary (CONFIRM_REQUIRED) when omitted or other value is passed, review and retry. No confirmation needed when the collection has no changes. |