{"id":"84ca6037-3ea7-4164-9893-2a56c2737d5b","entityType":"agent","slug":"clawhub-binggg-cloudbase","name":"腾讯云 CloudBase · Tencent CloudBase","canonicalUrl":"https://www.xpersona.co/agent/clawhub-binggg-cloudbase","canonicalPath":"/agent/clawhub-binggg-cloudbase","generatedAt":"2026-10-09T12:51:34.432Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:34:32.561Z","emptyReason":null},"description":"Use this skill when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android, Flutter, React Native). Covers UI (页面, 界面, 表单, dashboard, prototype, 原型); auth (登录, 注册, OAuth, publishable key); databases (NoSQL 文档数据库, MySQL 关系型数据库, PostgreSQL/CloudBase PG, app.rdb(), queryPgDatabase/managePgDatabase, CRUD, security rules); 云函数/cloud functions (serverless, scf_bootstrap); CloudRun (云托管, Dockerfile); 云存储; built-in AI (内置大模型, AI 对话, streaming, 流式输出, 图片生成, generateText, streamText, createModel, generateImage, TokenHub, Hunyuan, DeepSeek, GLM, Kimi, Token Credits 资源包, 小程序成长计划); third-party/custom model onboarding (第三方大模型接入, 大模型调用, LLM API); AI agent (智能体, AG-UI, LangGraph); ops troubleshooting (巡检, 诊断, 日志); spec workflow (需求文档, 技术方案, requirements, tasks.md). Do NOT use for non-CloudBase projects, pure frontend without CloudBase, or self-hosted backends without CloudBase.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 9.1K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17cgdbxp195f7dy8f5h6p0d9183h6nq:cloudbase","sourceUrl":"https://clawhub.ai/binggg/cloudbase","homepage":"https://clawhub.ai/binggg/skills/cloudbase","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/binggg/cloudbase","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/binggg/skills/cloudbase","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"腾讯云 CloudBase · Tencent CloudBase technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:34:32.561Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:34:32.561Z","emptyReason":null},"stars":null,"forks":null,"downloads":9139,"packageName":null,"latestVersion":"1.92.120","tractionLabel":"9.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:34:32.560Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T02:34:32.561Z","lastCrawledAt":"2026-10-09T02:34:32.560Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T02:34:32.560Z","lastVerifiedAt":null,"highlights":[{"version":"1.92.120","createdAt":"2026-09-30T13:37:41.404Z","changelog":"Recent commits / 最近提交: | - fix(clawhub): 🏷️ publish the curated display name and topics (#1124) | - docs: 🔄 sync CloudBase CloudAPI reference page | - feat(evals): ✨ score the secret and migration tasks (#1122) | - feat(evals): add the scenario runner and point it at a local endpoint (#1119) | - fix(mcp): 🔧 report local endpoint failures directly (#1118)","fileCount":159,"zipByteSize":588296},{"version":"1.92.119","createdAt":"2026-09-30T06:07:25.433Z","changelog":"Recent commits / 最近提交: | - chore(release): bump version to v2.34.8 | - fix(mcp): 🔒 bind the two-phase function deploy to the upload target it signed (#1114) | - feat(mcp): route cloud API calls to a local endpoint (#1116) | - feat(evals): ✨ point the public dry run at a scored task (#1113) | - fix(dsh-plugin): 📝 describe database, storage, auth, and deploy (#1117)","fileCount":159,"zipByteSize":588177},{"version":"1.92.118","createdAt":"2026-09-29T09:28:04.471Z","changelog":"Recent commits / 最近提交: | - feat(mcp): add a default feedback plugin for session drafts (#1109) | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore(scripts): harden the internal archive against secret spill and overwrite (#1105) | - Merge branch 'main' of https://github.com/TencentCloudBase/CloudBase-AI-Toolkit | - chore(dsh-plugin): bump version to 0.1.3","fileCount":159,"zipByteSize":588222},{"version":"1.92.117","createdAt":"2026-09-28T09:41:34.452Z","changelog":"Recent commits / 最近提交: | - fix(skills): 📄 correct CDC prerequisite failure modes and conditional wording (#1099) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - chore(experts): auto-bump versions for changed packs [skip ci] | - fix(skills): document config.presence.key in the realtime reference (#1100)","fileCount":159,"zipByteSize":587800},{"version":"1.92.116","createdAt":"2026-09-28T09:24:14.046Z","changelog":"Recent commits / 最近提交: | - docs(skills): cover PG spec-change expectations and custom domains (#1094) | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - chore(experts): auto-bump versions for changed packs [skip ci]","fileCount":159,"zipByteSize":587055},{"version":"1.92.115","createdAt":"2026-09-28T08:52:59.097Z","changelog":"Recent commits / 最近提交: | - docs(skills): add PostgreSQL instance recipe, refine ICP readiness, record merge recovery (#1090) | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore(experts): auto-bump versions for changed packs [skip ci]","fileCount":158,"zipByteSize":566106},{"version":"1.92.114","createdAt":"2026-09-24T15:56:45.200Z","changelog":"Recent commits / 最近提交: | - fix(skills): 🧭 correct mini program subject and environment preflight (#1096) | - chore(mcp): 🧹 drop IDE compat artifacts committed under mcp/ (#1095) | - feat(functions): two-phase ZIP deploy via presigned COS upload (#1084) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci]","fileCount":157,"zipByteSize":557872},{"version":"1.92.113","createdAt":"2026-09-24T08:02:41.663Z","changelog":"Recent commits / 最近提交: | - fix(skills): 🐛 fix manageApps action names and default-domain note (#1092) | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs(marketplace): refresh the listing matrix and regenerate the report (#1091) | - docs(readme): replace Repobeats embed with a self-hosted activity card (#1089) | - docs(skills): 🧭 record stacked-PR recovery and the paths-filter trap (#1088)","fileCount":157,"zipByteSize":554965}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17cgdbxp195f7dy8f5h6p0d9183h6nq:cloudbase","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17cgdbxp195f7dy8f5h6p0d9183h6nq:cloudbase` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/binggg/cloudbase before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T12:51:34.426Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-binggg-cloudbase/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:34:32.561Z","emptyReason":null},"readme":"Skill: 腾讯云 CloudBase · Tencent CloudBase\n\nOwner: binggg\n\nSummary: Use this skill when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android, Flutter, React Native). Covers UI (页面, 界面, 表单, dashboard, prototype, 原型); auth (登录, 注册, OAuth, publishable key); databases (NoSQL 文档数据库, MySQL 关系型数据库, PostgreSQL/CloudBase PG, app.rdb(), queryPgDatabase/managePgDatabase, CRUD, security rules); 云函数/cloud functions (serverless, scf_bootstrap); CloudRun (云托管, Dockerfile); 云存储; built-in AI (内置大模型, AI 对话, streaming, 流式输出, 图片生成, generateText, streamText, createModel, generateImage, TokenHub, Hunyuan, DeepSeek, GLM, Kimi, Token Credits 资源包, 小程序成长计划); third-party/custom model onboarding (第三方大模型接入, 大模型调用, LLM API); AI agent (智能体, AG-UI, LangGraph); ops troubleshooting (巡检, 诊断, 日志); spec workflow (需求文档, 技术方案, requirements, tasks.md). Do NOT use for non-CloudBase projects, pure frontend without CloudBase, or self-hosted backends without CloudBase.\n\nTags: latest:1.92.120\n\nVersion history:\n\nv1.92.120 | 2026-09-30T13:37:41.404Z | user\n\nRecent commits / 最近提交: | - fix(clawhub): 🏷️ publish the curated display name and topics (#1124) | - docs: 🔄 sync CloudBase CloudAPI reference page | - feat(evals): ✨ score the secret and migration tasks (#1122) | - feat(evals): add the scenario runner and point it at a local endpoint (#1119) | - fix(mcp): 🔧 report local endpoint failures directly (#1118)\n\nv1.92.119 | 2026-09-30T06:07:25.433Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.8 | - fix(mcp): 🔒 bind the two-phase function deploy to the upload target it signed (#1114) | - feat(mcp): route cloud API calls to a local endpoint (#1116) | - feat(evals): ✨ point the public dry run at a scored task (#1113) | - fix(dsh-plugin): 📝 describe database, storage, auth, and deploy (#1117)\n\nv1.92.118 | 2026-09-29T09:28:04.471Z | user\n\nRecent commits / 最近提交: | - feat(mcp): add a default feedback plugin for session drafts (#1109) | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore(scripts): harden the internal archive against secret spill and overwrite (#1105) | - Merge branch 'main' of https://github.com/TencentCloudBase/CloudBase-AI-Toolkit | - chore(dsh-plugin): bump version to 0.1.3\n\nv1.92.117 | 2026-09-28T09:41:34.452Z | user\n\nRecent commits / 最近提交: | - fix(skills): 📄 correct CDC prerequisite failure modes and conditional wording (#1099) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - chore(experts): auto-bump versions for changed packs [skip ci] | - fix(skills): document config.presence.key in the realtime reference (#1100)\n\nv1.92.116 | 2026-09-28T09:24:14.046Z | user\n\nRecent commits / 最近提交: | - docs(skills): cover PG spec-change expectations and custom domains (#1094) | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - chore(experts): auto-bump versions for changed packs [skip ci]\n\nv1.92.115 | 2026-09-28T08:52:59.097Z | user\n\nRecent commits / 最近提交: | - docs(skills): add PostgreSQL instance recipe, refine ICP readiness, record merge recovery (#1090) | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore(experts): auto-bump versions for changed packs [skip ci]\n\nv1.92.114 | 2026-09-24T15:56:45.200Z | user\n\nRecent commits / 最近提交: | - fix(skills): 🧭 correct mini program subject and environment preflight (#1096) | - chore(mcp): 🧹 drop IDE compat artifacts committed under mcp/ (#1095) | - feat(functions): two-phase ZIP deploy via presigned COS upload (#1084) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci]\n\nv1.92.113 | 2026-09-24T08:02:41.663Z | user\n\nRecent commits / 最近提交: | - fix(skills): 🐛 fix manageApps action names and default-domain note (#1092) | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs(marketplace): refresh the listing matrix and regenerate the report (#1091) | - docs(readme): replace Repobeats embed with a self-hosted activity card (#1089) | - docs(skills): 🧭 record stacked-PR recovery and the paths-filter trap (#1088)\n\nv1.92.112 | 2026-09-23T11:57:36.429Z | user\n\nRecent commits / 最近提交: | - fix(ci): 🔧 keep skill versions and the compat baseline in sync (#1080) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci] | - fix(compat): refresh the compat baseline (#1078) | - docs(faq): split product questions from tool questions in the help section (#1081)\n\nv1.92.111 | 2026-09-23T10:09:31.545Z | user\n\nRecent commits / 最近提交: | - fix(compat): refresh the compat baseline (#1078) | - docs(faq): split product questions from tool questions in the help section (#1081) | - docs(marketplace): record awesome-dsh CloudBase listing success (#1082) | - chore: sync cloudbase plugin skills from upstream | - chore(connectors): sync generated cloudbase-intl package [skip ci]\n\nv1.92.110 | 2026-09-23T08:41:22.254Z | user\n\nRecent commits / 最近提交: | - fix(skills): get() must be a template literal; document missing-target failure (#1086) | - fix(ci): 🔧 guard PR metadata and commit messages against internal references (#1087) | - fix(mcp): 🐛 report AUTH_REQUIRED from getEnvId when the session is not logged in (#1085) | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs: 🔄 sync CloudBase CloudAPI reference page\n\nv1.92.109 | 2026-09-21T13:08:21.047Z | user\n\nRecent commits / 最近提交: | - Merge branch 'feat/function-publish-version-9cb1bf6e' | - Merge remote-tracking branch 'origin/main' | - feat(skills): 🧭 settle the site on first run instead of re-deciding per session | - feat(capi): 🇨🇳 add the ICP filing (ba) service and its recipe | - fix(rag): 🔒 readDoc only reads the official docs site\n\nv1.92.108 | 2026-09-20T09:18:03.995Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.5 | - fix(internal-sync): 🧹 keep atomic-write temp files out of the archive (#1070) | - chore(experts): auto-bump versions for changed packs [skip ci] | - chore(dsh-plugin): bump version to 0.1.2 | - chore(experts): auto-bump versions for changed packs [skip ci]\n\nv1.92.107 | 2026-09-20T08:00:50.137Z | user\n\nRecent commits / 最近提交: | - fix(databasePG): 🗑️ drop rollbackMigration, whose cloud API action is unimplemented (#1069) | - chore(experts): auto-bump versions for changed packs [skip ci] | - feat(mcp): ✨ report login_uin so usage can be attributed to an account (#1067) | - chore(experts): auto-bump versions for changed packs [skip ci] | - fix(issue-auto): 🛡️ stop publishing raw model output in PR bodies (#1068)\n\nv1.92.106 | 2026-09-20T04:21:02.743Z | user\n\nRecent commits / 最近提交: | - docs(miniprogram-expert): note trial accounts do not support CloudBase (#1065) | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore: sync cloudbase plugin skills from upstream | - chore(experts): auto-bump versions for changed packs [skip ci] | - feat(mcp): support shared COS buckets (ExternalStorage) (#1059)\n\nv1.92.105 | 2026-09-18T13:09:12.971Z | user\n\nRecent commits / 最近提交: | - feat(mcp): support shared COS buckets (ExternalStorage) (#1059) | - chore(experts): auto-bump versions for changed packs [skip ci] | - fix(cloudrun,storage,pg): 🔒 reject path-shaped names, and let initEnv be called as documented (#1056) | - chore(experts): auto-bump versions for changed packs [skip ci] | - feat(experts): broaden main expert coverage and persona-tune prompts (#1057)\n\nv1.92.104 | 2026-09-18T06:54:18.268Z | user\n\nRecent commits / 最近提交: | - fix(cloudrun): 🔍 补发布任务状态查询，修正 force 误导文案与等待语义 (#1053) | - chore: sync cloudbase plugin skills from upstream | - docs(mcp): 🌐 document remote-first dual-site connection, drop invalid site param (#1049) | - docs: 🔄 sync CloudBase CloudAPI reference page | - feat(mcp): 🌐 localize tool schemas, drop envQuery, and gate PG tools (#1048)\n\nv1.92.103 | 2026-09-18T03:57:50.709Z | user\n\nRecent commits / 最近提交: | - docs(mcp): 🌐 document remote-first dual-site connection, drop invalid site param (#1049) | - docs: 🔄 sync CloudBase CloudAPI reference page | - feat(mcp): 🌐 localize tool schemas, drop envQuery, and gate PG tools (#1048) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source\n\nv1.92.102 | 2026-09-16T09:34:38.202Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.4 | - chore: sync cloudbase plugin skills from upstream | - feat(skills): 📚 add PostgreSQL access-pattern best practices (#1046) | - fix(mcp): 🧭 按 OpenAI hosted Scan 收紧工具注解 (#1047) | - docs: 🔄 sync CloudBase CloudAPI reference page\n\nv1.92.101 | 2026-09-16T09:14:39.943Z | user\n\nRecent commits / 最近提交: | - feat(skills): 📚 add PostgreSQL access-pattern best practices (#1046) | - fix(mcp): 🧭 按 OpenAI hosted Scan 收紧工具注解 (#1047) | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore: sync cloudbase plugin skills from upstream | - fix(cloudrun): state the runtime contract and the credential gate (#1045)\n\nv1.92.100 | 2026-09-15T09:45:15.528Z | user\n\nRecent commits / 最近提交: | - fix(cloudrun): state the runtime contract and the credential gate (#1045) | - docs: 🔄 sync CloudBase CloudAPI reference page | - fix: 🤖 attempt fix for issue #1043 (#1044) | - feat(rag): serve the skill and OpenAPI catalog on demand (#1042) | - docs(skills): 📝 add docs-site sync step to add_video_tutorial (#1041)\n\nv1.92.99 | 2026-09-14T05:10:54.063Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.3 | - fix(mcp): 🐛 harden hosted tool contracts and error signalling (#1039) | - fix(ci): 🔧 run the plugin-skill pull-back after the upstream push (#1038) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source\n\nv1.92.98 | 2026-09-13T16:35:26.163Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.2 | - fix(mcp): 🐛 align the login_by_api_key hint with the parameter the tool reads (envId → apiKeyEnvId) (#1037) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source | - chore(release): bump version to v2.34.1\n\nv1.92.97 | 2026-09-13T16:00:09.707Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.1 | - chore: sync cloudbase plugin skills from upstream | - chore(experts): auto-bump versions for changed packs [skip ci] | - feat: 把部署后分享环节送到专家包与实际部署路径上 (#1036) | - fix(mcp): keep the OpenAPI doc list order stable across builds (#1035)\n\nv1.92.96 | 2026-09-13T15:39:52.666Z | user\n\nRecent commits / 最近提交: | - feat: 把部署后分享环节送到专家包与实际部署路径上 (#1036) | - fix(mcp): keep the OpenAPI doc list order stable across builds (#1035) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source | - chore(release): bump version to v2.34.0\n\nv1.92.95 | 2026-09-13T14:50:03.671Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.34.0 | - chore(release): refresh generated tools artifacts | - chore(gitignore): 忽略 plugin 发布产物的带时间戳变体 | - fix(mcp): 放宽 STS 资源级 E2E 的超时预算，消除云存储用例偶发超时 (#1034) | - fix(tools): CNB 链接存活检查区分「待合并后可见」，并刷掉自己的 compat 欠账 (#1033)\n\nv1.92.94 | 2026-09-13T12:42:25.662Z | user\n\nRecent commits / 最近提交: | - fix(docs): point skill docs at the site's current Markdown addresses (#1032) | - chore: sync cloudbase plugin skills from upstream | - feat(mcp): runtime-guard param-level i18n and cap describe length (#1030) | - chore: sync cloudbase plugin skills from upstream | - feat(mcp): callCloudApi 服务白名单扩至 57 个并内置版本映射 (#1029)\n\nv1.92.93 | 2026-09-13T11:57:17.872Z | user\n\nRecent commits / 最近提交: | - feat(mcp): runtime-guard param-level i18n and cap describe length (#1030) | - chore: sync cloudbase plugin skills from upstream | - feat(mcp): callCloudApi 服务白名单扩至 57 个并内置版本映射 (#1029) | - docs: 🔄 sync CloudBase CloudAPI reference page | - fix(docs): api-reference 段内标题降级一级，消除空段标题 (#1028)\n\nv1.92.92 | 2026-09-13T08:38:25.103Z | user\n\nRecent commits / 最近提交: | - feat(mcp): callCloudApi 服务白名单扩至 57 个并内置版本映射 (#1029) | - docs: 🔄 sync CloudBase CloudAPI reference page | - fix(docs): api-reference 段内标题降级一级，消除空段标题 (#1028) | - chore: sync cloudbase plugin skills from upstream | - feat(i18n): tool copy 全量国际化 + auth site/region/lang 参数 + 实例级 lang (#1016)\n\nv1.92.91 | 2026-09-12T14:45:07.693Z | user\n\nRecent commits / 最近提交: | - feat(i18n): tool copy 全量国际化 + auth site/region/lang 参数 + 实例级 lang (#1016) | - docs: 🔄 sync CloudBase CloudAPI reference page | - feat(mcp): auth 支持 site 参数，并补齐 prompts skill 覆盖与同步护栏 (#1024) | - fix(mcp): queryEnv 如实回执 region 生效情况，domains 尊重传入的 envId (#1027) | - feat(mcp): skill 兜底读取改指官方分发仓并返回 references 地址清单 (#1026)\n\nv1.92.90 | 2026-09-11T08:00:30.761Z | user\n\nRecent commits / 最近提交: | - feat(skills): add SDK-first database access decision gate to cloudrun-development (#1022) | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore: sync cloudbase plugin skills from upstream | - feat(skills): add optional Deployment Share after verified deploys (#1023) | - chore: sync cloudbase plugin skills from upstream\n\nv1.92.89 | 2026-09-10T12:49:58.345Z | user\n\nRecent commits / 最近提交: | - feat(skills): add optional Deployment Share after verified deploys (#1023) | - chore: sync cloudbase plugin skills from upstream | - docs(skills): promote publishable key auto-provisioning to a cross-skill convention (#1020) (#1021) | - fix: correct stale entry points and version pins, sync server.json at publish time (#1018) | - docs(skills): PG env routing, owner-table template, public-read bucket RLS, migration retry semantics (#1019)\n\nv1.92.88 | 2026-09-10T08:37:24.095Z | user\n\nRecent commits / 最近提交: | - docs(skills): promote publishable key auto-provisioning to a cross-skill convention (#1020) (#1021) | - fix: correct stale entry points and version pins, sync server.json at publish time (#1018) | - docs(skills): PG env routing, owner-table template, public-read bucket RLS, migration retry semantics (#1019) | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs: 🔄 sync CloudBase CloudAPI reference page\n\nv1.92.87 | 2026-09-10T08:16:45.430Z | user\n\nRecent commits / 最近提交: | - docs(skills): PG env routing, owner-table template, public-read bucket RLS, migration retry semantics (#1019) | - docs: 🔄 sync CloudBase CloudAPI reference page | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore: sync cloudbase plugin skills from upstream | - chore(ci): decouple npm publish from skills lint, unbreak main sync blind spot (#1015)\n\nv1.92.86 | 2026-09-09T05:22:18.495Z | user\n\nRecent commits / 最近提交: | - fix(skills): add missing sibling-skills section to unblock v2.33.2 npm publish (#1011) | - Merge pull request #1010 from TencentCloudBase/feature/expert-office-series | - ci: auto-bump expert pack versions on content change | - feat: add workbench & collect-form expert packs | - chore: sync cloudbase plugin skills from upstream\n\nv1.92.85 | 2026-09-08T12:59:00.311Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.33.2 | - chore: sync claude skills mirror from source | - Merge pull request #980 from yulinlin2020/feature/deploy0831 | - Merge pull request #1009 from TencentCloudBase/feat/webdev-expert-prereq-checks | - feat(experts): add connector & skill prerequisite checks to cloudbase-webdev-expert\n\nv1.92.84 | 2026-09-08T12:29:15.636Z | user\n\nRecent commits / 最近提交: | - Merge pull request #980 from yulinlin2020/feature/deploy0831 | - Merge pull request #1009 from TencentCloudBase/feat/webdev-expert-prereq-checks | - feat(experts): add connector & skill prerequisite checks to cloudbase-webdev-expert | - Merge pull request #1008 from TencentCloudBase/chore/bump-expert-plugins-version | - fix(plugin): 🔧 add cloud-api-operations skill-metadata entry to fix skill-manifest build\n\nv1.92.83 | 2026-09-08T11:53:42.011Z | user\n\nRecent commits / 最近提交: | - Merge pull request #1007 from TencentCloudBase/feat/cloud-api-operations-skill | - feat(skill): add cloud-api-operations skill and open monitor/postgres for callCloudApi | - docs: 🔄 sync CloudBase CloudAPI reference page | - chore: sync claude skills mirror from source | - chore(release): bump version to v2.33.1\n\nv1.92.82 | 2026-09-08T04:24:58.359Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.33.1 | - chore(release): build artifacts for v2.33.1 | - Merge branch 'feature/tool-naming-env-domain-converge' | - feat(telemetry): add client param and region/site reporting for hosted MCP | - Merge pull request #1006 from TencentCloudBase/fix/intl-device-flow-auth-url\n\nv1.92.81 | 2026-09-04T09:54:34.096Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.33.0 (eea512f9) | - feat(functions): 支持云函数自定义镜像部署与异步部署状态查询 (#985) | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source | - refactor(env): converge env domain tool naming into query*/manage* system (#997)\n\nv1.92.80 | 2026-09-04T09:23:48.948Z | user\n\nRecent commits / 最近提交: | - refactor(env): converge env domain tool naming into query*/manage* system (#997) | - refactor(dsh-plugin): 下线右侧 details 面板（0.1.0 精简，v0.2 以 kit 回归） (#996) | - fix(errors): centralize error guidance by Code instead of per-tool message regex (#994) | - test(hosted-mcp): cloud hosted MCP E2E with official SDK client (#977) | - feat(apps): cloud upload channel — queryApps getUploadUrl + deployApp cosTimestamp either-or (#989)\n\nv1.92.79 | 2026-09-04T06:48:20.065Z | user\n\nRecent commits / 最近提交: | - fix(skills): 🔤 restore activation-critical model vocabulary in cloudbase description (#993) | - chore: sync cloudbase plugin skills from upstream | - chore: sync cloudbase plugin skills from upstream | - fix: hosted MCP defect batch (cloud-mode gating, PG/dataModel, skills docs quality) (#991) | - chore(experts): polish miniprogram-clouddev-expert package description (#990)\n\nv1.92.78 | 2026-09-04T03:59:03.708Z | user\n\nRecent commits / 最近提交: | - fix: hosted MCP defect batch (cloud-mode gating, PG/dataModel, skills docs quality) (#991) | - chore(experts): polish miniprogram-clouddev-expert package description (#990) | - chore: sync claude skills mirror from source | - feat(skills): add mini program virtual payment reference (#988) | - fix(apps): harden cloud-mode deployApp localPath gate (e5dcba51) (#984)\n\nv1.92.77 | 2026-09-04T02:57:30.998Z | user\n\nRecent commits / 最近提交: | - feat(skills): add mini program virtual payment reference (#988) | - fix(apps): harden cloud-mode deployApp localPath gate (e5dcba51) (#984) | - feat(env-binding): use cloudbaserc.json as field-level binding fallback (#987) | - fix(issue-auto): 🤖 attempt fix for issue #982 (#983) | - feat(experts): attach expert package zips to release assets (#986)\n\nv1.92.76 | 2026-09-01T10:41:22.665Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.32.5 (4e6ca71c) | - fix(auth): international-site (TCB_SITE=intl) API key routing, device flow and diagnostics (#972) | - fix(mcp): queryEnv(list) pin to bound env for hosted OAuth token (环境级 STS) (#968) | - refactor(rag): remove vector mode from searchKnowledgeBase (#973) | - fix(cloudrun): mask service env params by default in queryCloudRun detail (#975)\n\nv1.92.75 | 2026-08-28T12:54:21.220Z | user\n\nRecent commits / 最近提交: | - feat(ide): add Kimi Code & Kimi Work IDE support (#966) | - fix: correct misleading output from queryHosting, PG sqlPreview and queryEnv errors (#967) | - chore: sync cloudbase plugin skills from upstream | - chore: sync cloudbase plugin skills from upstream | - chore: sync claude skills mirror from source\n\nv1.92.74 | 2026-08-28T04:23:27.480Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.32.4 (a9cd97d2) | - chore: sync claude skills mirror from source | - fix(auth): give OTP sdkHints full call context and messageId caution (#964) | - chore: sync cloudbase plugin skills from upstream | - docs(release): add v2.32.3 release notes (7b513c4e)\n\nv1.92.73 | 2026-08-28T03:20:30.202Z | user\n\nRecent commits / 最近提交: | - fix(auth): give OTP sdkHints full call context and messageId caution (#964) | - chore: sync cloudbase plugin skills from upstream | - docs(release): add v2.32.3 release notes (7b513c4e) | - chore: sync claude skills mirror from source | - chore(release): bump version to v2.32.3 (7b513c4e)\n\nv1.92.72 | 2026-08-26T13:22:39.178Z | user\n\nRecent commits / 最近提交: | - chore(release): bump version to v2.32.3 (7b513c4e) | - fix(auth): 🔧 resolve ambiguous-region credentials from the only usable site slot (#962) | - fix(tests): 🔨 retry temp dir cleanup in cloudbase-sites-plugin tests (#961) | - feat(pg): default ExecutePGSql role to cloudbase_postgres, reserve cloudbase_admin (#959) | - feat(dsh-plugin): @cloudbase/dsh-plugin — CloudBase backend for DeepSeek Harness (#933)\n\nv1.92.71 | 2026-08-25T10:34:40.661Z | user\n\nRecent commits / 最近提交: | - chore(release): 🚀 bump version to v2.32.2 (eec8ec79) | - Merge pull request #958 from TencentCloudBase/feat/msg-push-container-mode | - chore(deps): ⬆️ bump @cloudbase/manager-node to 5.8.2 (requestFn support, MR !150) | - Merge pull request #956 from TencentCloudBase/feat/git-guard-pre-push | - Revert \"fix(nosql): 🐛 route tcb-domain DB calls via requestFn when present (WeChat IDE has no Tencent creds) (dc0eaaf9)\"\n\nArchive index:\n\nArchive v1.92.120: 159 files, 588296 bytes\n\nFiles: references/activation-map.yaml (13877b), references/ai-model-nodejs/references/api-reference.md (4689b), references/ai-model-nodejs/references/custom-onboarding.md (1470b), references/ai-model-nodejs/SKILL.md (20129b), references/ai-model-web/SKILL.md (24545b), references/ai-model-wechat/SKILL.md (26030b), references/auth-nodejs-cloudbase/SKILL.md (16766b), references/auth-tool-cloudbase/checklist.md (1351b), references/auth-tool-cloudbase/references/extended-guide.md (14642b), references/auth-tool-cloudbase/SKILL.md (4750b), references/auth-web-cloudbase/references/extended-guide.md (14005b), references/auth-web-cloudbase/SKILL.md (17719b), references/auth-wechat-miniprogram/references/extended-guide.md (10365b), references/auth-wechat-miniprogram/SKILL.md (5459b), references/cloud-api-operations/references/calling-methods.md (14068b), references/cloud-api-operations/references/recipes/custom-domain.md (31051b), references/cloud-api-operations/references/recipes/icp-filing-readiness.md (15989b), references/cloud-api-operations/references/recipes/pg-instance-spec.md (25111b), references/cloud-api-operations/references/recipes/pg-storage-alarm.md (6647b), references/cloud-api-operations/references/recipes/README.md (3137b), references/cloud-api-operations/references/service-versions.md (4967b), references/cloud-api-operations/SKILL.md (6148b), references/cloud-functions/checklist.md (4729b), references/cloud-functions/references.md (3510b), references/cloud-functions/references/event-functions.md (3533b), references/cloud-functions/references/http-function-credentials.md (5674b), references/cloud-functions/references/http-functions-custom-image.md (10784b), references/cloud-functions/references/http-functions.md (16073b), references/cloud-functions/references/operations-and-config.md (9919b), references/cloud-functions/references/vpc-and-tcp-database.md (3734b), references/cloud-functions/SKILL.md (31537b), references/cloud-storage-web/SKILL.md (17940b), references/cloudbase-agent/py/adapter-coze.md (9666b), references/cloudbase-agent/py/adapter-development.md (17170b), references/cloudbase-agent/py/adapter-langgraph.md (14678b), references/cloudbase-agent/py/agent-deployment.md (14285b), references/cloudbase-agent/py/authentication.md (14607b), references/cloudbase-agent/py/references/observability.md (8796b), references/cloudbase-agent/py/references/recipes.md (9126b), references/cloudbase-agent/py/references/server.md (4858b), references/cloudbase-agent/py/references/storage.md (6843b), references/cloudbase-agent/py/references/tools.md (4832b), references/cloudbase-agent/py/server-quickstart.md (11359b), references/cloudbase-agent/py/skill.md (12104b), references/cloudbase-agent/SKILL.md (1916b), references/cloudbase-agent/ts/adapter-development.md (1913b), references/cloudbase-agent/ts/adapter-langchain.md (2662b), references/cloudbase-agent/ts/adapter-langgraph.md (5380b), references/cloudbase-agent/ts/agent-deployment.md (5156b), references/cloudbase-agent/ts/agui-protocol.md (2333b), references/cloudbase-agent/ts/server-quickstart.md (3640b), references/cloudbase-agent/ts/skill.md (3786b), references/cloudbase-agent/ts/ui-clients.md (1281b), references/cloudbase-agent/ts/ui-miniprogram.md (4206b), references/cloudbase-cli/references/access.md (9126b), references/cloudbase-cli/references/app.md (9279b), references/cloudbase-cli/references/cloudrun.md (9825b), references/cloudbase-cli/references/core.md (18940b), references/cloudbase-cli/references/functions.md (13304b), references/cloudbase-cli/references/hosting.md (6156b), references/cloudbase-cli/references/mysql.md (9284b), references/cloudbase-cli/references/nosql.md (9590b), references/cloudbase-cli/references/permission.md (11247b), references/cloudbase-cli/references/storage.md (10543b), references/cloudbase-cli/SKILL.md (6953b), references/cloudbase-code-review/references/lint-rules/README.md (17763b), references/cloudbase-code-review/references/RULES_INDEX.md (13173b), references/cloudbase-code-review/references/rules/cross-cutting/AUTH001.md (2481b), references/cloudbase-code-review/references/rules/cross-cutting/SEC001.md (2323b), references/cloudbase-code-review/references/rules/cross-cutting/SKILL001.md (1581b), references/cloudbase-code-review/references/rules/postgresql/PG-CR001.md (2751b), references/cloudbase-code-review/references/rules/postgresql/PG-CR002.md (2903b), references/cloudbase-code-review/references/rules/postgresql/PG-CR003.md (1915b), references/cloudbase-code-review/references/rules/postgresql/PG-CR004.md (2942b), references/cloudbase-code-review/references/rules/postgresql/PG-CR005.md (2338b), references/cloudbase-code-review/references/rules/storage/STORAGE001.md (1991b), references/cloudbase-code-review/SKILL.md (4497b), references/cloudbase-declarative-deploy/references/config-schema.md (5510b), references/cloudbase-declarative-deploy/references/multi-env.md (2065b), references/cloudbase-declarative-deploy/references/plan-and-apply.md (7554b)\n\nFile v1.92.120:references/ai-model-nodejs/SKILL.md\n\n---\nname: ai-model-nodejs\ndescription: \"Use this skill for Node.js backend AI via @cloudbase/node-sdk (>=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration. The only SDK supporting image generation (ai.createImageModel + generateImage). Text via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*; model ids (e.g. deepseek-v4-flash, glm-5, kimi-k2.6) go in the `model` field of generateText/streamText. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web) or Mini Program (use ai-model-wechat).\"\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## When to use this skill\n\nUse this skill for **calling AI models from Node.js backends, cloud functions, or CloudRun services** via `@cloudbase/node-sdk`.\n\n> 🧭 **Runtime-plane fit.** This is the right skill when the AI call truly belongs on the server: image generation (the only SDK that supports it), long-running agent jobs, orchestration across multiple tools, scheduled tasks, or flows that must keep secrets server-side. **If the user is building a Web page / frontend AI chat UI, do NOT wrap this SDK behind a backend proxy** — route to `ai-model-web` and call the model directly from the browser. For WeChat Mini Programs use `ai-model-wechat`. Routing is decided by runtime plane first; the concrete model (`deepseek-*`, `glm-*`, `hunyuan-*`, `kimi-*`, …) only affects the `model` field.\n\n**Use it when you need to:**\n\n- Integrate AI text generation into a backend service\n- Generate images with the Hunyuan Image model\n- Call AI models from CloudBase cloud functions or CloudRun\n- Do server-side AI processing (agent orchestration, batch jobs, scheduled tasks)\n\n**Do NOT use for:**\n\n- Browser/Web apps → use the `ai-model-web` skill\n- WeChat Mini Program → use the `ai-model-wechat` skill\n- Runtimes without a CloudBase SDK (Python, Go, PHP, curl, etc.) → use the `http-api-cloudbase` skill (it now includes the `ai_model` OpenAPI spec for direct HTTP calls to the AI model endpoint; do NOT wrap this SDK behind an HTTP proxy)\n\n---\n\n## ⛔ STOP — `ai.createModel(...)` argument is **not** a vendor / model name\n\nRead this before writing any `createModel(...)` line. Agents frequently hallucinate this argument. There are **exactly three** legal shapes. Anything else is a bug.\n\n| ✅ Legal `ai.createModel(...)` argument | When to use it |\n|----------------------------------------|----------------|\n| `\"cloudbase\"` | **The main managed group for server-side projects** (TokenHub-backed, multi-vendor pool). Vendor + concrete model go into the **`model` field** of `generateText` / `streamText`, e.g. `{ model: \"deepseek-v4-flash\" }`. **No model is enabled by default — always check `DescribeAIModels` first and, if the target model is missing, enable it with `UpdateAIModel` before calling the SDK.** |\n| `\"hunyuan-exp\"` | Only if `DescribeAIModels` explicitly returns this legacy builtin group for the current env. |\n| `\"custom-<your-name>\"` | A user-defined GroupName you onboarded via `CreateAIModel`. **Must** start with `custom-` (e.g. `custom-kimi`, `custom-openai-compat`). |\n\n> Image generation is a separate entry point: `ai.createImageModel(\"hunyuan-image\")`. Do not mix it with `createModel(...)`.\n\n### ❌ Wrong argument patterns\n\nAnything that is not one of the three legal values above: vendor names (`\"deepseek\"`, `\"glm\"`, `\"kimi\"`, `\"openai\"`, `\"moonshot\"`, …), concrete model ids (`\"deepseek-v4-flash\"`, `\"hunyuan-2.0-instruct-20251111\"`), the bare placeholder `\"custom\"`, or a variable holding the model id. All of these are bugs in `createModel(...)`.\n\n### ✅ Correct pattern — GroupName vs Model are two different fields\n\n```js\nconst model = ai.createModel(\"cloudbase\");          // ← GroupName\nawait model.generateText({\n  model: \"deepseek-v4-flash\",                       // ← concrete model id\n  messages: [...]\n});\n```\n\n### Decision procedure (when the user names a specific model)\n\n1. The user says \"use DeepSeek v3.2\" / \"use hunyuan instruct\" / \"use Kimi k2.6\" / \"use GLM-5\" / …\n2. `createModel(\"cloudbase\")` stays the same.\n3. Put the model id into the **`model` field**: `{ model: \"deepseek-v3.2\" }`, `{ model: \"hunyuan-2.0-instruct-20251111\" }`, `{ model: \"kimi-k2.6\" }`, `{ model: \"glm-5\" }`, …\n4. **Never assume the model is already enabled.** Before calling the SDK, verify it is present in `DescribeAIModels({ GroupName: \"cloudbase\" }).Models[]`. If missing, call `DescribeManagedAIModelList` to confirm the exact `Model` name the platform supports (case-sensitive — do **not** guess the spelling) and then enable it via `UpdateAIModel` with `Status: 1` (remember `Models` is a full replacement).\n\n> If you are about to type `ai.createModel(` and the thing inside the parentheses is a vendor name, a model name, or a guess — **stop**. It is almost certainly one of the three legal values above.\n\n---\n\n## Mandatory Two-Step Preflight (before any SDK code)\n\nBefore calling any AI API on the server, **run the two-step preflight**: ① eligibility, ② group readiness. **Text generation and image generation draw from the same Token Credits resource pack**, and both must complete the preflight before code is emitted.\n\n### Step 0: obtain the environment ID\n\nCall the MCP tool `queryEnv` with `action=info` and read `EnvId` from the response.\n\n---\n\n### Preflight ① — Eligibility (Token Credits resource pack)\n\nCall the MCP tool:\n\n```\ncallCloudApi(service=\"tcb\", action=\"DescribeEnvPostpayPackage\", params={ EnvId })\n```\n\n**Pass conditions (all required):**\n- `envPostpayPackageInfoList` contains at least one entry\n- That entry's `postpayPackageId` starts with `pkg_tcb_tokencredits_`\n- That entry's `status` is NOT in `[3, 4]` (3 / 4 typically mean expired / disabled; trust the live response)\n\n- ❌ **Not satisfied** → **stop writing code** and surface this to the user (replacing `{envId}` with the real id):\n  > The current environment has no active Token Credits resource pack. Please purchase one before calling any AI API:\n  > https://buy.cloud.tencent.com/lowcode?buyType=resPack&envId={envId}&resourceType=token\n  >\n  > Let me know once it's done and I'll re-check the resource pack status.\n\n- ✅ **Satisfied** → proceed to preflight ②.\n\n> Parameter casing is PascalCase by contract. If the call returns `InvalidParameter`, fall back to camelCase (`envId`) and trust the live response.\n\n---\n\n### Preflight ② — Group readiness (`DescribeAIModels` → `UpdateAIModel` if needed)\n\nEligibility alone is not enough. **Do not write `createModel(\"cloudbase\")` yet.** First confirm that the target `GroupName` exists in the env with `Status=1`, and that the target `Model` is present in its `Models[]`.\n\n1. **List groups configured in the current env:**\n\n   ```\n   callCloudApi(service=\"tcb\", action=\"DescribeAIModels\", params={ EnvId })\n   ```\n\n   Returns `AIModelGroups: AIModelGroup[]` with `GroupName`, `Type` (`builtin` / `custom`), `Models: [{ Model, EnableMCP, Tags }]`, `Status` (1 / 2), `BaseUrl`, `Secret`, `Remark`. The main managed `GroupName` is `cloudbase`.\n\n2. **Never assume a model is already enabled.** Inspect `AIModelGroups[?].Models[].Model` for the target group. If the text model you plan to use (e.g. `deepseek-v4-flash`, or whatever the user asked for) is missing from the `cloudbase` group's `Models[]`, jump to step 4 and enable it — do not call `createModel(\"cloudbase\")` yet. Image generation uses `createImageModel(\"hunyuan-image\")` + `model: \"hunyuan-image\"`; verify it is likewise enabled before the call.\n\n3. **User asked for a model from the managed catalog** (e.g. `deepseek-v3.2`, `hunyuan-2.0-instruct-20251111`): check whether that `Model` is already in the `cloudbase` group's `Models[]`. If not, jump to step 4. **Do not guess the exact model id** — confirm the canonical spelling in `DescribeManagedAIModelList` first.\n\n4. **Enable / add a managed model** (always inspect the authoritative catalog + pricing first):\n\n   ```\n   callCloudApi(service=\"tcb\", action=\"DescribeManagedAIModelList\", params={ EnvId })\n   ```\n\n   Returns `ManagedAIModelGroup[]` with `GroupName`, `Remark`, and `Models: [{ Model, EnableMCP, ModelSpec, ModelChargingInfo }]`. **This is the single source of truth for supported model names and pricing — do not infer them from memory. Use the exact `Model` string from here when calling `UpdateAIModel`.** `ModelChargingInfo` includes input / output prices and billing unit. Surface the prices to the user before enabling.\n\n   Then enable (note: `Models` is a **full replacement** — always resend the already-enabled models together with the new one):\n\n   ```\n   callCloudApi(service=\"tcb\", action=\"UpdateAIModel\", params={\n     EnvId,\n     GroupName: \"cloudbase\",\n     Models: [\n       // resend every model that DescribeAIModels already showed as enabled\n       { Model: \"<already-enabled model>\" },\n       // append the newly-requested one, using the exact spelling from DescribeManagedAIModelList\n       { Model: \"<target model>\" }\n     ],\n     Status: 1\n   })\n   ```\n\n5. **The requested model is not in the managed catalog** (not found by `DescribeManagedAIModelList`) → jump to the next section, **Custom onboarding (models outside the managed catalog)**.\n\n> All Actions use `service=tcb`, `Version=2018-06-08`. Parameters are PascalCase; fall back to camelCase only on `InvalidParameter`.\n\n---\n\n## Available Providers and Models\n\n`ai.createModel(<GroupName>)` accepts exactly three kinds of legal values; `ai.createImageModel(\"hunyuan-image\")` is the dedicated image-generation entry point.\n\n### 1. `\"cloudbase\"` — the main managed group (recommended)\n\n- `GroupName: \"cloudbase\"`, `Type: \"builtin\"`, `Remark: \"腾讯云开发\"` (Tencent CloudBase)\n- Backed by **Tencent Cloud TokenHub**, a unified managed pool covering multiple vendors — **Hunyuan** (HY 2.0 Instruct, HY 2.0 Think, Hunyuan-role, Hy3 preview, …), **DeepSeek** (DeepSeek-V4-Pro, DeepSeek-V4-Flash, Deepseek-v3.2, Deepseek-v3.1, Deepseek-r1-0528, Deepseek-v3-0324, …), **Zhipu GLM** (GLM-5, GLM-5-Turbo, GLM-5.1, GLM-5V-Turbo), **Kimi** (K2.5, K2.6), **MiniMax** (M2.5, M2.7), and more. The roster evolves — **do not hard-code specific SKUs**; discover at runtime\n- **No model is enabled by default.** Always call `DescribeAIModels` first to see what the env has actually enabled; if your target model is missing, call `DescribeManagedAIModelList` for the authoritative catalog + pricing and then `UpdateAIModel` (`Status: 1`, `Models` full-replacement) to enable it before making the SDK call.\n- Authoritative catalog + pricing: `DescribeManagedAIModelList`\n- Env-enabled set: `DescribeAIModels`\n\n### 2. `\"hunyuan-exp\"` — legacy builtin group (kept for compatibility)\n\n- Default model: `hunyuan-2.0-instruct-20251111`; additional hunyuan SKUs must be discovered at runtime via `DescribeAIModels({ GroupName: \"hunyuan-exp\" }).Models[]` — do not hard-code other IDs\n- Use it directly only if `DescribeAIModels` actually returns this group with `Status=1`. New projects should prefer `cloudbase`\n\n### 3. User-defined GroupName\n\n- Onboarded via `CreateAIModel` (see the next section). The custom `GroupName` **MUST start with `custom-`** (e.g. `custom-kimi`, `custom-moonshot`, `custom-openai-compat`). This naming convention prevents future collisions with built-in / vendor GroupNames (like `cloudbase`, `hunyuan-exp`, `deepseek`, `glm`, `kimi`, `minimax`) that the platform may introduce over time\n- Examples: `createModel(\"custom-kimi\")`, `createModel(\"custom-openai-compat\")`\n\n### Image generation (independent API)\n\n- `ai.createImageModel(\"hunyuan-image\")` + `model: \"hunyuan-image\"`. Only supported in the Node SDK\n\n> **Never** write guesses like `createModel(\"deepseek\")` or `createModel(\"custom\")` unless `DescribeAIModels` explicitly returned that exact `GroupName`.\n\n---\n\n## Custom onboarding (models outside the managed catalog)\n\nWhen the user wants a **non-managed** text model (self-hosted, enterprise-internal, third-party OpenAI-compatible endpoint, …), **do not block**. Guide them through onboarding — console flow, the full `CreateAIModel` payload, and follow-up management steps: [custom-onboarding.md](references/custom-onboarding.md). The custom `GroupName` MUST start with `custom-`; custom-model billing is covered by the third-party provider and does not draw from the Token Credits resource pack.\n\n---\n\n## Installation\n\n```bash\nnpm install @cloudbase/node-sdk\n```\n\n⚠️ **The AI feature requires version 3.16.0 or above.** Check with `npm list @cloudbase/node-sdk`.\n\n---\n\n## Initialization\n\n### Inside a CloudBase cloud function\n\n```js\nconst tcb = require('@cloudbase/node-sdk');\nconst app = tcb.init({ env: '<YOUR_ENV_ID>' });\n\nexports.main = async (event, context) => {\n  const ai = app.ai();\n  // Use AI features\n};\n```\n\n### Cloud function configuration for AI models\n\n⚠️ **Important:** when creating cloud functions that use AI models (especially `generateImage()` and large text generation), set a longer timeout — these operations can be slow.\n\n**Using the MCP tool `manageFunctions(action=\"createFunction\")`:**\n\nLegacy compatibility: if an older prompt still says `createFunction`, keep the same payload shape but execute it through `manageFunctions(action=\"createFunction\")`.\n\nSet `timeout` inside the `func` object:\n\n- **Parameter**: `func.timeout` (number)\n- **Unit**: seconds\n- **Range**: 1 – 900\n- **Default**: 20 seconds (usually too short for AI operations)\n\n**Recommended timeouts:**\n- **Text generation (`generateText`)**: 60 – 120 s\n- **Streaming (`streamText`)**: 60 – 120 s\n- **Image generation (`generateImage`)**: 300 – 900 s (recommended: 900 s)\n- **Combined operations**: 900 s (maximum allowed)\n\n### In a regular Node.js server\n\n```js\nconst tcb = require('@cloudbase/node-sdk');\nconst app = tcb.init({\n  env: '<YOUR_ENV_ID>',\n  secretId: '<YOUR_SECRET_ID>',\n  secretKey: '<YOUR_SECRET_KEY>'\n});\n\nconst ai = app.ai();\n```\n\n---\n\n## SDK API Reference (on demand)\n\nFor full `generateText` / `streamText` / `generateImage` code examples, the error-handling pattern, image-generation parameters, and the complete TypeScript type definitions, read [api-reference.md](references/api-reference.md). That file (together with this SKILL.md) is the authoritative reference for `@cloudbase/node-sdk`'s AI surface — look up method signatures there before writing code. If a method or field is not documented there, stop and ask, or check the live contract via the MCP tools. No guessing.\n\n---\n\n## Best Practices\n\n1. **Run the two-step preflight before writing business code** — ① eligibility: `queryEnv` → `callCloudApi(tcb, DescribeEnvPostpayPackage)` to confirm the Token Credits resource pack (text + image share the same pack); ② group readiness: `DescribeAIModels` for the `cloudbase` group and its `Models[]`, `DescribeManagedAIModelList` for the authoritative supported-model catalog, `UpdateAIModel` with a full-replacement `Models[]` + `Status: 1` when the target model is missing. If the pack is missing, return the purchase link `https://buy.cloud.tencent.com/lowcode?buyType=resPack&envId={envId}&resourceType=token` instead of emitting SDK code and letting the user debug runtime errors.\n2. **Never assume any model is already enabled** — not `deepseek-v4-flash`, not `hunyuan-image`, not anything. Always verify with `DescribeAIModels` first; if the target is missing, look up the exact `Model` string in `DescribeManagedAIModelList` (do **not** guess the spelling) and then `UpdateAIModel` to enable it.\n3. **`createModel` accepts exactly three kinds of values** — `\"cloudbase\"` (the main managed group), `\"hunyuan-exp\"` (legacy builtin), or a user-defined GroupName registered via `CreateAIModel` (**MUST start with `custom-`**, e.g. `custom-kimi`, `custom-openai-compat`). **Never** guess with `createModel(\"deepseek\")` / `createModel(\"kimi\")` / `createModel(\"custom\")` — the first two are vendor/model names, the last is a placeholder. `createImageModel(\"hunyuan-image\")` is a separate image API — keep it as-is.\n4. **Do not invent SDK method names or parameters.** This skill (SKILL.md + `references/api-reference.md`) is the authoritative reference for `@cloudbase/node-sdk`'s AI surface — look up the method signature there before writing code. If a method or field is not documented there, stop and ask, or check the live contract via the MCP tools. No guessing.\n5. **Show pricing before enabling a new managed model** — `DescribeManagedAIModelList` returns `ModelSpec` (context length, max input/output tokens) + `ModelChargingInfo` (input / output / cache prices, billing unit). Show the prices to the user before calling `UpdateAIModel`.\n6. **Plan timeout and quota separately for image generation** — `generateImage` costs more per call than text and takes longer. For cloud functions, set `timeout` to `900s`. HTTP-function gateways cap at 60s, so use an async-task + polling pattern. Throttle per-user concurrency and frequency to avoid burning an entire Token pack on one failure.\n7. **Prefer streaming for long-form interactions** — in HTTP-function or cloud-function SSE scenarios, use `streamText` + `for await (const chunk of result.textStream)` to flush chunks back to the client incrementally. Handle stream interruption in `catch` and close the underlying response.\n8. **Pin `@cloudbase/node-sdk` >= 3.16.0** on the server — image generation is only available from this version. Verify with `npm ls @cloudbase/node-sdk` to confirm the version actually loaded by the cloud function / cloud run runtime — local and production can drift.\n9. **Centralize model names in config, not scattered literals.** Keep the chosen text / image model in a single constant and source from `DescribeAIModels` / `DescribeManagedAIModelList`. The managed catalog evolves; a single source of truth makes upgrades cheap. For models outside the managed catalog, follow the Custom Onboarding section — never hard-code third-party API keys in business code (let `CreateAIModel.Secret.ApiKey` hold them via CloudBase).\n10. **Distinguish \"preflight failure\" from \"model call failure\"** — the former means the resource pack is not active or the target model has not been enabled via `UpdateAIModel` (guide the user to purchase / enable). The latter is a parameter issue or upstream error. Do not wrap both in one generic toast.\n11. **Do not log full prompts or generated text in production** — log only `usage.total_tokens` and a short prefix. Prompts can leak sensitive content; token counts can leak cost signals.\n12. **TypeScript: do NOT use `any` to silence SDK type errors.** The Node SDK ships its own types; narrow with `unknown` + a type guard, write a precise `interface` for the shape you consume, or augment types in a local `.d.ts`. Never `: any`, `as any`, `@ts-ignore`, `@ts-nocheck`. See the Engineering constitution in the `web-development` skill — it applies to backend TS too.\n13. **Self-verify before claiming done.** `tsc --noEmit` + project build + actually invoke the function (local invoke / `manageFunctions(action=\"invokeFunction\")` / direct HTTP hit) and confirm `usage.total_tokens > 0` and the returned text is not an error envelope. \"It should work\" without a real round-trip is not acceptable evidence.\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [api-reference.md](references/api-reference.md) — generateText / streamText / generateImage examples, error-handling pattern, image parameters, TypeScript type definitions\n- [custom-onboarding.md](references/custom-onboarding.md) — onboarding models outside the managed catalog (console flow + `CreateAIModel`)\n\nFile v1.92.120:references/ai-model-web/SKILL.md\n\n---\nname: ai-model-web\ndescription: \"Use this skill when a browser/Web app (React, Vue, Next, Nuxt, static sites, SPAs, dashboards, AI chat UI, 页面, 前端, 网页) needs AI models via @cloudbase/js-sdk. Default routing for Web/frontend AI — call directly from the browser, do NOT propose a Node.js proxy. Covers generateText and streamText; models via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*, model id in the `model` field. MUST run two-step preflight before code — see body. NOT for Node.js backend (use ai-model-nodejs), Mini Program (use ai-model-wechat), or image generation (Node SDK only).\"\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## When to use this skill\n\nUse this skill for **calling AI models in browser/Web applications** via `@cloudbase/js-sdk`.\n\n> 🧭 **Runtime-plane default for Web.** Any time the user's request is framed around a page, a Web app, the frontend, React/Vue/Next/Nuxt, a dashboard UI, or \"add AI to my H5\", this skill is the default routing target. **Do NOT first propose a Node.js / cloud-function / CloudRun proxy**; `@cloudbase/js-sdk` can call the model from the browser directly. Only switch to `ai-model-nodejs` if the user explicitly asks for a backend/server call, image generation, or a scenario that truly needs server-side keys or long-running work. This decision is independent of which concrete model the user picks — model names (`deepseek-*`, `glm-*`, `hunyuan-*`, `kimi-*`, …) only affect the `model` field, not the routing plane.\n\n**Use it when you need to:**\n\n- Integrate AI text generation into a frontend Web app\n- Stream AI responses for a better UX\n- Call Hunyuan / DeepSeek / GLM / Kimi / MiniMax models from the browser\n\n**Do NOT use for:**\n\n- Node.js backend or cloud functions → use the `ai-model-nodejs` skill\n- WeChat Mini Program → use the `ai-model-wechat` skill\n- Image generation → use the `ai-model-nodejs` skill (Node SDK only)\n- Runtimes without a CloudBase SDK (native apps, Python, Go, etc.) → use the `http-api-cloudbase` skill (it now includes the `ai_model` OpenAPI spec for direct HTTP calls; do NOT build a custom HTTP proxy)\n\n---\n\n## ⛔ STOP — `ai.createModel(...)` argument is **not** a vendor / model name\n\nRead this before writing any `createModel(...)` line. The single most common mistake when agents generate code for this SDK is hallucinating the argument. There are **exactly three** legal shapes. Anything else is a bug.\n\n| ✅ Legal `ai.createModel(...)` argument | When to use it |\n|----------------------------------------|----------------|\n| `\"cloudbase\"` | **The main managed group for new projects** (TokenHub-backed, multi-vendor pool). Vendor + concrete model go into the **`model` field** of `generateText` / `streamText`, e.g. `{ model: \"deepseek-v4-flash\" }`. **No model is enabled by default — always check `DescribeAIModels` first and, if the target model is missing, enable it with `UpdateAIModel` before calling the SDK.** |\n| `\"hunyuan-exp\"` | Only if `DescribeAIModels` explicitly returns this legacy builtin group for the current env (mainly the Mini Program Growth Plan — see `ai-model-wechat`). |\n| `\"custom-<your-name>\"` | A user-defined GroupName you onboarded via `CreateAIModel`. **Must** start with `custom-` (e.g. `custom-kimi`, `custom-openai-compat`). |\n\n### ❌ Do NOT write any of these — they are all wrong\n\n```js\nai.createModel(\"deepseek\")                 // wrong — that's a vendor, not a GroupName\nai.createModel(\"deepseek-v4-flash\")        // wrong — that's a model name, goes in the `model` field\nai.createModel(\"hunyuan\")                  // wrong — vendor family, not a GroupName\nai.createModel(\"hunyuan-2.0-instruct-20251111\")  // wrong — model name\nai.createModel(\"glm\") / ai.createModel(\"kimi\") / ai.createModel(\"minimax\")  // wrong — vendor names\nai.createModel(\"openai\") / ai.createModel(\"moonshot\")  // wrong — vendor names\nai.createModel(\"custom\")                   // wrong — placeholder; use your real custom-<name>\nai.createModel(modelName)                  // wrong — do not reuse the variable that holds the model id\n```\n\n### ✅ Correct pattern — GroupName vs Model are two different fields\n\n```js\nconst model = ai.createModel(\"cloudbase\");          // ← GroupName\nawait model.generateText({\n  model: \"deepseek-v4-flash\",                       // ← concrete model id\n  messages: [...]\n});\n```\n\n### Decision procedure (when the user names a specific model)\n\n1. The user says \"use DeepSeek v3.2\" / \"use hunyuan instruct\" / \"use Kimi k2.6\" / \"use GLM-5\" / …\n2. `createModel(\"cloudbase\")` stays the same.\n3. Put the model id into the **`model` field**: `{ model: \"deepseek-v3.2\" }`, `{ model: \"hunyuan-2.0-instruct-20251111\" }`, `{ model: \"kimi-k2.6\" }`, `{ model: \"glm-5\" }`, …\n4. **Never assume the model is already enabled.** Before writing the SDK call, verify it is present in `DescribeAIModels({ GroupName: \"cloudbase\" }).Models[]`. If missing, call `DescribeManagedAIModelList` to confirm the exact `Model` name the platform supports (case-sensitive — do **not** guess the spelling), then enable it via `UpdateAIModel` with `Status: 1` (remember `Models` is a full replacement, so resend everything already enabled + the new one).\n\n> If you are about to type `ai.createModel(` and the thing inside the parentheses is a vendor name, a model name, or a guess — **stop**. It is almost certainly one of the three legal values above.\n\n---\n\n## Mandatory Two-Step Preflight (before any SDK code)\n\nBefore generating any AI-related SDK code, **run the two-step preflight**: ① eligibility, ② group readiness. Emitting `createModel(...)` straight away and letting the user debug runtime errors is significantly more costly.\n\n### Step 0: obtain the environment ID\n\nCall the MCP tool `queryEnv` with `action=info` and read `EnvId` from the response. Every subsequent check and purchase link uses this `EnvId`.\n\n---\n\n### Preflight ① — Eligibility (Token Credits resource pack)\n\nCall the MCP tool:\n\n```\ncallCloudApi(service=\"tcb\", action=\"DescribeEnvPostpayPackage\", params={ EnvId })\n```\n\n**Pass conditions (all required):**\n- `envPostpayPackageInfoList` contains at least one entry\n- That entry's `postpayPackageId` starts with `pkg_tcb_tokencredits_`\n- That entry's `status` is NOT in `[3, 4]` (3 / 4 typically mean expired / disabled; trust the live response)\n\n- ❌ **Not satisfied** → **stop writing code** and surface this to the user (replacing `{envId}` with the real id):\n  > The current environment has no active Token Credits resource pack. Please purchase one before calling any AI API:\n  > https://buy.cloud.tencent.com/lowcode?buyType=resPack&envId={envId}&resourceType=token\n  >\n  > Let me know once it's done and I'll re-check the resource pack status.\n\n- ✅ **Satisfied** → proceed to preflight ②.\n\n> Parameter casing is PascalCase by contract. If the call returns `InvalidParameter`, fall back to camelCase (`envId` / `envPostpayPackageInfoList`) and trust the live response. For the Mini Program scenario there is an additional growth-plan branch — switch to the `ai-model-wechat` skill.\n\n---\n\n### Preflight ② — Group readiness (`DescribeAIModels` → `UpdateAIModel` if needed)\n\nEligibility alone is not enough. **Do not write `createModel(\"cloudbase\")` yet.** First confirm that the target `GroupName` exists in the env with `Status=1`, and that the target `Model` is present in its `Models[]`.\n\n1. **List groups configured in the current env:**\n\n   ```\n   callCloudApi(service=\"tcb\", action=\"DescribeAIModels\", params={ EnvId })\n   ```\n\n   Returns `AIModelGroups: AIModelGroup[]`, where each `AIModelGroup` includes `GroupName`, `Type` (`builtin` / `custom`), `Models: [{ Model, EnableMCP, Tags }]`, `Status` (1 = on / 2 = off), `BaseUrl`, `Secret`, `Remark`. The main managed `GroupName` is `cloudbase`.\n\n2. **Never assume a model is already enabled.** Inspect `AIModelGroups[?].Models[].Model` for the `cloudbase` group. If the target model (or, when the user did not specify one, the model you intend to default to such as `deepseek-v4-flash`) is missing, jump to step 4 and enable it — do not call `createModel(\"cloudbase\")` yet. If the `cloudbase` group itself is missing or has `Status=2`, also jump to step 4.\n\n3. **User asked for a model that belongs to the managed catalog** (e.g. `deepseek-v3.2`, `hunyuan-2.0-instruct-20251111`, `glm-5`, `kimi-k2.6`, …): check whether that `Model` is already in the `cloudbase` group's `Models[]`. If not, jump to step 4. **Do not guess the exact model id** — verify the canonical spelling in `DescribeManagedAIModelList` first (step 4 covers this).\n\n4. **Enable / add a managed model** (always inspect the authoritative catalog + pricing first):\n\n   ```\n   callCloudApi(service=\"tcb\", action=\"DescribeManagedAIModelList\", params={ EnvId })\n   ```\n\n   Returns `ManagedAIModelGroup[]`, where each group lists `GroupName` (e.g. `cloudbase`), `Remark`, and `Models: [{ Model, EnableMCP, ModelSpec{ContextLength, MaxInputToken, MaxOutputToken}, ModelChargingInfo[{Type, InputPrice, OutputPrice, InputOutputUnit, CachePrice}] }]`. **This is the single source of truth for supported model names and pricing — do not infer them from memory. Use the exact `Model` string returned here when calling `UpdateAIModel`.** Also surface the prices to the user before enabling.\n\n   Then enable (note: `Models` is a **full replacement** — always resend the already-enabled models together with the new one):\n\n   ```\n   callCloudApi(service=\"tcb\", action=\"UpdateAIModel\", params={\n     EnvId,\n     GroupName: \"cloudbase\",\n     Models: [\n       // resend every model that DescribeAIModels already showed as enabled\n       { Model: \"<already-enabled model, e.g. deepseek-v4-flash>\" },\n       // append the newly-requested one, using the exact spelling from DescribeManagedAIModelList\n       { Model: \"<target model>\" }\n     ],\n     Status: 1\n   })\n   ```\n\n5. **The requested model is not in the managed catalog** (not found by `DescribeManagedAIModelList`) → jump to the next section, **Custom onboarding (models outside the managed catalog)**.\n\n> All Actions use `service=tcb`, `Version=2018-06-08`. Parameters are PascalCase (`EnvId` / `GroupName` / `Models` / `Status`). Fall back to camelCase only if the call returns `InvalidParameter`.\n\n---\n\n## Available Providers and Models\n\n`ai.createModel(<GroupName>)` accepts exactly three kinds of legal values:\n\n### 1. `\"cloudbase\"` — the main managed group (recommended)\n\n- `GroupName: \"cloudbase\"`, `Type: \"builtin\"`, `Remark: \"腾讯云开发\"` (Tencent CloudBase)\n- Backed by **Tencent Cloud TokenHub**, a unified managed pool covering multiple vendors — **Hunyuan** (HY 2.0 Instruct, HY 2.0 Think, Hunyuan-role, Hy3 preview, …), **DeepSeek** (DeepSeek-V4-Pro, DeepSeek-V4-Flash, Deepseek-v3.2, Deepseek-v3.1, Deepseek-r1-0528, Deepseek-v3-0324, …), **Zhipu GLM** (GLM-5, GLM-5-Turbo, GLM-5.1, GLM-5V-Turbo), **Kimi** (K2.5, K2.6), **MiniMax** (M2.5, M2.7), and more. The roster evolves — **do not hard-code specific SKUs** in application code; discover at runtime.\n- **No model is enabled by default.** Always call `DescribeAIModels` first to see what the env has actually enabled; if your target model is missing, call `DescribeManagedAIModelList` for the authoritative catalog + pricing and then `UpdateAIModel` (`Status: 1`, `Models` full-replacement) to enable it before making the SDK call.\n- Authoritative catalog + pricing: `DescribeManagedAIModelList`\n- Env-enabled set: `DescribeAIModels`\n\n### 2. `\"hunyuan-exp\"` — legacy builtin group (kept for compatibility)\n\n- Primarily relevant to the Mini Program Growth Plan scenario; do not use from Web unless the env explicitly still has it (switch to the `ai-model-wechat` skill for that flow)\n- Default model: `hunyuan-2.0-instruct-20251111`; additional hunyuan SKUs must be discovered at runtime via `DescribeAIModels({ GroupName: \"hunyuan-exp\" }).Models[]` — do not hard-code other IDs\n\n### 3. User-defined GroupName\n\n- Onboarded via `CreateAIModel` (see the next section). The custom `GroupName` **MUST start with `custom-`** (e.g. `custom-kimi`, `custom-moonshot`, `custom-openai-compat`). This naming convention prevents future collisions with built-in / vendor GroupNames (`cloudbase`, `hunyuan-exp`, `deepseek`, `glm`, `kimi`, `minimax`, …) that the platform may introduce over time\n- Examples: `createModel(\"custom-kimi\")`, `createModel(\"custom-openai-compat\")`\n\n> **Never** write guesses like `createModel(\"deepseek\")` or `createModel(\"custom\")` unless `DescribeAIModels` explicitly returned that exact `GroupName` (old envs may still carry historical `deepseek` / `hunyuan-exp` builtin groups — that stays legal for compatibility, but new projects should always go through `cloudbase`).\n\n---\n\n## Custom onboarding (models outside the managed catalog)\n\nWhen the user wants to call a **non-managed** model (self-hosted, enterprise-internal, third-party OpenAI-compatible endpoint, …), **do not block**. Guide them through onboarding:\n\n### Option 1: console flow (recommended, user handles it)\n\n`https://tcb.cloud.tencent.com/dev?envId={envId}#/ai`\n\n### Option 2: programmatic onboarding (`CreateAIModel`)\n\n```\ncallCloudApi(service=\"tcb\", action=\"CreateAIModel\", params={\n  EnvId: \"<envId>\",\n  GroupName: \"custom-<your-name>\",  // MUST start with \"custom-\" (e.g. custom-kimi, custom-openai-compat); never start with \"cloudbase\"\n  BaseUrl: \"<OpenAI-compatible endpoint, e.g. https://api.moonshot.cn/v1>\",\n  Models: [\n    { Model: \"<model name, e.g. kimi-k2.5>\", EnableMCP: true }\n  ],\n  Remark: \"<optional remark>\",\n  Status: 1,\n  Secret: { ApiKey: \"<vendor api key supplied by the user>\" }\n})\n```\n\nOnce onboarded, confirm with `DescribeAIModels` that the group is ready, then call `ai.createModel(\"<the GroupName you just registered>\")` from your code. Use `UpdateAIModel` to add/remove models, rotate keys, or change `BaseUrl` (remember `Models` is a **full replacement**). Use `DeleteAIModel` to remove a custom group (builtin groups cannot be deleted).\n\n> Custom-model billing is covered by the third-party provider and does not draw from the Token Credits resource pack. Field casing follows the live contract — fall back to camelCase on `InvalidParameter`.\n\n---\n\n## Installation\n\n```bash\nnpm install @cloudbase/js-sdk\n```\n\n## Initialization\n\n> ⚠️ **Do not use anonymous sign-in as the default.** Anonymous login is **disabled by default** for new environments, and inactive existing environments have also been automatically disabled. Even when anonymous login is manually enabled, **anonymous users are denied AI model invocation permissions by default**. The AI-model skill does **not** prescribe a specific login UI — delegate that concern:\n>\n> - **Enabling / configuring login providers** (phone SMS, email, WeChat Open Platform, username+password, OAuth, …) → follow the **`auth-tool-cloudbase`** skill (backend config via `callCloudApi`).\n> - **Building the actual sign-in flow in the browser** (login form, callbacks, session guarding) → follow the **`auth-web-cloudbase`** skill (`@cloudbase/js-sdk` auth API, e.g. `signInWithPassword`, `signInWithPhone`, `getSession`).\n>\n> Do **not** fall back to `signInAnonymously()` for AI features — anonymous users cannot call AI models. Only use anonymous login for non-AI read-only demos where the user explicitly requests it and accepts the trade-off.\n\n```js\nimport cloudbase from \"@cloudbase/js-sdk\";\n\nconst app = cloudbase.init({\n  env: \"<YOUR_ENV_ID>\",\n  accessKey: import.meta.env.VITE_PUBLISHABLE_KEY  // auto-provision via queryAppAuth / manageAppAuth, write to .env.local (see auth-web-cloudbase prerequisites)\n});\n\nconst auth = app.auth;\n\n// CRITICAL: Use auth.getSession() to check login — NOT the deprecated getLoginState().\n// getLoginState() returns uid even without real login (just accessKey), causing false positives.\n// getSession() returns data.session === undefined when no real login exists.\n// Anonymous users are DENIED AI model permissions — calling AI without real login will fail.\nconst { data: sessionData } = await auth.getSession();\nif (!sessionData?.session || sessionData.session.user?.is_anonymous) {\n  // No real login or anonymous session — route to sign-in page\n  window.location.href = \"/login\";\n  return;\n}\n\nconst ai = app.ai();\n```\n\n**Important notes:**\n\n- Use synchronous initialization with a top-level import\n- **`accessKey` causes `getLoginState()` to return misleading auth data** — the deprecated `getLoginState()` returns an object with `uid` even without real login, which breaks naive `!!loginState` checks. Use `auth.getSession()` instead: it returns `data.session === undefined` when no real login exists, so `!!data.session` is a reliable auth gate.\n- The user MUST be authenticated with a verified login (phone, email, WeChat, username+password, custom) before using AI features. Anonymous users are denied AI model permissions. The exact flow is the responsibility of the `auth-web-cloudbase` skill.\n- Get `accessKey` from the CloudBase console\n\n---\n\n## generateText() — non-streaming\n\n> **Prerequisite:** the two-step preflight (eligibility + group readiness) has passed, and the target model has been confirmed present in `DescribeAIModels({ GroupName: \"cloudbase\" }).Models[]` — if it was not, it should already have been enabled via `UpdateAIModel`. The example below uses `deepseek-v4-flash` only for illustration; substitute the actual model the user asked for.\n\n```js\nconst model = ai.createModel(\"cloudbase\");\n\nconst result = await model.generateText({\n  model: \"deepseek-v4-flash\",  // must already be enabled in this env (DescribeAIModels → UpdateAIModel)\n  messages: [{ role: \"user\", content: \"Give me a one-paragraph intro to Li Bai.\" }],\n});\n\nconsole.log(result.text);           // generated text string\nconsole.log(result.usage);          // { prompt_tokens, completion_tokens, total_tokens }\nconsole.log(result.messages);       // full message history\nconsole.log(result.rawResponses);   // raw model responses\n```\n\n---\n\n## streamText() — streaming\n\n> **Prerequisite:** the two-step preflight has passed.\n\n```js\nconst model = ai.createModel(\"cloudbase\");\n\nconst res = await model.streamText({\n  model: \"deepseek-v4-flash\",\n  messages: [{ role: \"user\", content: \"Give me a one-paragraph intro to Li Bai.\" }],\n});\n\n// Option 1: iterate the text stream (recommended)\nfor await (let text of res.textStream) {\n  console.log(text);  // incremental text chunks\n}\n\n// Option 2: iterate the data stream for full response chunks\nfor await (let data of res.dataStream) {\n  console.log(data);  // full response chunk with metadata\n}\n\n// Option 3: access final results\nconst messages = await res.messages;  // full message history\nconst usage = await res.usage;        // token usage\n```\n\n---\n\n## Error Handling Pattern\n\n```js\nconst model = ai.createModel(\"cloudbase\");\n\ntry {\n  const result = await model.generateText({\n    model: \"deepseek-v4-flash\",\n    messages: [{ role: \"user\", content: \"Generate a concise onboarding checklist.\" }],\n  });\n\n  console.log(result.text);\n} catch (error) {\n  console.error(\"Failed to call CloudBase AI from Web\", error);\n}\n```\n\n---\n\n## Type Definitions\n\n```ts\ninterface BaseChatModelInput {\n  model: string;                        // required: model name\n  messages: Array<ChatModelMessage>;    // required: message array\n  temperature?: number;                 // optional: sampling temperature\n  topP?: number;                        // optional: nucleus sampling\n}\n\ntype ChatModelMessage =\n  | { role: \"user\"; content: string }\n  | { role: \"system\"; content: string }\n  | { role: \"assistant\"; content: string };\n\ninterface GenerateTextResult {\n  text: string;                         // generated text\n  messages: Array<ChatModelMessage>;    // full message history\n  usage: Usage;                         // token usage\n  rawResponses: Array<unknown>;         // raw model responses\n  error?: unknown;                      // error if any\n}\n\ninterface StreamTextResult {\n  textStream: AsyncIterable<string>;    // incremental text stream\n  dataStream: AsyncIterable<DataChunk>; // full data stream\n  messages: Promise<ChatModelMessage[]>;// final message history\n  usage: Promise<Usage>;                // final token usage\n  error?: unknown;                      // error if any\n}\n\ninterface Usage {\n  prompt_tokens: number;\n  completion_tokens: number;\n  total_tokens: number;\n}\n```\n\n---\n\n## Best Practices\n\n1. **Run the two-step preflight first** — ① eligibility (Token Credits resource pack via `DescribeEnvPostpayPackage`) + ② group readiness (`DescribeAIModels` to inspect what is enabled, `DescribeManagedAIModelList` for the authoritative supported-model catalog, `UpdateAIModel` with a full-replacement `Models[]` and `Status: 1` when the target model is missing). Skipping preflight leads straight to \"model not found\" / \"model not enabled\" errors at runtime.\n2. **Never assume any model is already enabled** — not `deepseek-v4-flash`, not `hunyuan-*`, not anything. Always verify with `DescribeAIModels` first; if the target is missing, look up the exact `Model` string in `DescribeManagedAIModelList` (do **not** guess the spelling or invent vendor prefixes) and then `UpdateAIModel` to enable it.\n3. **`createModel` accepts exactly three kinds of values** — `\"cloudbase\"` (the main managed group), `\"hunyuan-exp\"` (legacy builtin, Growth Plan scenarios), or a user-defined GroupName registered via `CreateAIModel` (**MUST start with `custom-`**, e.g. `custom-kimi`, `custom-openai-compat`). **Never** guess with `createModel(\"deepseek\")` / `createModel(\"kimi\")` / `createModel(\"custom\")`.\n4. **Do not invent SDK method names or parameters.** This SKILL.md is the authoritative reference for `@cloudbase/js-sdk`'s AI surface — look up the method signature here (or in the Type Definitions section below) before writing code. If a method or field is not documented here, stop and ask, or check the live contract via the MCP tools. No guessing.\n5. **Show pricing before enabling a new managed model** — `DescribeManagedAIModelList` returns `ModelSpec` (context length, max input/output tokens) + `ModelChargingInfo` (input / output / cache prices, billing unit). Surface the prices to the user before calling `UpdateAIModel`.\n6. **Use streaming for long responses** — better perceived latency and interactivity.\n7. **Handle errors gracefully** — wrap AI calls in try/catch.\n8. **Keep `accessKey` safe** — use a publishable key, never a secret key.\n9. **Initialize early** — set up the SDK at app entry so auth and AI are both ready before routing.\n10. **Do NOT use anonymous auth for AI features** — anonymous login is disabled by default for new environments, and anonymous users are denied AI model permissions. Require a verified sign-in (phone, email, username+password, WeChat, custom) before calling any AI API. Delegate provider configuration to the `auth-tool-cloudbase` skill and the browser sign-in flow to the `auth-web-cloudbase` skill; the AI-model skill checks `auth.getSession()` and verifies `loginType` before gating the call.\n11. **Distinguish \"preflight failure\" from \"model call failure\"** — the former means the user needs to buy a resource pack or call `UpdateAIModel`; the latter is a prompt / parameter / network issue. Give the user different guidance for each.\n12. **TypeScript: do NOT use `any` to silence type errors from the SDK.** The SDK ships its own types; if an error shows up, narrow with `unknown` + a type guard, write a precise `interface` for the shape you actually consume, or augment types in a local `.d.ts`. Never `: any`, `as any`, `@ts-ignore`, or `@ts-nocheck`. See the Engineering constitution in the `web-development` skill.\n13. **Self-verify before claiming done.** Run `tsc --noEmit` + the project build + open the page with `agent-browser` and actually trigger the AI call. Confirm: (a) the text stream reaches the UI, (b) no new console errors, (c) `result.usage` is non-zero. Saying \"it should work\" without evidence is not acceptable — follow `web-development/browser-testing.md`.\n\nFile v1.92.120:references/ai-model-wechat/SKILL.md\n\n---\nname: ai-model-wechat\ndescription: \"Use this skill for WeChat Mini Program AI via wx.cloud.extend.AI (小程序, wx.cloud apps). Covers generateText and streamText with callbacks (onText, onEvent, onFinish); streamText needs a data wrapper, generateText returns the raw response. Models via wx.cloud.extend.AI.createModel with groups hunyuan-exp (小程序成长计划), cloudbase (main managed), or custom-*; model id goes in the data wrapper `model` field. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web), Node.js backend (use ai-model-nodejs), or image generation (use ai-model-nodejs).\"\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## When to use this skill\n\nUse this skill for **calling AI models in WeChat Mini Program** using `wx.cloud.extend.AI`.\n\n**Use it when you need to:**\n\n- Integrate AI text generation in a Mini Program\n- Stream AI responses with callback support\n- Call Hunyuan models from the WeChat environment\n\n**Do NOT use for:**\n\n- Browser/Web apps → use `ai-model-web` skill\n- Node.js backend or cloud functions → use `ai-model-nodejs` skill\n- Image generation → use `ai-model-nodejs` skill (not available in Mini Program)\n- Runtimes without a CloudBase SDK (native apps, Python, etc.) → use `http-api-cloudbase` skill (it now includes the `ai_model` OpenAPI spec for direct HTTP calls)\n\n---\n\n## ⛔ STOP — `wx.cloud.extend.AI.createModel(provider)` argument is **not** a vendor / model name\n\nRead this before writing any `createModel(...)` line. Agents frequently hallucinate this argument. There are **exactly three** legal shapes. Anything else is a bug.\n\n| ✅ Legal `createModel(provider)` argument | When to use it |\n|-----------------------------------------|----------------|\n| `\"hunyuan-exp\"` | The Mini Program **成长计划** (`ai_miniprogram_inspire_plan`) is enrolled for the current env. Default model: `hunyuan-2.0-instruct-20251111`. |\n| `\"cloudbase\"` | Default fallback. Main managed group (TokenHub-backed, multi-vendor pool). Vendor + concrete model go into the **`model` field**, e.g. `{ model: \"deepseek-v4-flash\" }`. |\n| `\"custom-<your-name>\"` | A user-defined GroupName you onboarded via `CreateAIModel`. **Must** start with `custom-` (e.g. `custom-kimi`, `custom-openai-compat`). |\n\n### ❌ Do NOT write any of these — they are all wrong\n\n```js\nwx.cloud.extend.AI.createModel(\"deepseek\")                   // wrong — vendor, not GroupName\nwx.cloud.extend.AI.createModel(\"deepseek-v4-flash\")          // wrong — model id goes in `model`\nwx.cloud.extend.AI.createModel(\"hunyuan\")                    // wrong — vendor family\nwx.cloud.extend.AI.createModel(\"hunyuan-2.0-instruct-20251111\")  // wrong — model name\nwx.cloud.extend.AI.createModel(\"glm\") / \"kimi\" / \"minimax\"   // wrong — vendor names\nwx.cloud.extend.AI.createModel(\"custom\")                     // wrong — placeholder\nwx.cloud.extend.AI.createModel(modelName)                    // wrong — do not reuse the model-id variable\n```\n\n### ✅ Correct pattern — provider vs model are two different fields\n\n```js\n// Growth Plan branch\nconst model = wx.cloud.extend.AI.createModel(\"hunyuan-exp\"); // ← provider / GroupName\nawait model.streamText({\n  data: { model: \"hunyuan-2.0-instruct-20251111\", messages: [...] }  // ← concrete model id\n});\n\n// Token Credits branch\nconst model = wx.cloud.extend.AI.createModel(\"cloudbase\");\nawait model.streamText({\n  data: { model: \"deepseek-v4-flash\", messages: [...] }\n});\n```\n\n### Decision procedure (when the user names a specific model)\n\n1. The user says \"use DeepSeek v3.2\" / \"use hunyuan thinking\" / \"use Kimi k2.6\" / …\n2. First run the eligibility decision tree below — the correct `provider` may be `\"hunyuan-exp\"` (if the env is on Growth Plan and the user asked for a `hunyuan-*` model) or `\"cloudbase\"` (anything else in the managed catalog).\n3. Put the model id into the **`model` field** inside `data`: `{ model: \"deepseek-v3.2\" }`, `{ model: \"hunyuan-2.0-instruct-20251111\" }`, `{ model: \"kimi-k2.6\" }`, …\n4. Before using the model id, make sure it is present in `DescribeAIModels({ GroupName: \"cloudbase\" }).Models[]`. If not, enable it via `UpdateAIModel`.\n\n> If you are about to type `wx.cloud.extend.AI.createModel(` and the thing inside the parentheses is a vendor name or a model id — **stop**. It is almost certainly one of the three legal values above.\n\n---\n\n## Mandatory Two-Step Preflight\n\nYou MUST NOT jump straight into `wx.cloud.extend.AI.createModel(...)`. Before writing any business code, confirm **billing eligibility** and **group readiness** in this fixed order: **① eligibility → ② group readiness**. Do not swap the two.\n\n### Preflight ① · Billing Eligibility (two parallel billing paths)\n\nThe Mini Program side has two billing paths: **小程序成长计划** (checked first; if enrolled, use `hunyuan-exp`) and **Token Credits 资源包** (generic fallback; if available, use the `cloudbase` main managed group).\n\n1. Fetch `envId` via the MCP tool `queryEnv action=info`.\n\n2. Pick the branch by user intent:\n\n| User intent | Eligibility to check first | `createModel` provider on hit | Model selection | Guidance on miss |\n|-------------|----------------------------|-------------------------------|-----------------|------------------|\n| No model specified / default call | Check **小程序成长计划** enrollment first; if not enrolled, fall back to Token Credits resource pack | Enrolled: `\"hunyuan-exp\"`; otherwise: `\"cloudbase\"` | Enrolled: `hunyuan-2.0-instruct-20251111` (the 成长计划 default). Otherwise: pick a text model with the user, then verify/enable it in the `\"cloudbase\"` group via `DescribeAIModels` → `DescribeManagedAIModelList` → `UpdateAIModel` | Plan not enrolled → point to `https://docs.cloudbase.net/ai/ai-inspire-plan`; resource pack missing → purchase link |\n| User requests a `hunyuan-*` model | **小程序成长计划** enrollment | `\"hunyuan-exp\"` (plan-exclusive Token pack billing) | `hunyuan-2.0-instruct-20251111` if present; otherwise verify via `DescribeAIModels({ GroupName: \"hunyuan-exp\" }).Models[]` and `UpdateAIModel` to enable | Not enrolled → enroll first, or switch to `\"cloudbase\"` + a non-hunyuan model |\n| User requests `deepseek-*` / `glm-*` / `kimi-*` / `minimax-*` / other non-hunyuan managed models | **Token Credits 资源包** activation | `\"cloudbase\"` | Do NOT assume the model is already enabled. `DescribeAIModels` → if missing, `DescribeManagedAIModelList` for the canonical `Model` string → `UpdateAIModel` with `Status: 1` (full-replacement `Models[]`) | Resource pack not activated → purchase link |\n| User requests a third-party / self-hosted (non-managed) model | Skip billing eligibility and go to \"Custom onboarding\" | Custom GroupName (must start with `custom-`) | Registered via `CreateAIModel.Models[]` | Offer both console + `CreateAIModel` paths |\n\n3. Check 小程序成长计划 enrollment:\n\n```ts\ncallCloudApi({\n  service: \"tcb\",\n  action: \"DescribeActivityInfo\",\n  params: {\n    ActivityNames: [\"ai_miniprogram_inspire_plan\"], // PascalCase preferred; switch to camelCase if InvalidParameter is returned\n  },\n})\n```\n\n**Hit criterion:** the response's `attendRecords` contains at least one entry where `activityName === \"ai_miniprogram_inspire_plan\"` and `envId` matches the current environment. On hit, default to `createModel(\"hunyuan-exp\")` + `hunyuan-2.0-instruct-20251111`; billing uses the plan-exclusive Token pack `pkg_hunyuan_token_la_inspire_100m`.\n\n**On miss:** do NOT silently fall back. Tell the user \"the current environment is not enrolled in 小程序成长计划\", surface the enrollment entry `https://docs.cloudbase.net/ai/ai-inspire-plan`, and ask whether to enroll and retry, or to switch to the Token Credits resource pack path with a non-hunyuan model.\n\n4. Check the Token Credits resource pack (when the path leads to the `\"cloudbase\"` main managed group):\n\n```ts\ncallCloudApi({\n  service: \"tcb\",\n  action: \"DescribeEnvPostpayPackage\",\n  params: {\n    EnvId: \"<current envId>\",\n  },\n})\n```\n\n**Hit criterion:** `envPostpayPackageInfoList` contains an entry whose `postpayPackageId` starts with `pkg_tcb_tokencredits_`, has `status ∉ [3, 4]` (not expired, not disabled), and `versionSwitchStatus` is not in a blocking state.\n\n**On miss:** surface the purchase link (replace `{envId}` with the real ID — never leave the placeholder):\n\n```\nhttps://buy.cloud.tencent.com/lowcode?buyType=resPack&envId={envId}&resourceType=token\n```\n\n### Preflight ② · Group Readiness (mandatory for every Mini Program AI call)\n\nPassing eligibility does not mean the target model is callable. **No model is enabled by default** in the `\"cloudbase\"` main managed group — you must first call `DescribeAIModels` to see what is enabled, then (if missing) `DescribeManagedAIModelList` for the authoritative supported-model catalog and `UpdateAIModel` with `Status: 1` to enable it. The `\"hunyuan-exp\"` group's readiness is driven by 成长计划 enrollment — enrollment alone makes `hunyuan-2.0-instruct-20251111` available, but any other hunyuan SKU still has to be checked against `DescribeAIModels({ GroupName: \"hunyuan-exp\" }).Models[]` and enabled via `UpdateAIModel` if missing.\n\n1. Query the groups and switches currently configured in the environment (`tcb` Action `DescribeAIModels`, Version `2018-06-08`):\n\n```ts\ncallCloudApi({\n  service: \"tcb\",\n  action: \"DescribeAIModels\",\n  params: { EnvId: \"<envId>\" },\n})\n```\n\nReturns `AIModelGroups: AIModelGroup[]`. Each `AIModelGroup` has `GroupName` (e.g. `cloudbase` / `hunyuan-exp` / your custom group), `Type` (`builtin` / `custom`), `Models: [{ Model, EnableMCP, Tags }]`, and `Status` (1=on / 2=off). Group readiness = all three of: the `GroupName` exists + `Status === 1` + the target `Model` is present in `Models[]`.\n\n2. If the target model is not in the `DescribeAIModels` response, query the platform catalog + pricing via `DescribeManagedAIModelList` — it returns `ManagedAIModelGroup[]` including `ModelSpec` (context length, etc.) and `ModelChargingInfo` (`Uniform` / `Tiered` pricing). Pick the target model, then enable it via `UpdateAIModel`:\n\n```ts\ncallCloudApi({\n  service: \"tcb\",\n  action: \"UpdateAIModel\",\n  params: {\n    EnvId: \"<envId>\",\n    GroupName: \"cloudbase\",\n    Status: 1, // 1=on, 2=off\n    Models: [\n      { Model: \"deepseek-v4-flash\", EnableMCP: false },\n      { Model: \"deepseek-v3.2\", EnableMCP: false },   // append the new model to enable\n    ],\n    // ⚠️ `Models` is a FULL REPLACEMENT, not incremental; merge the old list + new entries before passing.\n  },\n})\n```\n\n3. Once both steps pass, only THEN write `wx.cloud.extend.AI.createModel(\"<GroupName>\")` in the Mini Program code, and pass a `model` value that exists in that group's `Models[]`.\n\n> **Order is fixed.** Without eligibility, no enabled model will bill; without group readiness, even with eligibility you will receive `ModelNotEnabled`-class errors. Both must be done before business code.\n>\n> **API casing tip:** `tcb` public-service Actions officially use PascalCase (`EnvId`, `GroupName`, `ActivityNames`); some docs show camelCase. On the first call, if you hit `InvalidParameter`, switch casing and retry, then freeze the working form in your project's wrapper.\n\n---\n\n## Available Providers and Models\n\nThe `provider` argument of `wx.cloud.extend.AI.createModel(provider)` equals the `GroupName` returned by `DescribeAIModels`. Only three kinds of values are legal. Run the decision tree before choosing.\n\n### A. 小程序成长计划 exclusive (default when enrolled)\n\n| createModel provider | Default model | Other available models | Notes |\n|----------------------|---------------|------------------------|-------|\n| `\"hunyuan-exp\"` | `hunyuan-2.0-instruct-20251111` | Additional hunyuan SKUs (e.g. instruct / thinking / turbos / role variants) — **query at runtime** via `DescribeAIModels({ GroupName: \"hunyuan-exp\" }).Models[]`, do NOT hard-code | Legacy `Type=builtin` GroupName; billed via `pkg_hunyuan_token_la_inspire_100m`; do NOT use without 成长计划 enrollment |\n\n### B. Main managed group (Token Credits pack scenario, recommended default)\n\nThe `\"cloudbase\"` GroupName is backed by **Tencent Cloud TokenHub**, a unified managed pool that covers multiple first-party and third-party vendors — including the **Hunyuan** family (HY 2.0 Instruct, HY 2.0 Think, Hunyuan-role, Hy3 preview, …), **DeepSeek** family (DeepSeek-V4-Pro, DeepSeek-V4-Flash, Deepseek-v3.2, Deepseek-v3.1, Deepseek-r1-0528, Deepseek-v3-0324, …), **Zhipu GLM** (GLM-5, GLM-5-Turbo, GLM-5.1, GLM-5V-Turbo), **Kimi** (K2.5, K2.6), **MiniMax** (M2.5, M2.7) and more. The roster evolves over time, so **do not hard-code the list in application code** — always discover it at runtime.\n\n| createModel provider | Model readiness | How to enable a model | Notes |\n|----------------------|-----------------|-----------------------|-------|\n| `\"cloudbase\"` | **No model is enabled by default** — always check `DescribeAIModels({ GroupName: \"cloudbase\" }).Models[]` first | 1) Fetch the authoritative catalog + pricing via `DescribeManagedAIModelList` (do NOT guess the `Model` string). 2) Call `UpdateAIModel` with `Status: 1` and a full-replacement `Models[]` that includes the target model | Unified managed group (`Type=builtin`), Remark `\"腾讯云开发\"`, depends on a `pkg_tcb_tokencredits_*` resource pack |\n\n> ⚠️ Common Mini Program mistake: writing `createModel(\"deepseek\")` / `createModel(\"hunyuan\")` / `createModel(\"glm\")` / `createModel(\"kimi\")` / `createModel(\"minimax\")` / `createModel(\"custom\")`. All wrong — those are **vendor / model names**, not provider / GroupName. The provider must be one of the `GroupName` values returned by `DescribeAIModels`. New projects always use the unified `\"cloudbase\"` managed group and select the concrete vendor model via the `model` field.\n\n### C. Not in the managed catalog → Custom onboarding\n\nModels involving third-party / self-hosted / OpenAI-compatible endpoints (anything not appearing in A/B) do NOT go through the billing paths above. You must register a `Type=custom` GroupName via \"Custom onboarding\" first. See the next section.\n\n---\n\n## Custom Onboarding (when not in the managed catalog)\n\nWhen the user specifies a model that is neither in 成长计划 (`hunyuan-exp`) nor in the main managed group (`cloudbase`) catalog (e.g. enterprise-hosted OpenAI-compatible endpoints, third-party model services), pick one of the two paths below. Use neutral phrasing such as \"third-party / self-hosted / OpenAI-compatible endpoint\" — **do not name specific competitor brands**.\n\n**Path 1 · Register in the console**\n\nPoint the user to the CloudBase console AI model page:\n\n```\nhttps://tcb.cloud.tencent.com/dev?envId={envId}#/ai\n```\n\nReplace `{envId}` with the real environment ID and let the user fill in model name, endpoint, API key, etc.\n\n**Path 2 · Register via `callCloudApi` + `CreateAIModel`**\n\nThe `tcb` Action `CreateAIModel` (Version `2018-06-08`) creates a `Type=custom` AI model group in the current environment:\n\n```ts\ncallCloudApi({\n  service: \"tcb\",\n  action: \"CreateAIModel\",\n  params: {\n    EnvId: \"<current envId>\",\n    GroupName: \"custom-openai-compat\",  // ⚠️ MUST start with \"custom-\" (e.g. custom-kimi, custom-moonshot) to avoid colliding with built-in / vendor GroupNames; this becomes the value passed to createModel(provider)\n    BaseUrl: \"https://api.example.com/v1\",\n    Models: [\n      { Model: \"gpt-4o-mini\", EnableMCP: false },\n      { Model: \"gpt-4o\",       EnableMCP: false },\n    ],\n    Remark: \"Internal OpenAI-compatible endpoint\",\n    Status: 1,                         // 1=on, 2=off\n    Secret: {\n      // Key / ApiKey: pick one; OpenAI-compatible endpoints usually use ApiKey\n      ApiKey: \"<vendor-api-key>\",\n    },\n  },\n})\n```\n\nAfter registration:\n- Run `DescribeAIModels` to confirm the `GroupName` exists with `Status=1` and the target `Model` appears in `Models[]`.\n- In the Mini Program, call `wx.cloud.extend.AI.createModel(\"custom-openai-compat\")` and pass a registered model name (e.g. `\"gpt-4o-mini\"`) as the `model` field.\n- To add or modify models later, use `UpdateAIModel` (remember `Models` is a **full replacement**; `Status` uses 1/2 as on/off). To delete an entire custom group, use `DeleteAIModel` (custom groups only; batch via `GroupNames.N`).\n- All calls still hit the environment's billing path. If such custom models also need Token settlement, eligibility must be verified first.\n\n---\n\n## Prerequisites\n\n- WeChat base library **3.7.1+**\n- No extra SDK installation needed\n\n---\n\n## Initialization\n\n```js\n// app.js\nApp({\n  onLaunch: function() {\n    wx.cloud.init({ env: \"<YOUR_ENV_ID>\" });\n  }\n})\n```\n\n---\n\n## generateText() - Non-streaming\n\n⚠️ **Different from JS/Node SDK:** the return value is the raw model response.\n\n> **Prerequisite:** the \"Mandatory Two-Step Preflight\" has been completed **and** the target model has been confirmed enabled via `DescribeAIModels` (or enabled via `UpdateAIModel` if missing). The example below assumes the current environment is enrolled in 小程序成长计划 and uses `createModel(\"hunyuan-exp\")` + `hunyuan-2.0-instruct-20251111`. If the eligibility branch landed on the resource pack, swap the provider to `\"cloudbase\"` and set the `model` to whatever the user chose and you have just enabled via `UpdateAIModel` — never assume `deepseek-v4-flash` is already on.\n\n```js\nconst model = wx.cloud.extend.AI.createModel(\"hunyuan-exp\");\n\nconst res = await model.generateText({\n  model: \"hunyuan-2.0-instruct-20251111\",  // plan-enrolled default\n  messages: [{ role: \"user\", content: \"hi\" }],\n});\n\n// ⚠️ Return value is the RAW model response, NOT wrapped like JS/Node SDK\nconsole.log(res.choices[0].message.content);  // access via choices array\nconsole.log(res.usage);                        // token usage\n```\n\n---\n\n## streamText() - Streaming\n\n⚠️ **Different from JS/Node SDK:** parameters MUST be wrapped in a `data` object; callbacks are supported.\n\n> **Prerequisite:** the \"Mandatory Two-Step Preflight\" has been completed and the target model has been enabled. The example below uses the 成长计划 branch; for the resource pack branch, swap `createModel(\"hunyuan-exp\")` to `createModel(\"cloudbase\")` and the `model` to whatever the user chose and you have just enabled via `UpdateAIModel` (no model is enabled by default).\n\n```js\nconst model = wx.cloud.extend.AI.createModel(\"hunyuan-exp\");\n\n// ⚠️ Parameters MUST be wrapped in a `data` object\nconst res = await model.streamText({\n  data: {                              // ⚠️ Required wrapper\n    model: \"hunyuan-2.0-instruct-20251111\",  // plan-enrolled default\n    messages: [{ role: \"user\", content: \"hi\" }]\n  },\n  onText: (text) => {                  // Optional: incremental text callback\n    console.log(\"New text:\", text);\n  },\n  onEvent: ({ data }) => {             // Optional: raw event callback\n    console.log(\"Event:\", data);\n  },\n  onFinish: (fullText) => {            // Optional: completion callback\n    console.log(\"Done:\", fullText);\n  }\n});\n\n// Async iteration is also available\nfor await (let str of res.textStream) {\n  console.log(str);\n}\n\n// Check for completion via eventStream\nfor await (let event of res.eventStream) {\n  console.log(event);\n  if (event.data === \"[DONE]\") {       // ⚠️ Check for [DONE] to stop\n    break;\n  }\n}\n```\n\n---\n\n## Error Handling Pattern\n\n> **Prerequisite:** the \"Mandatory Two-Step Preflight\" has been completed. For the resource pack branch, use `\"cloudbase\"` + the specific text model you just verified/enabled via `DescribeAIModels` / `UpdateAIModel` — no model is enabled by default.\n\n```js\nconst model = wx.cloud.extend.AI.createModel(\"cloudbase\");\n\ntry {\n  const res = await model.generateText({\n    model: \"deepseek-v4-flash\",\n    messages: [{ role: \"user\", content: \"Write a welcome message\" }],\n  });\n\n  console.log(res.choices[0].message.content);\n} catch (error) {\n  console.error(\"Mini Program AI request failed\", error);\n}\n```\n\n---\n\n## API Comparison: JS/Node SDK vs WeChat Mini Program\n\n| Feature | JS/Node SDK | WeChat Mini Program |\n|---------|-------------|---------------------|\n| **Namespace** | `app.ai()` | `wx.cloud.extend.AI` |\n| **generateText params** | Direct object | Direct object |\n| **generateText return** | `{ text, usage, messages }` | Raw: `{ choices, usage }` |\n| **streamText params** | Direct object | ⚠️ Wrapped in `data: {...}` |\n| **streamText return** | `{ textStream, dataStream }` | `{ textStream, eventStream }` |\n| **Callbacks** | Not supported | `onText`, `onEvent`, `onFinish` |\n| **Image generation** | Node SDK only | Not available |\n\n---\n\n## Type Definitions\n\n### streamText() Input\n\n```ts\ninterface WxStreamTextInput {\n  data: {                              // ⚠️ Required wrapper object\n    model: string;\n    messages: Array<{\n      role: \"user\" | \"system\" | \"assistant\";\n      content: string;\n    }>;\n  };\n  onText?: (text: string) => void;     // incremental text callback\n  onEvent?: (prop: { data: string }) => void;  // raw event callback\n  onFinish?: (text: string) => void;   // completion callback\n}\n```\n\n### streamText() Return\n\n```ts\ninterface WxStreamTextResult {\n  textStream: AsyncIterable<string>;   // incremental text stream\n  eventStream: AsyncIterable<{         // raw event stream\n    event?: unknown;\n    id?: unknown;\n    data: string;                      // \"[DONE]\" when complete\n  }>;\n}\n```\n\n### generateText() Return\n\n```ts\n// Raw model response (OpenAI-compatible format)\ninterface WxGenerateTextResponse {\n  id: string;\n  object: \"chat.completion\";\n  created: number;\n  model: string;\n  choices: Array<{\n    index: number;\n    message: {\n      role: \"assistant\";\n      content: string;\n    };\n    finish_reason: string;\n  }>;\n  usage: {\n    prompt_tokens: number;\n    completion_tokens: number;\n    total_tokens: number;\n  };\n}\n```\n\n---\n\n## Best Practices\n\n1. **Run the two-step preflight before writing business code.** Fixed order: ① `DescribeActivityInfo` / `DescribeEnvPostpayPackage` for billing eligibility → ② `DescribeAIModels` for group readiness (if needed, `DescribeManagedAIModelList` for catalog + pricing, then `UpdateAIModel` to enable the target model). Only after both pass should you write `wx.cloud.extend.AI.createModel(...)`.\n2. **`createModel(provider)` accepts only three kinds of values** — `\"hunyuan-exp\"` (成长计划 exclusive legacy group), `\"cloudbase\"` (main managed group, default for new projects), or the custom-onboarding `GroupName` (**MUST start with `custom-`**, e.g. `custom-kimi`, `custom-openai-compat`, to avoid colliding with built-in / vendor names). **Never** write `createModel(\"deepseek\")` (unless `DescribeAIModels` truly returns a legacy builtin group named `deepseek`), `createModel(\"hunyuan\")`, `createModel(\"kimi\")`, or `createModel(\"custom\")` — these are model/vendor names or placeholders, not GroupNames.\n3. **The `model` field must come from `DescribeAIModels`.** Pass a value that actually exists in the `Models[].Model` list of the chosen group. The main managed group only has `deepseek-v4-flash` enabled by default; to use others, call `UpdateAIModel` first.\n4. **Hunyuan models are strictly bound to 成长计划.** To use a `hunyuan-*` model, the 成长计划 must be enrolled. When not enrolled, guide the user to `https://docs.cloudbase.net/ai/ai-inspire-plan`, or switch to `\"cloudbase\"` + `deepseek-v4-flash`. Do not bypass the check and call anyway.\n5. **Check pricing before enabling more models.** `DescribeManagedAIModelList` returns `ModelChargingInfo` (`Uniform` flat price / `Tiered` tiered pricing) + `ModelSpec.ContextLength`. Confirm before calling `UpdateAIModel`. `Models` is a **full replacement** — merge the old list + the new entry before passing.\n6. **Check base library version.** 3.7.1+ is required; on older versions `wx.cloud.extend.AI` is `undefined` — do not debug it as a model issue.\n7. **Use callbacks for UI updates.** `onText` is well-suited for progressively refreshing chat bubbles; manually concatenating from `eventStream` tends to drop separators.\n8. **Check for `[DONE]`.** When iterating `eventStream`, stop only when `event.data === \"[DONE]\"`, otherwise the stream waits forever for the next frame.\n9. **Remember the `data` wrapper.** `streamText` parameters MUST be wrapped in `data: { ... }` — unlike JS/Node SDK. Forgetting it yields a parameter error.\n10. **Distinguish \"not-eligible / group-not-ready\" from \"call failure\".** The former should guide the user into enrollment / purchase / `UpdateAIModel` flows; the latter is about debugging prompts, parameters, or the network. The error messages and next actions are completely different.\n11. **Do not hardcode third-party model API keys in the Mini Program.** For models outside the managed catalog, use `CreateAIModel` (`Secret.ApiKey`) so the key is stored on the CloudBase side; keep only the `GroupName` in the Mini Program.\n12. **TypeScript: do NOT use `any` to silence type errors.** If the `wx.cloud.extend.AI` surface is missing types, declare a precise `interface` for the slice you actually use, or augment via a local `.d.ts`. Never `: any`, `as any`, `@ts-ignore`, `@ts-nocheck`.\n13. **Self-verify before claiming done.** Build the Mini Program, open it in the WeChat DevTools simulator, exercise the real `streamText` / `generateText` flow end-to-end, and confirm: (a) the text chunks arrive via `onText`, (b) `[DONE]` terminates the stream, (c) no new console errors. \"It should work\" without an actual run is not acceptable evidence.\n\nFile v1.92.120:references/auth-nodejs-cloudbase/SKILL.md\n\n---\nname: auth-nodejs-cloudbase\ndescription: CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase; not when configuring providers or building client login UI.\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## Activation Contract\n\n### Use this first when\n\n- Node.js code in cloud functions or backend services must read caller identity, look up users, or issue custom login tickets.\n- The backend responsibility is auth / identity, not provider setup or frontend login UI.\n\n### Read before writing code if\n\n- The task mentions `@cloudbase/node-sdk`, server-side auth, custom login tickets, or \"who is calling\".\n- The request mixes frontend login with backend identity logic; split the flow and route client-side work elsewhere.\n\n### Then also read\n\n- Provider setup / publishable key -> `../auth-tool-cloudbase/SKILL.md`\n- Web login UI that consumes custom tickets -> `../auth-web-cloudbase/SKILL.md`\n- Raw HTTP auth client -> `../http-api-cloudbase/SKILL.md`\n\n### Do NOT use for\n\n- Provider enable/disable or login console configuration.\n- Frontend login / sign-up UI.\n- Mini program native auth.\n\n### Common mistakes / gotchas\n\n- Using this skill as the entry point for every auth request.\n- Mixing provider-management work with Node-side identity code.\n- Reaching for raw HTTP examples when Node SDK already covers the job.\n\n## When to use this skill\n\nUse this skill whenever the task involves **server-side authentication or identity** in a CloudBase project, and the code is running in **Node.js**, for example:\n\n- CloudBase 云函数 (Node runtime) that needs to know **who is calling**\n- Node services that use **CloudBase Node SDK** to look up user information\n- Backends that issue **custom login tickets** for Web / mobile clients\n- Admin or ops tools that need to inspect CloudBase end-user profiles\n\n**Do NOT use this skill for:**\n\n- Frontend Web login / sign-up flows using `@cloudbase/js-sdk` (handle those with the **auth-web** skill, not this Node skill).\n- Direct HTTP auth API integrations (this skill does not describe raw HTTP endpoints; use the **http-api** skill instead).\n- Database or storage operations that do not involve identity (use database/storage docs or skills).\n\nWhen the user request mixes frontend and backend concerns (e.g. \"build a web login page and a Node API that knows the user\"), treat them separately:\n\n- Use Web-side auth docs/skills for client login and UX.\n- Use this Node Auth skill for how the backend sees and uses the authenticated user.\n\n---\n\n## How to use this skill (for a coding agent)\n\nWhen you load this skill to work on a task:\n\n1. **Clarify the runtime and responsibility**\n\n   Ask the user:\n\n   - Where does this Node code run?\n     - CloudBase 云函数\n     - Long‑running Node service using CloudBase\n   - What do they need from auth?\n     - Just the **caller identity** for authorization?\n     - **Look up arbitrary users** by UID / login identifier?\n     - **Bridge their own user system** into CloudBase via custom login?\n\n2. **Confirm CloudBase environment and SDK**\n\n   - Ask for:\n     - `env` – CloudBase environment ID\n   - Install the latest `@cloudbase/node-sdk` from npm if it is not already available.\n   - Always initialize the SDK using this pattern (values can change, shape must not):\n\n   ```ts\n   import tcb from \"@cloudbase/node-sdk\";\n\n   const app = tcb.init({ env: \"your-env-id\" });\n   const auth = app.auth();\n   ```\n\n3. **Pick the relevant scenario from this file**\n\n   - For **caller identity inside a function**, use the `getUserInfo` scenarios.\n   - For **full user profile or admin lookup**, use the `getEndUserInfo` and `queryUserInfo` scenarios.\n   - For **client systems that already have their own users**, use the **custom login ticket** scenarios built on `createTicket`.\n   - For **logging / security**, use the `getClientIP` scenario.\n\n4. **Follow Node SDK API shapes exactly**\n\n   - Treat all `auth.*` methods and parameter shapes in this file as canonical.\n   - You may change variable names and framework (e.g. Express vs 云函数 handler), but **do not change SDK method names or parameter fields**.\n   - If you see a method in older code that is not listed here or in the Node SDK docs mirror, treat it as suspect and avoid using it.\n\n5. **If you are unsure about an API**\n\n   - Consult the official CloudBase Auth Node SDK documentation.\n   - Only use methods and shapes that appear in the official documentation.\n   - If you cannot find an API you want:\n     - Prefer composing flows from the documented methods, or\n     - Explain that this skill only covers Node SDK auth, and suggest using the relevant CloudBase Web or HTTP auth documentation for client-side or raw-HTTP flows.\n\n---\n\n## Node auth architecture – how Node fits into CloudBase Auth\n\nCloudBase Auth separates **where users log in** from **where backend code runs**:\n\n- Users log in through the supported auth methods (username/password, SMS, email, WeChat, custom login, anonymous — disabled by default, etc.) using client SDKs or HTTP interfaces, as described in the official CloudBase Auth overview documentation.\n- Once logged in, CloudBase attaches the user identity and tokens to the environment.\n- Node code then **reads** that identity using the Node SDK, or **bridges** external identities into CloudBase using custom login.\n\nIn practice, Node code usually does one or more of:\n\n1. **Identify the current caller**\n\n   - In 云函数, use `auth.getUserInfo()` to read `uid`, `openId`, and `customUserId`.\n   - Use this identity for **authorization decisions**, logging, and personalisation.\n\n2. **Look up other users**\n\n   - Use `auth.getEndUserInfo(uid)` when you know the CloudBase `uid`.\n   - Use `auth.queryUserInfo({ platform, platformId, uid? })` when you only have login identifiers such as phone, email, username, or a custom ID.\n\n3. **Issue custom login tickets**\n\n   - When you already have your own user system, your Node backend can call `auth.createTicket(customUserId, options)` and return the ticket to a trusted client.\n   - The client (typically Web) then uses this ticket with the Web SDK to log the user into CloudBase without forcing them to sign up again.\n\n4. **Log client IP for security**\n\n   - In 云函数, `auth.getClientIP()` returns the caller IP, which you can use for audit logs, anomaly detection, or access control.\n\nThe scenarios later in this file turn these responsibilities into explicit, copy‑pasteable patterns.\n\n---\n\n## Node Auth APIs covered by this skill\n\nThis skill covers the following `auth` methods on the CloudBase Node SDK. Treat these method signatures as the only supported entry points for Node auth flows when using this skill:\n\n- `getUserInfo(): IGetUserInfoResult`\n  Returns `{ openId, appId, uid, customUserId }` for the **current caller**.\n\n- `getEndUserInfo(uid?: string, opts?: ICustomReqOpts): Promise<{ userInfo: EndUserInfo; requestId?: string }>`\n  Returns detailed CloudBase end‑user profile for a given `uid` or for the current caller (when `uid` is omitted).\n\n- `queryUserInfo(query: IUserInfoQuery, opts?: ICustomReqOpts): Promise<{ userInfo: EndUserInfo; requestId?: string }>`\n  Finds a user by login identifier (`platform` + `platformId`) or `uid`.\n\n- `getClientIP(): string`\n  Returns the caller’s IP address when running in a supported environment (e.g. 云函数).\n\n- `createTicket(customUserId: string, options?: ICreateTicketOpts): string`\n  Creates a **custom login ticket** for the given `customUserId` that clients can exchange for a CloudBase login.\n\nThe exact field names and allowed values for `EndUserInfo`, `IUserInfoQuery`, and `ICreateTicketOpts` are defined by the official CloudBase Node SDK typings and documentation. When writing Node code, do not guess shapes; follow the SDK types and the examples in this file.\n\n---\n\n## Scenarios – Node auth patterns\n\n### Scenario 1: Initialize Node SDK and auth in a CloudBase function\n\nUse this when writing a CloudBase 云函数 that needs to interact with Auth:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\n\nconst app = tcb.init({ env: \"your-env-id\" });\nconst auth = app.auth();\n\nexports.main = async (event, context) => {\n  // Your logic here\n};\n```\n\nKey points:\n\n- Use the same `env` as configured for the function’s CloudBase 环境.\n- Avoid hardcoding sensitive values; prefer environment variables or function configuration.\n\n### Scenario 2: Get caller identity in a CloudBase function\n\nUse this when you need to know **who is calling** your cloud function:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\n\nconst app = tcb.init({ env: \"your-env-id\" });\nconst auth = app.auth();\n\nexports.main = async (event, context) => {\n  const { openId, appId, uid, customUserId } = auth.getUserInfo();\n\n  console.log(\"Caller identity\", { openId, appId, uid, customUserId });\n\n  // Use uid / customUserId for authorization decisions\n  // e.g. check roles, permissions, or data ownership\n};\n```\n\nBest practices:\n\n- Treat `uid` as the canonical CloudBase user identifier.\n- Use `customUserId` only when you have enabled **自定义登录** and mapped your own users.\n- Never trust `openId`/`appId` alone for authorization; they are WeChat‑specific identifiers.\n\n### Scenario 3: Get full end‑user profile by UID\n\nUse this when you know a user’s CloudBase `uid` (for example, from a database record) and you need detailed profile information:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\n\nconst app = tcb.init({ env: \"your-env-id\" });\nconst auth = app.auth();\n\nexports.main = async (event, context) => {\n  const uid = \"user-uid\";\n\n  try {\n    const { userInfo } = await auth.getEndUserInfo(uid);\n    console.log(\"User profile\", userInfo);\n  } catch (error) {\n    console.error(\"Failed to get end user info\", error.message);\n  }\n};\n```\n\nBest practices:\n\n- Call `getEndUserInfo` from trusted backend code only; do not expose it directly to untrusted clients.\n- Log minimal necessary data for debugging; avoid logging full profiles in production.\n\n### Scenario 4: Get full profile for the current caller\n\nUse this when you want the **current caller’s** full profile without manually passing `uid`:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\n\nconst app = tcb.init({ env: \"your-env-id\" });\nconst auth = app.auth();\n\nexports.main = async (event, context) => {\n  try {\n    const { userInfo } = await auth.getEndUserInfo();\n    console.log(\"Current caller profile\", userInfo);\n  } catch (error) {\n    console.error(\"Failed to get current caller profile\", error.message);\n  }\n};\n```\n\nThis relies on the environment providing the caller’s identity (e.g. within a CloudBase 云函数). If called where no caller context exists, refer to the official docs and handle errors gracefully.\n\n### Scenario 5: Query user by login identifier\n\nUse this when you only know a user’s login identifier (phone, email, username, or custom ID) and need their CloudBase profile:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\n\nconst app = tcb.init({ env: \"your-env-id\" });\nconst auth = app.auth();\n\nexports.main = async (event, context) => {\n  try {\n    // Find by phone number\n    const { userInfo: byPhone } = await auth.queryUserInfo({\n      platform: \"PHONE\",\n      platformId: \"+86 13800000000\",\n    });\n\n    // Find by email\n    const { userInfo: byEmail } = await auth.queryUserInfo({\n      platform: \"EMAIL\",\n      platformId: \"test@example.com\",\n    });\n\n    // Find by customUserId\n    const { userInfo: byCustomId } = await auth.queryUserInfo({\n      platform: \"CUSTOM\",\n      platformId: \"your-customUserId\",\n    });\n\n    console.log({ byPhone, byEmail, byCustomId });\n  } catch (error) {\n    console.error(\"Failed to query user info\", error.message);\n  }\n};\n```\n\nBest practices:\n\n- Prefer `uid` when you already have it; use `queryUserInfo` only when needed.\n- Make sure `platformId` uses the exact format you used at sign‑up (e.g. `+86` + phone number).\n\n### Scenario 6: Get client IP in a function\n\nUse this for logging or basic IP‑based checks:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\n\nconst app = tcb.init({ env: \"your-env-id\" });\nconst auth = app.auth();\n\nexports.main = async (event, context) => {\n  const ip = auth.getClientIP();\n  console.log(\"Caller IP\", ip);\n\n  // e.g. block or flag suspicious IPs\n};\n```\n\n---\n\n## Custom login tickets (Node side only)\n\nCustom login lets you keep your existing user system while still mapping each user to a CloudBase account.\n\n### Scenario 7: Initialize Node SDK with custom login credentials\n\nBefore issuing tickets, install the custom login private key file from the CloudBase console and load it in Node:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\nimport path from \"node:path\";\n\nconst app = tcb.init({\n  env: \"your-env-id\",\n  credentials: require(path.join(__dirname, \"tcb_custom_login.json\")),\n});\n\nconst auth = app.auth();\n```\n\nKeep `tcb_custom_login.json` secret and **never** bundle it into frontend code.\n\n### Scenario 8: Issue a custom login ticket for a given customUserId\n\nUse this in backend code that has already authenticated your own user and wants to let them log into CloudBase:\n\n```ts\nimport tcb from \"@cloudbase/node-sdk\";\n\nconst app = tcb.init({\n  env: \"your-env-id\",\n  credentials: require(\"/secure/path/to/tcb_custom_login.json\"),\n});\n\nconst auth = app.auth();\n\nexports.main = async (event, context) => {\n  const customUserId = \"your-customUserId\";\n\n  const ticket = auth.createTicket(customUserId, {\n    refresh: 3600 * 1000,       // access_token refresh interval (ms)\n    expire: 24 * 3600 * 1000,   // ticket expiration time (ms)\n  });\n\n  // Return the ticket to the trusted client (e.g. via HTTP response)\n  return { ticket };\n};\n```\n\nConstraints for `customUserId` (from official docs):\n\n- Length 4–32 characters.\n- Allowed characters: letters, digits, and `_-#@(){}[]:.,<>+#~`.\n\nBest practices:\n\n- Only issue tickets after your own user authentication succeeds.\n- Store `customUserId` in your own user database and keep it stable over time.\n- Do not reuse `customUserId` for multiple distinct people.\n\n### Scenario 9: How this pairs with Web custom login\n\nThis skill only covers **Node-side** ticket issuance. For the **client-side** flow:\n\n- On the client (Web), use `@cloudbase/js-sdk`'s custom login support:\n  - Call your backend endpoint that returns `ticket`.\n  - Configure `auth.setCustomSignFunc(async () => ticketFromBackend)`.\n  - Call `auth.signInWithCustomTicket()` to finish login.\n\nKeep the responsibility clear:\n\n- Node: authenticate your own user → create ticket → return ticket securely.\n- Web: receive ticket → sign into CloudBase using documented Web SDK APIs.\n\n---\n\n## Node auth best practices\n\n- **Single source of truth for identity**\n  - Treat CloudBase `uid` as the primary key when relating end‑user records.\n  - Use `customUserId` only as a bridge to your own user system.\n\n- **Least privilege**\n  - Perform authorization checks in Node using `uid`, roles, and ownership, not just login success.\n  - Avoid exposing raw `getEndUserInfo` / `queryUserInfo` results directly to clients.\n\n- **Error handling**\n  - Wrap all `auth.*` calls in `try/catch` when they return promises.\n  - Log `error.message` (and `error.code` if present), but avoid logging sensitive data.\n\n- **Security**\n  - Protect `tcb_custom_login.json` as you would any private key.\n  - Rotate custom login keys according to CloudBase guidance when necessary.\n  - Use HTTPS and proper authentication between your clients and Node backend when exchanging tickets.\n\n---\n\n## Summary\n\nUse this Node Auth skill whenever you need to:\n\n- Know **who** is calling your Node code in CloudBase.\n- Look up CloudBase users by `uid` or login identifier.\n- Bridge an existing user system into CloudBase with **custom login tickets**.\n- Apply consistent, secure, server‑side auth best practices.\n\nFor end‑to‑end experiences, pair this skill with:\n\n- Web‑side auth documentation (for all browser‑side login and UX using `@cloudbase/js-sdk`).\n- CloudBase HTTP auth documentation (for language‑agnostic HTTP integrations, if you are using those).\n\nTreat the official CloudBase Auth Node SDK documentation as the canonical reference for Node auth APIs, and treat the scenarios in this file as vetted best‑practice building blocks.\n\nFile v1.92.120:references/auth-tool-cloudbase/SKILL.md\n\n---\nname: auth-tool-cloudbase\ndescription: CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## Activation Contract\n\n### Use this first when\n\n- The task is to inspect, enable, disable, or configure CloudBase auth providers, login methods, publishable key prerequisites, SMS/email delivery, or third-party login readiness.\n- An auth implementation cannot proceed until provider status and login configuration are confirmed.\n- A CloudBase Web auth flow needs provider verification before `auth-web-cloudbase`.\n\n### Read before writing code if\n\n- The request mentions provider setup, auth console configuration, publishable key retrieval, login method availability, SMS/email sender setup, or third-party provider credentials.\n- The task mixes provider configuration with Web, mini program, Node, or raw HTTP auth implementation.\n\n### Then also read\n\n- Web auth UI -> `../auth-web-cloudbase/SKILL.md`\n- Mini program native auth -> `../auth-wechat-miniprogram/SKILL.md`\n- Node server-side identity / custom ticket -> `../auth-nodejs-cloudbase/SKILL.md`\n- Native App / raw HTTP auth client -> `../http-api-cloudbase/SKILL.md`\n\n### Do NOT use this as\n\n- The default implementation guide for every login or registration request.\n- A replacement for mini program native auth behavior when no provider change is involved.\n- A replacement for Node-side caller identity, user lookup, or custom login ticket flows.\n- A replacement for frontend integration, session handling, or client UX implementation.\n\n### Common mistakes / gotchas\n\n- Writing login UI before enabling the required provider.\n- Treating any mention of \"auth\" as a provider-management task.\n- Implementing Web login in cloud functions.\n- Routing native App auth to Web SDK flows.\n- Making configuration or code changes without first following the Change Safety Protocol (`cloudbase-platform/references/protocols/change-safety-protocol.md`).\n- In an existing application, looping on provider queries after readiness is already known instead of wiring the active login and register handlers.\n\n### Minimal checklist\n\n- Read [Authentication Activation Checklist](checklist.md) before auth implementation.\n- Anonymous login is disabled by default. Publishable `accessKey` alone does **not** create a gateway-authenticated anonymous session. With `@cloudbase/js-sdk` **3.x**, enable anonymous via this skill when needed, then clients must call `await auth.signInAnonymously()` (or an equivalent authenticated session) **before** NoSQL `app.database()` CRUD — otherwise the gateway returns **401**. For apps that require verified login (e.g. admin panels), enforce AuthGuard / RLS and reject `is_anonymous` rather than relying on the login strategy toggle alone.\n\n## Overview\n\nConfigure CloudBase authentication providers: Anonymous, Username/Password, SMS, Email, WeChat, Google, and more.\n\n**Prerequisites**: CloudBase environment ID (`env`)\n\n## MCP Tool Boundary\n\nKeep these two auth domains separate:\n\n- `auth`: MCP / management-side login only. Use it for `status`, `start_auth`, `set_env`, `logout`, and `get_temp_credentials`.\n- `queryAppAuth` / `manageAppAuth`: app-side authentication configuration. Use them for login methods, provider settings, publishable key, static domain, client config, and custom login keys.\n\nPreferred execution order for this skill:\n\n1. Use `queryAppAuth` / `manageAppAuth` first when the needed action exists there.\n2. Use `callCloudApi` only as a fallback or for debugging raw request shapes.\n3. Do not route app-side provider configuration back to the MCP `auth` tool.\n4. In existing projects with active login and register handlers, stop revisiting provider setup after the required login method and publishable key are confirmed. Move back to the active frontend handler and finish the actual user flow.\n\n---\n\n## Extended guide\n\nFor detailed scenarios, examples, and patterns, read [extended-guide.md](references/extended-guide.md).\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [extended-guide.md](references/extended-guide.md)\n\nFile v1.92.120:references/auth-web-cloudbase/SKILL.md\n\n---\nname: auth-web-cloudbase\ndescription: CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management.\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## Activation Contract\n\n### Use this first when\n\n- The task is a CloudBase Web login, registration, session, or user profile flow built with `@cloudbase/js-sdk` and the auth provider setup has already been checked.\n\n### Read before writing code if\n\n- The user needs a login page, auth modal, session handling, or protected Web route. Read `auth-tool-cloudbase` first to ensure providers are enabled, then return here for frontend integration.\n\n### Then also read\n\n- `../auth-tool-cloudbase/SKILL.md` for provider setup\n- `../web-development/SKILL.md` for Web project structure and deployment\n\n### Do not start here first when\n\n- The request is a Web auth flow but provider configuration has not been verified yet.\n- In that case, activate `auth-tool-cloudbase` before `auth-web-cloudbase`.\n\n### Do NOT use for\n\n- Mini program auth, native App auth, or server-side auth setup.\n\n### Common mistakes / gotchas\n\n- Skipping publishable key and provider checks.\n- Replacing built-in Web auth with cloud function login logic.\n- Reusing this flow in Flutter, React Native, or native iOS/Android code.\n- Creating a detached helper file with `auth.signUp` / `verifyOtp` but never wiring it into the existing form handlers, so the actual button clicks still do nothing.\n- Using `signInWithEmailAndPassword` or `signUpWithEmailAndPassword` for username-style accounts such as `admin` and `editor`.\n- Keeping the login or register account input as `type=\"email\"` when the task explicitly says the account identifier is a plain username string.\n- Starting implementation before calling `queryAppAuth(action=\"getLoginConfig\")` and enabling `usernamePassword` when it is still off.\n- **Writing `auth.signInWithPassword(...)` or `auth.signUp(...)` code without first confirming the provider is enabled via MCP.** Before writing any sign-in or sign-up code in the browser, call `queryAppAuth(action=\"listProviders\")` to verify the target provider (e.g. `email`, `phone`, `usernamePassword`) has `On: \"TRUE\"`. For email-based sign-up (`auth.signUp({ email, password })`), additionally confirm SMTP is configured — otherwise the provider may throw `\"provider email not found\"` or similar errors. For username/password login, use `auth.signInWithPassword({ username, password })`; registration is best done through the management API (`manageAppAuth(action=\"createUser\")`) or by confirming email provider readiness first.\n- **Treating `auth.getUser()` or deprecated `auth.getLoginState()` as proof of real login.** When the SDK is initialized with `accessKey`, the deprecated `getLoginState()` may still return an object with a valid `uid` even without any login — causing route guards that check `!!loginState` or `!!uid` to incorrectly pass. That misleading `uid` is **not** a gateway-authenticated session. Use `auth.getSession()` instead: it returns `data.session === undefined` when no real login has occurred. Only `!!data.session` from `getSession()` is a reliable authentication check.\n- **Assuming publishable `accessKey` alone is enough for NoSQL CRUD.** NoSQL `app.database()` `get` / `add` / `update` / `watch` requires a gateway-authenticated **session**: use a real login (password / OTP / OAuth). Anonymous login is a demo-only escape hatch for explicitly-public, non-user data — it is disabled by default, denied AI model permissions, and must never stand in for real auth in user-scoped apps. Skipping any login yields **gateway 401**. `checkLogin()` / `getSession()` alone do **not** create a usable write session.\n- **Copying old CloudBase auth snippets from training data.** Do not use `auth.getLoginState()`, `auth.hasLoginState()`, `auth.getCurrentUser()`, or `auth.toDefaultLoginPage()` as the default Web flow. Use the Web SDK v3 auth methods in this file and provider readiness from `auth-tool-cloudbase`.\n- **Calling a standalone `auth.verifyOtp({ token })` for OTP login.** CloudBase Web SDK v3 returns `verifyOtp` as a callback on the `signInWithOtp` / `signUp` result: send the code first, keep the returned `data`, then call `data.verifyOtp({ token })`. A standalone `auth.verifyOtp({ token })` without `messageId` fails with `\"messageId is required\"` — seeing that error means the callback form was skipped. See `references/extended-guide.md` for the full send → save callback → verify flow.\n  \n  Note: anonymous login is **disabled by default** for new environments and inactive existing environments. Do not enable it to work around permission errors — enable via `auth-tool-cloudbase` only when the app explicitly serves public non-user data (e.g. NoSQL read-only demos). Always use `auth.getSession()` for auth guards.\n\n## Overview\n\n**Prerequisites**: CloudBase environment ID (`env`)\n**Prerequisites**: CloudBase environment Region (`region`)\n\n---\n\n## Core Capabilities\n\n**Use Case**: Web frontend projects using `@cloudbase/js-sdk@latest` for user authentication  \n**Key Benefits**: **Supabase-compatible Auth API** — all methods return `{ data, error }`, supports phone, email, anonymous (disabled by default), username/password, OAuth, and third-party login methods\n\n> 📌 **Supabase API Compatibility**: CloudBase Web SDK v3 auth module is designed with Supabase-like API ergonomics. If you are familiar with `supabase-js` auth patterns, the same mental model applies:\n> - All methods return `Promise<{ data, error }>` — always check `error` first\n> - `signInWithPassword`, `signInWithOtp`, `signUp`, `signOut`, `getSession`, `getUser` follow the same naming as Supabase\n> - `onAuthStateChange(callback)` provides reactive auth state observation (events: `INITIAL_SESSION`, `SIGNED_IN`, `SIGNED_OUT`, `TOKEN_REFRESHED`, `USER_UPDATED`, `PASSWORD_RECOVERY`, `BIND_IDENTITY`)\n> - Session management via `getSession()` / `refreshSession()` / `setSession()` mirrors Supabase patterns\n> \n> **Key differences from Supabase**:\n> - **OTP verification**: Supabase uses a standalone `auth.verifyOtp({ phone, token, type })` call; CloudBase returns `verifyOtp` as a callback on `data` — call `data.verifyOtp({ token })` from the `signInWithOtp` / `signUp` result\n> - **`accessKey`** replaces Supabase's `anonKey`; environment uses `env` + `region` instead of Supabase's `url`\n> - **`signInWithIdToken`** for direct third-party token login (similar to Supabase's same-named method)\n\nUse npm installation for modern Web projects. In React, Vue, Vite, and other bundler-based apps, install and import `@cloudbase/js-sdk` from the project dependencies instead of using a CDN script.\n\n## Prerequisites\n\n- Automatically use `auth-tool-cloudbase` to check app-side auth readiness via `queryAppAuth` / `manageAppAuth`, then get the `publishable key` and configure login methods.\n- **Publishable key readiness (do not skip):** call `queryAppAuth(action=\"getPublishableKey\")`. If it is empty, call `manageAppAuth(action=\"ensurePublishableKey\")` first — new environments may not have one provisioned, and skipping this step leaves the frontend without a data-plane credential, surfacing later as gateway auth failures instead of an obvious missing-key error.\n- **Persist the key, don't hoard it in conversation:** after retrieval, write the publishable key to `.env.local` as `VITE_PUBLISHABLE_KEY` (create the file if missing) and read it in client code via `import.meta.env.VITE_PUBLISHABLE_KEY`. Never hardcode the key into source files, and never ask the user to fetch it from the console — fall back to the console link below only if both MCP calls fail.\n- If `auth-tool-cloudbase` failed, let user go to `https://tcb.cloud.tencent.com/dev?envId={env}#/env/apikey` to get `publishable key` and `https://tcb.cloud.tencent.com/dev?envId={env}#/identity/login-manage` to set up login methods\n\n### Parameter map\n\n- For username-style identifiers, the required precondition is `loginMethods.usernamePassword === true` from `queryAppAuth(action=\"getLoginConfig\")`. If it is false, enable it with `manageAppAuth(action=\"patchLoginStrategy\", patch={ usernamePassword: true })` before wiring frontend auth code.\n- If the conversation only provides an environment alias, nickname, or other shorthand, resolve it with `queryEnv(action=\"list\", alias=..., aliasExact=true)` first and use the returned canonical full `EnvId` for SDK init, console links, and generated config. Do not pass alias-like short forms directly into `cloudbase.init({ env })`.\n- Treat CloudBase Web Auth as **Supabase-like**, not “every `supabase-js` auth example is valid unchanged”\n- When `queryAppAuth` / `manageAppAuth` returns `sdkStyle: \"supabase-like\"` and `sdkHints`, follow those method and parameter hints first\n- `auth.signInWithOtp({ phone })` and `auth.signUp({ phone })` use the phone number in a `phone` field, not `phone_number`\n- `auth.signInWithOtp({ email })` and `auth.signUp({ email })` use `email`\n- `auth.signInWithPassword({ username, password })` is the canonical Web login path for username/password accounts\n- Treat direct Web `auth.signUp({ username, password })` as conditional. Verify `sdkHints` and the installed SDK first; some versions only support `signUp` for OTP/provider-token flows and will not create username/password users.\n- If the task gives accounts like `admin`, `editor`, or another plain string without `@`, treat it as a username-style identifier rather than an email address\n- `data.verifyOtp({ token })` — the `verifyOtp` callback on the `signInWithOtp` / `signUp` result `data` — expects the SMS or email code in `token`; do not invent a standalone `auth.verifyOtp({ token })` call, which additionally requires `messageId`\n- `accessKey` is the publishable key from `queryAppAuth` / `manageAppAuth` via `auth-tool-cloudbase`, not a secret key\n- **`accessKey` alone does not create a gateway-authenticated session.** Publishable `accessKey` initializes the SDK; it does **not** replace a login for NoSQL CRUD. Any `app.database()` `get` / `add` / `update` / `watch` needs a session — prefer a real login (password / OTP / OAuth); `signInAnonymously()` only for explicitly-public demo data (disabled by default, denied AI model permissions). Otherwise the gateway returns **401**. Separately: the deprecated `auth.getLoginState()` may still return a misleading `uid` without login; use `auth.getSession()` for route guards (`data.session === undefined` when not logged in). `checkLogin()` / `getSession()` alone do **not** create a usable write session.\n- Never set `accessKey` to `envId`, a username, or any placeholder string. If you do not have a real Publishable Key yet, do not fabricate one.\n- If the task mentions provider setup, stop and read `auth-tool-cloudbase` before writing frontend code\n\n## Quick Start\n\nSDK init reference: [docs.cloudbase.net/api-reference/webv3/initialization.md](https://docs.cloudbase.net/api-reference/webv3/initialization.md)（URL 加 `.md` 可取 raw markdown 原文）\n\n```js\n// npm install @cloudbase/js-sdk\nimport cloudbase from '@cloudbase/js-sdk'\n\nconst app = cloudbase.init({\n  env: 'your-full-env-id', // Canonical full CloudBase environment ID resolved from queryEnv or the console, not an alias or shorthand\n  region: 'ap-shanghai',  // CloudBase environment Region, default 'ap-shanghai'\n  accessKey: 'publishable key', // required, get from auth-tool-cloudbase\n  // ⚠️ accessKey alone ≠ a login session. NoSQL CRUD needs a session —\n  // real login preferred; signInAnonymously() only for public demo data.\n  // Use auth.getSession() for route guards; deprecated getLoginState()\n  // may return a misleading uid without a real session.\n  auth: { detectSessionInUrl: true }, // required\n})\n\nconst auth = app.auth\n\n// NoSQL app.database() CRUD requires a session (js-sdk 3.x + publishable key).\n// Real login (see cookbook). Anonymous, only for public non-user demos:\n// const { error } = await auth.signInAnonymously()\n// if (error) throw error\n```\n\nIf the current task has not retrieved a real Publishable Key, omit `accessKey` instead of inventing one. A wrong `accessKey` can break auth-state checks and protected-route behavior.\n\n## Auth code cookbook (official v3 API — copy these, do not re-derive from .d.ts)\n\nEvery method returns the unified shape `{ data, error }` — branch on `error` first and surface `error.message`. The auth API is identical in traditional and PG environments. Source: [official auth docs](https://docs.cloudbase.net/api-reference/webv3/authentication.md)（raw markdown, cross-check snippets there when in doubt）.\n\n**Default auth UI contract:** when the user asks for 登录/注册/账号体系/user system without restricting the method, the login page must make ALL of these reachable (tabs or separate forms): password sign-in, OTP sign-in, verified sign-up (code + password), and forgot-password (whenever password sign-in exists). Never ship OTP-only or password-only UI unless explicitly asked. Never reveal whether an identifier is already registered in user-facing copy — route existing users to login with neutral wording.\n\n**Password sign-in** (username-style or email identifiers both go here):\n\n```js\nconst { data, error } = await auth.signInWithPassword({ username, password })\n// email accounts: auth.signInWithPassword({ email, password })\nif (error) { /* show error.message */ } else { /* data.user */ }\n```\n\n**Anonymous sign-in — demo-only, not a default.** NoSQL `app.database()` CRUD needs some session (PG anon reads work with accessKey alone). Prefer a real login; reach for anonymous ONLY when the app explicitly serves public non-user data and the user accepts the trade-off — it is disabled by default, denied AI model permissions, and its `uid` must never own user-scoped rows:\n\n```js\nconst { error } = await auth.signInAnonymously()\n```\n\n**Registration — verification code is MANDATORY.** There is no password-only signup: `signUp` itself sends a code, and `data.verifyOtp` must complete it. Smart flow: existing identifier → plain login; new identifier → register + auto-login. Phone/SMS is 上海地域 only — prefer email:\n\n```js\nconst { data, error } = await auth.signUp({ email, password }) // or { phone, password }\nif (error) throw error\n// user types the code from their inbox...\nconst { data: login, error: verifyErr } = await data.verifyOtp({ token: code })\n// login.user / login.session — signed in on both paths\n```\n\n**OTP sign-in (no password)** — same shape as `signUp`, auto-creates the user by default (`shouldCreateUser: false` to refuse unknown users). Requires 邮箱/短信验证码登录 enabled in console → 身份认证/登录方式:\n\n```js\nconst { data, error } = await auth.signInWithOtp({ email }) // or { phone }\nconst { data: login, error: verifyErr } = await data.verifyOtp({ token: code })\n```\n\n**Forgot password** — email code → set new password → auto sign-in (emits `PASSWORD_RECOVERY`):\n\n```js\nconst { data, error } = await auth.resetPasswordForEmail(email)\nif (error) throw error\nconst { data: login, error: resetErr } = await data.updateUser({ nonce: code, password: newPassword })\n```\n\n**OTP closure vs standalone `verifyOtp` — do not mix.** The `data.verifyOtp` returned by `signUp` / `signInWithOtp` / `resetPasswordForEmail` has the message ID bound (pass only `{ token }`). The standalone `auth.verifyOtp(...)` requires `messageId` and **only logs in — it never registers**. Always use the returned closure.\n\n**Session check / route guard** — always `getSession()`, never the deprecated `getLoginState()`:\n\n```js\nconst { data } = await auth.getSession()\nconst session = data?.session // undefined === not logged in\n```\n\n**Auth state listener** (wire this once at app bootstrap):\n\n```js\nauth.onAuthStateChange((event, session) => {\n  // event: INITIAL_SESSION | SIGNED_IN | SIGNED_OUT | PASSWORD_RECOVERY\n  //        | TOKEN_REFRESHED | USER_UPDATED | BIND_IDENTITY\n})\n```\n\n**Sign out:**\n\n```js\nconst { error } = await auth.signOut()\n```\n\n**Mandatory auth gate before user-scoped data.** Before reading/writing user-owned PG rows or Storage objects, check the session and show login when absent — never \"fix\" data errors by silently calling `signInAnonymously`:\n\n```js\nconst { data } = await auth.getSession()\nif (!data?.session) { navigate('/login'); return }\n```\n\n**Completion Bar** — before calling the auth task done, the generated source must have ALL of:\n\n- [ ] `signInWithPassword` (when password login is part of the UI)\n- [ ] a verification-code path: `signUp` + `data.verifyOtp` and/or `signInWithOtp`\n- [ ] auth gate before user-scoped DB/Storage calls (rule above)\n- [ ] `onAuthStateChange` wired at bootstrap (route guard reacts to `SIGNED_OUT`)\n- [ ] errors surfaced from `error.message`, no invented error text\n- [ ] NO `signInAnonymously` as a fallback for permission errors, no mock/localStorage sessions\n\n---\n\n## Extended guide\n\nFor detailed scenarios, examples, and patterns, read [extended-guide.md](references/extended-guide.md).\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [extended-guide.md](references/extended-guide.md)\n\nFile v1.92.120:references/auth-wechat-miniprogram/SKILL.md\n\n---\nname: auth-wechat-miniprogram\ndescription: CloudBase WeChat Mini Program native authentication guide. This skill should be used when users need mini program identity handling, OPENID/UNIONID access, or `wx.cloud` auth behavior in projects where login is native and automatic.\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## Activation Contract\n\n### Use this first when\n\n- The task is about WeChat Mini Program auth behavior, `wx.cloud` identity, `OPENID` / `UNIONID`, or how a mini program caller is identified in CloudBase.\n- The project is a CloudBase mini program and the auth question is about native mini program identity rather than provider configuration.\n\n### Read before writing code if\n\n- The request mentions mini program login, user identity in cloud functions, or `wx.cloud` auth assumptions.\n- The user expects a Web-style login page or explicit token exchange in a mini program; route them back to native mini program auth behavior.\n\n### Then also read\n\n- Mini program project implementation -> `../miniprogram-development/SKILL.md`\n- Cloud function implementation -> `../cloud-functions/SKILL.md`\n\n### Do NOT use for\n\n- Web-based WeChat login or Web auth UI.\n- Provider enable/disable or auth console setup.\n- Generic Node-side auth flows outside mini program identity handling.\n\n### Common mistakes / gotchas\n\n- Generating a Web-style login page for a `wx.cloud` mini program.\n- Treating mini program auth as a provider-configuration problem.\n- Forgetting that caller identity is injected in cloud functions automatically.\n\n## When to use this skill\n\nUse this skill for **WeChat Mini Program (小程序) authentication** in a CloudBase project.\n\nUse it when you need to:\n\n- Implement identity-aware WeChat Mini Program flows with CloudBase\n- Access user identity (openid, unionid) in cloud functions\n- Understand how WeChat authentication integrates with CloudBase\n- Build Mini Program features that require user identification\n\n**Key advantage:** WeChat Mini Program authentication with CloudBase is **seamless and automatic** - no complex OAuth flows needed. When a Mini Program calls a cloud function, the user's `openid` is automatically injected and verified by WeChat.\n\n**Do NOT use for:**\n\n- Web-based WeChat login (use the **auth-web** skill)\n- Server-side auth with Node SDK (use the **auth-nodejs** skill)\n- Non-WeChat authentication methods (use appropriate auth skills)\n\n---\n\n## How to use this skill (for a coding agent)\n\n1. **Confirm CloudBase environment**\n   - Ask the user for:\n     - `env` – CloudBase environment ID\n     - Confirm the Mini Program is linked to the CloudBase environment\n\n2. **Understand the authentication flow**\n   - WeChat Mini Program authentication is **native and automatic**\n   - No explicit login API calls needed in most cases\n   - User identity is automatically available in cloud functions\n   - CloudBase handles all authentication verification\n\n3. **Pick a scenario from this file**\n   - For basic user identity in cloud functions, use **Scenario 2**\n   - For Mini Program initialization, use **Scenario 1**\n   - For calling a cloud function from the Mini Program and receiving user identity, use **Scenario 3**\n   - For testing authentication, use **Scenario 4**\n\n4. **Follow CloudBase API shapes exactly**\n   - Use `wx-server-sdk` in cloud functions\n   - Use `wx.cloud` in Mini Program client code\n   - Treat method names and parameter shapes in this file as canonical\n\n5. **If you're unsure about an API**\n   - Consult the official CloudBase Mini Program documentation\n   - Only use methods that appear in official documentation\n\n---\n\n## Core concepts\n\n### How WeChat Mini Program authentication works with CloudBase\n\n1. **Automatic authentication:**\n   - When a Mini Program user calls a cloud function, WeChat automatically injects the user's identity\n   - No need for complex OAuth flows or token management\n   - CloudBase verifies the authenticity of the identity\n\n2. **User identifiers:**\n   - `OPENID` – Unique identifier for the user in this specific Mini Program\n   - `APPID` – The Mini Program's App ID\n   - `UNIONID` – (Optional) Unique identifier across all apps under the same WeChat Open Platform account\n     - Only available when the Mini Program is bound to a WeChat Open Platform account\n     - Useful for identifying the same user across multiple Mini Programs or Official Accounts\n\n3. **Security:**\n   - The `openid`, `appid`, and `unionid` are **verified and trustworthy**\n   - WeChat has already completed authentication\n   - Developers can directly use these identifiers without additional verification\n\n4. **No explicit login required:**\n   - Users are automatically authenticated when they use the Mini Program\n   - No need to call login APIs in most cases\n   - Identity is available immediately in cloud functions\n\n---\n\n## Extended guide\n\nFor detailed scenarios, examples, and patterns, read [extended-guide.md](references/extended-guide.md).\n\n## Reference index\n\nAll packaged reference files (required for skill lint reachability):\n\n- [extended-guide.md](references/extended-guide.md)\n\nFile v1.92.120:references/cloud-api-operations/SKILL.md\n\n---\nname: cloud-api-operations\ndescription: Operate Tencent Cloud control-plane resources (monitoring/alarms, CLB, CAM roles, COS, MySQL, SCF) via cloud APIs when no dedicated MCP tool covers the task. Use when a task needs control-plane operations beyond CloudBase's own tooling, or when a callCloudApi call failed and needs classifying.\nversion: 2.34.8\n---\n\n# Cloud API Operations\n\nOperate Tencent Cloud resources that CloudBase depends on but that no dedicated MCP tool covers (monitoring & alarms, CLB, CAM roles, cross-product infra). Two goals: **find the right API without guessing**, and **reuse proven workflows instead of re-exploring**.\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../cloudbase-platform/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## When to use\n\n- The user asks to manage/operate Tencent Cloud resources beyond CloudBase's dedicated MCP tools (e.g. configure alarm policies, inspect CLB, attach CAM policies).\n- The user wants to control these resources from code and asks which API/SDK to use.\n- A callCloudApi call failed and you need to classify the error (wrong Action / wrong params / missing CAM permission) and recover.\n\n## Workflow\n\n### 1. Discover the API — resolve names from a documented source\n\n1. **Read the API index first**: https://docs.cloudbase.net/ai/cloudbase-ai-toolkit/api-reference.md — auto-synced daily, action-level coverage (TCB 105 + dependency products: MySQL / SCF / COS). Check rate limits there too. The index check is a quick grep — run it in parallel with step 2/3 fetches, do not serialize.\n2. If the index does not cover the target product, go to the product's official API docs (e.g. monitor: https://cloud.tencent.com/document/product/649/30343) and confirm the exact Action name, Version, and parameters.\n3. For machine-readable parameter schema, fetch the official SDK models source directly — see `./references/calling-methods.md` §2 item 4.\n\n**Done when**: the Action name, Version, and full parameter shape each trace to the index, official product docs, or SDK models source — nothing from memory. A call that still returns `action ... is invalid or not found` means a name was not resolved this way; classify and recover via the error table in `./references/calling-methods.md` §1.\n\n> **API first：公开 API 概览就是契约边界。** 索引里查不到某个能力，它就不在公开契约内 —— 不要拿某个 SDK 的封装方法反推未公开的 Action 名去调（这类 Action 不受公开文档保护，非该语言的使用者也无从照做）。此时改用有公开 API 的等价路径，或把缺口明确告诉用户。本 skill 的 recipes 只收录公开 API 覆盖的场景。\n\n### 2. Choose the calling path\n\n| Scenario | Path | Reference |\n| --- | --- | --- |\n| Interactive ops inside this session | MCP `callCloudApi` | `./references/calling-methods.md` §1 |\n| Picking the `service` identifier / deciding whether `version` is needed | MCP `callCloudApi` | `./references/service-versions.md` |\n| User's code / scripts | Official SDKs (TC3-HMAC-SHA256) or `@cloudbase/manager-node` | `./references/calling-methods.md` §2 |\n| Quick one-off verification | API Explorer (https://console.cloud.tencent.com/api/explorer) | — |\n\nPriority rule: if `@cloudbase/manager-node` has a matching method, use it; drop to raw cloud API only when it does not.\n\n### 3. Check credentials before the first call\n\n- Read the current credential scope from `auth` tools: `credential_scope: account` = account-level, reaches control-plane APIs subject to that identity's CAM policies; `env` = API Key, scoped to one environment's data plane plus the fixed TCB policies.\n- Permission comes from a different place per credential identity: the account-level identity's own policies, the API Key model (no channel to attach arbitrary CAM policies), or the TCB service role that CLI / MCP assume. Which cross-product capabilities that role family already covers is not fixed — read the attached policies (`ListAttachedRolePolicies` + `GetPolicy`) instead of assuming, and treat `UnauthorizedOperation` as \"this identity lacks this action\", never as a broken setup.\n- On `UnauthorizedOperation` / `AuthFailure`, hand the user a **one-click CAM grant link** (role name + policy name + `principal`) instead of telling them to go find the policy in the console, then retry the original call. Role targets, the `principal` values, and which preset policy covers what: `./references/calling-methods.md` §3.\n\n**Done when**: the credential identity is known, and every permission error has been converted into a clickable authorization link carrying a concrete policy name before any retry.\n\n### 4. Follow a proven recipe when one exists\n\nRecipes encode the exact call sequence, required parameters, and empirically discovered pitfalls so the flow works on the first pass. One scenario per file — start from the index `./references/recipes/README.md`, whose 状态 column records how far each recipe has been verified:\n\n- **PostgreSQL storage-usage alarm**: `./references/recipes/pg-storage-alarm.md`\n- **ICP filing readiness and wait-time checks**: `./references/recipes/icp-filing-readiness.md`\n- **PostgreSQL instance spec change and shared-to-dedicated upgrade**: `./references/recipes/pg-instance-spec.md`\n- **Custom domain onboarding for an env (HTTP access domain, certificate, DNS binding)**: `./references/recipes/custom-domain.md`\n\n**Done when**: every parameter value in the call sequence traces to a recipe value marked as verified (实测) or to official docs.\n\n## Constraints\n\n- Region is a top-level `region` argument (X-TC-Region), never a body param. Some APIs additionally take a short region code inside `Dimensions` (e.g. `sh` vs `ap-shanghai`) — these are different fields.\n- Route SDK-language details to official SDK docs or sdkHints; keep this skill SDK-language-agnostic.\n\nFile v1.92.120:references/cloud-functions/SKILL.md\n\n---\nname: cloud-functions\ndescription: CloudBase function runtime guide for building, deploying, and debugging your own Event Functions or HTTP Functions. This skill should be used when users need application runtime code on CloudBase, not when they are merely calling CloudBase official platform APIs.\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n**Cross-cutting protocols** (required before code changes or deployments):\n- Change Safety Protocol: `../cloudbase-platform/references/protocols/change-safety-protocol.md`\n- Deployment Gate: `../cloudbase-platform/references/protocols/deployment-gate.md`\n- Sensitive Runtime Data Protection: `../cloudbase-platform/references/protocols/sensitive-runtime-data-protection.md`\n\n# Cloud Functions Development\n\n## Activation Contract\n\n### Use this first when\n\n- The task is to create, update, deploy, inspect, or debug a CloudBase Event Function or HTTP Function that serves application runtime logic.\n- The request mentions function runtime, function logs, `scf_bootstrap`, function triggers, or function gateway exposure.\n\n### Read before writing code if\n\n- You still need to decide between Event Function and HTTP Function.\n- The task mentions `manageFunctions`, `queryFunctions`, `manageGateway`, or legacy function-tool names.\n- The task might require `callCloudApi` as a fallback for logs or gateway setup.\n- An HTTP Function will call CloudBase resources through `@cloudbase/node-sdk` or `@cloudbase/manager-node` -> read `./references/http-function-credentials.md`. HTTP Functions must use explicit credentials; do not rely on the Event Function passwordless runtime path.\n\n### Exception only (do not read by default)\n\n- Migrating an **existing** app that already uses classic TCP DB clients (`DATABASE_URL` / Prisma / `mysql2` / `pg` / Redis) → read `./references/vpc-and-tcp-database.md` via `./references.md`. New business CRUD must prefer CloudBase native SDK (`app.database()` / `app.rdb()`) or MCP SQL tools instead of TCP.\n\n### Then also read\n\n- Detailed reference routing -> `./references.md`\n- Auth setup or provider-related backend work -> `../auth-tool-cloudbase/SKILL.md`\n- CloudBase Integration Center generated WeChat Pay or Official Account functions -> `../cloudbase-wechat-integration/SKILL.md` (official docs: `https://docs.cloudbase.net/integration/introduce.md`)\n- AI in functions -> `../ai-model-nodejs/SKILL.md`\n- Long-lived container services or Agent runtimes -> `../cloudrun-development/SKILL.md`\n- Calling CloudBase official platform APIs from a client or script -> `../http-api-cloudbase/SKILL.md`\n\n### Do NOT use for\n\n- CloudRun container services.\n- Web authentication UI implementation.\n- Database-schema design or general data-model work.\n- CloudBase official platform API clients or raw HTTP integrations that only consume platform endpoints.\n- Creating Integration Center instances through guessed APIs. For WeChat Pay or Official Account generated functions, use `cloudbase-wechat-integration` for the business contract and this skill only for function operations.\n- **Tasks that the CloudBase JS SDK can handle directly** — simple data reads/writes, leaderboards, file uploads, real-time queries. Reach for the matching SDK surface before writing a function: `db.collection(...).get/add/update` only for confirmed NoSQL collections, and `app.rdb().from(...)` for CloudBase PG tables. Functions add deployment complexity, CORS configuration, and HTTP gateway binding that the SDK eliminates entirely.\n\n### Common mistakes / gotchas\n\n- Picking the wrong function type and trying to compensate later.\n- Confusing official CloudBase API client work with building your own HTTP function.\n- Mixing Event Function code shape (`exports.main(event, context)`) with HTTP Function code shape (`req` / `res` on port `9000`).\n- Treating HTTP Access as the implementation model for HTTP Functions. HTTP Access is a gateway configuration for Event Functions, not the HTTP Function runtime model.\n- Assuming `db.collection(\"name\").add(...)` will create a missing document-database collection automatically. Collection creation is a separate management step.\n- Forgetting that runtime cannot be changed after creation.\n- Using cloud functions as the first answer for Web login.\n- Forgetting that HTTP Functions must ship `scf_bootstrap`, listen on port `9000`, and include dependencies.\n- Assuming an HTTP Function can use CloudBase SDKs without explicit credentials. The default temporary credential path is not reliable for HTTP Functions and credential rotation can break a running service. Use a CloudBase server API Key or Tencent Cloud key pair for `@cloudbase/node-sdk`; use a Tencent Cloud key pair for `@cloudbase/manager-node`. See `references/http-function-credentials.md`.\n- Forgetting to configure function security rules after creating an HTTP Function. Default rules reject anonymous callers with `EXCEED_AUTHORITY`. Note: anonymous login is disabled by default for new environments — if the function needs public access without authentication, configure the security rule to allow all callers rather than relying on anonymous login.\n- Mismatching the `scf_bootstrap` Node.js binary path with the function runtime (e.g. using `/var/lang/node18/bin/node` but setting `runtime: \"Nodejs16.13\"`).\n- For Custom Image HTTP Functions: forgetting that TCR, the CloudApp build, and SCF must be in the same region; using `:latest` instead of a unique tag; or confusing the request-driven port-`9000` image model with a long-lived CloudRun container that listens on the injected `PORT`.\n- Assuming MCP covers the whole image pipeline. `manageFunctions` covers SCF image deploy (Stage B) via `runtime: \"CustomImage\"` + `imageConfig`, but the CloudApp custom build → TCR push (Stage A) is a raw Tencent Cloud API path — confirm action names and parameters from official docs before any `callCloudApi` fallback.\n- Making code or configuration changes without first following the Change Safety Protocol (`cloudbase-platform/references/protocols/change-safety-protocol.md`).\n- Exposing functions publicly or deploying without first completing the checks in `cloudbase-platform/references/protocols/deployment-gate.md`.\n- **Returning `req.headers`, `process.env`, `event`, or `context` wholesale** — gateways may inject `x-cloudbase-context` (base64 temporary credentials). Never echo that header or dump credential env vars to clients. Follow `../cloudbase-platform/references/protocols/sensitive-runtime-data-protection.md`.\n- **Using a bare layer name (e.g. `common`) across environments.** SCF LayerName is an account-scoped shared namespace: same name → shared version sequence. Create new layers with fixed format `{layerName}_{当前envId}` (e.g. `common_cloud1-d9ghadgak3edf6b36`). Pass the full name as `layerName` — do not invent automatic suffixes. Treat MCP layer `warnings` as soft advisories (operation still succeeds). Details: `./references/operations-and-config.md`.\n- **Long-running MCP image deployments must complete the full workflow**: When using `manageFunctions` with `deployFunction` for a real `cloud` or `local` deployment, prefer `wait=false` to avoid blocking a single Tool Call for an extended period. If the tool returns a `taskId`, do not end the workflow, report success, or ask the user to wait while the status is `running`. Automatically call `queryFunctions(action=\"getFunctionDeployStatus\", taskId=\"...\")` and continue polling according to the reported progress until the status becomes `succeeded` or `failed`. Only after reaching a reasonable polling limit may you report that the deployment is still in progress; include the `taskId`, current stage, and latest progress. On success, report the image URI or build ID, function status, and Gateway URL. On failure, report the failed stage, error code, request ID, and diagnostic guidance. If the status is `expired`, explain that the local task record exceeded its retention window; the cloud deployment may still be running, so call `getFunctionDetail` to confirm the actual cloud-side status instead of treating it as a failure.\n\n### Minimal checklist\n\n- Read [Cloud Functions Execution Checklist](checklist.md) before deployment or runtime changes.\n- Decide whether the task is Event Function, HTTP Function, or actually CloudRun.\n- Pick the detailed reference file in [references.md](references.md) before writing implementation code.\n\n## MCP image deployment with polling\n\nFor real `cloud` or `local` custom-image deployments, prefer:\n\n```json\n{\n  \"action\": \"deployFunction\",\n  \"dryRun\": false,\n  \"confirm\": true,\n  \"wait\": false,\n  \"deployConfig\": {}\n}\n```\n\nThe `wait` field controls whether the current MCP Tool call waits for the complete deployment:\n\n- `wait=true`: wait for the manager deployment to reach a terminal result and return it.\n- `wait=false`: return a `taskId` promptly while the deployment continues in the MCP background.\n\nWhen `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action=\"getFunctionDeployStatus\"` and that `taskId`; continue while the status is `running`, then stop only at `succeeded` or `failed`. Wait about 5 seconds before the first follow-up query and use the returned progress/`nextActions` to continue without aggressive polling. Do not tell the user to ask again or imply success before a terminal status is returned. An `expired` status means the task exceeded the maximum retention window and was force-terminated locally — the cloud deployment may still be in progress, so confirm the real state with `getFunctionDetail` instead of reporting failure.\n\nIf a reasonable polling limit is reached, report only that the task is still running, including the `taskId`, current status, current stage, and latest progress. For a terminal result, report the deployment strategy, action, image URI/digest, build ID, function status, Gateway URL, or the failed stage, error code, request ID, and diagnostic next step.\n\n### Personal-tier TCR credentials — never put the password in tool arguments\n\nPersonal-tier image builds (`imageConfig.imageType=\"personal\"` with `local` / `cloud`) need a TCR push credential. Read it from the MCP process environment, not from tool arguments:\n\n- Leave `func.imageConfig.build.registryCredential` **out of the request** when `TCB_TCR_USERNAME` and `TCB_TCR_PASSWORD` are set in the MCP server `env` block — the MCP fills them in automatically, the same way `TENCENTCLOUD_SECRETID` works.\n- **Never ask the user to paste the password into chat, and never write it into tool arguments.** Anything placed in arguments enters the model context and the tool-call history.\n- If deployment fails with `CLOUD_REGISTRY_CREDENTIAL_MISSING` or `CLOUD_REGISTRY_CREDENTIAL_INVALID`, instruct the user to add these two variables to the `env` block of their MCP configuration and restart the MCP server. Do not work around it by passing the credential inline.\n- The username is the Tencent Cloud account UIN and is not itself a secret; it may be passed explicitly if needed. Explicit arguments take precedence per field, so username-in-argument plus password-from-environment is a valid combination.\n\n**Know when that environment channel does not exist.** It works only for a local stdio MCP server whose client configuration exposes a custom `env` block. Some GUI clients do not inherit shell exports, and IDE-embedded MCP servers usually inject credentials from a hard-coded allowlist (often only `TENCENTCLOUD_*`), leaving the user no way to set arbitrary variables. Telling those users to \"set it in the MCP `env` block\" is an instruction they cannot act on. Route them to an enterprise registry (`imageType=\"enterprise\"`, which mints a short-lived TCR token instead of using a fixed password) or to `buildStrategy=\"image\"` with an already-pushed image.\n\n### Enterprise-tier builds require a login state with CAM permission\n\n`cloud` / `local` builds against an enterprise registry mint a TCR token through CAM (as does `autoGrant`). Environment-level API Keys and OAuth-issued STS credentials carry no CAM policy, so those calls fail with `UnauthorizedOperation`. The MCP probes the login state before starting a real enterprise build and refuses up front rather than failing midway;...","readmeExcerpt":"Skill: 腾讯云 CloudBase · Tencent CloudBase Owner: binggg Summary: Use this skill when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android, Flutter, React Native). Covers UI (页面, 界面, 表单, dashboard, prototype, 原型); auth (登录, 注册, OAuth, publishable key); databases (NoSQL 文档数据库, MySQL 关系型数据库, PostgreSQL/CloudBase PG","codeSnippets":[],"executableExamples":[{"language":"js","snippet":"const model = ai.createModel(\"cloudbase\");          // ← GroupName\nawait model.generateText({\n  model: \"deepseek-v4-flash\",                       // ← concrete model id\n  messages: [...]\n});"},{"language":"text","snippet":"callCloudApi(service=\"tcb\", action=\"DescribeEnvPostpayPackage\", params={ EnvId })"},{"language":"text","snippet":"callCloudApi(service=\"tcb\", action=\"DescribeAIModels\", params={ EnvId })"},{"language":"text","snippet":"callCloudApi(service=\"tcb\", action=\"DescribeManagedAIModelList\", params={ EnvId })"},{"language":"text","snippet":"callCloudApi(service=\"tcb\", action=\"UpdateAIModel\", params={\n     EnvId,\n     GroupName: \"cloudbase\",\n     Models: [\n       // resend every model that DescribeAIModels already showed as enabled\n       { Model: \"<already-enabled model>\" },\n       // append the newly-requested one, using the exact spelling from DescribeManagedAIModelList\n       { Model: \"<target model>\" }\n     ],\n     Status: 1\n   })"},{"language":"bash","snippet":"npm install @cloudbase/node-sdk"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"references/ai-model-nodejs/SKILL.md","content":"---\nname: ai-model-nodejs\ndescription: \"Use this skill for Node.js backend AI via @cloudbase/node-sdk (>=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration. The only SDK supporting image generation (ai.createImageModel + generateImage). Text via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*; model ids (e.g. deepseek-v4-flash, glm-5, kimi-k2.6) go in the `model` field of generateText/streamText. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web) or Mini Program (use ai-model-wechat).\"\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## When to use this skill\n\nUse this skill for **calling AI models from Node.js backends, cloud functions, or CloudRun services** via `@cloudbase/node-sdk`.\n\n> 🧭 **Runtime-plane fit.** This is the right skill when the AI call truly belongs on the server: image generation (the only SDK that supports it), long-running agent jobs, orchestration across multiple tools, scheduled tasks, or flows that must keep secrets server-side. **If the user is building a Web page / frontend AI chat UI, do NOT wrap this SDK behind a backend proxy** — route to `ai-model-web` and call the model directly from the browser. For WeChat Mini Programs use `ai-model-wechat`. Routing is decided by runtime plane first; the concrete model (`deepseek-*`, `glm-*`, `hunyuan-*`, `kimi-*`, …) only affects the `model` field.\n\n**Use it when you need to:**\n\n- Integrate AI text generation into a backend service\n- Generate images with the Hunyuan Image model\n- Call AI models from CloudBase cloud functions or CloudRun\n- Do server-side AI processing (agent orchestration, batch jobs, scheduled tasks)\n\n**Do NOT use for:**\n\n- Browser/Web apps → use the `ai-model-web` skill\n- WeChat Mini Program → use the `ai-model-wechat` skill\n- Runtimes without a CloudBase SDK (Python, Go, PHP, curl, etc.) → use the `http-api-cloudbase` skill (it now includes the `ai_model` OpenAPI spec for direct HTTP calls to the AI model endpoint; do NOT wrap this SDK behind an HTTP proxy)\n\n---\n\n## ⛔ STOP — `ai.createModel(...)` argument is **not** a vendor / model name\n\nRead this before writing any `createModel(...)` line. Agents frequently hallucinate this argument. There are **exactly three** legal shapes. Anything else is a bug.\n\n| ✅ Legal `ai.createModel(...)` argument | When to use it |\n|----------------------------------------|----------------|\n| `\"cloudbase\"` | **The main managed group for server-side projects** (TokenHub-backed, multi-vendor pool). Vendor + concrete model go into the **`model` field*"},{"path":"references/ai-model-web/SKILL.md","content":"---\nname: ai-model-web\ndescription: \"Use this skill when a browser/Web app (React, Vue, Next, Nuxt, static sites, SPAs, dashboards, AI chat UI, 页面, 前端, 网页) needs AI models via @cloudbase/js-sdk. Default routing for Web/frontend AI — call directly from the browser, do NOT propose a Node.js proxy. Covers generateText and streamText; models via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*, model id in the `model` field. MUST run two-step preflight before code — see body. NOT for Node.js backend (use ai-model-nodejs), Mini Program (use ai-model-wechat), or image generation (Node SDK only).\"\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## When to use this skill\n\nUse this skill for **calling AI models in browser/Web applications** via `@cloudbase/js-sdk`.\n\n> 🧭 **Runtime-plane default for Web.** Any time the user's request is framed around a page, a Web app, the frontend, React/Vue/Next/Nuxt, a dashboard UI, or \"add AI to my H5\", this skill is the default routing target. **Do NOT first propose a Node.js / cloud-function / CloudRun proxy**; `@cloudbase/js-sdk` can call the model from the browser directly. Only switch to `ai-model-nodejs` if the user explicitly asks for a backend/server call, image generation, or a scenario that truly needs server-side keys or long-running work. This decision is independent of which concrete model the user picks — model names (`deepseek-*`, `glm-*`, `hunyuan-*`, `kimi-*`, …) only affect the `model` field, not the routing plane.\n\n**Use it when you need to:**\n\n- Integrate AI text generation into a frontend Web app\n- Stream AI responses for a better UX\n- Call Hunyuan / DeepSeek / GLM / Kimi / MiniMax models from the browser\n\n**Do NOT use for:**\n\n- Node.js backend or cloud functions → use the `ai-model-nodejs` skill\n- WeChat Mini Program → use the `ai-model-wechat` skill\n- Image generation → use the `ai-model-nodejs` skill (Node SDK only)\n- Runtimes without a CloudBase SDK (native apps, Python, Go, etc.) → use the `http-api-cloudbase` skill (it now includes the `ai_model` OpenAPI spec for direct HTTP calls; do NOT build a custom HTTP proxy)\n\n---\n\n## ⛔ STOP — `ai.createModel(...)` argument is **not** a vendor / model name\n\nRead this before writing any `createModel(...)` line. The single most common mistake when agents generate code for this SDK is hallucinating the argument. There are **exactly three** legal shapes. Anything else is a bug.\n\n| ✅ Legal `ai.createModel(...)` argument | When to use it |\n|----------------------------------------|----------------|\n| `\"cloudbase\"` | **The main managed group for new projects** (TokenHub-backed, multi-ven"},{"path":"references/ai-model-wechat/SKILL.md","content":"---\nname: ai-model-wechat\ndescription: \"Use this skill for WeChat Mini Program AI via wx.cloud.extend.AI (小程序, wx.cloud apps). Covers generateText and streamText with callbacks (onText, onEvent, onFinish); streamText needs a data wrapper, generateText returns the raw response. Models via wx.cloud.extend.AI.createModel with groups hunyuan-exp (小程序成长计划), cloudbase (main managed), or custom-*; model id goes in the data wrapper `model` field. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web), Node.js backend (use ai-model-nodejs), or image generation (use ai-model-nodejs).\"\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## When to use this skill\n\nUse this skill for **calling AI models in WeChat Mini Program** using `wx.cloud.extend.AI`.\n\n**Use it when you need to:**\n\n- Integrate AI text generation in a Mini Program\n- Stream AI responses with callback support\n- Call Hunyuan models from the WeChat environment\n\n**Do NOT use for:**\n\n- Browser/Web apps → use `ai-model-web` skill\n- Node.js backend or cloud functions → use `ai-model-nodejs` skill\n- Image generation → use `ai-model-nodejs` skill (not available in Mini Program)\n- Runtimes without a CloudBase SDK (native apps, Python, etc.) → use `http-api-cloudbase` skill (it now includes the `ai_model` OpenAPI spec for direct HTTP calls)\n\n---\n\n## ⛔ STOP — `wx.cloud.extend.AI.createModel(provider)` argument is **not** a vendor / model name\n\nRead this before writing any `createModel(...)` line. Agents frequently hallucinate this argument. There are **exactly three** legal shapes. Anything else is a bug.\n\n| ✅ Legal `createModel(provider)` argument | When to use it |\n|-----------------------------------------|----------------|\n| `\"hunyuan-exp\"` | The Mini Program **成长计划** (`ai_miniprogram_inspire_plan`) is enrolled for the current env. Default model: `hunyuan-2.0-instruct-20251111`. |\n| `\"cloudbase\"` | Default fallback. Main managed group (TokenHub-backed, multi-vendor pool). Vendor + concrete model go into the **`model` field**, e.g. `{ model: \"deepseek-v4-flash\" }`. |\n| `\"custom-<your-name>\"` | A user-defined GroupName you onboarded via `CreateAIModel`. **Must** start with `custom-` (e.g. `custom-kimi`, `custom-openai-compat`). |\n\n### ❌ Do NOT write any of these — they are all wrong\n\n```js\nwx.cloud.extend.AI.createModel(\"deepseek\")                   // wrong — vendor, not GroupName\nwx.cloud.extend.AI.createModel(\"deepseek-v4-flash\")          // wrong — model id goes in `model`\nwx.cloud.extend.AI.createModel(\"hunyuan\")                    // wrong — vendor family\nwx.cloud.extend.AI.createModel(\"hunyuan-2.0-instr"},{"path":"references/auth-nodejs-cloudbase/SKILL.md","content":"---\nname: auth-nodejs-cloudbase\ndescription: CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase; not when configuring providers or building client login UI.\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## Activation Contract\n\n### Use this first when\n\n- Node.js code in cloud functions or backend services must read caller identity, look up users, or issue custom login tickets.\n- The backend responsibility is auth / identity, not provider setup or frontend login UI.\n\n### Read before writing code if\n\n- The task mentions `@cloudbase/node-sdk`, server-side auth, custom login tickets, or \"who is calling\".\n- The request mixes frontend login with backend identity logic; split the flow and route client-side work elsewhere.\n\n### Then also read\n\n- Provider setup / publishable key -> `../auth-tool-cloudbase/SKILL.md`\n- Web login UI that consumes custom tickets -> `../auth-web-cloudbase/SKILL.md`\n- Raw HTTP auth client -> `../http-api-cloudbase/SKILL.md`\n\n### Do NOT use for\n\n- Provider enable/disable or login console configuration.\n- Frontend login / sign-up UI.\n- Mini program native auth.\n\n### Common mistakes / gotchas\n\n- Using this skill as the entry point for every auth request.\n- Mixing provider-management work with Node-side identity code.\n- Reaching for raw HTTP examples when Node SDK already covers the job.\n\n## When to use this skill\n\nUse this skill whenever the task involves **server-side authentication or identity** in a CloudBase project, and the code is running in **Node.js**, for example:\n\n- CloudBase 云函数 (Node runtime) that needs to know **who is calling**\n- Node services that use **CloudBase Node SDK** to look up user information\n- Backends that issue **custom login tickets** for Web / mobile clients\n- Admin or ops tools that need to inspect CloudBase end-user profiles\n\n**Do NOT use this skill for:**\n\n- Frontend Web login / sign-up flows using `@cloudbase/js-sdk` (handle those with the **auth-web** skill, not this Node skill).\n- Direct HTTP auth API integrations (this skill does not describe raw HTTP endpoints; use the **http-api** skill instead).\n- Database or storage operations that do not involve identity (use database/storage docs or skills).\n\nWhen the user request mixes frontend and backend concerns (e.g. \"build a web login page and a Node API that knows the user\"), treat them separately:\n\n- Use Web-side auth docs/skills for client login and UX.\n- Use this Node Auth skill for how the backend sees and"},{"path":"references/auth-tool-cloudbase/SKILL.md","content":"---\nname: auth-tool-cloudbase\ndescription: CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.\nversion: 2.34.8\nalwaysApply: false\n---\n\n## Sibling skills (local only)\n\nSibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.\n\nIf a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.\n\n## Activation Contract\n\n### Use this first when\n\n- The task is to inspect, enable, disable, or configure CloudBase auth providers, login methods, publishable key prerequisites, SMS/email delivery, or third-party login readiness.\n- An auth implementation cannot proceed until provider status and login configuration are confirmed.\n- A CloudBase Web auth flow needs provider verification before `auth-web-cloudbase`.\n\n### Read before writing code if\n\n- The request mentions provider setup, auth console configuration, publishable key retrieval, login method availability, SMS/email sender setup, or third-party provider credentials.\n- The task mixes provider configuration with Web, mini program, Node, or raw HTTP auth implementation.\n\n### Then also read\n\n- Web auth UI -> `../auth-web-cloudbase/SKILL.md`\n- Mini program native auth -> `../auth-wechat-miniprogram/SKILL.md`\n- Node server-side identity / custom ticket -> `../auth-nodejs-cloudbase/SKILL.md`\n- Native App / raw HTTP auth client -> `../http-api-cloudbase/SKILL.md`\n\n### Do NOT use this as\n\n- The default implementation guide for every login or registration request.\n- A replacement for mini program native auth behavior when no provider change is involved.\n- A replacement for Node-side caller identity, user lookup, or custom login ticket flows.\n- A replacement for frontend integration, session handling, or client UX implementation.\n\n### Common mistakes / gotchas\n\n- Writing login UI before enabling the required provider.\n- Treating any mention of \"auth\" as a provider-management task.\n- Implementing Web login in cloud functions.\n- Routing native App auth to Web SDK flows.\n- Making configuration or code changes without first following the Change Safety Protocol (`cloudbase-platform/references/protocols/change-safety-protocol.md`).\n- In an existing application, looping on provider queries after readiness is already known instead of wiring the active login and register handlers.\n\n### Minimal checklist\n\n- Read [Authentication Activation Checklist](checklist.md) before auth implementation.\n- Anonymous login is disabled by default. Publishable `accessKey` alone does **not** create a gateway-authenticated anonymous session. With `@cloudbase/js-sdk` *"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":3069,"uniquenessScore":29,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T02:34:32.561Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T02:34:32.561Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:51:34.432Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}