{"id":"97cde980-e033-4977-bd32-8f1c395a0576","entityType":"agent","slug":"clawhub-binggg-cloudbase-wechat-integration","name":"微信生态集成 · WeChat Integration","canonicalUrl":"https://www.xpersona.co/agent/clawhub-binggg-cloudbase-wechat-integration","canonicalPath":"/agent/clawhub-binggg-cloudbase-wechat-integration","generatedAt":"2026-10-09T13:48:31.351Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T07:34:55.285Z","emptyReason":null},"description":"CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 3.6K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17cgdbxp195f7dy8f5h6p0d9183h6nq:cloudbase-wechat-integration","sourceUrl":"https://clawhub.ai/binggg/cloudbase-wechat-integration","homepage":"https://clawhub.ai/binggg/skills/cloudbase-wechat-integration","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/binggg/cloudbase-wechat-integration","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/binggg/skills/cloudbase-wechat-integration","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":71,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"微信生态集成 · WeChat Integration technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T07:34:55.285Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T07:34:55.285Z","emptyReason":null},"stars":null,"forks":null,"downloads":3574,"packageName":null,"latestVersion":"1.2.57","tractionLabel":"3.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T07:34:55.284Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T07:34:55.285Z","lastCrawledAt":"2026-10-09T07:34:55.284Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T07:34:55.284Z","lastVerifiedAt":null,"highlights":[{"version":"1.2.57","createdAt":"2026-10-09T05:41:53.531Z","changelog":"Recent commits / 最近提交: | - fix(env): 🐛 stop shipping package IDs that do not exist (#1136) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - feat(mcp): retire MySQL provisioning from the tool surface (#1137) | - chore(deps): 🔒 把安全 overrides 顶到已修复版本 (#1135)","fileCount":10,"zipByteSize":17458},{"version":"1.2.56","createdAt":"2026-10-09T04:35:12.526Z","changelog":"Recent commits / 最近提交: | - feat(mcp): retire MySQL provisioning from the tool surface (#1137) | - chore(deps): 🔒 把安全 overrides 顶到已修复版本 (#1135) | - feat(mcp): harden hosted requests without a shared server (#1133) | - fix(mcp): 🔐 让项目级凭据优先于账号级登录态 (#1134) | - docs: 🔄 sync CloudBase CloudAPI reference page","fileCount":10,"zipByteSize":17381},{"version":"1.2.55","createdAt":"2026-09-30T13:29:16.622Z","changelog":"Recent commits / 最近提交: | - fix(clawhub): 🏷️ publish the curated display name and topics (#1124) | - docs: 🔄 sync CloudBase CloudAPI reference page | - feat(evals): ✨ score the secret and migration tasks (#1122) | - feat(evals): add the scenario runner and point it at a local endpoint (#1119) | - fix(mcp): 🔧 report local endpoint failures directly (#1118)","fileCount":10,"zipByteSize":17384},{"version":"1.2.54","createdAt":"2026-09-30T06:00:05.845Z","changelog":"Recent commits / 最近提交: | - chore(release): bump version to v2.34.8 | - fix(mcp): 🔒 bind the two-phase function deploy to the upload target it signed (#1114) | - feat(mcp): route cloud API calls to a local endpoint (#1116) | - feat(evals): ✨ point the public dry run at a scored task (#1113) | - fix(dsh-plugin): 📝 describe database, storage, auth, and deploy (#1117)","fileCount":10,"zipByteSize":17488},{"version":"1.2.53","createdAt":"2026-09-21T13:17:43.690Z","changelog":"Recent commits / 最近提交: | - chore(release): bump version to v2.34.6 | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - chore(experts): auto-bump versions for changed packs [skip ci] | - Merge branch 'feat/function-publish-version-9cb1bf6e'","fileCount":10,"zipByteSize":17975},{"version":"1.2.52","createdAt":"2026-09-20T09:07:10.076Z","changelog":"Recent commits / 最近提交: | - chore(release): bump version to v2.34.5 | - fix(internal-sync): 🧹 keep atomic-write temp files out of the archive (#1070) | - chore(experts): auto-bump versions for changed packs [skip ci] | - chore(dsh-plugin): bump version to 0.1.2 | - chore(experts): auto-bump versions for changed packs [skip ci]","fileCount":10,"zipByteSize":17863},{"version":"1.2.51","createdAt":"2026-09-16T09:27:40.879Z","changelog":"Recent commits / 最近提交: | - chore(release): bump version to v2.34.4 | - chore: sync cloudbase plugin skills from upstream | - feat(skills): 📚 add PostgreSQL access-pattern best practices (#1046) | - fix(mcp): 🧭 按 OpenAI hosted Scan 收紧工具注解 (#1047) | - docs: 🔄 sync CloudBase CloudAPI reference page","fileCount":10,"zipByteSize":17866},{"version":"1.2.50","createdAt":"2026-09-14T05:00:10.934Z","changelog":"Recent commits / 最近提交: | - chore(release): bump version to v2.34.3 | - fix(mcp): 🐛 harden hosted tool contracts and error signalling (#1039) | - fix(ci): 🔧 run the plugin-skill pull-back after the upstream push (#1038) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source","fileCount":10,"zipByteSize":17966}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17cgdbxp195f7dy8f5h6p0d9183h6nq:cloudbase-wechat-integration","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17cgdbxp195f7dy8f5h6p0d9183h6nq:cloudbase-wechat-integration` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/binggg/cloudbase-wechat-integration before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T13:48:31.346Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase-wechat-integration/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T07:34:55.285Z","emptyReason":null},"readme":"Skill: 微信生态集成 · WeChat Integration\n\nOwner: binggg\n\nSummary: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.\n\nTags: latest:1.2.57\n\nVersion history:\n\nv1.2.57 | 2026-10-09T05:41:53.531Z | user\n\nRecent commits / 最近提交: | - fix(env): 🐛 stop shipping package IDs that do not exist (#1136) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - feat(mcp): retire MySQL provisioning from the tool surface (#1137) | - chore(deps): 🔒 把安全 overrides 顶到已修复版本 (#1135)\n\nv1.2.56 | 2026-10-09T04:35:12.526Z | user\n\nRecent commits / 最近提交: | - feat(mcp): retire MySQL provisioning from the tool surface (#1137) | - chore(deps): 🔒 把安全 overrides 顶到已修复版本 (#1135) | - feat(mcp): harden hosted requests without a shared server (#1133) | - fix(mcp): 🔐 让项目级凭据优先于账号级登录态 (#1134) | - docs: 🔄 sync CloudBase CloudAPI reference page\n\nv1.2.55 | 2026-09-30T13:29:16.622Z | user\n\nRecent commits / 最近提交: | - fix(clawhub): 🏷️ publish the curated display name and topics (#1124) | - docs: 🔄 sync CloudBase CloudAPI reference page | - feat(evals): ✨ score the secret and migration tasks (#1122) | - feat(evals): add the scenario runner and point it at a local endpoint (#1119) | - fix(mcp): 🔧 report local endpoint failures directly (#1118)\n\nv1.2.54 | 2026-09-30T06:00:05.845Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.8 | - fix(mcp): 🔒 bind the two-phase function deploy to the upload target it signed (#1114) | - feat(mcp): route cloud API calls to a local endpoint (#1116) | - feat(evals): ✨ point the public dry run at a scored task (#1113) | - fix(dsh-plugin): 📝 describe database, storage, auth, and deploy (#1117)\n\nv1.2.53 | 2026-09-21T13:17:43.690Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.6 | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - chore(experts): auto-bump versions for changed packs [skip ci] | - Merge branch 'feat/function-publish-version-9cb1bf6e'\n\nv1.2.52 | 2026-09-20T09:07:10.076Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.5 | - fix(internal-sync): 🧹 keep atomic-write temp files out of the archive (#1070) | - chore(experts): auto-bump versions for changed packs [skip ci] | - chore(dsh-plugin): bump version to 0.1.2 | - chore(experts): auto-bump versions for changed packs [skip ci]\n\nv1.2.51 | 2026-09-16T09:27:40.879Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.4 | - chore: sync cloudbase plugin skills from upstream | - feat(skills): 📚 add PostgreSQL access-pattern best practices (#1046) | - fix(mcp): 🧭 按 OpenAI hosted Scan 收紧工具注解 (#1047) | - docs: 🔄 sync CloudBase CloudAPI reference page\n\nv1.2.50 | 2026-09-14T05:00:10.934Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.3 | - fix(mcp): 🐛 harden hosted tool contracts and error signalling (#1039) | - fix(ci): 🔧 run the plugin-skill pull-back after the upstream push (#1038) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source\n\nv1.2.49 | 2026-09-13T16:24:48.113Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.2 | - fix(mcp): 🐛 align the login_by_api_key hint with the parameter the tool reads (envId → apiKeyEnvId) (#1037) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source | - chore(release): bump version to v2.34.1\n\nv1.2.48 | 2026-09-13T15:49:48.149Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.1 | - chore: sync cloudbase plugin skills from upstream | - chore(experts): auto-bump versions for changed packs [skip ci] | - feat: 把部署后分享环节送到专家包与实际部署路径上 (#1036) | - fix(mcp): keep the OpenAPI doc list order stable across builds (#1035)\n\nv1.2.47 | 2026-09-13T14:39:12.926Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.0 | - chore(release): refresh generated tools artifacts | - chore(gitignore): 忽略 plugin 发布产物的带时间戳变体 | - fix(mcp): 放宽 STS 资源级 E2E 的超时预算，消除云存储用例偶发超时 (#1034) | - fix(tools): CNB 链接存活检查区分「待合并后可见」，并刷掉自己的 compat 欠账 (#1033)\n\nv1.2.46 | 2026-09-13T12:27:10.969Z | user\n\nRecent commits / 最近提交: | - fix(docs): point skill docs at the site's current Markdown addresses (#1032) | - chore: sync cloudbase plugin skills from upstream | - feat(mcp): runtime-guard param-level i18n and cap describe length (#1030) | - chore: sync cloudbase plugin skills from upstream | - feat(mcp): callCloudApi 服务白名单扩至 57 个并内置版本映射 (#1029)\n\nv1.2.45 | 2026-09-08T12:44:24.790Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.33.2 | - chore: sync claude skills mirror from source | - Merge pull request #980 from yulinlin2020/feature/deploy0831 | - Merge pull request #1009 from TencentCloudBase/feat/webdev-expert-prereq-checks | - feat(experts): add connector & skill prerequisite checks to cloudbase-webdev-expert\n\nv1.2.44 | 2026-09-08T04:15:08.074Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.33.1 | - chore(release): build artifacts for v2.33.1 | - Merge branch 'feature/tool-naming-env-domain-converge' | - feat(telemetry): add client param and region/site reporting for hosted MCP | - Merge pull request #1006 from TencentCloudBase/fix/intl-device-flow-auth-url\n\nv1.2.43 | 2026-09-04T09:44:47.511Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.33.0 (eea512f9) | - feat(functions): 支持云函数自定义镜像部署与异步部署状态查询 (#985) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source | - refactor(env): converge env domain tool naming into query*/manage* system (#997)\n\nv1.2.42 | 2026-09-04T02:47:59.024Z | user\n\nRecent commits / 最近提交: | - feat(skills): add mini program virtual payment reference (#988) | - fix(apps): harden cloud-mode deployApp localPath gate (e5dcba51) (#984) | - feat(env-binding): use cloudbaserc.json as field-level binding fallback (#987) | - fix(issue-auto): 🤖 attempt fix for issue #982 (#983) | - feat(experts): attach expert package zips to release assets (#986)\n\nv1.2.41 | 2026-09-01T10:32:19.007Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.32.5 (4e6ca71c) | - fix(auth): international-site (TCB_SITE=intl) API key routing, device flow and diagnostics (#972) | - fix(mcp): queryEnv(list) pin to bound env for hosted OAuth token (环境级 STS) (#968) | - refactor(rag): remove vector mode from searchKnowledgeBase (#973) | - fix(cloudrun): mask service env params by default in queryCloudRun detail (#975)\n\nv1.2.40 | 2026-08-28T04:13:48.894Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.32.4 (a9cd97d2) | - chore: sync claude skills mirror from source | - fix(auth): give OTP sdkHints full call context and messageId caution (#964) | - chore: sync cloudbase plugin skills from upstream | - docs(release): add v2.32.3 release notes (7b513c4e)\n\nv1.2.39 | 2026-08-26T13:12:17.952Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.32.3 (7b513c4e) | - fix(auth): 🔧 resolve ambiguous-region credentials from the only usable site slot (#962) | - fix(tests): 🔨 retry temp dir cleanup in cloudbase-sites-plugin tests (#961) | - feat(pg): default ExecutePGSql role to cloudbase_postgres, reserve cloudbase_admin (#959) | - feat(dsh-plugin): @cloudbase/dsh-plugin — CloudBase backend for DeepSeek Harness (#933)\n\nv1.2.38 | 2026-08-25T10:25:25.539Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.32.2 (eec8ec79) | - Merge pull request #958 from TencentCloudBase/feat/msg-push-container-mode | - chore(deps): ⬆️ bump @cloudbase/manager-node to 5.8.2 (requestFn support, MR !150) | - Merge pull request #956 from TencentCloudBase/feat/git-guard-pre-push | - Revert \"fix(nosql): 🐛 route tcb-domain DB calls via requestFn when present (WeChat IDE has no Tencent creds) (dc0eaaf9)\"\n\nv1.2.37 | 2026-08-25T05:03:13.999Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.32.1 (82a92358) | - Merge pull request #957 from TencentCloudBase/feat/msg-push-container-mode | - docs(skill): 🔧 use WeChat-side tool names (cloud_query_msg_push/cloud_manage_msg_push) in skill docs (dc0eaaf9) | - docs(skill): 📚 add push-mode (cloudfunction/container) chapter to message-push reference (dc0eaaf9) | - fix(msg-push): ⚠️ degrade function-existence check when host hook absent (compat with WeChat IDE, dc0eaaf9)\n\nv1.2.36 | 2026-08-24T13:04:35.683Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.32.0 (e30ee663) | - chore: sync cloudbase plugin skills from upstream | - Merge pull request #949 from TencentCloudBase/feat/virtual-payment-mcp | - fix(skill): 📏 compress miniprogram-development description under Codex 1024-char limit (dc0eaaf9) | - Merge remote-tracking branch 'origin/main' into feat/virtual-payment-mcp\n\nv1.2.35 | 2026-08-20T15:26:19.158Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.31.0 (7efa4dd50) | - Merge pull request #947 from TencentCloudBase/feat/getdeploylog-coding-fix | - fix(cloudrun): 🔧 align getDeployLog coding fallback next_step action union (b2cb3661) | - task: queryCloudRun getDeployLog 遇 CODING 未登录改 (18efa60c) | - chore: sync cloudbase plugin skills from upstream\n\nv1.2.34 | 2026-08-20T12:17:02.806Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.30.1 (9326243c1) | - Merge pull request #944 from TencentCloudBase/feat/kimi-plugin-zip-cleanup | - refactor(kimi): 🧹 assemble sibling skills into cloudbase/references | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source\n\nv1.2.33 | 2026-08-20T07:59:39.271Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.30.0 (a84f982e) | - Merge pull request #943 from TencentCloudBase/feat/kimi-plugin-zip-cleanup | - refactor(kimi): 🧹 whitelist-only zip with version-free asset name | - Merge pull request #942 from TencentCloudBase/feat/mcp-region-env-scope | - chore: sync claude skills mirror from source\n\nv1.2.32 | 2026-08-20T07:30:29.241Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.29.0 (3636e6c7) | - Merge pull request #941 from TencentCloudBase/feat/kimi-plugin-publish | - feat(kimi): 📦 pack Kimi plugin zip and attach to release assets | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source\n\nv1.2.31 | 2026-08-18T12:03:01.593Z | user\n\nRecent commits / 最近提交: | - chore(release): merge main into v2.28.1 bump (52383793) | - Merge pull request #932 from TencentCloudBase/feat/kimi-plugin-shared-manifest | - chore(release): 🚀 bump version to v2.28.1 (52383793) | - fix(kimi): drop tcb CLI from skillInstructions — login via MCP auth tool | - docs(kimi): align interface copy with Vercel/Supabase Codex plugin pattern\n\nv1.2.30 | 2026-08-18T02:37:59.612Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.28.0 (5520bd3b) | - Merge pull request #926 from TencentCloudBase/task/cloudbase-mcp-20260818 | - fix(compat): pass-through copies only git-tracked files; refresh baseline without gitignored skills | - fix(compat): support .yaml/.yml in compat baseline classifier + refresh baseline | - docs(cloudrun): add container deploy failure SOP (bde80f9c)\n\nv1.2.29 | 2026-08-14T16:20:58.002Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.27.0 | - chore(release): 🛠️ refresh generated tools docs before v2.27.0 | - Merge pull request #909 from TencentCloudBase/fix/remove-download-path-test | - fix: 移除 downloadRemoteFile 遗留集成测试与文档分类映射 | - Merge pull request #908 from TencentCloudBase/feat/remove-downloadRemoteFile\n\nv1.2.28 | 2026-08-10T02:57:59.513Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.26.0 | - chore(release): 🛠️ refresh generated tools docs before v2.26.0 | - feat(gateway): 🔌 add enableRoute/disableRoute for gateway routes (#901) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source\n\nv1.2.27 | 2026-08-05T10:23:57.405Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.25.10 | - fix(ci): 🩹 refresh compat baseline after codebuddy plugin.json change (#892) | - fix(deps): 🔒 upgrade MCP SDK to 1.30.0 and retain category annotations (#873) | - fix(env): detect RuntimeBackends.nosql from flexdb tnt InstanceId (#891) | - fix(partner): 🩹 post-#886 prewarm cleanup, skill install path, CI sync (#888)\n\nv1.2.26 | 2026-08-05T09:09:32.006Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.25.9 | - fix(ci): 📦 install examples scripts deps before build-zips (#890) | - feat(skills): add minimal-web-baas-demo and publish path (#886) | - docs(marketplace): mark Trae community MCP and skills listed (#885) | - chore(ci): ⬆️ bump clawhub CLI pin to 0.23.3 after upload-ticket fix (#884)\n\nv1.2.25 | 2026-08-05T05:51:28.944Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.25.8 | - fix(cli): break cloud-mode↔logger cycle crashing --cloud-mode (#879) | - Merge pull request #877 from TencentCloudBase/docs/awesome-copilot-intake-rerun-status | - docs(marketplace): ✅ note Awesome Copilot intake re-pass and ready-for-review | - docs(marketplace): 📝 record Awesome Copilot intake re-pass after skill-fetch strip\n\nv1.2.24 | 2026-08-05T04:24:08.871Z | user\n\nRecent commits / 最近提交: | - Merge pull request #875 from TencentCloudBase/fix/awesome-copilot-strip-remote-skill-urls | - fix(security): 🛡️ strip remote skill-fetch URLs for Copilot review | - chore: sync claude skills mirror from source | - chore(release): 🚀 bump version to v2.25.7 | - fix(ci): 🛡️ use rsync --checksum for skills repo sync (#874)\n\nv1.2.23 | 2026-08-05T03:41:04.883Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.25.7 | - fix(ci): 🛡️ use rsync --checksum for skills repo sync (#874) | - fix(deps): Dependabot security overrides + vitest 3.2.7 (#871) | - fix(ci): 🛡️ use rsync --checksum for plugin repo sync (#872) | - fix(ci): 🩹 restore workflow_dispatch inputs after concurrency insert (#870)\n\nv1.2.22 | 2026-08-04T09:47:18.039Z | user\n\nRecent commits / 最近提交: | - fix(ci): 🩹 pin clawhub CLI and harden plugin skills sync push (#868) | - chore: sync claude skills mirror from source | - chore(release): 🚀 bump version to v2.25.6 | - chore(release): 🏗️ build artifacts for v2.25.6 | - fix(functions): 🩹 accept func.name as functionName fallback\n\nv1.2.21 | 2026-08-03T15:04:46.837Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.25.5 | - fix(pg-mcp): hydrate remote migration history + poll DescribeTaskResult in applyMigration (#859) | - chore: sync cloudbase plugin skills from upstream | - feat(gateway): 🔗 add bindCustomDomain accessType/customCname (#858) | - fix(gateway): ❓ report unknown status when privilege fields are missing (#856)\n\nv1.2.20 | 2026-08-03T10:42:49.794Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.25.4 | - chore(release): build artifacts for v2.25.3 | - chore: sync claude skills mirror from source | - chore: sync cloudbase plugin skills from upstream | - feat(gateway): 🔌 add HTTP gateway privilege query and switch actions (#855)\n\nv1.2.19 | 2026-08-03T09:42:39.547Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.25.3 | - chore: sync cloudbase plugin skills from upstream | - feat(mcp): harden manageEnv billing UX and gateway HTTPSERVICE defaults (#854) | - fix(pg): 🛡️ fail closed when applyMigration does not land (#852) | - chore: sync claude skills mirror from source\n\nv1.2.18 | 2026-07-30T07:13:55.143Z | user\n\nRecent commits / 最近提交: | - chore(release): 🔖 bump version to v2.25.2 | - chore(release): 📦 rebuild prompts for v2.25.2 | - chore: sync cloudbase plugin skills from upstream | - Merge pull request #841 from TencentCloudBase/feature/multi-region-refactor-research | - Merge pull request #842 from TencentCloudBase/feature/sync-codebuddy-marketplace-fork\n\nv1.2.17 | 2026-07-28T11:57:55.435Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.25.1 | - chore: sync cloudbase plugin skills from upstream | - Merge pull request #837 from TencentCloudBase/feature/gateway-path-transmission-drop-invite | - feat(gateway): 🧭 unify upstreamResourceType and drop invite-code | - Merge pull request #836 from TencentCloudBase/fix/claude-skills-mirror-race\n\nv1.2.16 | 2026-07-28T08:43:04.848Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.25.0 | - chore(release): build artifacts for v2.25.0 | - Merge pull request #835 from TencentCloudBase/docs/cursor-directory-submitted | - docs(marketplace): 📝 track cursor.directory cloudbase listing | - Merge pull request #834 from TencentCloudBase/feature/open-plugin-logo\n\nv1.2.15 | 2026-07-28T05:30:20.812Z | user\n\nRecent commits / 最近提交: | - Merge pull request #830 from TencentCloudBase/feature/vally-skill-dir-rename | - fix(tests): 🔧 expect renamed kiro auth-web-cloudbase path | - fix(skills): 🔧 align skill directories with frontmatter names for vally | - Merge pull request #829 from TencentCloudBase/feature/cnb-plugin-mirror | - feat(plugins): mirror OPS plugin repos to CNB like skills\n\nv1.2.14 | 2026-07-21T05:51:51.250Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.24.1 | - Merge pull request #819 from TencentCloudBase/feat/plugin-beacon-dau-telemetry | - feat(plugin): 📡 add Vercel-style DAU telemetry via Beacon | - Merge pull request #818 from TencentCloudBase/feat/telemetry-mcp-client-info | - chore: sync claude skills mirror from source\n\nv1.2.13 | 2026-07-20T12:53:12.354Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.24.0 | - Merge pull request #813 from TencentCloudBase/feat/pg-migration-contract-hardening | - Merge pull request #814 from TencentCloudBase/fix/dedicated-repo-ops-only | - fix(plugin): 📦 keep dedicated repos Open Plugin Spec only | - feat(pg): 🔒 require explicit migrationVersion and default DDL to applyMigration\n\nv1.2.12 | 2026-07-15T13:05:50.888Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.23.11 | - chore(release): build artifacts for v2.23.11 | - Merge pull request #806 from TencentCloudBase/feat/plugin-review-and-skill-inject-eval | - fix: 🐛 remove unused imports flagged by github-code-quality review | - fix(compat): 🐛 fix cloudbaase typo in build-compat-config.mjs guideline targets\n\nv1.2.11 | 2026-07-14T09:11:02.157Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.23.10 | - chore(release): build artifacts | - Merge pull request #803 from TencentCloudBase/fix/search-knowledgebase-skill-search-roots | - chore: 📦 update compat baseline for .agents/skills and .claude/skills | - fix(mcp): 🔧 add .agents/skills and .claude/skills to build and searchKnowledgeBase\n\nv1.2.10 | 2026-07-13T09:22:04.488Z | user\n\nRecent commits / 最近提交: | - chore(release): 🔖 bump version to v2.23.9 | - Merge pull request #800 from TencentCloudBase/feat/pg-context-stateless | - feat(pg): ♻️ remove stateful init step, derive context per call | - Merge pull request #799 from TencentCloudBase/feat/plugin-hooks-commands-agents | - chore(deps): 🔒 update pnpm-lock.yaml for @cloudbase/manager-node\n\nv1.2.9 | 2026-07-09T06:54:12.232Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.23.8 | - chore(release): build artifacts for v2.23.8 | - feat(cloudrun): 🚀 add 12 new serverConfig params from manager-node v5.6.1 | - feat(cloudrun): 🚀 add 12 new serverConfig params from manager-node v5.6.1 | - chore: sync cloudbase plugin skills from upstream\n\nv1.2.8 | 2026-07-08T10:27:02.289Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.23.7 | - chore(release): build artifacts for v2.23.7 | - fix: 🐛 resolve deleteAccess failure when only accessId is provided | - fix: 🐛 resolve deleteAccess failure when only accessId is provided | - fix: 🐛 sanitize agent name to avoid invalid alias characters\n\nArchive index:\n\nArchive v1.2.57: 10 files, 17458 bytes\n\nFiles: references/mini-program-pay.md (3300b), references/native-qr-pay.md (2349b), references/official-account-jsapi-pay.md (2572b), references/official-account-oauth.md (2436b), references/overview.md (2636b), references/troubleshooting.md (3670b), references/virtual-payment.md (8237b), skill-card.md (2585b), SKILL.md (7636b), _meta.json (148b)\n\nFile v1.2.57:SKILL.md\n\n---\nname: cloudbase-wechat-integration\ndescription: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.\nversion: 2.35.0\nalwaysApply: false\n---\n\n# CloudBase WeChat Integration\n\nThis skill routes WeChat payment and official-account work through CloudBase Integration Center. It gives the agent the stable execution contract and points to the official Markdown docs for console details that may change.\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\nOfficial CloudBase Integration Center docs (human reference — do not treat as skill markdown to fetch into agent context as a sibling skill substitute):\n- CloudBase Integration Center overview: `https://docs.cloudbase.net/integration/introduce.md`\n- CloudBase Integration Center usage: `https://docs.cloudbase.net/integration/usage.md`\n- When cloud function deployment or log operations are needed and no sibling skill is available, use the current platform's CloudBase MCP tools or CloudBase console instead of guessing unsupported APIs.\n\n## Activation Contract\n\n### Use this first when\n\n- The user asks about WeChat Pay, 小程序支付, 微信支付, JSAPI 支付, 公众号支付, Native 扫码支付, 二维码支付, refund callbacks, payment callbacks, `wx.requestPayment`, `WeixinJSBridge`, `openid`, or Official Account OAuth in a CloudBase app.\n- The user asks about 虚拟支付 (virtual payment) for virtual goods: 道具直购, 代币充值, `wx.requestVirtualPayment`, OfferID, AppKey 签名, `xpay_*` callbacks (发货推送/查单/退款), or MP 后台虚拟支付开通与配置.\n- The task mentions CloudBase Integration Center, 集成中心, generated payment functions, `pay-common`, `offiaccount-common`, or callback routing for WeChat payment.\n- The user needs to extend a CloudBase Integration Center generated function with order persistence, idempotency, fulfillment, or payment-status sync.\n\n### Then also read\n\n- Mini Program structure and preview work -> `../miniprogram-development/SKILL.md` (if unavailable, use the current mini program platform docs and the mini-program payment reference in this skill)\n- Web frontend work -> `../web-development/SKILL.md` (if unavailable, use the JSAPI or Native references in this skill)\n- Cloud function runtime, logs, deployment, or gateway work -> `../cloud-functions/SKILL.md` (if unavailable, use CloudBase console/MCP function tools and the generated-function guidance in this skill)\n\n### Do NOT use for\n\n- Generic CloudBase Web Auth or Mini Program native identity work that does not involve WeChat payment or official-account OAuth.\n- General CloudBase cloud function development unrelated to Integration Center generated functions.\n- Creating or managing Integration Center instances through guessed MCP tools, guessed Manager SDK methods, or undocumented Cloud API actions.\n- Storing merchant secrets, private keys, APIv3 keys, AppSecret values, or certificates in app source code, generated examples, README files, commits, or prompts.\n\n## Operating Rules\n\n1. Treat Integration Center creation as a console-first workflow unless a public Manager SDK or Cloud API contract is confirmed in official docs.\n2. Use official `index.md` docs for console UI steps and credential fields; do not copy stale console screenshots or invent field names.\n3. Never ask the user to paste secrets into chat. Tell them to configure merchant and official-account credentials in the CloudBase console Integration Center form.\n4. Do not assume generated function names are fixed. `pay-common` and `offiaccount-common` are examples; ask for or inspect the actual function name before writing calls.\n5. Treat frontend payment success as UI feedback only. The authoritative payment state must come from server-side query results or payment callbacks.\n6. When extending generated functions, preserve credential environment variables and generated callback verification/decryption logic. Add business logic around order checks, persistence, idempotency, and fulfillment.\n7. Before changing payment or callback code, identify the target scenario and load only the matching reference file.\n\n## Routing\n\n| Task | Read | Why |\n| --- | --- | --- |\n| Capability selection, console-first boundaries, independent distribution | `references/overview.md` | Establishes the Integration Center model and safety rules |\n| Mini Program WeChat Pay, `wx.cloud.callHTTPFunction`, `wx.requestPayment` | `references/mini-program-pay.md` | Covers Mini Program openid injection, order creation, and callback expectations |\n| Mini Program 虚拟支付, virtual goods, `wx.requestVirtualPayment`, `xpay_*` callbacks | `references/virtual-payment.md` | Covers OfferID/AppKey signing, sandbox vs 现网, delivery callbacks, query-order fallback, iOS IAP rules |\n| Official Account JSAPI pay, H5 inside WeChat, `WeixinJSBridge.invoke` | `references/official-account-jsapi-pay.md` | Covers official-account openid and JSAPI invocation |\n| Native QR-code pay for PC/Web checkout | `references/native-qr-pay.md` | Covers `code_url`, QR rendering, and polling/query flow |\n| Official Account OAuth, openid/userinfo retrieval | `references/official-account-oauth.md` | Covers OAuth routes generated by the official-account integration |\n| 404, missing credentials, openid mismatch, callback failures, logs | `references/troubleshooting.md` | Provides diagnosis steps before changing code |\n\n## Quick Workflow\n\n1. Classify the scenario: Mini Program Pay, Virtual Payment (虚拟支付), JSAPI Pay, Native Pay, Official Account OAuth, generated-function extension, or troubleshooting.\n2. Load the matching reference and the official `index.md` docs linked there.\n3. Confirm the actual CloudBase environment ID and generated function name.\n4. Generate or modify only the required client/backend code; keep merchant credentials in Integration Center configuration.\n5. Add order-status query, callback idempotency, and amount/order validation when payment state affects business data.\n6. Verify through function logs, callback logs, and an end-to-end payment sandbox or low-value production test as appropriate.\n\n## Minimum Self-Check\n\n- Did I avoid guessing undocumented Integration Center management APIs?\n- Did I use the actual generated function name instead of assuming `pay-common`?\n- Did I keep all merchant secrets and certificates out of source code and chat?\n- Did the payment flow rely on callback/query state rather than only frontend success?\n- Did I load only the scenario reference needed for the user's task?\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [mini-program-pay.md](references/mini-program-pay.md)\n- [native-qr-pay.md](references/native-qr-pay.md)\n- [official-account-jsapi-pay.md](references/official-account-jsapi-pay.md)\n- [official-account-oauth.md](references/official-account-oauth.md)\n- [overview.md](references/overview.md)\n- [troubleshooting.md](references/troubleshooting.md)\n\nFile v1.2.57:_meta.json\n\n{\n  \"ownerId\": \"kn7emfp36dbn1xx4fz4s5q4a6180439j\",\n  \"slug\": \"cloudbase-wechat-integration\",\n  \"version\": \"1.2.57\",\n  \"publishedAt\": 1791524513531\n}\n\nFile v1.2.57:references/mini-program-pay.md\n\n# Mini Program WeChat Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Mini Program payment flows on CloudBase, including 小程序微信支付, `wx.cloud.callHTTPFunction`, `wx.requestPayment`, Mini Program openid handling, payment callbacks, refunds, and order-status sync.\n\n## Agent Must Know\n\n- The CloudBase Integration Center generated payment function is an HTTP cloud function.\n- `pay-common` is an example function name; use the actual generated function name.\n- Mini Program openid can be injected by CloudBase when calling through the Mini Program cloud function path.\n- The client-side `wx.requestPayment` success callback is not the final business truth.\n- Fulfillment must be driven by callback handling or explicit order query.\n\n## Minimal Contract\n\nTypical Mini Program flow:\n\n1. Mini Program calls the generated payment function over `wx.cloud.callHTTPFunction`.\n2. The request path targets the generated payment route, commonly an order-creation path such as `/wx-pay/wxpay_order`.\n3. The generated function returns payment parameters for `wx.requestPayment`.\n4. The Mini Program invokes `wx.requestPayment`.\n5. Backend callback or query logic confirms paid state before updating business data.\n\nExample shape:\n\n```js\nconst functionName = \"replace-with-generated-payment-function\";\n\nconst orderResult = await wx.cloud.callHTTPFunction({\n  name: functionName,\n  path: \"/wx-pay/wxpay_order\",\n  data: {\n    out_trade_no: orderId,\n    description: \"Order payment\",\n    amount: {\n      total: 1,\n      currency: \"CNY\",\n    },\n  },\n});\n\n// callHTTPFunction returns { data, statusCode, header }\n// The generated function typically returns { code, data, message }\n// Payment params are under orderResult.data.data\nconst payment = orderResult.data?.data;\nif (!payment) {\n  throw new Error(\"Missing payment parameters from CloudBase payment function\");\n}\n\nawait wx.requestPayment(payment);\n```\n\nAdjust field names to the official docs and the generated function contract before using in production.\n\n## Implementation Checklist\n\n- Confirm `wx.cloud.init({ env })` uses the canonical full CloudBase environment ID.\n- Confirm the Mini Program AppID matches the WeChat Pay merchant binding.\n- Confirm the generated function name and path in CloudBase console.\n- Generate a unique `out_trade_no` on the backend or trusted business layer.\n- Validate amount and product data server-side before creating payment.\n- Persist pending order state before initiating payment.\n- Handle payment callback idempotently.\n- Query the order after client payment success before showing final fulfillment state.\n\n## Common Extensions\n\n- Write order and payment status to CloudBase database.\n- Add an idempotency key on `out_trade_no`.\n- Add fulfillment only after callback/query confirms success.\n- Add refund initiation and refund callback handling if the product supports refunds.\n\n## Do Not\n\n- Do not place merchant keys or certificates in Mini Program code.\n- Do not trust client-provided amount without server-side validation.\n- Do not assume frontend success means the order is paid.\n- Do not hard-code `pay-common` if the console generated a different function name.\n\nFile v1.2.57:references/native-qr-pay.md\n\n# Native QR-Code Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for PC/Web checkout, Native WeChat Pay, QR-code payment, or flows where the generated function returns a payment `code_url` for the frontend to render as a QR code.\n\n## Agent Must Know\n\n- Native payment does not use `wx.requestPayment` or `WeixinJSBridge`.\n- The generated payment function creates an order and returns a QR-code URL such as `code_url`.\n- The frontend renders the QR code and polls or subscribes to payment state.\n- Fulfillment must wait for callback or query confirmation.\n\n## Minimal Contract\n\nTypical Native flow:\n\n1. Backend or frontend calls the generated payment function to create a Native order.\n2. The generated function returns `code_url`.\n3. The frontend renders `code_url` as a QR code.\n4. The user scans the QR code in WeChat.\n5. The app polls order status or waits for callback-driven state changes.\n\nExample frontend shape:\n\n```js\nasync function createNativePayment(orderId) {\n  const response = await fetch(\"/api/pay/native-order\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ orderId }),\n  });\n  const data = await response.json();\n  if (!data.code_url) {\n    throw new Error(\"Missing Native payment code_url\");\n  }\n  return data.code_url;\n}\n```\n\nIn CloudBase frontend-only projects, the API wrapper can call the generated HTTP function directly if the access model and CORS/security rules are appropriate. For production, prefer a trusted backend or generated function extension that validates amount and order ownership.\n\n## Implementation Checklist\n\n- Confirm this is Native QR-code payment, not JSAPI or Mini Program payment.\n- Confirm generated function name and Native order path.\n- Generate a unique order number and persist pending state.\n- Validate amount and goods details before creating payment.\n- Render QR code from `code_url`.\n- Poll order status with backoff, or update UI from callback-driven status.\n- Expire stale QR codes and handle closed orders.\n\n## Do Not\n\n- Do not call `wx.requestPayment` for Native QR-code pay.\n- Do not fulfill the order when the QR code is generated.\n- Do not rely on frontend polling alone if callback data says otherwise.\n\nFile v1.2.57:references/official-account-jsapi-pay.md\n\n# Official Account JSAPI Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account webpage payment, JSAPI payment inside the WeChat browser, H5 checkout that calls `WeixinJSBridge.invoke`, and flows that need an official-account openid before creating the payment order.\n\n## Agent Must Know\n\n- JSAPI payment requires the page to run in the WeChat built-in browser.\n- The payer openid must belong to the correct Official Account, not the Mini Program openid.\n- Official Account OAuth is commonly needed before JSAPI order creation.\n- The generated payment function name and routes must be read from the user's Integration Center setup.\n- Final business state still depends on payment callback or order query.\n\n## Minimal Contract\n\nTypical JSAPI flow:\n\n1. Redirect the user through Official Account OAuth to get an openid.\n2. Call the generated payment function to create a JSAPI order.\n3. Pass returned payment parameters to `WeixinJSBridge.invoke(\"getBrandWCPayRequest\", ...)`.\n4. Use payment callback or order query to confirm paid state.\n\nExample invocation shape:\n\n```js\nfunction invokeJsapiPay(paymentParams) {\n  return new Promise((resolve, reject) => {\n    if (!window.WeixinJSBridge) {\n      reject(new Error(\"WeixinJSBridge is unavailable; open this page in WeChat\"));\n      return;\n    }\n\n    window.WeixinJSBridge.invoke(\n      \"getBrandWCPayRequest\",\n      paymentParams,\n      (res) => {\n        if (res.err_msg === \"get_brand_wcpay_request:ok\") {\n          resolve(res);\n          return;\n        }\n        reject(new Error(res.err_msg || \"JSAPI payment failed\"));\n      },\n    );\n  });\n}\n```\n\nAdjust request paths and parameter names to the generated function contract and official docs.\n\n## Implementation Checklist\n\n- Confirm the app is an Official Account web flow, not a Mini Program page.\n- Confirm the page runs inside WeChat before showing JSAPI checkout.\n- Obtain the Official Account openid through OAuth before order creation.\n- Confirm merchant account binding matches the Official Account AppID.\n- Persist pending order state before invoking payment.\n- Confirm paid state through callback or query before fulfillment.\n\n## Do Not\n\n- Do not reuse Mini Program openid for Official Account JSAPI pay.\n- Do not show JSAPI checkout in a normal desktop browser.\n- Do not put AppSecret, merchant private keys, or APIv3 keys in browser code.\n\nFile v1.2.57:references/official-account-oauth.md\n\n# Official Account OAuth\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account OAuth, openid retrieval, userinfo retrieval, token refresh, OAuth config inspection, or preparation for Official Account JSAPI payment.\n\n## Agent Must Know\n\n- Official Account openid is different from Mini Program openid.\n- OAuth credentials should be configured through CloudBase Integration Center, not embedded in frontend code.\n- The generated official-account function name may differ from example names such as `offiaccount-common`.\n- OAuth route names must be confirmed from the generated function and official docs.\n\n## Minimal Contract\n\nCommon generated OAuth routes include:\n\n- `/oauth/config`\n- `/oauth/token`\n- `/oauth/refresh`\n- `/oauth/userinfo`\n- `/oauth/verify`\n\nTypical flow:\n\n1. Get OAuth config or construct the authorization URL according to the generated function contract.\n2. Redirect the user to WeChat authorization.\n3. Exchange the returned code for token/openid through the generated function.\n4. Optionally fetch userinfo if the scope and product requirement allow it.\n5. Store only the user identifiers and business-safe profile fields required by the app.\n\nExample exchange shape:\n\n```js\nasync function exchangeOfficialAccountCode(code) {\n  const response = await fetch(\"/api/wechat/oauth/token\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ code }),\n  });\n  const data = await response.json();\n  if (!data.openid) {\n    throw new Error(\"Missing Official Account openid\");\n  }\n  return data;\n}\n```\n\nUse the actual generated function path or an application backend wrapper instead of copying this path literally.\n\n## Implementation Checklist\n\n- Confirm the target is an Official Account web scenario.\n- Confirm OAuth callback domain and redirect URI are configured.\n- Confirm the generated function name and OAuth routes.\n- Decide whether the product needs only openid or also userinfo.\n- Store tokens securely if refresh is required.\n- For JSAPI pay, pass the Official Account openid into the payment order creation flow.\n\n## Do Not\n\n- Do not expose AppSecret in browser code.\n- Do not confuse Official Account openid with Mini Program openid.\n- Do not request userinfo scope unless the product actually needs profile data.\n\nFile v1.2.57:references/overview.md\n\n# CloudBase WeChat Integration Overview\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## What Integration Center Provides\n\nCloudBase Integration Center is a console-driven capability for connecting third-party services to CloudBase. For WeChat scenarios, it can generate HTTP cloud functions, inject configuration through managed environment variables, and handle platform-specific callback verification or decryption.\n\nUse this skill for the application-side work around those integrations:\n\n- generating client calls to the generated functions\n- adding order persistence, idempotency, and fulfillment logic\n- diagnosing callback, credential, and routing issues\n- guiding the user through console setup without collecting secrets\n\n## Agent Must Know\n\n- Creation and credential binding are console-first unless official public API support is confirmed.\n- Generated function names may vary. Examples such as `pay-common` and `offiaccount-common` are not a contract.\n- Merchant secrets, private keys, APIv3 keys, AppSecret values, and certificates belong in CloudBase console configuration, not in source code.\n- The payment callback or order-query result is the authoritative state for business fulfillment.\n- Generated functions should be treated as platform-managed templates with safe business extensions, not as blank custom functions.\n\n## Scenario Map\n\n| User wording | Route |\n| --- | --- |\n| 小程序支付, 微信支付, `wx.requestPayment` | `mini-program-pay.md` |\n| 公众号支付, JSAPI 支付, 微信内网页支付 | `official-account-jsapi-pay.md` |\n| Native 支付, 扫码支付, 二维码支付 | `native-qr-pay.md` |\n| 公众号授权, openid, userinfo, OAuth | `official-account-oauth.md` |\n| 回调失败, 404, 凭证, openid 不匹配 | `troubleshooting.md` |\n\n## Console-First Setup Checklist\n\n1. Confirm the CloudBase environment ID.\n2. Open Integration Center in the CloudBase console.\n3. Choose the matching WeChat integration type.\n4. Fill merchant or official-account credentials in the console form.\n5. Record the generated function name and HTTP route paths.\n6. Run a minimal call before adding business logic.\n7. Add business data handling after the generated function works.\n\n## Independent Distribution Notes\n\nWhen this skill is installed alone:\n\n- Use only the references in this directory plus the official docs above.\n- If no CloudBase MCP tools are available, guide the user to inspect function logs and configuration in the console.\n- Do not reference local repository paths that may not exist in the target platform.\n\nFile v1.2.57:references/troubleshooting.md\n\n# WeChat Integration Troubleshooting\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n\n## First Checks\n\n1. Confirm the scenario: Mini Program Pay, JSAPI Pay, Native Pay, or Official Account OAuth.\n2. Confirm the CloudBase environment ID.\n3. Confirm the actual generated function name.\n4. Confirm the exact route path from Integration Center or generated function docs.\n5. Check cloud function logs before changing code.\n6. Check whether the issue is credential setup, route mismatch, callback delivery, or business logic.\n\n## Common Symptoms\n\n### 404 or route not found\n\nLikely causes:\n\n- wrong function name\n- wrong HTTP path\n- calling Mini Program payment path from the wrong client\n- generated function was deleted or redeployed incorrectly\n\nActions:\n\n- inspect the generated function routes\n- confirm the call target uses the actual function name\n- check CloudBase function logs and HTTP access logs\n\n### Missing credentials or credential initialization errors\n\nLikely causes:\n\n- Integration Center form is incomplete\n- merchant certificate/APIv3 key/private key was not configured\n- function environment variables were removed or overwritten\n\nActions:\n\n- re-check Integration Center credential configuration in the console\n- do not paste secrets into code or chat\n- restore generated environment variables if they were overwritten\n\n### Openid mismatch\n\nLikely causes:\n\n- Mini Program openid used for Official Account JSAPI pay\n- Official Account AppID does not match merchant binding\n- user authorized a different app than the one used for payment\n\nActions:\n\n- identify whether the flow needs Mini Program openid or Official Account openid\n- verify AppID and merchant binding\n- rerun OAuth or Mini Program call in the correct client context\n\n### Payment succeeds in frontend but order is not fulfilled\n\nLikely causes:\n\n- business logic trusts frontend success only\n- callback did not reach the generated function\n- callback handler is not idempotent\n- order status query is missing\n\nActions:\n\n- use callback or query as the authoritative payment state\n- add idempotent order update logic\n- inspect payment callback logs\n- verify `out_trade_no` maps to the application's order record\n\n### Callback not received\n\nLikely causes:\n\n- merchant platform notification URL is wrong\n- callback path does not match generated function route\n- APIv3 key/certificate mismatch prevents verification/decryption\n- function security or deployment issue\n\nActions:\n\n- check Integration Center callback configuration\n- check merchant platform callback settings\n- inspect generated function logs\n- retry with a low-value test order after fixing configuration\n\n### `callHTTPFunction is not a function`\n\nLikely causes:\n\n- Mini Program base library or CloudBase SDK capability is too old\n- the project is not initialized with `wx.cloud.init`\n- the flow is running outside Mini Program runtime\n\nActions:\n\n- confirm Mini Program runtime and base library support\n- initialize CloudBase with the canonical full environment ID\n- use the correct client flow for Web/JSAPI/Native scenarios\n\n## Before Editing Generated Code\n\n- Keep generated credential handling intact.\n- Add business logic around generated handlers instead of replacing verification/decryption logic.\n- Preserve callback idempotency and order lookup.\n- Keep secrets out of source code.\n\nFile v1.2.57:references/virtual-payment.md\n\n# Mini Program Virtual Payment (虚拟支付)\n\nOfficial docs:\n\n- `https://developers.weixin.qq.com/minigame/dev/wxcloud/guide/wechatpay/ai-virtualpayl-person.html`（AI 工具快速接入虚拟支付，含小游戏/小程序）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment`（企业/个体户接入指引）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment/person`（个人主体接入指引）\n- Client API: `https://developers.weixin.qq.com/miniprogram/dev/api/payment/wx.requestVirtualPayment.html`\n\n## When To Use\n\nUse this reference for **虚拟支付**（virtual goods payment）flows: 道具直购、代币、`wx.requestVirtualPayment`、`xpay_*` 回调事件、OfferID / AppKey 签名、发货推送、查单兜底。\n\n**与微信支付的边界**：虚拟支付走 MP 后台「虚拟支付」通道（`wx.requestVirtualPayment`， OfferID + AppKey 签名），与 Integration Center 生成的微信支付（`wx.requestPayment`，商户号 + APIv3）是**两套独立链路**。卖实物/服务用微信支付（见 `mini-program-pay.md`）；卖虚拟道具/代币用本参考。\n\n## Prerequisites\n\n| 条件 | 说明 |\n| --- | --- |\n| 主体资质 | 个人 / 企业 / 个体户均可；个人主体需服务类目含「工具」，且**全终端月支付限额 10 万元** |\n| 开通入口 | MP 后台 → 支付与交易 → 虚拟支付 → 开通 |\n| 关键参数 | AppID（设置）、OfferID、现网 AppKey、沙箱 AppKey（均在 虚拟支付 → 基本配置） |\n| 道具 | 虚拟支付 → 道具管理 创建并**发布**；发布后需等几分钟到半小时全平台同步，期间下单报 `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` |\n| iOS 支付 | 需先配置「小程序简称」（Apple 展示名）并开通苹果 IAP；用户微信客户端需 **8.0.68+**，代码里先校验版本再拉起支付 |\n\n## Sandbox vs 现网\n\n| 模式 | 适用版本 | 限制 |\n| --- | --- | --- |\n| 沙箱 | 开发版 / 体验版 | 真机预览下会被 `PAYMENT_ILLEGAL_IN_SANDBOX` 拦截 |\n| 现网 | 全版本 | iOS 真机需开通 IAP |\n\n- 沙箱仅适合开发者工具内调试；真实联调用现网（`env: 0`、正式 AppKey）。\n- 沙箱 AppKey 不要出现在生产代码里。\n\n## Core Flow\n\n```text\n① 前端请求服务端下单 → 服务端生成唯一 outTradeNo，构造 signData，算 paySig + signature\n② 前端调用 wx.requestVirtualPayment(payData) 拉起支付\n③ 服务端确认支付并发货：\n   路径 A：收到 xpay_goods_deliver_notify 发货推送 → 幂等发货\n   路径 B：推送丢失时定时调 query_order 查单 → 已支付则补发货\n④ 前端查服务端订单状态 → 展示购买成功\n```\n\n关键点：\n\n- 发货以「发货推送」为主、`query_order` 查单兜底；**前端 success 回调不作为发货依据**。\n- 幂等以平台单号 `wx_order_id`（回调里 `WeChatPayInfo.MchOrderNo`）去重。\n- `outTradeNo` 每次下单重新生成、8-32 位、不能以下划线开头、不可复用。\n\n### payData fields\n\n| 字段 | 说明 |\n| --- | --- |\n| signData | JSON 字符串：`offerId` / `buyQuantity` / `env`（固定 0）/ `currencyType`（固定 CNY）/ `productId` / `goodsPrice`（单位：**分**，与后台道具价一致）/ `outTradeNo` / `attach`（透传，发货时原样返回） |\n| mode | 道具直购固定 `short_series_goods` |\n| paySig | 服务端用 **AppKey** 对 `requestVirtualPayment&signData` 做 HMAC-SHA256 |\n| signature | 服务端用 **sessionKey**（`auth.code2Session` 获取）对 signData 做 HMAC-SHA256 |\n\n### 签名规则\n\n- `paySig` 消息体 = `uri + '&' + post_body`；`post_body` 必须与实际发出的请求体**完全一致**（不格式化、不改键顺序）。\n- C 端下单 uri 固定 `requestVirtualPayment`；B 端服务接口（如 `/xpay/query_order`）用实际路径。\n\n### Callback events (xpay_*)\n\n| Event | 说明 | 处理 |\n| --- | --- | --- |\n| `xpay_goods_deliver_notify` | 道具发货通知 | 核心事件：幂等发货，返回 `<xml><ErrCode>0</ErrCode><ErrMsg><![CDATA[success]]></ErrMsg></xml>`，否则平台重试（最多 15 次） |\n| `xpay_coin_pay_notify` | 代币支付通知 | 更新代币余额 |\n| `xpay_refund_notify` | 退款通知 | 更新订单状态、回收道具 |\n| `xpay_complaint_notify` | 用户投诉通知 | 记录并人工跟进 |\n| `xpay_subscribe_signing_result_notify` | 订阅签约结果 | 更新订阅状态 |\n| `xpay_subscribe_pay_fail_notify` | 订阅支付失败 | 提示用户 |\n| `xpay_subscribe_ios_refund_query_notify` | iOS 订阅退款问询 | **3 秒内**返回 `result_code`（0=建议退款，1=拒绝），否则 Apple 连续问询 3 次后标「不确定」 |\n\n发货推送核心字段：`OpenId`（发给谁）、`OutTradeNo`（业务单号）、`WeChatPayInfo.MchOrderNo`（平台单号）、`GoodsInfo.ProductId` / `GoodsInfo.Quantity`（发什么、发多少）。\n\n### Query order (查单兜底)\n\n`POST /xpay/query_order`（带 pay_sig 签名）：\n\n```json\n{ \"openid\": \"用户openid\", \"env\": 0, \"order_id\": \"业务单号 outTradeNo\" }\n```\n\n> ⚠️ 参数名是 `order_id`（传 outTradeNo），不是 `out_trade_no`。建议每 5 分钟定时查一次未完成订单。\n\n## Refunds & Settlement\n\n| 终端 | 退款 | 结算周期 | 费率 |\n| --- | --- | --- | --- |\n| Android 等 | 开发者主动（MP 后台或 `refund_order` 接口） | T+3 | 1%（腾讯技术服务费） |\n| iOS | ❌ 开发者无法主动退款；用户在 App Store → 购买记录申请，Apple 审批后推送 `xpay_refund_notify` | 约 45-60 天 | 12%（Apple 佣金） |\n\n- 支付 180 天内退款平台退还手续费，超过 180 天不退。\n- iOS 订单在前端「我的」等场景建议**隐藏退款入口**，改为引导用户去 App Store 申请。\n\n## Common Errors\n\n| 错误 | 原因 | 解法 |\n| --- | --- | --- |\n| `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` | 道具刚发布，平台同步延迟 | 等几分钟到半小时再试 |\n| `PAYMENT_ILLEGAL_IN_SANDBOX` | 沙箱模式在真机预览下被拒 | 切现网（`env: 0` + 正式 AppKey） |\n| 当前商户尚未开启 iOS 支付 | iOS 端 IAP 未开通 | MP 后台配置小程序简称 + 开通 IAP |\n\n## On 微信云开发 (WeChat CloudBase)\n\n用微信云开发承接时无需自建服务器/证书：云函数承担下单签名、回调处理、查单兜底，云数据库存订单。典型拆分：\n\n- 下单云函数：生成业务单号、构造 signData、计算双签名，返回 payData\n- 回调云函数：接收 `xpay_*` 推送，幂等校验后发放/回收道具（需在 MP 后台配置发货推送 URL 并订阅事件）\n- 查单云函数：推送丢失时调 `query_order` 补发货，兼作订单/道具查询\n\n配合 Nightly 微信开发者工具（≥ 2.02.2608312）与 `wechatide` CLI / IDE MCP，可自动完成云函数部署与消息推送订阅（见 `../miniprogram-development/SKILL.md` 的 DevTools 工作流）。\n\n## Implementation Checklist\n\n- [ ] 已开通虚拟支付，拿到 AppID / OfferID / 现网 AppKey\n- [ ] 道具已创建**并发布**（留意同步延迟）\n- [ ] iOS 支付：小程序简称已配置、IAP 已开通、客户端已校验微信 ≥ 8.0.68\n- [ ] 签名实现与官方示例核对一致；`post_body` 与实际请求体逐字节一致\n- [ ] 金额单位全程「分」，不换算；`env` 固定 0\n- [ ] 发货推送已配置 URL，回调以 `wx_order_id` 幂等去重\n- [ ] `query_order` 兜底查单已就绪\n- [ ] 已向用户说明退款规则与费率（Android 1% / iOS 12%、个人主体月限额 10 万）\n- [ ] 上线后小额真单验证：支付 → 推送 → 发货 → 后台账单金额一致\n\n## Do Not\n\n- Do not use 沙箱 AppKey or sandbox mode for production / real-device verification.\n- Do not treat the frontend `wx.requestVirtualPayment` success callback as the fulfillment trigger.\n- Do not reuse `outTradeNo` across orders.\n- Do not attempt server-side refund for iOS orders (user-initiated via App Store only).\n- Do not place AppKey / sessionKey in mini program client code.\n- Do not mix this flow with Integration Center 微信支付 (`wx.requestPayment`) contracts.\n\nFile v1.2.57:skill-card.md\n\n## Description:\n\nGuides developers through CloudBase integrations for WeChat payments, virtual payments, Official Account OAuth, and payment callbacks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[binggg](https://clawhub.ai/user/binggg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers use this skill to implement or troubleshoot WeChat payment and Official Account flows in CloudBase apps, including generated function calls, order verification, and fulfillment.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Payment credentials or certificates could be exposed in source code or chat.\n\nMitigation: Configure secrets in CloudBase Integration Center; do not paste or embed them in code or prompts.\n\nRisk: Client-side payment success could trigger fulfillment before payment is confirmed.\n\nMitigation: Verify payment through a server-side order query or callback; validate order details and handle fulfillment idempotently.\n\nRisk: Example function names or routes might not match the deployed integration.\n\nMitigation: Inspect the actual generated function and routes, review resulting code, and test with sandbox or low-value transactions before production use.\n\n## Reference(s):\n\n- [CloudBase Integration Center overview](https://docs.cloudbase.net/integration/introduce.md)\n- [CloudBase Integration Center usage](https://docs.cloudbase.net/integration/usage.md)\n- [CloudBase Mini Program WeChat Pay](https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md)\n- [CloudBase Official Account JSAPI Pay](https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md)\n- [CloudBase Native QR-code Pay](https://docs.cloudbase.net/integration/wechat-pay-native.md)\n- [CloudBase Official Account OAuth](https://docs.cloudbase.net/integration/wechat-official-oauth.md)\n- [WeChat Mini Program virtual payment API](https://developers.weixin.qq.com/miniprogram/dev/api/payment/wx.requestVirtualPayment.html)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Code, Configuration instructions]\n\n**Output Format:** [Markdown with code snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Confirm generated function names and routes before using examples.]\n\n## Skill Version(s):\n\n1.2.57 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.56: 10 files, 17381 bytes\n\nFiles: references/mini-program-pay.md (3300b), references/native-qr-pay.md (2349b), references/official-account-jsapi-pay.md (2572b), references/official-account-oauth.md (2436b), references/overview.md (2636b), references/troubleshooting.md (3670b), references/virtual-payment.md (8237b), skill-card.md (2273b), SKILL.md (7636b), _meta.json (148b)\n\nFile v1.2.56:SKILL.md\n\n---\nname: cloudbase-wechat-integration\ndescription: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.\nversion: 2.35.0\nalwaysApply: false\n---\n\n# CloudBase WeChat Integration\n\nThis skill routes WeChat payment and official-account work through CloudBase Integration Center. It gives the agent the stable execution contract and points to the official Markdown docs for console details that may change.\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\nOfficial CloudBase Integration Center docs (human reference — do not treat as skill markdown to fetch into agent context as a sibling skill substitute):\n- CloudBase Integration Center overview: `https://docs.cloudbase.net/integration/introduce.md`\n- CloudBase Integration Center usage: `https://docs.cloudbase.net/integration/usage.md`\n- When cloud function deployment or log operations are needed and no sibling skill is available, use the current platform's CloudBase MCP tools or CloudBase console instead of guessing unsupported APIs.\n\n## Activation Contract\n\n### Use this first when\n\n- The user asks about WeChat Pay, 小程序支付, 微信支付, JSAPI 支付, 公众号支付, Native 扫码支付, 二维码支付, refund callbacks, payment callbacks, `wx.requestPayment`, `WeixinJSBridge`, `openid`, or Official Account OAuth in a CloudBase app.\n- The user asks about 虚拟支付 (virtual payment) for virtual goods: 道具直购, 代币充值, `wx.requestVirtualPayment`, OfferID, AppKey 签名, `xpay_*` callbacks (发货推送/查单/退款), or MP 后台虚拟支付开通与配置.\n- The task mentions CloudBase Integration Center, 集成中心, generated payment functions, `pay-common`, `offiaccount-common`, or callback routing for WeChat payment.\n- The user needs to extend a CloudBase Integration Center generated function with order persistence, idempotency, fulfillment, or payment-status sync.\n\n### Then also read\n\n- Mini Program structure and preview work -> `../miniprogram-development/SKILL.md` (if unavailable, use the current mini program platform docs and the mini-program payment reference in this skill)\n- Web frontend work -> `../web-development/SKILL.md` (if unavailable, use the JSAPI or Native references in this skill)\n- Cloud function runtime, logs, deployment, or gateway work -> `../cloud-functions/SKILL.md` (if unavailable, use CloudBase console/MCP function tools and the generated-function guidance in this skill)\n\n### Do NOT use for\n\n- Generic CloudBase Web Auth or Mini Program native identity work that does not involve WeChat payment or official-account OAuth.\n- General CloudBase cloud function development unrelated to Integration Center generated functions.\n- Creating or managing Integration Center instances through guessed MCP tools, guessed Manager SDK methods, or undocumented Cloud API actions.\n- Storing merchant secrets, private keys, APIv3 keys, AppSecret values, or certificates in app source code, generated examples, README files, commits, or prompts.\n\n## Operating Rules\n\n1. Treat Integration Center creation as a console-first workflow unless a public Manager SDK or Cloud API contract is confirmed in official docs.\n2. Use official `index.md` docs for console UI steps and credential fields; do not copy stale console screenshots or invent field names.\n3. Never ask the user to paste secrets into chat. Tell them to configure merchant and official-account credentials in the CloudBase console Integration Center form.\n4. Do not assume generated function names are fixed. `pay-common` and `offiaccount-common` are examples; ask for or inspect the actual function name before writing calls.\n5. Treat frontend payment success as UI feedback only. The authoritative payment state must come from server-side query results or payment callbacks.\n6. When extending generated functions, preserve credential environment variables and generated callback verification/decryption logic. Add business logic around order checks, persistence, idempotency, and fulfillment.\n7. Before changing payment or callback code, identify the target scenario and load only the matching reference file.\n\n## Routing\n\n| Task | Read | Why |\n| --- | --- | --- |\n| Capability selection, console-first boundaries, independent distribution | `references/overview.md` | Establishes the Integration Center model and safety rules |\n| Mini Program WeChat Pay, `wx.cloud.callHTTPFunction`, `wx.requestPayment` | `references/mini-program-pay.md` | Covers Mini Program openid injection, order creation, and callback expectations |\n| Mini Program 虚拟支付, virtual goods, `wx.requestVirtualPayment`, `xpay_*` callbacks | `references/virtual-payment.md` | Covers OfferID/AppKey signing, sandbox vs 现网, delivery callbacks, query-order fallback, iOS IAP rules |\n| Official Account JSAPI pay, H5 inside WeChat, `WeixinJSBridge.invoke` | `references/official-account-jsapi-pay.md` | Covers official-account openid and JSAPI invocation |\n| Native QR-code pay for PC/Web checkout | `references/native-qr-pay.md` | Covers `code_url`, QR rendering, and polling/query flow |\n| Official Account OAuth, openid/userinfo retrieval | `references/official-account-oauth.md` | Covers OAuth routes generated by the official-account integration |\n| 404, missing credentials, openid mismatch, callback failures, logs | `references/troubleshooting.md` | Provides diagnosis steps before changing code |\n\n## Quick Workflow\n\n1. Classify the scenario: Mini Program Pay, Virtual Payment (虚拟支付), JSAPI Pay, Native Pay, Official Account OAuth, generated-function extension, or troubleshooting.\n2. Load the matching reference and the official `index.md` docs linked there.\n3. Confirm the actual CloudBase environment ID and generated function name.\n4. Generate or modify only the required client/backend code; keep merchant credentials in Integration Center configuration.\n5. Add order-status query, callback idempotency, and amount/order validation when payment state affects business data.\n6. Verify through function logs, callback logs, and an end-to-end payment sandbox or low-value production test as appropriate.\n\n## Minimum Self-Check\n\n- Did I avoid guessing undocumented Integration Center management APIs?\n- Did I use the actual generated function name instead of assuming `pay-common`?\n- Did I keep all merchant secrets and certificates out of source code and chat?\n- Did the payment flow rely on callback/query state rather than only frontend success?\n- Did I load only the scenario reference needed for the user's task?\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [mini-program-pay.md](references/mini-program-pay.md)\n- [native-qr-pay.md](references/native-qr-pay.md)\n- [official-account-jsapi-pay.md](references/official-account-jsapi-pay.md)\n- [official-account-oauth.md](references/official-account-oauth.md)\n- [overview.md](references/overview.md)\n- [troubleshooting.md](references/troubleshooting.md)\n\nFile v1.2.56:_meta.json\n\n{\n  \"ownerId\": \"kn7emfp36dbn1xx4fz4s5q4a6180439j\",\n  \"slug\": \"cloudbase-wechat-integration\",\n  \"version\": \"1.2.56\",\n  \"publishedAt\": 1791520512526\n}\n\nFile v1.2.56:references/mini-program-pay.md\n\n# Mini Program WeChat Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Mini Program payment flows on CloudBase, including 小程序微信支付, `wx.cloud.callHTTPFunction`, `wx.requestPayment`, Mini Program openid handling, payment callbacks, refunds, and order-status sync.\n\n## Agent Must Know\n\n- The CloudBase Integration Center generated payment function is an HTTP cloud function.\n- `pay-common` is an example function name; use the actual generated function name.\n- Mini Program openid can be injected by CloudBase when calling through the Mini Program cloud function path.\n- The client-side `wx.requestPayment` success callback is not the final business truth.\n- Fulfillment must be driven by callback handling or explicit order query.\n\n## Minimal Contract\n\nTypical Mini Program flow:\n\n1. Mini Program calls the generated payment function over `wx.cloud.callHTTPFunction`.\n2. The request path targets the generated payment route, commonly an order-creation path such as `/wx-pay/wxpay_order`.\n3. The generated function returns payment parameters for `wx.requestPayment`.\n4. The Mini Program invokes `wx.requestPayment`.\n5. Backend callback or query logic confirms paid state before updating business data.\n\nExample shape:\n\n```js\nconst functionName = \"replace-with-generated-payment-function\";\n\nconst orderResult = await wx.cloud.callHTTPFunction({\n  name: functionName,\n  path: \"/wx-pay/wxpay_order\",\n  data: {\n    out_trade_no: orderId,\n    description: \"Order payment\",\n    amount: {\n      total: 1,\n      currency: \"CNY\",\n    },\n  },\n});\n\n// callHTTPFunction returns { data, statusCode, header }\n// The generated function typically returns { code, data, message }\n// Payment params are under orderResult.data.data\nconst payment = orderResult.data?.data;\nif (!payment) {\n  throw new Error(\"Missing payment parameters from CloudBase payment function\");\n}\n\nawait wx.requestPayment(payment);\n```\n\nAdjust field names to the official docs and the generated function contract before using in production.\n\n## Implementation Checklist\n\n- Confirm `wx.cloud.init({ env })` uses the canonical full CloudBase environment ID.\n- Confirm the Mini Program AppID matches the WeChat Pay merchant binding.\n- Confirm the generated function name and path in CloudBase console.\n- Generate a unique `out_trade_no` on the backend or trusted business layer.\n- Validate amount and product data server-side before creating payment.\n- Persist pending order state before initiating payment.\n- Handle payment callback idempotently.\n- Query the order after client payment success before showing final fulfillment state.\n\n## Common Extensions\n\n- Write order and payment status to CloudBase database.\n- Add an idempotency key on `out_trade_no`.\n- Add fulfillment only after callback/query confirms success.\n- Add refund initiation and refund callback handling if the product supports refunds.\n\n## Do Not\n\n- Do not place merchant keys or certificates in Mini Program code.\n- Do not trust client-provided amount without server-side validation.\n- Do not assume frontend success means the order is paid.\n- Do not hard-code `pay-common` if the console generated a different function name.\n\nFile v1.2.56:references/native-qr-pay.md\n\n# Native QR-Code Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for PC/Web checkout, Native WeChat Pay, QR-code payment, or flows where the generated function returns a payment `code_url` for the frontend to render as a QR code.\n\n## Agent Must Know\n\n- Native payment does not use `wx.requestPayment` or `WeixinJSBridge`.\n- The generated payment function creates an order and returns a QR-code URL such as `code_url`.\n- The frontend renders the QR code and polls or subscribes to payment state.\n- Fulfillment must wait for callback or query confirmation.\n\n## Minimal Contract\n\nTypical Native flow:\n\n1. Backend or frontend calls the generated payment function to create a Native order.\n2. The generated function returns `code_url`.\n3. The frontend renders `code_url` as a QR code.\n4. The user scans the QR code in WeChat.\n5. The app polls order status or waits for callback-driven state changes.\n\nExample frontend shape:\n\n```js\nasync function createNativePayment(orderId) {\n  const response = await fetch(\"/api/pay/native-order\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ orderId }),\n  });\n  const data = await response.json();\n  if (!data.code_url) {\n    throw new Error(\"Missing Native payment code_url\");\n  }\n  return data.code_url;\n}\n```\n\nIn CloudBase frontend-only projects, the API wrapper can call the generated HTTP function directly if the access model and CORS/security rules are appropriate. For production, prefer a trusted backend or generated function extension that validates amount and order ownership.\n\n## Implementation Checklist\n\n- Confirm this is Native QR-code payment, not JSAPI or Mini Program payment.\n- Confirm generated function name and Native order path.\n- Generate a unique order number and persist pending state.\n- Validate amount and goods details before creating payment.\n- Render QR code from `code_url`.\n- Poll order status with backoff, or update UI from callback-driven status.\n- Expire stale QR codes and handle closed orders.\n\n## Do Not\n\n- Do not call `wx.requestPayment` for Native QR-code pay.\n- Do not fulfill the order when the QR code is generated.\n- Do not rely on frontend polling alone if callback data says otherwise.\n\nFile v1.2.56:references/official-account-jsapi-pay.md\n\n# Official Account JSAPI Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account webpage payment, JSAPI payment inside the WeChat browser, H5 checkout that calls `WeixinJSBridge.invoke`, and flows that need an official-account openid before creating the payment order.\n\n## Agent Must Know\n\n- JSAPI payment requires the page to run in the WeChat built-in browser.\n- The payer openid must belong to the correct Official Account, not the Mini Program openid.\n- Official Account OAuth is commonly needed before JSAPI order creation.\n- The generated payment function name and routes must be read from the user's Integration Center setup.\n- Final business state still depends on payment callback or order query.\n\n## Minimal Contract\n\nTypical JSAPI flow:\n\n1. Redirect the user through Official Account OAuth to get an openid.\n2. Call the generated payment function to create a JSAPI order.\n3. Pass returned payment parameters to `WeixinJSBridge.invoke(\"getBrandWCPayRequest\", ...)`.\n4. Use payment callback or order query to confirm paid state.\n\nExample invocation shape:\n\n```js\nfunction invokeJsapiPay(paymentParams) {\n  return new Promise((resolve, reject) => {\n    if (!window.WeixinJSBridge) {\n      reject(new Error(\"WeixinJSBridge is unavailable; open this page in WeChat\"));\n      return;\n    }\n\n    window.WeixinJSBridge.invoke(\n      \"getBrandWCPayRequest\",\n      paymentParams,\n      (res) => {\n        if (res.err_msg === \"get_brand_wcpay_request:ok\") {\n          resolve(res);\n          return;\n        }\n        reject(new Error(res.err_msg || \"JSAPI payment failed\"));\n      },\n    );\n  });\n}\n```\n\nAdjust request paths and parameter names to the generated function contract and official docs.\n\n## Implementation Checklist\n\n- Confirm the app is an Official Account web flow, not a Mini Program page.\n- Confirm the page runs inside WeChat before showing JSAPI checkout.\n- Obtain the Official Account openid through OAuth before order creation.\n- Confirm merchant account binding matches the Official Account AppID.\n- Persist pending order state before invoking payment.\n- Confirm paid state through callback or query before fulfillment.\n\n## Do Not\n\n- Do not reuse Mini Program openid for Official Account JSAPI pay.\n- Do not show JSAPI checkout in a normal desktop browser.\n- Do not put AppSecret, merchant private keys, or APIv3 keys in browser code.\n\nFile v1.2.56:references/official-account-oauth.md\n\n# Official Account OAuth\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account OAuth, openid retrieval, userinfo retrieval, token refresh, OAuth config inspection, or preparation for Official Account JSAPI payment.\n\n## Agent Must Know\n\n- Official Account openid is different from Mini Program openid.\n- OAuth credentials should be configured through CloudBase Integration Center, not embedded in frontend code.\n- The generated official-account function name may differ from example names such as `offiaccount-common`.\n- OAuth route names must be confirmed from the generated function and official docs.\n\n## Minimal Contract\n\nCommon generated OAuth routes include:\n\n- `/oauth/config`\n- `/oauth/token`\n- `/oauth/refresh`\n- `/oauth/userinfo`\n- `/oauth/verify`\n\nTypical flow:\n\n1. Get OAuth config or construct the authorization URL according to the generated function contract.\n2. Redirect the user to WeChat authorization.\n3. Exchange the returned code for token/openid through the generated function.\n4. Optionally fetch userinfo if the scope and product requirement allow it.\n5. Store only the user identifiers and business-safe profile fields required by the app.\n\nExample exchange shape:\n\n```js\nasync function exchangeOfficialAccountCode(code) {\n  const response = await fetch(\"/api/wechat/oauth/token\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ code }),\n  });\n  const data = await response.json();\n  if (!data.openid) {\n    throw new Error(\"Missing Official Account openid\");\n  }\n  return data;\n}\n```\n\nUse the actual generated function path or an application backend wrapper instead of copying this path literally.\n\n## Implementation Checklist\n\n- Confirm the target is an Official Account web scenario.\n- Confirm OAuth callback domain and redirect URI are configured.\n- Confirm the generated function name and OAuth routes.\n- Decide whether the product needs only openid or also userinfo.\n- Store tokens securely if refresh is required.\n- For JSAPI pay, pass the Official Account openid into the payment order creation flow.\n\n## Do Not\n\n- Do not expose AppSecret in browser code.\n- Do not confuse Official Account openid with Mini Program openid.\n- Do not request userinfo scope unless the product actually needs profile data.\n\nFile v1.2.56:references/overview.md\n\n# CloudBase WeChat Integration Overview\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## What Integration Center Provides\n\nCloudBase Integration Center is a console-driven capability for connecting third-party services to CloudBase. For WeChat scenarios, it can generate HTTP cloud functions, inject configuration through managed environment variables, and handle platform-specific callback verification or decryption.\n\nUse this skill for the application-side work around those integrations:\n\n- generating client calls to the generated functions\n- adding order persistence, idempotency, and fulfillment logic\n- diagnosing callback, credential, and routing issues\n- guiding the user through console setup without collecting secrets\n\n## Agent Must Know\n\n- Creation and credential binding are console-first unless official public API support is confirmed.\n- Generated function names may vary. Examples such as `pay-common` and `offiaccount-common` are not a contract.\n- Merchant secrets, private keys, APIv3 keys, AppSecret values, and certificates belong in CloudBase console configuration, not in source code.\n- The payment callback or order-query result is the authoritative state for business fulfillment.\n- Generated functions should be treated as platform-managed templates with safe business extensions, not as blank custom functions.\n\n## Scenario Map\n\n| User wording | Route |\n| --- | --- |\n| 小程序支付, 微信支付, `wx.requestPayment` | `mini-program-pay.md` |\n| 公众号支付, JSAPI 支付, 微信内网页支付 | `official-account-jsapi-pay.md` |\n| Native 支付, 扫码支付, 二维码支付 | `native-qr-pay.md` |\n| 公众号授权, openid, userinfo, OAuth | `official-account-oauth.md` |\n| 回调失败, 404, 凭证, openid 不匹配 | `troubleshooting.md` |\n\n## Console-First Setup Checklist\n\n1. Confirm the CloudBase environment ID.\n2. Open Integration Center in the CloudBase console.\n3. Choose the matching WeChat integration type.\n4. Fill merchant or official-account credentials in the console form.\n5. Record the generated function name and HTTP route paths.\n6. Run a minimal call before adding business logic.\n7. Add business data handling after the generated function works.\n\n## Independent Distribution Notes\n\nWhen this skill is installed alone:\n\n- Use only the references in this directory plus the official docs above.\n- If no CloudBase MCP tools are available, guide the user to inspect function logs and configuration in the console.\n- Do not reference local repository paths that may not exist in the target platform.\n\nFile v1.2.56:references/troubleshooting.md\n\n# WeChat Integration Troubleshooting\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n\n## First Checks\n\n1. Confirm the scenario: Mini Program Pay, JSAPI Pay, Native Pay, or Official Account OAuth.\n2. Confirm the CloudBase environment ID.\n3. Confirm the actual generated function name.\n4. Confirm the exact route path from Integration Center or generated function docs.\n5. Check cloud function logs before changing code.\n6. Check whether the issue is credential setup, route mismatch, callback delivery, or business logic.\n\n## Common Symptoms\n\n### 404 or route not found\n\nLikely causes:\n\n- wrong function name\n- wrong HTTP path\n- calling Mini Program payment path from the wrong client\n- generated function was deleted or redeployed incorrectly\n\nActions:\n\n- inspect the generated function routes\n- confirm the call target uses the actual function name\n- check CloudBase function logs and HTTP access logs\n\n### Missing credentials or credential initialization errors\n\nLikely causes:\n\n- Integration Center form is incomplete\n- merchant certificate/APIv3 key/private key was not configured\n- function environment variables were removed or overwritten\n\nActions:\n\n- re-check Integration Center credential configuration in the console\n- do not paste secrets into code or chat\n- restore generated environment variables if they were overwritten\n\n### Openid mismatch\n\nLikely causes:\n\n- Mini Program openid used for Official Account JSAPI pay\n- Official Account AppID does not match merchant binding\n- user authorized a different app than the one used for payment\n\nActions:\n\n- identify whether the flow needs Mini Program openid or Official Account openid\n- verify AppID and merchant binding\n- rerun OAuth or Mini Program call in the correct client context\n\n### Payment succeeds in frontend but order is not fulfilled\n\nLikely causes:\n\n- business logic trusts frontend success only\n- callback did not reach the generated function\n- callback handler is not idempotent\n- order status query is missing\n\nActions:\n\n- use callback or query as the authoritative payment state\n- add idempotent order update logic\n- inspect payment callback logs\n- verify `out_trade_no` maps to the application's order record\n\n### Callback not received\n\nLikely causes:\n\n- merchant platform notification URL is wrong\n- callback path does not match generated function route\n- APIv3 key/certificate mismatch prevents verification/decryption\n- function security or deployment issue\n\nActions:\n\n- check Integration Center callback configuration\n- check merchant platform callback settings\n- inspect generated function logs\n- retry with a low-value test order after fixing configuration\n\n### `callHTTPFunction is not a function`\n\nLikely causes:\n\n- Mini Program base library or CloudBase SDK capability is too old\n- the project is not initialized with `wx.cloud.init`\n- the flow is running outside Mini Program runtime\n\nActions:\n\n- confirm Mini Program runtime and base library support\n- initialize CloudBase with the canonical full environment ID\n- use the correct client flow for Web/JSAPI/Native scenarios\n\n## Before Editing Generated Code\n\n- Keep generated credential handling intact.\n- Add business logic around generated handlers instead of replacing verification/decryption logic.\n- Preserve callback idempotency and order lookup.\n- Keep secrets out of source code.\n\nFile v1.2.56:references/virtual-payment.md\n\n# Mini Program Virtual Payment (虚拟支付)\n\nOfficial docs:\n\n- `https://developers.weixin.qq.com/minigame/dev/wxcloud/guide/wechatpay/ai-virtualpayl-person.html`（AI 工具快速接入虚拟支付，含小游戏/小程序）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment`（企业/个体户接入指引）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment/person`（个人主体接入指引）\n- Client API: `https://developers.weixin.qq.com/miniprogram/dev/api/payment/wx.requestVirtualPayment.html`\n\n## When To Use\n\nUse this reference for **虚拟支付**（virtual goods payment）flows: 道具直购、代币、`wx.requestVirtualPayment`、`xpay_*` 回调事件、OfferID / AppKey 签名、发货推送、查单兜底。\n\n**与微信支付的边界**：虚拟支付走 MP 后台「虚拟支付」通道（`wx.requestVirtualPayment`， OfferID + AppKey 签名），与 Integration Center 生成的微信支付（`wx.requestPayment`，商户号 + APIv3）是**两套独立链路**。卖实物/服务用微信支付（见 `mini-program-pay.md`）；卖虚拟道具/代币用本参考。\n\n## Prerequisites\n\n| 条件 | 说明 |\n| --- | --- |\n| 主体资质 | 个人 / 企业 / 个体户均可；个人主体需服务类目含「工具」，且**全终端月支付限额 10 万元** |\n| 开通入口 | MP 后台 → 支付与交易 → 虚拟支付 → 开通 |\n| 关键参数 | AppID（设置）、OfferID、现网 AppKey、沙箱 AppKey（均在 虚拟支付 → 基本配置） |\n| 道具 | 虚拟支付 → 道具管理 创建并**发布**；发布后需等几分钟到半小时全平台同步，期间下单报 `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` |\n| iOS 支付 | 需先配置「小程序简称」（Apple 展示名）并开通苹果 IAP；用户微信客户端需 **8.0.68+**，代码里先校验版本再拉起支付 |\n\n## Sandbox vs 现网\n\n| 模式 | 适用版本 | 限制 |\n| --- | --- | --- |\n| 沙箱 | 开发版 / 体验版 | 真机预览下会被 `PAYMENT_ILLEGAL_IN_SANDBOX` 拦截 |\n| 现网 | 全版本 | iOS 真机需开通 IAP |\n\n- 沙箱仅适合开发者工具内调试；真实联调用现网（`env: 0`、正式 AppKey）。\n- 沙箱 AppKey 不要出现在生产代码里。\n\n## Core Flow\n\n```text\n① 前端请求服务端下单 → 服务端生成唯一 outTradeNo，构造 signData，算 paySig + signature\n② 前端调用 wx.requestVirtualPayment(payData) 拉起支付\n③ 服务端确认支付并发货：\n   路径 A：收到 xpay_goods_deliver_notify 发货推送 → 幂等发货\n   路径 B：推送丢失时定时调 query_order 查单 → 已支付则补发货\n④ 前端查服务端订单状态 → 展示购买成功\n```\n\n关键点：\n\n- 发货以「发货推送」为主、`query_order` 查单兜底；**前端 success 回调不作为发货依据**。\n- 幂等以平台单号 `wx_order_id`（回调里 `WeChatPayInfo.MchOrderNo`）去重。\n- `outTradeNo` 每次下单重新生成、8-32 位、不能以下划线开头、不可复用。\n\n### payData fields\n\n| 字段 | 说明 |\n| --- | --- |\n| signData | JSON 字符串：`offerId` / `buyQuantity` / `env`（固定 0）/ `currencyType`（固定 CNY）/ `productId` / `goodsPrice`（单位：**分**，与后台道具价一致）/ `outTradeNo` / `attach`（透传，发货时原样返回） |\n| mode | 道具直购固定 `short_series_goods` |\n| paySig | 服务端用 **AppKey** 对 `requestVirtualPayment&signData` 做 HMAC-SHA256 |\n| signature | 服务端用 **sessionKey**（`auth.code2Session` 获取）对 signData 做 HMAC-SHA256 |\n\n### 签名规则\n\n- `paySig` 消息体 = `uri + '&' + post_body`；`post_body` 必须与实际发出的请求体**完全一致**（不格式化、不改键顺序）。\n- C 端下单 uri 固定 `requestVirtualPayment`；B 端服务接口（如 `/xpay/query_order`）用实际路径。\n\n### Callback events (xpay_*)\n\n| Event | 说明 | 处理 |\n| --- | --- | --- |\n| `xpay_goods_deliver_notify` | 道具发货通知 | 核心事件：幂等发货，返回 `<xml><ErrCode>0</ErrCode><ErrMsg><![CDATA[success]]></ErrMsg></xml>`，否则平台重试（最多 15 次） |\n| `xpay_coin_pay_notify` | 代币支付通知 | 更新代币余额 |\n| `xpay_refund_notify` | 退款通知 | 更新订单状态、回收道具 |\n| `xpay_complaint_notify` | 用户投诉通知 | 记录并人工跟进 |\n| `xpay_subscribe_signing_result_notify` | 订阅签约结果 | 更新订阅状态 |\n| `xpay_subscribe_pay_fail_notify` | 订阅支付失败 | 提示用户 |\n| `xpay_subscribe_ios_refund_query_notify` | iOS 订阅退款问询 | **3 秒内**返回 `result_code`（0=建议退款，1=拒绝），否则 Apple 连续问询 3 次后标「不确定」 |\n\n发货推送核心字段：`OpenId`（发给谁）、`OutTradeNo`（业务单号）、`WeChatPayInfo.MchOrderNo`（平台单号）、`GoodsInfo.ProductId` / `GoodsInfo.Quantity`（发什么、发多少）。\n\n### Query order (查单兜底)\n\n`POST /xpay/query_order`（带 pay_sig 签名）：\n\n```json\n{ \"openid\": \"用户openid\", \"env\": 0, \"order_id\": \"业务单号 outTradeNo\" }\n```\n\n> ⚠️ 参数名是 `order_id`（传 outTradeNo），不是 `out_trade_no`。建议每 5 分钟定时查一次未完成订单。\n\n## Refunds & Settlement\n\n| 终端 | 退款 | 结算周期 | 费率 |\n| --- | --- | --- | --- |\n| Android 等 | 开发者主动（MP 后台或 `refund_order` 接口） | T+3 | 1%（腾讯技术服务费） |\n| iOS | ❌ 开发者无法主动退款；用户在 App Store → 购买记录申请，Apple 审批后推送 `xpay_refund_notify` | 约 45-60 天 | 12%（Apple 佣金） |\n\n- 支付 180 天内退款平台退还手续费，超过 180 天不退。\n- iOS 订单在前端「我的」等场景建议**隐藏退款入口**，改为引导用户去 App Store 申请。\n\n## Common Errors\n\n| 错误 | 原因 | 解法 |\n| --- | --- | --- |\n| `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` | 道具刚发布，平台同步延迟 | 等几分钟到半小时再试 |\n| `PAYMENT_ILLEGAL_IN_SANDBOX` | 沙箱模式在真机预览下被拒 | 切现网（`env: 0` + 正式 AppKey） |\n| 当前商户尚未开启 iOS 支付 | iOS 端 IAP 未开通 | MP 后台配置小程序简称 + 开通 IAP |\n\n## On 微信云开发 (WeChat CloudBase)\n\n用微信云开发承接时无需自建服务器/证书：云函数承担下单签名、回调处理、查单兜底，云数据库存订单。典型拆分：\n\n- 下单云函数：生成业务单号、构造 signData、计算双签名，返回 payData\n- 回调云函数：接收 `xpay_*` 推送，幂等校验后发放/回收道具（需在 MP 后台配置发货推送 URL 并订阅事件）\n- 查单云函数：推送丢失时调 `query_order` 补发货，兼作订单/道具查询\n\n配合 Nightly 微信开发者工具（≥ 2.02.2608312）与 `wechatide` CLI / IDE MCP，可自动完成云函数部署与消息推送订阅（见 `../miniprogram-development/SKILL.md` 的 DevTools 工作流）。\n\n## Implementation Checklist\n\n- [ ] 已开通虚拟支付，拿到 AppID / OfferID / 现网 AppKey\n- [ ] 道具已创建**并发布**（留意同步延迟）\n- [ ] iOS 支付：小程序简称已配置、IAP 已开通、客户端已校验微信 ≥ 8.0.68\n- [ ] 签名实现与官方示例核对一致；`post_body` 与实际请求体逐字节一致\n- [ ] 金额单位全程「分」，不换算；`env` 固定 0\n- [ ] 发货推送已配置 URL，回调以 `wx_order_id` 幂等去重\n- [ ] `query_order` 兜底查单已就绪\n- [ ] 已向用户说明退款规则与费率（Android 1% / iOS 12%、个人主体月限额 10 万）\n- [ ] 上线后小额真单验证：支付 → 推送 → 发货 → 后台账单金额一致\n\n## Do Not\n\n- Do not use 沙箱 AppKey or sandbox mode for production / real-device verification.\n- Do not treat the frontend `wx.requestVirtualPayment` success callback as the fulfillment trigger.\n- Do not reuse `outTradeNo` across orders.\n- Do not attempt server-side refund for iOS orders (user-initiated via App Store only).\n- Do not place AppKey / sessionKey in mini program client code.\n- Do not mix this flow with Integration Center 微信支付 (`wx.requestPayment`) contracts.\n\nFile v1.2.56:skill-card.md\n\n## Description:\n\nGuides developers through CloudBase integrations for WeChat payments, Mini Program virtual payments, Official Account OAuth, payment callbacks, and troubleshooting.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[binggg](https://clawhub.ai/user/binggg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers use this skill to add, extend, and debug WeChat payment and Official Account flows in CloudBase applications, including secure configuration, order handling, and callback-based fulfillment.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Payment changes can cause incorrect orders or fulfillment.\n\nMitigation: Review payment-related changes and validate callbacks, order state, and fulfillment with sandbox or low-value production tests.\n\nRisk: Merchant keys and Official Account secrets may be exposed in chat or source code.\n\nMitigation: Configure credentials in the CloudBase or WeChat console; do not paste them into chat or commit them to source code.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/binggg/skills/cloudbase-wechat-integration)\n- [CloudBase Integration Center overview](https://docs.cloudbase.net/integration/introduce.md)\n- [CloudBase Integration Center usage](https://docs.cloudbase.net/integration/usage.md)\n- [Mini Program WeChat Pay](references/mini-program-pay.md)\n- [Mini Program virtual payment](references/virtual-payment.md)\n- [Official Account JSAPI Pay](references/official-account-jsapi-pay.md)\n- [Native QR-code Pay](references/native-qr-pay.md)\n- [Official Account OAuth](references/official-account-oauth.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Code, Configuration instructions]\n\n**Output Format:** [Markdown with code examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Scenario-specific integration guidance; no merchant secrets in generated examples.]\n\n## Skill Version(s):\n\n1.2.56 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.55: 10 files, 17384 bytes\n\nFiles: references/mini-program-pay.md (3300b), references/native-qr-pay.md (2349b), references/official-account-jsapi-pay.md (2572b), references/official-account-oauth.md (2436b), references/overview.md (2636b), references/troubleshooting.md (3670b), references/virtual-payment.md (8237b), skill-card.md (2343b), SKILL.md (7636b), _meta.json (148b)\n\nFile v1.2.55:SKILL.md\n\n---\nname: cloudbase-wechat-integration\ndescription: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.\nversion: 2.34.8\nalwaysApply: false\n---\n\n# CloudBase WeChat Integration\n\nThis skill routes WeChat payment and official-account work through CloudBase Integration Center. It gives the agent the stable execution contract and points to the official Markdown docs for console details that may change.\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\nOfficial CloudBase Integration Center docs (human reference — do not treat as skill markdown to fetch into agent context as a sibling skill substitute):\n- CloudBase Integration Center overview: `https://docs.cloudbase.net/integration/introduce.md`\n- CloudBase Integration Center usage: `https://docs.cloudbase.net/integration/usage.md`\n- When cloud function deployment or log operations are needed and no sibling skill is available, use the current platform's CloudBase MCP tools or CloudBase console instead of guessing unsupported APIs.\n\n## Activation Contract\n\n### Use this first when\n\n- The user asks about WeChat Pay, 小程序支付, 微信支付, JSAPI 支付, 公众号支付, Native 扫码支付, 二维码支付, refund callbacks, payment callbacks, `wx.requestPayment`, `WeixinJSBridge`, `openid`, or Official Account OAuth in a CloudBase app.\n- The user asks about 虚拟支付 (virtual payment) for virtual goods: 道具直购, 代币充值, `wx.requestVirtualPayment`, OfferID, AppKey 签名, `xpay_*` callbacks (发货推送/查单/退款), or MP 后台虚拟支付开通与配置.\n- The task mentions CloudBase Integration Center, 集成中心, generated payment functions, `pay-common`, `offiaccount-common`, or callback routing for WeChat payment.\n- The user needs to extend a CloudBase Integration Center generated function with order persistence, idempotency, fulfillment, or payment-status sync.\n\n### Then also read\n\n- Mini Program structure and preview work -> `../miniprogram-development/SKILL.md` (if unavailable, use the current mini program platform docs and the mini-program payment reference in this skill)\n- Web frontend work -> `../web-development/SKILL.md` (if unavailable, use the JSAPI or Native references in this skill)\n- Cloud function runtime, logs, deployment, or gateway work -> `../cloud-functions/SKILL.md` (if unavailable, use CloudBase console/MCP function tools and the generated-function guidance in this skill)\n\n### Do NOT use for\n\n- Generic CloudBase Web Auth or Mini Program native identity work that does not involve WeChat payment or official-account OAuth.\n- General CloudBase cloud function development unrelated to Integration Center generated functions.\n- Creating or managing Integration Center instances through guessed MCP tools, guessed Manager SDK methods, or undocumented Cloud API actions.\n- Storing merchant secrets, private keys, APIv3 keys, AppSecret values, or certificates in app source code, generated examples, README files, commits, or prompts.\n\n## Operating Rules\n\n1. Treat Integration Center creation as a console-first workflow unless a public Manager SDK or Cloud API contract is confirmed in official docs.\n2. Use official `index.md` docs for console UI steps and credential fields; do not copy stale console screenshots or invent field names.\n3. Never ask the user to paste secrets into chat. Tell them to configure merchant and official-account credentials in the CloudBase console Integration Center form.\n4. Do not assume generated function names are fixed. `pay-common` and `offiaccount-common` are examples; ask for or inspect the actual function name before writing calls.\n5. Treat frontend payment success as UI feedback only. The authoritative payment state must come from server-side query results or payment callbacks.\n6. When extending generated functions, preserve credential environment variables and generated callback verification/decryption logic. Add business logic around order checks, persistence, idempotency, and fulfillment.\n7. Before changing payment or callback code, identify the target scenario and load only the matching reference file.\n\n## Routing\n\n| Task | Read | Why |\n| --- | --- | --- |\n| Capability selection, console-first boundaries, independent distribution | `references/overview.md` | Establishes the Integration Center model and safety rules |\n| Mini Program WeChat Pay, `wx.cloud.callHTTPFunction`, `wx.requestPayment` | `references/mini-program-pay.md` | Covers Mini Program openid injection, order creation, and callback expectations |\n| Mini Program 虚拟支付, virtual goods, `wx.requestVirtualPayment`, `xpay_*` callbacks | `references/virtual-payment.md` | Covers OfferID/AppKey signing, sandbox vs 现网, delivery callbacks, query-order fallback, iOS IAP rules |\n| Official Account JSAPI pay, H5 inside WeChat, `WeixinJSBridge.invoke` | `references/official-account-jsapi-pay.md` | Covers official-account openid and JSAPI invocation |\n| Native QR-code pay for PC/Web checkout | `references/native-qr-pay.md` | Covers `code_url`, QR rendering, and polling/query flow |\n| Official Account OAuth, openid/userinfo retrieval | `references/official-account-oauth.md` | Covers OAuth routes generated by the official-account integration |\n| 404, missing credentials, openid mismatch, callback failures, logs | `references/troubleshooting.md` | Provides diagnosis steps before changing code |\n\n## Quick Workflow\n\n1. Classify the scenario: Mini Program Pay, Virtual Payment (虚拟支付), JSAPI Pay, Native Pay, Official Account OAuth, generated-function extension, or troubleshooting.\n2. Load the matching reference and the official `index.md` docs linked there.\n3. Confirm the actual CloudBase environment ID and generated function name.\n4. Generate or modify only the required client/backend code; keep merchant credentials in Integration Center configuration.\n5. Add order-status query, callback idempotency, and amount/order validation when payment state affects business data.\n6. Verify through function logs, callback logs, and an end-to-end payment sandbox or low-value production test as appropriate.\n\n## Minimum Self-Check\n\n- Did I avoid guessing undocumented Integration Center management APIs?\n- Did I use the actual generated function name instead of assuming `pay-common`?\n- Did I keep all merchant secrets and certificates out of source code and chat?\n- Did the payment flow rely on callback/query state rather than only frontend success?\n- Did I load only the scenario reference needed for the user's task?\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [mini-program-pay.md](references/mini-program-pay.md)\n- [native-qr-pay.md](references/native-qr-pay.md)\n- [official-account-jsapi-pay.md](references/official-account-jsapi-pay.md)\n- [official-account-oauth.md](references/official-account-oauth.md)\n- [overview.md](references/overview.md)\n- [troubleshooting.md](references/troubleshooting.md)\n\nFile v1.2.55:_meta.json\n\n{\n  \"ownerId\": \"kn7emfp36dbn1xx4fz4s5q4a6180439j\",\n  \"slug\": \"cloudbase-wechat-integration\",\n  \"version\": \"1.2.55\",\n  \"publishedAt\": 1790774956622\n}\n\nFile v1.2.55:references/mini-program-pay.md\n\n# Mini Program WeChat Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Mini Program payment flows on CloudBase, including 小程序微信支付, `wx.cloud.callHTTPFunction`, `wx.requestPayment`, Mini Program openid handling, payment callbacks, refunds, and order-status sync.\n\n## Agent Must Know\n\n- The CloudBase Integration Center generated payment function is an HTTP cloud function.\n- `pay-common` is an example function name; use the actual generated function name.\n- Mini Program openid can be injected by CloudBase when calling through the Mini Program cloud function path.\n- The client-side `wx.requestPayment` success callback is not the final business truth.\n- Fulfillment must be driven by callback handling or explicit order query.\n\n## Minimal Contract\n\nTypical Mini Program flow:\n\n1. Mini Program calls the generated payment function over `wx.cloud.callHTTPFunction`.\n2. The request path targets the generated payment route, commonly an order-creation path such as `/wx-pay/wxpay_order`.\n3. The generated function returns payment parameters for `wx.requestPayment`.\n4. The Mini Program invokes `wx.requestPayment`.\n5. Backend callback or query logic confirms paid state before updating business data.\n\nExample shape:\n\n```js\nconst functionName = \"replace-with-generated-payment-function\";\n\nconst orderResult = await wx.cloud.callHTTPFunction({\n  name: functionName,\n  path: \"/wx-pay/wxpay_order\",\n  data: {\n    out_trade_no: orderId,\n    description: \"Order payment\",\n    amount: {\n      total: 1,\n      currency: \"CNY\",\n    },\n  },\n});\n\n// callHTTPFunction returns { data, statusCode, header }\n// The generated function typically returns { code, data, message }\n// Payment params are under orderResult.data.data\nconst payment = orderResult.data?.data;\nif (!payment) {\n  throw new Error(\"Missing payment parameters from CloudBase payment function\");\n}\n\nawait wx.requestPayment(payment);\n```\n\nAdjust field names to the official docs and the generated function contract before using in production.\n\n## Implementation Checklist\n\n- Confirm `wx.cloud.init({ env })` uses the canonical full CloudBase environment ID.\n- Confirm the Mini Program AppID matches the WeChat Pay merchant binding.\n- Confirm the generated function name and path in CloudBase console.\n- Generate a unique `out_trade_no` on the backend or trusted business layer.\n- Validate amount and product data server-side before creating payment.\n- Persist pending order state before initiating payment.\n- Handle payment callback idempotently.\n- Query the order after client payment success before showing final fulfillment state.\n\n## Common Extensions\n\n- Write order and payment status to CloudBase database.\n- Add an idempotency key on `out_trade_no`.\n- Add fulfillment only after callback/query confirms success.\n- Add refund initiation and refund callback handling if the product supports refunds.\n\n## Do Not\n\n- Do not place merchant keys or certificates in Mini Program code.\n- Do not trust client-provided amount without server-side validation.\n- Do not assume frontend success means the order is paid.\n- Do not hard-code `pay-common` if the console generated a different function name.\n\nFile v1.2.55:references/native-qr-pay.md\n\n# Native QR-Code Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for PC/Web checkout, Native WeChat Pay, QR-code payment, or flows where the generated function returns a payment `code_url` for the frontend to render as a QR code.\n\n## Agent Must Know\n\n- Native payment does not use `wx.requestPayment` or `WeixinJSBridge`.\n- The generated payment function creates an order and returns a QR-code URL such as `code_url`.\n- The frontend renders the QR code and polls or subscribes to payment state.\n- Fulfillment must wait for callback or query confirmation.\n\n## Minimal Contract\n\nTypical Native flow:\n\n1. Backend or frontend calls the generated payment function to create a Native order.\n2. The generated function returns `code_url`.\n3. The frontend renders `code_url` as a QR code.\n4. The user scans the QR code in WeChat.\n5. The app polls order status or waits for callback-driven state changes.\n\nExample frontend shape:\n\n```js\nasync function createNativePayment(orderId) {\n  const response = await fetch(\"/api/pay/native-order\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ orderId }),\n  });\n  const data = await response.json();\n  if (!data.code_url) {\n    throw new Error(\"Missing Native payment code_url\");\n  }\n  return data.code_url;\n}\n```\n\nIn CloudBase frontend-only projects, the API wrapper can call the generated HTTP function directly if the access model and CORS/security rules are appropriate. For production, prefer a trusted backend or generated function extension that validates amount and order ownership.\n\n## Implementation Checklist\n\n- Confirm this is Native QR-code payment, not JSAPI or Mini Program payment.\n- Confirm generated function name and Native order path.\n- Generate a unique order number and persist pending state.\n- Validate amount and goods details before creating payment.\n- Render QR code from `code_url`.\n- Poll order status with backoff, or update UI from callback-driven status.\n- Expire stale QR codes and handle closed orders.\n\n## Do Not\n\n- Do not call `wx.requestPayment` for Native QR-code pay.\n- Do not fulfill the order when the QR code is generated.\n- Do not rely on frontend polling alone if callback data says otherwise.\n\nFile v1.2.55:references/official-account-jsapi-pay.md\n\n# Official Account JSAPI Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account webpage payment, JSAPI payment inside the WeChat browser, H5 checkout that calls `WeixinJSBridge.invoke`, and flows that need an official-account openid before creating the payment order.\n\n## Agent Must Know\n\n- JSAPI payment requires the page to run in the WeChat built-in browser.\n- The payer openid must belong to the correct Official Account, not the Mini Program openid.\n- Official Account OAuth is commonly needed before JSAPI order creation.\n- The generated payment function name and routes must be read from the user's Integration Center setup.\n- Final business state still depends on payment callback or order query.\n\n## Minimal Contract\n\nTypical JSAPI flow:\n\n1. Redirect the user through Official Account OAuth to get an openid.\n2. Call the generated payment function to create a JSAPI order.\n3. Pass returned payment parameters to `WeixinJSBridge.invoke(\"getBrandWCPayRequest\", ...)`.\n4. Use payment callback or order query to confirm paid state.\n\nExample invocation shape:\n\n```js\nfunction invokeJsapiPay(paymentParams) {\n  return new Promise((resolve, reject) => {\n    if (!window.WeixinJSBridge) {\n      reject(new Error(\"WeixinJSBridge is unavailable; open this page in WeChat\"));\n      return;\n    }\n\n    window.WeixinJSBridge.invoke(\n      \"getBrandWCPayRequest\",\n      paymentParams,\n      (res) => {\n        if (res.err_msg === \"get_brand_wcpay_request:ok\") {\n          resolve(res);\n          return;\n        }\n        reject(new Error(res.err_msg || \"JSAPI payment failed\"));\n      },\n    );\n  });\n}\n```\n\nAdjust request paths and parameter names to the generated function contract and official docs.\n\n## Implementation Checklist\n\n- Confirm the app is an Official Account web flow, not a Mini Program page.\n- Confirm the page runs inside WeChat before showing JSAPI checkout.\n- Obtain the Official Account openid through OAuth before order creation.\n- Confirm merchant account binding matches the Official Account AppID.\n- Persist pending order state before invoking payment.\n- Confirm paid state through callback or query before fulfillment.\n\n## Do Not\n\n- Do not reuse Mini Program openid for Official Account JSAPI pay.\n- Do not show JSAPI checkout in a normal desktop browser.\n- Do not put AppSecret, merchant private keys, or APIv3 keys in browser code.\n\nFile v1.2.55:references/official-account-oauth.md\n\n# Official Account OAuth\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account OAuth, openid retrieval, userinfo retrieval, token refresh, OAuth config inspection, or preparation for Official Account JSAPI payment.\n\n## Agent Must Know\n\n- Official Account openid is different from Mini Program openid.\n- OAuth credentials should be configured through CloudBase Integration Center, not embedded in frontend code.\n- The generated official-account function name may differ from example names such as `offiaccount-common`.\n- OAuth route names must be confirmed from the generated function and official docs.\n\n## Minimal Contract\n\nCommon generated OAuth routes include:\n\n- `/oauth/config`\n- `/oauth/token`\n- `/oauth/refresh`\n- `/oauth/userinfo`\n- `/oauth/verify`\n\nTypical flow:\n\n1. Get OAuth config or construct the authorization URL according to the generated function contract.\n2. Redirect the user to WeChat authorization.\n3. Exchange the returned code for token/openid through the generated function.\n4. Optionally fetch userinfo if the scope and product requirement allow it.\n5. Store only the user identifiers and business-safe profile fields required by the app.\n\nExample exchange shape:\n\n```js\nasync function exchangeOfficialAccountCode(code) {\n  const response = await fetch(\"/api/wechat/oauth/token\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ code }),\n  });\n  const data = await response.json();\n  if (!data.openid) {\n    throw new Error(\"Missing Official Account openid\");\n  }\n  return data;\n}\n```\n\nUse the actual generated function path or an application backend wrapper instead of copying this path literally.\n\n## Implementation Checklist\n\n- Confirm the target is an Official Account web scenario.\n- Confirm OAuth callback domain and redirect URI are configured.\n- Confirm the generated function name and OAuth routes.\n- Decide whether the product needs only openid or also userinfo.\n- Store tokens securely if refresh is required.\n- For JSAPI pay, pass the Official Account openid into the payment order creation flow.\n\n## Do Not\n\n- Do not expose AppSecret in browser code.\n- Do not confuse Official Account openid with Mini Program openid.\n- Do not request userinfo scope unless the product actually needs profile data.\n\nFile v1.2.55:references/overview.md\n\n# CloudBase WeChat Integration Overview\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## What Integration Center Provides\n\nCloudBase Integration Center is a console-driven capability for connecting third-party services to CloudBase. For WeChat scenarios, it can generate HTTP cloud functions, inject configuration through managed environment variables, and handle platform-specific callback verification or decryption.\n\nUse this skill for the application-side work around those integrations:\n\n- generating client calls to the generated functions\n- adding order persistence, idempotency, and fulfillment logic\n- diagnosing callback, credential, and routing issues\n- guiding the user through console setup without collecting secrets\n\n## Agent Must Know\n\n- Creation and credential binding are console-first unless official public API support is confirmed.\n- Generated function names may vary. Examples such as `pay-common` and `offiaccount-common` are not a contract.\n- Merchant secrets, private keys, APIv3 keys, AppSecret values, and certificates belong in CloudBase console configuration, not in source code.\n- The payment callback or order-query result is the authoritative state for business fulfillment.\n- Generated functions should be treated as platform-managed templates with safe business extensions, not as blank custom functions.\n\n## Scenario Map\n\n| User wording | Route |\n| --- | --- |\n| 小程序支付, 微信支付, `wx.requestPayment` | `mini-program-pay.md` |\n| 公众号支付, JSAPI 支付, 微信内网页支付 | `official-account-jsapi-pay.md` |\n| Native 支付, 扫码支付, 二维码支付 | `native-qr-pay.md` |\n| 公众号授权, openid, userinfo, OAuth | `official-account-oauth.md` |\n| 回调失败, 404, 凭证, openid 不匹配 | `troubleshooting.md` |\n\n## Console-First Setup Checklist\n\n1. Confirm the CloudBase environment ID.\n2. Open Integration Center in the CloudBase console.\n3. Choose the matching WeChat integration type.\n4. Fill merchant or official-account credentials in the console form.\n5. Record the generated function name and HTTP route paths.\n6. Run a minimal call before adding business logic.\n7. Add business data handling after the generated function works.\n\n## Independent Distribution Notes\n\nWhen this skill is installed alone:\n\n- Use only the references in this directory plus the official docs above.\n- If no CloudBase MCP tools are available, guide the user to inspect function logs and configuration in the console.\n- Do not reference local repository paths that may not exist in the target platform.\n\nFile v1.2.55:references/troubleshooting.md\n\n# WeChat Integration Troubleshooting\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n\n## First Checks\n\n1. Confirm the scenario: Mini Program Pay, JSAPI Pay, Native Pay, or Official Account OAuth.\n2. Confirm the CloudBase environment ID.\n3. Confirm the actual generated function name.\n4. Confirm the exact route path from Integration Center or generated function docs.\n5. Check cloud function logs before changing code.\n6. Check whether the issue is credential setup, route mismatch, callback delivery, or business logic.\n\n## Common Symptoms\n\n### 404 or route not found\n\nLikely causes:\n\n- wrong function name\n- wrong HTTP path\n- calling Mini Program payment path from the wrong client\n- generated function was deleted or redeployed incorrectly\n\nActions:\n\n- inspect the generated function routes\n- confirm the call target uses the actual function name\n- check CloudBase function logs and HTTP access logs\n\n### Missing credentials or credential initialization errors\n\nLikely causes:\n\n- Integration Center form is incomplete\n- merchant certificate/APIv3 key/private key was not configured\n- function environment variables were removed or overwritten\n\nActions:\n\n- re-check Integration Center credential configuration in the console\n- do not paste secrets into code or chat\n- restore generated environment variables if they were overwritten\n\n### Openid mismatch\n\nLikely causes:\n\n- Mini Program openid used for Official Account JSAPI pay\n- Official Account AppID does not match merchant binding\n- user authorized a different app than the one used for payment\n\nActions:\n\n- identify whether the flow needs Mini Program openid or Official Account openid\n- verify AppID and merchant binding\n- rerun OAuth or Mini Program call in the correct client context\n\n### Payment succeeds in frontend but order is not fulfilled\n\nLikely causes:\n\n- business logic trusts frontend success only\n- callback did not reach the generated function\n- callback handler is not idempotent\n- order status query is missing\n\nActions:\n\n- use callback or query as the authoritative payment state\n- add idempotent order update logic\n- inspect payment callback logs\n- verify `out_trade_no` maps to the application's order record\n\n### Callback not received\n\nLikely causes:\n\n- merchant platform notification URL is wrong\n- callback path does not match generated function route\n- APIv3 key/certificate mismatch prevents verification/decryption\n- function security or deployment issue\n\nActions:\n\n- check Integration Center callback configuration\n- check merchant platform callback settings\n- inspect generated function logs\n- retry with a low-value test order after fixing configuration\n\n### `callHTTPFunction is not a function`\n\nLikely causes:\n\n- Mini Program base library or CloudBase SDK capability is too old\n- the project is not initialized with `wx.cloud.init`\n- the flow is running outside Mini Program runtime\n\nActions:\n\n- confirm Mini Program runtime and base library support\n- initialize CloudBase with the canonical full environment ID\n- use the correct client flow for Web/JSAPI/Native scenarios\n\n## Before Editing Generated Code\n\n- Keep generated credential handling intact.\n- Add business logic around generated handlers instead of replacing verification/decryption logic.\n- Preserve callback idempotency and order lookup.\n- Keep secrets out of source code.\n\nFile v1.2.55:references/virtual-payment.md\n\n# Mini Program Virtual Payment (虚拟支付)\n\nOfficial docs:\n\n- `https://developers.weixin.qq.com/minigame/dev/wxcloud/guide/wechatpay/ai-virtualpayl-person.html`（AI 工具快速接入虚拟支付，含小游戏/小程序）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment`（企业/个体户接入指引）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment/person`（个人主体接入指引）\n- Client API: `https://developers.weixin.qq.com/miniprogram/dev/api/payment/wx.requestVirtualPayment.html`\n\n## When To Use\n\nUse this reference for **虚拟支付**（virtual goods payment）flows: 道具直购、代币、`wx.requestVirtualPayment`、`xpay_*` 回调事件、OfferID / AppKey 签名、发货推送、查单兜底。\n\n**与微信支付的边界**：虚拟支付走 MP 后台「虚拟支付」通道（`wx.requestVirtualPayment`， OfferID + AppKey 签名），与 Integration Center 生成的微信支付（`wx.requestPayment`，商户号 + APIv3）是**两套独立链路**。卖实物/服务用微信支付（见 `mini-program-pay.md`）；卖虚拟道具/代币用本参考。\n\n## Prerequisites\n\n| 条件 | 说明 |\n| --- | --- |\n| 主体资质 | 个人 / 企业 / 个体户均可；个人主体需服务类目含「工具」，且**全终端月支付限额 10 万元** |\n| 开通入口 | MP 后台 → 支付与交易 → 虚拟支付 → 开通 |\n| 关键参数 | AppID（设置）、OfferID、现网 AppKey、沙箱 AppKey（均在 虚拟支付 → 基本配置） |\n| 道具 | 虚拟支付 → 道具管理 创建并**发布**；发布后需等几分钟到半小时全平台同步，期间下单报 `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` |\n| iOS 支付 | 需先配置「小程序简称」（Apple 展示名）并开通苹果 IAP；用户微信客户端需 **8.0.68+**，代码里先校验版本再拉起支付 |\n\n## Sandbox vs 现网\n\n| 模式 | 适用版本 | 限制 |\n| --- | --- | --- |\n| 沙箱 | 开发版 / 体验版 | 真机预览下会被 `PAYMENT_ILLEGAL_IN_SANDBOX` 拦截 |\n| 现网 | 全版本 | iOS 真机需开通 IAP |\n\n- 沙箱仅适合开发者工具内调试；真实联调用现网（`env: 0`、正式 AppKey）。\n- 沙箱 AppKey 不要出现在生产代码里。\n\n## Core Flow\n\n```text\n① 前端请求服务端下单 → 服务端生成唯一 outTradeNo，构造 signData，算 paySig + signature\n② 前端调用 wx.requestVirtualPayment(payData) 拉起支付\n③ 服务端确认支付并发货：\n   路径 A：收到 xpay_goods_deliver_notify 发货推送 → 幂等发货\n   路径 B：推送丢失时定时调 query_order 查单 → 已支付则补发货\n④ 前端查服务端订单状态 → 展示购买成功\n```\n\n关键点：\n\n- 发货以「发货推送」为主、`query_order` 查单兜底；**前端 success 回调不作为发货依据**。\n- 幂等以平台单号 `wx_order_id`（回调里 `WeChatPayInfo.MchOrderNo`）去重。\n- `outTradeNo` 每次下单重新生成、8-32 位、不能以下划线开头、不可复用。\n\n### payData fields\n\n| 字段 | 说明 |\n| --- | --- |\n| signData | JSON 字符串：`offerId` / `buyQuantity` / `env`（固定 0）/ `currencyType`（固定 CNY）/ `productId` / `goodsPrice`（单位：**分**，与后台道具价一致）/ `outTradeNo` / `attach`（透传，发货时原样返回） |\n| mode | 道具直购固定 `short_series_goods` |\n| paySig | 服务端用 **AppKey** 对 `requestVirtualPayment&signData` 做 HMAC-SHA256 |\n| signature | 服务端用 **sessionKey**（`auth.code2Session` 获取）对 signData 做 HMAC-SHA256 |\n\n### 签名规则\n\n- `paySig` 消息体 = `uri + '&' + post_body`；`post_body` 必须与实际发出的请求体**完全一致**（不格式化、不改键顺序）。\n- C 端下单 uri 固定 `requestVirtualPayment`；B 端服务接口（如 `/xpay/query_order`）用实际路径。\n\n### Callback events (xpay_*)\n\n| Event | 说明 | 处理 |\n| --- | --- | --- |\n| `xpay_goods_deliver_notify` | 道具发货通知 | 核心事件：幂等发货，返回 `<xml><ErrCode>0</ErrCode><ErrMsg><![CDATA[success]]></ErrMsg></xml>`，否则平台重试（最多 15 次） |\n| `xpay_coin_pay_notify` | 代币支付通知 | 更新代币余额 |\n| `xpay_refund_notify` | 退款通知 | 更新订单状态、回收道具 |\n| `xpay_complaint_notify` | 用户投诉通知 | 记录并人工跟进 |\n| `xpay_subscribe_signing_result_notify` | 订阅签约结果 | 更新订阅状态 |\n| `xpay_subscribe_pay_fail_notify` | 订阅支付失败 | 提示用户 |\n| `xpay_subscribe_ios_refund_query_notify` | iOS 订阅退款问询 | **3 秒内**返回 `result_code`（0=建议退款，1=拒绝），否则 Apple 连续问询 3 次后标「不确定」 |\n\n发货推送核心字段：`OpenId`（发给谁）、`OutTradeNo`（业务单号）、`WeChatPayInfo.MchOrderNo`（平台单号）、`GoodsInfo.ProductId` / `GoodsInfo.Quantity`（发什么、发多少）。\n\n### Query order (查单兜底)\n\n`POST /xpay/query_order`（带 pay_sig 签名）：\n\n```json\n{ \"openid\": \"用户openid\", \"env\": 0, \"order_id\": \"业务单号 outTradeNo\" }\n```\n\n> ⚠️ 参数名是 `order_id`（传 outTradeNo），不是 `out_trade_no`。建议每 5 分钟定时查一次未完成订单。\n\n## Refunds & Settlement\n\n| 终端 | 退款 | 结算周期 | 费率 |\n| --- | --- | --- | --- |\n| Android 等 | 开发者主动（MP 后台或 `refund_order` 接口） | T+3 | 1%（腾讯技术服务费） |\n| iOS | ❌ 开发者无法主动退款；用户在 App Store → 购买记录申请，Apple 审批后推送 `xpay_refund_notify` | 约 45-60 天 | 12%（Apple 佣金） |\n\n- 支付 180 天内退款平台退还手续费，超过 180 天不退。\n- iOS 订单在前端「我的」等场景建议**隐藏退款入口**，改为引导用户去 App Store 申请。\n\n## Common Errors\n\n| 错误 | 原因 | 解法 |\n| --- | --- | --- |\n| `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` | 道具刚发布，平台同步延迟 | 等几分钟到半小时再试 |\n| `PAYMENT_ILLEGAL_IN_SANDBOX` | 沙箱模式在真机预览下被拒 | 切现网（`env: 0` + 正式 AppKey） |\n| 当前商户尚未开启 iOS 支付 | iOS 端 IAP 未开通 | MP 后台配置小程序简称 + 开通 IAP |\n\n## On 微信云开发 (WeChat CloudBase)\n\n用微信云开发承接时无需自建服务器/证书：云函数承担下单签名、回调处理、查单兜底，云数据库存订单。典型拆分：\n\n- 下单云函数：生成业务单号、构造 signData、计算双签名，返回 payData\n- 回调云函数：接收 `xpay_*` 推送，幂等校验后发放/回收道具（需在 MP 后台配置发货推送 URL 并订阅事件）\n- 查单云函数：推送丢失时调 `query_order` 补发货，兼作订单/道具查询\n\n配合 Nightly 微信开发者工具（≥ 2.02.2608312）与 `wechatide` CLI / IDE MCP，可自动完成云函数部署与消息推送订阅（见 `../miniprogram-development/SKILL.md` 的 DevTools 工作流）。\n\n## Implementation Checklist\n\n- [ ] 已开通虚拟支付，拿到 AppID / OfferID / 现网 AppKey\n- [ ] 道具已创建**并发布**（留意同步延迟）\n- [ ] iOS 支付：小程序简称已配置、IAP 已开通、客户端已校验微信 ≥ 8.0.68\n- [ ] 签名实现与官方示例核对一致；`post_body` 与实际请求体逐字节一致\n- [ ] 金额单位全程「分」，不换算；`env` 固定 0\n- [ ] 发货推送已配置 URL，回调以 `wx_order_id` 幂等去重\n- [ ] `query_order` 兜底查单已就绪\n- [ ] 已向用户说明退款规则与费率（Android 1% / iOS 12%、个人主体月限额 10 万）\n- [ ] 上线后小额真单验证：支付 → 推送 → 发货 → 后台账单金额一致\n\n## Do Not\n\n- Do not use 沙箱 AppKey or sandbox mode for production / real-device verification.\n- Do not treat the frontend `wx.requestVirtualPayment` success callback as the fulfillment trigger.\n- Do not reuse `outTradeNo` across orders.\n- Do not attempt server-side refund for iOS orders (user-initiated via App Store only).\n- Do not place AppKey / sessionKey in mini program client code.\n- Do not mix this flow with Integration Center 微信支付 (`wx.requestPayment`) contracts.\n\nFile v1.2.55:skill-card.md\n\n## Description:\n\nGuides developers integrating WeChat payments and Official Account OAuth with CloudBase, including generated functions, callbacks, and troubleshooting.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[binggg](https://clawhub.ai/user/binggg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers building CloudBase applications use this skill to add or troubleshoot Mini Program and Official Account payment, virtual payment, QR-code checkout, OAuth, and payment callbacks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Generated payment or callback code could mishandle orders or fulfillment.\n\nMitigation: Review generated code and confirm payment with server-side callbacks or order queries before fulfillment.\n\nRisk: Merchant keys and Official Account credentials could be exposed in chat or source code.\n\nMitigation: Configure secrets in the CloudBase or WeChat console; do not paste them into chat or embed them in code.\n\nRisk: Real payments or deployment could change live systems.\n\nMitigation: Require explicit user approval before real-payment tests or deployment.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/binggg/skills/cloudbase-wechat-integration)\n- [CloudBase Integration Center overview](https://docs.cloudbase.net/integration/introduce.md)\n- [CloudBase Integration Center usage](https://docs.cloudbase.net/integration/usage.md)\n- [Mini Program WeChat Pay guide](references/mini-program-pay.md)\n- [Mini Program virtual payment guide](references/virtual-payment.md)\n- [Official Account OAuth guide](references/official-account-oauth.md)\n- [WeChat integration troubleshooting](references/troubleshooting.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Code, Configuration instructions]\n\n**Output Format:** [Markdown with code examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Scenario-specific guidance; generated payment and callback code requires review.]\n\n## Skill Version(s):\n\n1.2.55 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.54: 10 files, 17488 bytes\n\nFiles: references/mini-program-pay.md (3300b), references/native-qr-pay.md (2349b), references/official-account-jsapi-pay.md (2572b), references/official-account-oauth.md (2436b), references/overview.md (2636b), references/troubleshooting.md (3670b), references/virtual-payment.md (8237b), skill-card.md (2647b), SKILL.md (7636b), _meta.json (148b)\n\nFile v1.2.54:SKILL.md\n\n---\nname: cloudbase-wechat-integration\ndescription: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.\nversion: 2.34.8\nalwaysApply: false\n---\n\n# CloudBase WeChat Integration\n\nThis skill routes WeChat payment and official-account work through CloudBase Integration Center. It gives the agent the stable execution contract and points to the official Markdown docs for console details that may change.\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\nOfficial CloudBase Integration Center docs (human reference — do not treat as skill markdown to fetch into agent context as a sibling skill substitute):\n- CloudBase Integration Center overview: `https://docs.cloudbase.net/integration/introduce.md`\n- CloudBase Integration Center usage: `https://docs.cloudbase.net/integration/usage.md`\n- When cloud function deployment or log operations are needed and no sibling skill is available, use the current platform's CloudBase MCP tools or CloudBase console instead of guessing unsupported APIs.\n\n## Activation Contract\n\n### Use this first when\n\n- The user asks about WeChat Pay, 小程序支付, 微信支付, JSAPI 支付, 公众号支付, Native 扫码支付, 二维码支付, refund callbacks, payment callbacks, `wx.requestPayment`, `WeixinJSBridge`, `openid`, or Official Account OAuth in a CloudBase app.\n- The user asks about 虚拟支付 (virtual payment) for virtual goods: 道具直购, 代币充值, `wx.requestVirtualPayment`, OfferID, AppKey 签名, `xpay_*` callbacks (发货推送/查单/退款), or MP 后台虚拟支付开通与配置.\n- The task mentions CloudBase Integration Center, 集成中心, generated payment functions, `pay-common`, `offiaccount-common`, or callback routing for WeChat payment.\n- The user needs to extend a CloudBase Integration Center generated function with order persistence, idempotency, fulfillment, or payment-status sync.\n\n### Then also read\n\n- Mini Program structure and preview work -> `../miniprogram-development/SKILL.md` (if unavailable, use the current mini program platform docs and the mini-program payment reference in this skill)\n- Web frontend work -> `../web-development/SKILL.md` (if unavailable, use the JSAPI or Native references in this skill)\n- Cloud function runtime, logs, deployment, or gateway work -> `../cloud-functions/SKILL.md` (if unavailable, use CloudBase console/MCP function tools and the generated-function guidance in this skill)\n\n### Do NOT use for\n\n- Generic CloudBase Web Auth or Mini Program native identity work that does not involve WeChat payment or official-account OAuth.\n- General CloudBase cloud function development unrelated to Integration Center generated functions.\n- Creating or managing Integration Center instances through guessed MCP tools, guessed Manager SDK methods, or undocumented Cloud API actions.\n- Storing merchant secrets, private keys, APIv3 keys, AppSecret values, or certificates in app source code, generated examples, README files, commits, or prompts.\n\n## Operating Rules\n\n1. Treat Integration Center creation as a console-first workflow unless a public Manager SDK or Cloud API contract is confirmed in official docs.\n2. Use official `index.md` docs for console UI steps and credential fields; do not copy stale console screenshots or invent field names.\n3. Never ask the user to paste secrets into chat. Tell them to configure merchant and official-account credentials in the CloudBase console Integration Center form.\n4. Do not assume generated function names are fixed. `pay-common` and `offiaccount-common` are examples; ask for or inspect the actual function name before writing calls.\n5. Treat frontend payment success as UI feedback only. The authoritative payment state must come from server-side query results or payment callbacks.\n6. When extending generated functions, preserve credential environment variables and generated callback verification/decryption logic. Add business logic around order checks, persistence, idempotency, and fulfillment.\n7. Before changing payment or callback code, identify the target scenario and load only the matching reference file.\n\n## Routing\n\n| Task | Read | Why |\n| --- | --- | --- |\n| Capability selection, console-first boundaries, independent distribution | `references/overview.md` | Establishes the Integration Center model and safety rules |\n| Mini Program WeChat Pay, `wx.cloud.callHTTPFunction`, `wx.requestPayment` | `references/mini-program-pay.md` | Covers Mini Program openid injection, order creation, and callback expectations |\n| Mini Program 虚拟支付, virtual goods, `wx.requestVirtualPayment`, `xpay_*` callbacks | `references/virtual-payment.md` | Covers OfferID/AppKey signing, sandbox vs 现网, delivery callbacks, query-order fallback, iOS IAP rules |\n| Official Account JSAPI pay, H5 inside WeChat, `WeixinJSBridge.invoke` | `references/official-account-jsapi-pay.md` | Covers official-account openid and JSAPI invocation |\n| Native QR-code pay for PC/Web checkout | `references/native-qr-pay.md` | Covers `code_url`, QR rendering, and polling/query flow |\n| Official Account OAuth, openid/userinfo retrieval | `references/official-account-oauth.md` | Covers OAuth routes generated by the official-account integration |\n| 404, missing credentials, openid mismatch, callback failures, logs | `references/troubleshooting.md` | Provides diagnosis steps before changing code |\n\n## Quick Workflow\n\n1. Classify the scenario: Mini Program Pay, Virtual Payment (虚拟支付), JSAPI Pay, Native Pay, Official Account OAuth, generated-function extension, or troubleshooting.\n2. Load the matching reference and the official `index.md` docs linked there.\n3. Confirm the actual CloudBase environment ID and generated function name.\n4. Generate or modify only the required client/backend code; keep merchant credentials in Integration Center configuration.\n5. Add order-status query, callback idempotency, and amount/order validation when payment state affects business data.\n6. Verify through function logs, callback logs, and an end-to-end payment sandbox or low-value production test as appropriate.\n\n## Minimum Self-Check\n\n- Did I avoid guessing undocumented Integration Center management APIs?\n- Did I use the actual generated function name instead of assuming `pay-common`?\n- Did I keep all merchant secrets and certificates out of source code and chat?\n- Did the payment flow rely on callback/query state rather than only frontend success?\n- Did I load only the scenario reference needed for the user's task?\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [mini-program-pay.md](references/mini-program-pay.md)\n- [native-qr-pay.md](references/native-qr-pay.md)\n- [official-account-jsapi-pay.md](references/official-account-jsapi-pay.md)\n- [official-account-oauth.md](references/official-account-oauth.md)\n- [overview.md](references/overview.md)\n- [troubleshooting.md](references/troubleshooting.md)\n\nFile v1.2.54:_meta.json\n\n{\n  \"ownerId\": \"kn7emfp36dbn1xx4fz4s5q4a6180439j\",\n  \"slug\": \"cloudbase-wechat-integration\",\n  \"version\": \"1.2.54\",\n  \"publishedAt\": 1790748005845\n}\n\nFile v1.2.54:references/mini-program-pay.md\n\n# Mini Program WeChat Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Mini Program payment flows on CloudBase, including 小程序微信支付, `wx.cloud.callHTTPFunction`, `wx.requestPayment`, Mini Program openid handling, payment callbacks, refunds, and order-status sync.\n\n## Agent Must Know\n\n- The CloudBase Integration Center generated payment function is an HTTP cloud function.\n- `pay-common` is an example function name; use the actual generated function name.\n- Mini Program openid can be injected by CloudBase when calling through the Mini Program cloud function path.\n- The client-side `wx.requestPayment` success callback is not the final business truth.\n- Fulfillment must be driven by callback handling or explicit order query.\n\n## Minimal Contract\n\nTypical Mini Program flow:\n\n1. Mini Program calls the generated payment function over `wx.cloud.callHTTPFunction`.\n2. The request path targets the generated payment route, commonly an order-creation path such as `/wx-pay/wxpay_order`.\n3. The generated function returns payment parameters for `wx.requestPayment`.\n4. The Mini Program invokes `wx.requestPayment`.\n5. Backend callback or query logic confirms paid state before updating business data.\n\nExample shape:\n\n```js\nconst functionName = \"replace-with-generated-payment-function\";\n\nconst orderResult = await wx.cloud.callHTTPFunction({\n  name: functionName,\n  path: \"/wx-pay/wxpay_order\",\n  data: {\n    out_trade_no: orderId,\n    description: \"Order payment\",\n    amount: {\n      total: 1,\n      currency: \"CNY\",\n    },\n  },\n});\n\n// callHTTPFunction returns { data, statusCode, header }\n// The generated function typically returns { code, data, message }\n// Payment params are under orderResult.data.data\nconst payment = orderResult.data?.data;\nif (!payment) {\n  throw new Error(\"Missing payment parameters from CloudBase payment function\");\n}\n\nawait wx.requestPayment(payment);\n```\n\nAdjust field names to the official docs and the generated function contract before using in production.\n\n## Implementation Checklist\n\n- Confirm `wx.cloud.init({ env })` uses the canonical full CloudBase environment ID.\n- Confirm the Mini Program AppID matches the WeChat Pay merchant binding.\n- Confirm the generated function name and path in CloudBase console.\n- Generate a unique `out_trade_no` on the backend or trusted business layer.\n- Validate amount and product data server-side before creating payment.\n- Persist pending order state before initiating payment.\n- Handle payment callback idempotently.\n- Query the order after client payment success before showing final fulfillment state.\n\n## Common Extensions\n\n- Write order and payment status to CloudBase database.\n- Add an idempotency key on `out_trade_no`.\n- Add fulfillment only after callback/query confirms success.\n- Add refund initiation and refund callback handling if the product supports refunds.\n\n## Do Not\n\n- Do not place merchant keys or certificates in Mini Program code.\n- Do not trust client-provided amount without server-side validation.\n- Do not assume frontend success means the order is paid.\n- Do not hard-code `pay-common` if the console generated a different function name.\n\nFile v1.2.54:references/native-qr-pay.md\n\n# Native QR-Code Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for PC/Web checkout, Native WeChat Pay, QR-code payment, or flows where the generated function returns a payment `code_url` for the frontend to render as a QR code.\n\n## Agent Must Know\n\n- Native payment does not use `wx.requestPayment` or `WeixinJSBridge`.\n- The generated payment function creates an order and returns a QR-code URL such as `code_url`.\n- The frontend renders the QR code and polls or subscribes to payment state.\n- Fulfillment must wait for callback or query confirmation.\n\n## Minimal Contract\n\nTypical Native flow:\n\n1. Backend or frontend calls the generated payment function to create a Native order.\n2. The generated function returns `code_url`.\n3. The frontend renders `code_url` as a QR code.\n4. The user scans the QR code in WeChat.\n5. The app polls order status or waits for callback-driven state changes.\n\nExample frontend shape:\n\n```js\nasync function createNativePayment(orderId) {\n  const response = await fetch(\"/api/pay/native-order\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ orderId }),\n  });\n  const data = await response.json();\n  if (!data.code_url) {\n    throw new Error(\"Missing Native payment code_url\");\n  }\n  return data.code_url;\n}\n```\n\nIn CloudBase frontend-only projects, the API wrapper can call the generated HTTP function directly if the access model and CORS/security rules are appropriate. For production, prefer a trusted backend or generated function extension that validates amount and order ownership.\n\n## Implementation Checklist\n\n- Confirm this is Native QR-code payment, not JSAPI or Mini Program payment.\n- Confirm generated function name and Native order path.\n- Generate a unique order number and persist pending state.\n- Validate amount and goods details before creating payment.\n- Render QR code from `code_url`.\n- Poll order status with backoff, or update UI from callback-driven status.\n- Expire stale QR codes and handle closed orders.\n\n## Do Not\n\n- Do not call `wx.requestPayment` for Native QR-code pay.\n- Do not fulfill the order when the QR code is generated.\n- Do not rely on frontend polling alone if callback data says otherwise.\n\nFile v1.2.54:references/official-account-jsapi-pay.md\n\n# Official Account JSAPI Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account webpage payment, JSAPI payment inside the WeChat browser, H5 checkout that calls `WeixinJSBridge.invoke`, and flows that need an official-account openid before creating the payment order.\n\n## Agent Must Know\n\n- JSAPI payment requires the page to run in the WeChat built-in browser.\n- The payer openid must belong to the correct Official Account, not the Mini Program openid.\n- Official Account OAuth is commonly needed before JSAPI order creation.\n- The generated payment function name and routes must be read from the user's Integration Center setup.\n- Final business state still depends on payment callback or order query.\n\n## Minimal Contract\n\nTypical JSAPI flow:\n\n1. Redirect the user through Official Account OAuth to get an openid.\n2. Call the generated payment function to create a JSAPI order.\n3. Pass returned payment parameters to `WeixinJSBridge.invoke(\"getBrandWCPayRequest\", ...)`.\n4. Use payment callback or order query to confirm paid state.\n\nExample invocation shape:\n\n```js\nfunction invokeJsapiPay(paymentParams) {\n  return new Promise((resolve, reject) => {\n    if (!window.WeixinJSBridge) {\n      reject(new Error(\"WeixinJSBridge is unavailable; open this page in WeChat\"));\n      return;\n    }\n\n    window.WeixinJSBridge.invoke(\n      \"getBrandWCPayRequest\",\n      paymentParams,\n      (res) => {\n        if (res.err_msg === \"get_brand_wcpay_request:ok\") {\n          resolve(res);\n          return;\n        }\n        reject(new Error(res.err_msg || \"JSAPI payment failed\"));\n      },\n    );\n  });\n}\n```\n\nAdjust request paths and parameter names to the generated function contract and official docs.\n\n## Implementation Checklist\n\n- Confirm the app is an Official Account web flow, not a Mini Program page.\n- Confirm the page runs inside WeChat before showing JSAPI checkout.\n- Obtain the Official Account openid through OAuth before order creation.\n- Confirm merchant account binding matches the Official Account AppID.\n- Persist pending order state before invoking payment.\n- Confirm paid state through callback or query before fulfillment.\n\n## Do Not\n\n- Do not reuse Mini Program openid for Official Account JSAPI pay.\n- Do not show JSAPI checkout in a normal desktop browser.\n- Do not put AppSecret, merchant private keys, or APIv3 keys in browser code.\n\nFile v1.2.54:references/official-account-oauth.md\n\n# Official Account OAuth\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account OAuth, openid retrieval, userinfo retrieval, token refresh, OAuth config inspection, or preparation for Official Account JSAPI payment.\n\n## Agent Must Know\n\n- Official Account openid is different from Mini Program openid.\n- OAuth credentials should be configured through CloudBase Integration Center, not embedded in frontend code.\n- The generated official-account function name may differ from example names such as `offiaccount-common`.\n- OAuth route names must be confirmed from the generated function and official docs.\n\n## Minimal Contract\n\nCommon generated OAuth routes include:\n\n- `/oauth/config`\n- `/oauth/token`\n- `/oauth/refresh`\n- `/oauth/userinfo`\n- `/oauth/verify`\n\nTypical flow:\n\n1. Get OAuth config or construct the authorization URL according to the generated function contract.\n2. Redirect the user to WeChat authorization.\n3. Exchange the returned code for token/openid through the generated function.\n4. Optionally fetch userinfo if the scope and product requirement allow it.\n5. Store only the user identifiers and business-safe profile fields required by the app.\n\nExample exchange shape:\n\n```js\nasync function exchangeOfficialAccountCode(code) {\n  const response = await fetch(\"/api/wechat/oauth/token\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ code }),\n  });\n  const data = await response.json();\n  if (!data.openid) {\n    throw new Error(\"Missing Official Account openid\");\n  }\n  return data;\n}\n```\n\nUse the actual generated function path or an application backend wrapper instead of copying this path literally.\n\n## Implementation Checklist\n\n- Confirm the target is an Official Account web scenario.\n- Confirm OAuth callback domain and redirect URI are configured.\n- Confirm the generated function name and OAuth routes.\n- Decide whether the product needs only openid or also userinfo.\n- Store tokens securely if refresh is required.\n- For JSAPI pay, pass the Official Account openid into the payment order creation flow.\n\n## Do Not\n\n- Do not expose AppSecret in browser code.\n- Do not confuse Official Account openid with Mini Program openid.\n- Do not request userinfo scope unless the product actually needs profile data.\n\nFile v1.2.54:references/overview.md\n\n# CloudBase WeChat Integration Overview\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## What Integration Center Provides\n\nCloudBase Integration Center is a console-driven capability for connecting third-party services to CloudBase. For WeChat scenarios, it can generate HTTP cloud functions, inject configuration through managed environment variables, and handle platform-specific callback verification or decryption.\n\nUse this skill for the application-side work around those integrations:\n\n- generating client calls to the generated functions\n- adding order persistence, idempotency, and fulfillment logic\n- diagnosing callback, credential, and routing issues\n- guiding the user through console setup without collecting secrets\n\n## Agent Must Know\n\n- Creation and credential binding are console-first unless official public API support is confirmed.\n- Generated function names may vary. Examples such as `pay-common` and `offiaccount-common` are not a contract.\n- Merchant secrets, private keys, APIv3 keys, AppSecret values, and certificates belong in CloudBase console configuration, not in source code.\n- The payment callback or order-query result is the authoritative state for business fulfillment.\n- Generated functions should be treated as platform-managed templates with safe business extensions, not as blank custom functions.\n\n## Scenario Map\n\n| User wording | Route |\n| --- | --- |\n| 小程序支付, 微信支付, `wx.requestPayment` | `mini-program-pay.md` |\n| 公众号支付, JSAPI 支付, 微信内网页支付 | `official-account-jsapi-pay.md` |\n| Native 支付, 扫码支付, 二维码支付 | `native-qr-pay.md` |\n| 公众号授权, openid, userinfo, OAuth | `official-account-oauth.md` |\n| 回调失败, 404, 凭证, openid 不匹配 | `troubleshooting.md` |\n\n## Console-First Setup Checklist\n\n1. Confirm the CloudBase environment ID.\n2. Open Integration Center in the CloudBase console.\n3. Choose the matching WeChat integration type.\n4. Fill merchant or official-account credentials in the console form.\n5. Record the generated function name and HTTP route paths.\n6. Run a minimal call before adding business logic.\n7. Add business data handling after the generated function works.\n\n## Independent Distribution Notes\n\nWhen this skill is installed alone:\n\n- Use only the references in this directory plus the official docs above.\n- If no CloudBase MCP tools are available, guide the user to inspect function logs and configuration in the console.\n- Do not reference local repository paths that may not exist in the target platform.\n\nFile v1.2.54:references/troubleshooting.md\n\n# WeChat Integration Troubleshooting\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/introduce.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n\n## First Checks\n\n1. Confirm the scenario: Mini Program Pay, JSAPI Pay, Native Pay, or Official Account OAuth.\n2. Confirm the CloudBase environment ID.\n3. Confirm the actual generated function name.\n4. Confirm the exact route path from Integration Center or generated function docs.\n5. Check cloud function logs before changing code.\n6. Check whether the issue is credential setup, route mismatch, callback delivery, or business logic.\n\n## Common Symptoms\n\n### 404 or route not found\n\nLikely causes:\n\n- wrong function name\n- wrong HTTP path\n- calling Mini Program payment path from the wrong client\n- generated function was deleted or redeployed incorrectly\n\nActions:\n\n- inspect the generated function routes\n- confirm the call target uses the actual function name\n- check CloudBase function logs and HTTP access logs\n\n### Missing credentials or credential initialization errors\n\nLikely causes:\n\n- Integration Center form is incomplete\n- merchant certificate/APIv3 key/private key was not configured\n- function environment variables were removed or overwritten\n\nActions:\n\n- re-check Integration Center credential configuration in the console\n- do not paste secrets into code or chat\n- restore generated environment variables if they were overwritten\n\n### Openid mismatch\n\nLikely causes:\n\n- Mini Program openid used for Official Account JSAPI pay\n- Official Account AppID does not match merchant binding\n- user authorized a different app than the one used for payment\n\nActions:\n\n- identify whether the flow needs Mini Program openid or Official Account openid\n- verify AppID and merchant binding\n- rerun OAuth or Mini Program call in the correct client context\n\n### Payment succeeds in frontend but order is not fulfilled\n\nLikely causes:\n\n- business logic trusts frontend success only\n- callback did not reach the generated function\n- callback handler is not idempotent\n- order status query is missing\n\nActions:\n\n- use callback or query as the authoritative payment state\n- add idempotent order update logic\n- inspect payment callback logs\n- verify `out_trade_no` maps to the application's order record\n\n### Callback not received\n\nLikely causes:\n\n- merchant platform notification URL is wrong\n- callback path does not match generated function route\n- APIv3 key/certificate mismatch prevents verification/decryption\n- function security or deployment issue\n\nActions:\n\n- check Integration Center callback configuration\n- check merchant platform callback settings\n- inspect generated function logs\n- retry with a low-value test order after fixing configuration\n\n### `callHTTPFunction is not a function`\n\nLikely causes:\n\n- Mini Program base library or CloudBase SDK capability is too old\n- the project is not initialized with `wx.cloud.init`\n- the flow is running outside Mini Program runtime\n\nActions:\n\n- confirm Mini Program runtime and base library support\n- initialize CloudBase with the canonical full environment ID\n- use the correct client flow for Web/JSAPI/Native scenarios\n\n## Before Editing Generated Code\n\n- Keep generated credential handling intact.\n- Add business logic around generated handlers instead of replacing verification/decryption logic.\n- Preserve callback idempotency and order lookup.\n- Keep secrets out of source code.\n\nFile v1.2.54:references/virtual-payment.md\n\n# Mini Program Virtual Payment (虚拟支付)\n\nOfficial docs:\n\n- `https://developers.weixin.qq.com/minigame/dev/wxcloud/guide/wechatpay/ai-virtualpayl-person.html`（AI 工具快速接入虚拟支付，含小游戏/小程序）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment`（企业/个体户接入指引）\n- `https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment/person`（个人主体接入指引）\n- Client API: `https://developers.weixin.qq.com/miniprogram/dev/api/payment/wx.requestVirtualPayment.html`\n\n## When To Use\n\nUse this reference for **虚拟支付**（virtual goods payment）flows: 道具直购、代币、`wx.requestVirtualPayment`、`xpay_*` 回调事件、OfferID / AppKey 签名、发货推送、查单兜底。\n\n**与微信支付的边界**：虚拟支付走 MP 后台「虚拟支付」通道（`wx.requestVirtualPayment`， OfferID + AppKey 签名），与 Integration Center 生成的微信支付（`wx.requestPayment`，商户号 + APIv3）是**两套独立链路**。卖实物/服务用微信支付（见 `mini-program-pay.md`）；卖虚拟道具/代币用本参考。\n\n## Prerequisites\n\n| 条件 | 说明 |\n| --- | --- |\n| 主体资质 | 个人 / 企业 / 个体户均可；个人主体需服务类目含「工具」，且**全终端月支付限额 10 万元** |\n| 开通入口 | MP 后台 → 支付与交易 → 虚拟支付 → 开通 |\n| 关键参数 | AppID（设置）、OfferID、现网 AppKey、沙箱 AppKey（均在 虚拟支付 → 基本配置） |\n| 道具 | 虚拟支付 → 道具管理 创建并**发布**；发布后需等几分钟到半小时全平台同步，期间下单报 `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` |\n| iOS 支付 | 需先配置「小程序简称」（Apple 展示名）并开通苹果 IAP；用户微信客户端需 **8.0.68+**，代码里先校验版本再拉起支付 |\n\n## Sandbox vs 现网\n\n| 模式 | 适用版本 | 限制 |\n| --- | --- | --- |\n| 沙箱 | 开发版 / 体验版 | 真机预览下会被 `PAYMENT_ILLEGAL_IN_SANDBOX` 拦截 |\n| 现网 | 全版本 | iOS 真机需开通 IAP |\n\n- 沙箱仅适合开发者工具内调试；真实联调用现网（`env: 0`、正式 AppKey）。\n- 沙箱 AppKey 不要出现在生产代码里。\n\n## Core Flow\n\n```text\n① 前端请求服务端下单 → 服务端生成唯一 outTradeNo，构造 signData，算 paySig + signature\n② 前端调用 wx.requestVirtualPayment(payData) 拉起支付\n③ 服务端确认支付并发货：\n   路径 A：收到 xpay_goods_deliver_notify 发货推送 → 幂等发货\n   路径 B：推送丢失时定时调 query_order 查单 → 已支付则补发货\n④ 前端查服务端订单状态 → 展示购买成功\n```\n\n关键点：\n\n- 发货以「发货推送」为主、`query_order` 查单兜底；**前端 success 回调不作为发货依据**。\n- 幂等以平台单号 `wx_order_id`（回调里 `WeChatPayInfo.MchOrderNo`）去重。\n- `outTradeNo` 每次下单重新生成、8-32 位、不能以下划线开头、不可复用。\n\n### payData fields\n\n| 字段 | 说明 |\n| --- | --- |\n| signData | JSON 字符串：`offerId` / `buyQuantity` / `env`（固定 0）/ `currencyType`（固定 CNY）/ `productId` / `goodsPrice`（单位：**分**，与后台道具价一致）/ `outTradeNo` / `attach`（透传，发货时原样返回） |\n| mode | 道具直购固定 `short_series_goods` |\n| paySig | 服务端用 **AppKey** 对 `requestVirtualPayment&signData` 做 HMAC-SHA256 |\n| signature | 服务端用 **sessionKey**（`auth.code2Session` 获取）对 signData 做 HMAC-SHA256 |\n\n### 签名规则\n\n- `paySig` 消息体 = `uri + '&' + post_body`；`post_body` 必须与实际发出的请求体**完全一致**（不格式化、不改键顺序）。\n- C 端下单 uri 固定 `requestVirtualPayment`；B 端服务接口（如 `/xpay/query_order`）用实际路径。\n\n### Callback events (xpay_*)\n\n| Event | 说明 | 处理 |\n| --- | --- | --- |\n| `xpay_goods_deliver_notify` | 道具发货通知 | 核心事件：幂等发货，返回 `<xml><ErrCode>0</ErrCode><ErrMsg><![CDATA[success]]></ErrMsg></xml>`，否则平台重试（最多 15 次） |\n| `xpay_coin_pay_notify` | 代币支付通知 | 更新代币余额 |\n| `xpay_refund_notify` | 退款通知 | 更新订单状态、回收道具 |\n| `xpay_complaint_notify` | 用户投诉通知 | 记录并人工跟进 |\n| `xpay_subscribe_signing_result_notify` | 订阅签约结果 | 更新订阅状态 |\n| `xpay_subscribe_pay_fail_notify` | 订阅支付失败 | 提示用户 |\n| `xpay_subscribe_ios_refund_query_notify` | iOS 订阅退款问询 | **3 秒内**返回 `result_code`（0=建议退款，1=拒绝），否则 Apple 连续问询 3 次后标「不确定」 |\n\n发货推送核心字段：`OpenId`（发给谁）、`OutTradeNo`（业务单号）、`WeChatPayInfo.MchOrderNo`（平台单号）、`GoodsInfo.ProductId` / `GoodsInfo.Quantity`（发什么、发多少）。\n\n### Query order (查单兜底)\n\n`POST /xpay/query_order`（带 pay_sig 签名）：\n\n```json\n{ \"openid\": \"用户openid\", \"env\": 0, \"order_id\": \"业务单号 outTradeNo\" }\n```\n\n> ⚠️ 参数名是 `order_id`（传 outTradeNo），不是 `out_trade_no`。建议每 5 分钟定时查一次未完成订单。\n\n## Refunds & Settlement\n\n| 终端 | 退款 | 结算周期 | 费率 |\n| --- | --- | --- | --- |\n| Android 等 | 开发者主动（MP 后台或 `refund_order` 接口） | T+3 | 1%（腾讯技术服务费） |\n| iOS | ❌ 开发者无法主动退款；用户在 App Store → 购买记录申请，Apple 审批后推送 `xpay_refund_notify` | 约 45-60 天 | 12%（Apple 佣金） |\n\n- 支付 180 天内退款平台退还手续费，超过 180 天不退。\n- iOS 订单在前端「我的」等场景建议**隐藏退款入口**，改为引导用户去 App Store 申请。\n\n## Common Errors\n\n| 错误 | 原因 | 解法 |\n| --- | --- | --- |\n| `COIN_OR_PRODUCT_ID_CREATED_IN_RECENTLY` | 道具刚发布，平台同步延迟 | 等几分钟到半小时再试 |\n| `PAYMENT_ILLEGAL_IN_SANDBOX` | 沙箱模式在真机预览下被拒 | 切现网（`env: 0` + 正式 AppKey） |\n| 当前商户尚未开启 iOS 支付 | iOS 端 IAP 未开通 | MP 后台配置小程序简称 + 开通 IAP |\n\n## On 微信云开发 (WeChat CloudBase)\n\n用微信云开发承接时无需自建服务器/证书：云函数承担下单签名、回调处理、查单兜底，云数据库存订单。典型拆分：\n\n- 下单云函数：生成业务单号、构造 signData、计算双签名，返回 payData\n- 回调云函数：接收 `xpay_*` 推送，幂等校验后发放/回收道具（需在 MP 后台配置发货推送 URL 并订阅事件）\n- 查单云函数：推送丢失时调 `query_order` 补发货，兼作订单/道具查询\n\n配合 Nightly 微信开发者工具（≥ 2.02.2608312）与 `wechatide` CLI / IDE MCP，可自动完成云函数部署与消息推送订阅（见 `../miniprogram-development/SKILL.md` 的 DevTools 工作流）。\n\n## Implementation Checklist\n\n- [ ] 已开通虚拟支付，拿到 AppID / OfferID / 现网 AppKey\n- [ ] 道具已创建**并发布**（留意同步延迟）\n- [ ] iOS 支付：小程序简称已配置、IAP 已开通、客户端已校验微信 ≥ 8.0.68\n- [ ] 签名实现与官方示例核对一致；`post_body` 与实际请求体逐字节一致\n- [ ] 金额单位全程「分」，不换算；`env` 固定 0\n- [ ] 发货推送已配置 URL，回调以 `wx_order_id` 幂等去重\n- [ ] `query_order` 兜底查单已就绪\n- [ ] 已向用户说明退款规则与费率（Android 1% / iOS 12%、个人主体月限额 10 万）\n- [ ] 上线后小额真单验证：支付 → 推送 → 发货 → 后台账单金额一致\n\n## Do Not\n\n- Do not use 沙箱 AppKey or sandbox mode for production / real-device verification.\n- Do not treat the frontend `wx.requestVirtualPayment` success callback as the fulfillment trigger.\n- Do not reuse `outTradeNo` across orders.\n- Do not attempt server-side refund for iOS orders (user-initiated via App Store only).\n- Do not place AppKey / sessionKey in mini program client code.\n- Do not mix this flow with Integration Center 微信支付 (`wx.requestPayment`) contracts.\n\nFile v1.2.54:skill-card.md\n\n## Description:\n\nGuides developers through CloudBase integrations for WeChat payments, virtual purchases, Official Account OAuth, and payment troubleshooting.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[binggg](https://clawhub.ai/user/binggg)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers building CloudBase apps use this skill to implement or troubleshoot Mini Program and Official Account payment, virtual goods purchases, Native QR checkout, OAuth, and order callbacks.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Merchant credentials or OAuth secrets could be exposed in generated code or chat.\n\nMitigation: Configure secrets in the CloudBase console; do not paste them into chat or commit them to source control.\n\nRisk: Relying on client payment success could cause premature fulfillment or duplicate order updates.\n\nMitigation: Confirm payment through callbacks or order queries, and handle fulfillment idempotently.\n\nRisk: Incorrect generated function names or changes to callback logic could disrupt payments and OAuth flows.\n\nMitigation: Verify generated routes against official documentation and review changes to orders, refunds, fulfillment, and OAuth data before deployment.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/binggg/skills/cloudbase-wechat-integration)\n- [CloudBase Integration Center overview](https://docs.cloudbase.net/integration/introduce.md)\n- [CloudBase Mini Program WeChat Pay](https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md)\n- [CloudBase Official Account JSAPI Pay](https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md)\n- [CloudBase Native WeChat Pay](https://docs.cloudbase.net/integration/wechat-pay-native.md)\n- [CloudBase Official Account OAuth](https://docs.cloudbase.net/integration/wechat-official-oauth.md)\n- [WeChat Mini Program virtual payment](https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Code, Configuration instructions]\n\n**Output Format:** [Markdown with code examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Scenario-specific instructions; proposed changes require review before deployment.]\n\n## Skill Version(s):\n\n1.2.54 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.2.53: 10 files, 17975 bytes\n\nFiles: references/mini-program-pay.md (3300b), references/native-qr-pay.md (2349b), references/official-account-jsapi-pay.md (2572b), references/official-account-oauth.md (2436b), references/overview.md (2636b), references/troubleshooting.md (3670b), references/virtual-payment.md (8237b), skill-card.md (4196b), SKILL.md (7636b), _meta.json (148b)\n\nFile v1.2.53:SKILL.md\n\n---\nname: cloudbase-wechat-integration\ndescription: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.\nversion: 2.34.6\nalwaysApply: false\n---\n\n# CloudBase WeChat Integration\n\nThis skill routes WeChat payment and official-account work through CloudBase Integration Center. It gives the agent the stable execution contract and points to the official Markdown docs for console details that may change.\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\nOfficial CloudBase Integration Center docs (human reference — do not treat as skill markdown to fetch into agent context as a sibling skill substitute):\n- CloudBase Integration Center overview: `https://docs.cloudbase.net/integration/introduce.md`\n- CloudBase Integration Center usage: `https://docs.cloudbase.net/integration/usage.md`\n- When cloud function deployment or log operations are needed and no sibling skill is available, use the current platform's CloudBase MCP tools or CloudBase console instead of guessing unsupported APIs.\n\n## Activation Contract\n\n### Use this first when\n\n- The user asks about WeChat Pay, 小程序支付, 微信支付, JSAPI 支付, 公众号支付, Native 扫码支付, 二维码支付, refund callbacks, payment callbacks, `wx.requestPayment`, `WeixinJSBridge`, `openid`, or Official Account OAuth in a CloudBase app.\n- The user asks about 虚拟支付 (virtual payment) for virtual goods: 道具直购, 代币充值, `wx.requestVirtualPayment`, OfferID, AppKey 签名, `xpay_*` callbacks (发货推送/查单/退款), or MP 后台虚拟支付开通与配置.\n- The task mentions CloudBase Integration Center, 集成中心, generated payment functions, `pay-common`, `offiaccount-common`, or callback routing for WeChat payment.\n- The user needs to extend a CloudBase Integration Center generated function with order persistence, idempotency, fulfillment, or payment-status sync.\n\n### Then also read\n\n- Mini Program structure and preview work -> `../miniprogram-development/SKILL.md` (if unavailable, use the current mini program platform docs and the mini-program payment reference in this skill)\n- Web frontend work -> `../web-development/SKILL.md` (if unavailable, use the JSAPI or Native references in this skill)\n- Cloud function runtime, logs, deployment, or gateway work -> `../cloud-functions/SKILL.md` (if unavailable, use CloudBase console/MCP function tools and the generated-function guidance in this skill)\n\n### Do NOT use for\n\n- Generic CloudBase Web Auth or Mini Program native identity work that does not involve WeChat payment or official-account OAuth.\n- General CloudBase cloud function development unrelated to Integration Center generated functions.\n- Creating or managing Integration Center instances through guessed MCP tools, guessed Manager SDK methods, or undocumented Cloud API actions.\n- Storing merchant secrets, private keys, APIv3 keys, AppSecret values, or certificates in app source code, generated examples, README files, commits, or prompts.\n\n## Operating Rules\n\n1. Treat Integration Center creation as a console-first workflow unless a public Manager SDK or Cloud API contract is confirmed in official docs.\n2. Use official `index.md` docs for console UI steps and credential fields; do not copy stale console screenshots or invent field names.\n3. Never ask the user to paste secrets into chat. Tell them to configure merchant and official-account credentials in the CloudBase console Integration Center form.\n4. Do not assume generated function names are fixed. `pay-common` and `offiaccount-common` are examples; ask for or inspect the actual function name before writing calls.\n5. Treat frontend payment success as UI feedback only. The authoritative payment state must come from server-side query results or payment callbacks.\n6. When extending generated functions, preserve credential environment variables and generated callback verification/decryption logic. Add business logic around order checks, persistence, idempotency, and fulfillment.\n7. Before changing payment or callback code, identify the target scenario and load only the matching reference file.\n\n## Routing\n\n| Task | Read | Why |\n| --- | --- | --- |\n| Capability selection, console-first boundaries, independent distribution | `references/overview.md` | Establishes the Integration Center model and safety rules |\n| Mini Program WeChat Pay, `wx.cloud.callHTTPFunction`, `wx.requestPayment` | `references/mini-program-pay.md` | Covers Mini Program openid injection, order creation, and callback expectations |\n| Mini Program 虚拟支付, virtual goods, `wx.requestVirtualPayment`, `xpay_*` callbacks | `references/virtual-payment.md` | Covers OfferID/AppKey signing, sandbox vs 现网, delivery callbacks, query-order fallback, iOS IAP rules |\n| Official Account JSAPI pay, H5 inside WeChat, `WeixinJSBridge.invoke` | `references/official-account-jsapi-pay.md` | Covers official-account openid and JSAPI invocation |\n| Native QR-code pay for PC/Web checkout | `references/native-qr-pay.md` | Covers `code_url`, QR rendering, and polling/query flow |\n| Official Account OAuth, openid/userinfo retrieval | `references/official-account-oauth.md` | Covers OAuth routes generated by the official-account integration |\n| 404, missing credentials, openid mismatch, callback failures, logs | `references/troubleshooting.md` | Provides diagnosis steps before changing code |\n\n## Quick Workflow\n\n1. Classify the scenario: Mini Program Pay, Virtual Payment (虚拟支付), JSAPI Pay, Native Pay, Official Account OAuth, generated-function extension, or troubleshooting.\n2. Load the matching reference and the official `index.md` docs linked there.\n3. Confirm the actual CloudBase environment ID and generated function name.\n4. Generate or modify only the required client/backend code; keep merchant credentials in Integration Center configuration.\n5. Add order-status query, callback idempotency, and amount/order validation when payment state affects business data.\n6. Verify through function logs, callback logs, and an end-to-end payment sandbox or low-value production test as appropriate.\n\n## Minimum Self-Check\n\n- Did I avoid guessing undocumented Integration Center management APIs?\n- Did I use the actual generated function name instead of assuming `pay-common`?\n- Did I keep all merchant secrets and certificates out of source code and cha...","readmeExcerpt":"Skill: 微信生态集成 · WeChat Integration Owner: binggg Summary: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat ","codeSnippets":[],"executableExamples":[{"language":"js","snippet":"const functionName = \"replace-with-generated-payment-function\";\n\nconst orderResult = await wx.cloud.callHTTPFunction({\n  name: functionName,\n  path: \"/wx-pay/wxpay_order\",\n  data: {\n    out_trade_no: orderId,\n    description: \"Order payment\",\n    amount: {\n      total: 1,\n      currency: \"CNY\",\n    },\n  },\n});\n\n// callHTTPFunction returns { data, statusCode, header }\n// The generated function typically returns { code, data, message }\n// Payment params are under orderResult.data.data\nconst payment = orderResult.data?.data;\nif (!payment) {\n  throw new Error(\"Missing payment parameters from CloudBase payment function\");\n}\n\nawait wx.requestPayment(payment);"},{"language":"js","snippet":"async function createNativePayment(orderId) {\n  const response = await fetch(\"/api/pay/native-order\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ orderId }),\n  });\n  const data = await response.json();\n  if (!data.code_url) {\n    throw new Error(\"Missing Native payment code_url\");\n  }\n  return data.code_url;\n}"},{"language":"js","snippet":"function invokeJsapiPay(paymentParams) {\n  return new Promise((resolve, reject) => {\n    if (!window.WeixinJSBridge) {\n      reject(new Error(\"WeixinJSBridge is unavailable; open this page in WeChat\"));\n      return;\n    }\n\n    window.WeixinJSBridge.invoke(\n      \"getBrandWCPayRequest\",\n      paymentParams,\n      (res) => {\n        if (res.err_msg === \"get_brand_wcpay_request:ok\") {\n          resolve(res);\n          return;\n        }\n        reject(new Error(res.err_msg || \"JSAPI payment failed\"));\n      },\n    );\n  });\n}"},{"language":"js","snippet":"async function exchangeOfficialAccountCode(code) {\n  const response = await fetch(\"/api/wechat/oauth/token\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ code }),\n  });\n  const data = await response.json();\n  if (!data.openid) {\n    throw new Error(\"Missing Official Account openid\");\n  }\n  return data;\n}"},{"language":"text","snippet":"① 前端请求服务端下单 → 服务端生成唯一 outTradeNo，构造 signData，算 paySig + signature\n② 前端调用 wx.requestVirtualPayment(payData) 拉起支付\n③ 服务端确认支付并发货：\n   路径 A：收到 xpay_goods_deliver_notify 发货推送 → 幂等发货\n   路径 B：推送丢失时定时调 query_order 查单 → 已支付则补发货\n④ 前端查服务端订单状态 → 展示购买成功"},{"language":"json","snippet":"{ \"openid\": \"用户openid\", \"env\": 0, \"order_id\": \"业务单号 outTradeNo\" }"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: cloudbase-wechat-integration\ndescription: CloudBase WeChat integration guide for Mini Program WeChat Pay, Mini Program virtual payment (虚拟支付, wx.requestVirtualPayment), Official Account JSAPI Pay, Native QR-code Pay, Official Account OAuth, openid handling, payment callbacks, and CloudBase Integration Center generated functions. This skill should be used when users ask to add, debug, or extend WeChat payment, virtual payment, or official-account flows on CloudBase.\nversion: 2.35.0\nalwaysApply: false\n---\n\n# CloudBase WeChat Integration\n\nThis skill routes WeChat payment and official-account work through CloudBase Integration Center. It gives the agent the stable execution contract and points to the official Markdown docs for console details that may change.\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\nOfficial CloudBase Integration Center docs (human reference — do not treat as skill markdown to fetch into agent context as a sibling skill substitute):\n- CloudBase Integration Center overview: `https://docs.cloudbase.net/integration/introduce.md`\n- CloudBase Integration Center usage: `https://docs.cloudbase.net/integration/usage.md`\n- When cloud function deployment or log operations are needed and no sibling skill is available, use the current platform's CloudBase MCP tools or CloudBase console instead of guessing unsupported APIs.\n\n## Activation Contract\n\n### Use this first when\n\n- The user asks about WeChat Pay, 小程序支付, 微信支付, JSAPI 支付, 公众号支付, Native 扫码支付, 二维码支付, refund callbacks, payment callbacks, `wx.requestPayment`, `WeixinJSBridge`, `openid`, or Official Account OAuth in a CloudBase app.\n- The user asks about 虚拟支付 (virtual payment) for virtual goods: 道具直购, 代币充值, `wx.requestVirtualPayment`, OfferID, AppKey 签名, `xpay_*` callbacks (发货推送/查单/退款), or MP 后台虚拟支付开通与配置.\n- The task mentions CloudBase Integration Center, 集成中心, generated payment functions, `pay-common`, `offiaccount-common`, or callback routing for WeChat payment.\n- The user needs to extend a CloudBase Integration Center generated function with order persistence, idempotency, fulfillment, or payment-status sync.\n\n### Then also read\n\n- Mini Program structure and preview work -> `../miniprogram-development/SKILL.md` (if unavailable, use the current mini program platform docs and the mini-program payment reference in this skill)\n- Web frontend work -> `../web-development/SKILL.md` (if unavailable, use the JSAPI or Native references in this skill)\n- Cloud function runtime, logs, deployment, or gateway work -> `../cloud-functions/SKILL.md` (if unavailable, use CloudBase console/MCP function tools and the generated-function guidance in this skill)\n\n### Do NOT use "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7emfp36dbn1xx4fz4s5q4a6180439j\",\n  \"slug\": \"cloudbase-wechat-integration\",\n  \"version\": \"1.2.57\",\n  \"publishedAt\": 1791524513531\n}"},{"path":"references/mini-program-pay.md","content":"# Mini Program WeChat Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-miniprogram.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Mini Program payment flows on CloudBase, including 小程序微信支付, `wx.cloud.callHTTPFunction`, `wx.requestPayment`, Mini Program openid handling, payment callbacks, refunds, and order-status sync.\n\n## Agent Must Know\n\n- The CloudBase Integration Center generated payment function is an HTTP cloud function.\n- `pay-common` is an example function name; use the actual generated function name.\n- Mini Program openid can be injected by CloudBase when calling through the Mini Program cloud function path.\n- The client-side `wx.requestPayment` success callback is not the final business truth.\n- Fulfillment must be driven by callback handling or explicit order query.\n\n## Minimal Contract\n\nTypical Mini Program flow:\n\n1. Mini Program calls the generated payment function over `wx.cloud.callHTTPFunction`.\n2. The request path targets the generated payment route, commonly an order-creation path such as `/wx-pay/wxpay_order`.\n3. The generated function returns payment parameters for `wx.requestPayment`.\n4. The Mini Program invokes `wx.requestPayment`.\n5. Backend callback or query logic confirms paid state before updating business data.\n\nExample shape:\n\n```js\nconst functionName = \"replace-with-generated-payment-function\";\n\nconst orderResult = await wx.cloud.callHTTPFunction({\n  name: functionName,\n  path: \"/wx-pay/wxpay_order\",\n  data: {\n    out_trade_no: orderId,\n    description: \"Order payment\",\n    amount: {\n      total: 1,\n      currency: \"CNY\",\n    },\n  },\n});\n\n// callHTTPFunction returns { data, statusCode, header }\n// The generated function typically returns { code, data, message }\n// Payment params are under orderResult.data.data\nconst payment = orderResult.data?.data;\nif (!payment) {\n  throw new Error(\"Missing payment parameters from CloudBase payment function\");\n}\n\nawait wx.requestPayment(payment);\n```\n\nAdjust field names to the official docs and the generated function contract before using in production.\n\n## Implementation Checklist\n\n- Confirm `wx.cloud.init({ env })` uses the canonical full CloudBase environment ID.\n- Confirm the Mini Program AppID matches the WeChat Pay merchant binding.\n- Confirm the generated function name and path in CloudBase console.\n- Generate a unique `out_trade_no` on the backend or trusted business layer.\n- Validate amount and product data server-side before creating payment.\n- Persist pending order state before initiating payment.\n- Handle payment callback idempotently.\n- Query the order after client payment success before showing final fulfillment state.\n\n## Common Extensions\n\n- Write order and payment status to CloudBase database.\n- Add an idempotency key on `out_trade_no`.\n- Add fulfillment only after callback/query confirms success.\n- Add refund initiation and refund callback handling if the product supports refunds.\n\n## D"},{"path":"references/native-qr-pay.md","content":"# Native QR-Code Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-native.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for PC/Web checkout, Native WeChat Pay, QR-code payment, or flows where the generated function returns a payment `code_url` for the frontend to render as a QR code.\n\n## Agent Must Know\n\n- Native payment does not use `wx.requestPayment` or `WeixinJSBridge`.\n- The generated payment function creates an order and returns a QR-code URL such as `code_url`.\n- The frontend renders the QR code and polls or subscribes to payment state.\n- Fulfillment must wait for callback or query confirmation.\n\n## Minimal Contract\n\nTypical Native flow:\n\n1. Backend or frontend calls the generated payment function to create a Native order.\n2. The generated function returns `code_url`.\n3. The frontend renders `code_url` as a QR code.\n4. The user scans the QR code in WeChat.\n5. The app polls order status or waits for callback-driven state changes.\n\nExample frontend shape:\n\n```js\nasync function createNativePayment(orderId) {\n  const response = await fetch(\"/api/pay/native-order\", {\n    method: \"POST\",\n    headers: { \"Content-Type\": \"application/json\" },\n    body: JSON.stringify({ orderId }),\n  });\n  const data = await response.json();\n  if (!data.code_url) {\n    throw new Error(\"Missing Native payment code_url\");\n  }\n  return data.code_url;\n}\n```\n\nIn CloudBase frontend-only projects, the API wrapper can call the generated HTTP function directly if the access model and CORS/security rules are appropriate. For production, prefer a trusted backend or generated function extension that validates amount and order ownership.\n\n## Implementation Checklist\n\n- Confirm this is Native QR-code payment, not JSAPI or Mini Program payment.\n- Confirm generated function name and Native order path.\n- Generate a unique order number and persist pending state.\n- Validate amount and goods details before creating payment.\n- Render QR code from `code_url`.\n- Poll order status with backoff, or update UI from callback-driven status.\n- Expire stale QR codes and handle closed orders.\n\n## Do Not\n\n- Do not call `wx.requestPayment` for Native QR-code pay.\n- Do not fulfill the order when the QR code is generated.\n- Do not rely on frontend polling alone if callback data says otherwise."},{"path":"references/official-account-jsapi-pay.md","content":"# Official Account JSAPI Pay\n\nOfficial docs:\n\n- `https://docs.cloudbase.net/integration/wechat-pay-jsapi-h5.md`\n- `https://docs.cloudbase.net/integration/wechat-official-oauth.md`\n- `https://docs.cloudbase.net/integration/usage.md`\n\n## When To Use\n\nUse this reference for WeChat Official Account webpage payment, JSAPI payment inside the WeChat browser, H5 checkout that calls `WeixinJSBridge.invoke`, and flows that need an official-account openid before creating the payment order.\n\n## Agent Must Know\n\n- JSAPI payment requires the page to run in the WeChat built-in browser.\n- The payer openid must belong to the correct Official Account, not the Mini Program openid.\n- Official Account OAuth is commonly needed before JSAPI order creation.\n- The generated payment function name and routes must be read from the user's Integration Center setup.\n- Final business state still depends on payment callback or order query.\n\n## Minimal Contract\n\nTypical JSAPI flow:\n\n1. Redirect the user through Official Account OAuth to get an openid.\n2. Call the generated payment function to create a JSAPI order.\n3. Pass returned payment parameters to `WeixinJSBridge.invoke(\"getBrandWCPayRequest\", ...)`.\n4. Use payment callback or order query to confirm paid state.\n\nExample invocation shape:\n\n```js\nfunction invokeJsapiPay(paymentParams) {\n  return new Promise((resolve, reject) => {\n    if (!window.WeixinJSBridge) {\n      reject(new Error(\"WeixinJSBridge is unavailable; open this page in WeChat\"));\n      return;\n    }\n\n    window.WeixinJSBridge.invoke(\n      \"getBrandWCPayRequest\",\n      paymentParams,\n      (res) => {\n        if (res.err_msg === \"get_brand_wcpay_request:ok\") {\n          resolve(res);\n          return;\n        }\n        reject(new Error(res.err_msg || \"JSAPI payment failed\"));\n      },\n    );\n  });\n}\n```\n\nAdjust request paths and parameter names to the generated function contract and official docs.\n\n## Implementation Checklist\n\n- Confirm the app is an Official Account web flow, not a Mini Program page.\n- Confirm the page runs inside WeChat before showing JSAPI checkout.\n- Obtain the Official Account openid through OAuth before order creation.\n- Confirm merchant account binding matches the Official Account AppID.\n- Persist pending order state before invoking payment.\n- Confirm paid state through callback or query before fulfillment.\n\n## Do Not\n\n- Do not reuse Mini Program openid for Official Account JSAPI pay.\n- Do not show JSAPI checkout in a normal desktop browser.\n- Do not put AppSecret, merchant private keys, or APIv3 keys in browser code."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2111,"uniquenessScore":33,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T07:34:55.285Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T07:34:55.285Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T13:48:31.351Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}