tencentcloudbase/cloudbase-ai-toolkit-cloudbase-platform
CloudBase platform overview and routing guide. This skill should be used when users need high-level capability selection, platform concepts, console navigation, or cross-platform best practices before choosing a more specific implementation skill.
This is a copy. The original lives at tencentcloudbase/cloudbase-platform.
npx skills add https://github.com/TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform
If this environment only installed the current skill, start from the CloudBase main entry and use the published cloudbase/references/... paths for sibling skills.
https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/SKILL.mdhttps://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloudbase-platform/SKILL.mdKeep local references/... paths for files that ship with the current skill directory. When this file points to a sibling skill such as auth-tool-cloudbase or web-development, use the standalone fallback URL shown next to that reference.
Cross-cutting protocols (always load these when doing code changes or deployments in standalone mode):
https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloudbase-platform/references/protocols/change-safety-protocol.mdhttps://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloudbase-platform/references/protocols/deployment-gate.md../web-development/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/web-development/SKILL.md)../auth-tool-cloudbase/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/auth-tool-cloudbase/SKILL.md), ../auth-web-cloudbase/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/auth-web-cloudbase/SKILL.md)../miniprogram-development/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/miniprogram-development/SKILL.md)../cloudbase-wechat-integration/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloudbase-wechat-integration/SKILL.md; official docs: https://docs.cloudbase.net/integration/introduce/index.md)../cloud-functions/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloud-functions/SKILL.md)../http-api-cloudbase/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/http-api-cloudbase/SKILL.md)../cloudbase-document-database-web-sdk/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloudbase-document-database-web-sdk/SKILL.md) or ../cloudbase-document-database-in-wechat-miniprogram/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloudbase-document-database-in-wechat-miniprogram/SKILL.md)../postgresql-development-cloudbase/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/postgresql-development-cloudbase/SKILL.md)../relational-database-mcp-cloudbase/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/relational-database-mcp-cloudbase/SKILL.md) or ../data-model-creation/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/data-model-creation/SKILL.md)../cloud-storage-web/SKILL.md (standalone fallback: https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/cloudbase/references/cloud-storage-web/SKILL.md)cloudbase-platform/references/protocols/change-safety-protocol.md).cloudbase-platform/references/protocols/deployment-gate.md.envDomainManagement (action: create/delete) = Security domains (安全域名) for CORS/request source validation - used for browser upload whitelisting. Does NOT accept certificateId.manageGateway(action="bindCustomDomain") = Bind a new custom domain (自定义域名) for public HTTPS — requires domain + certificateId. If queryGateway(action="listCustomDomains") already returns a usable custom domain, prefer manageGateway(action="createRoute", domain="<existing-domain>") instead; routing does not need certificateId.Use this skill for CloudBase platform knowledge when you need to:
This skill provides foundational knowledge that applies to all CloudBase projects, regardless of whether they are Web, Mini Program, or backend services.
postgresql-development-cloudbase; do not reuse NoSQL app.database() / db.collection(...) snippets or MySQL queryMysqlDatabase / manageMysqlDatabase for PG data pathsenvQuery tool to get environment IDsrc/lib/backend.*, src/lib/auth.*, src/lib/*service.*, and bound page handlers before broad concept reading.cloudbase guidelinecloudbase guideline firstauth, while application-side auth configuration uses queryAppAuth / manageAppAuthWhen working with domain-related tasks, use the correct tool based on the requirement:
| Requirement | Tool | Parameters | Purpose |
|-------------|------|------------|---------|
| Security Domain (安全域名) | envDomainManagement | action, domains (array of host:port strings) | CORS/request source validation for browser uploads. No certificate involved. |
| Reuse existing Custom Domain | queryGateway(listCustomDomains) → manageGateway(createRoute) | domain = existing custom domain; route fields | Expose a service/path on an already-bound custom domain. No certificateId. Prefer this when a custom domain already exists. |
| Bind new Custom Domain (自定义域名) | manageGateway(action="bindCustomDomain") | domain (string), certificateId (string) | First-time bind of a new public HTTPS domain. Requires certId from SSL console. |
| Delete Custom Domain | manageGateway(action="deleteCustomDomain") | domain (string) | Remove custom domain binding (only after routes on that domain are deleted). |
Key indicators for choosing the right tool:
listCustomDomains then createRoute(domain=...) (no certificateId)manageGateway(action="bindCustomDomain")envDomainManagementcreateRoute when possible; only bindCustomDomain for first-time domain bindWhen a task explicitly requires recording operation steps or results to a file (e.g., RESULT.json):
Example structure for operation recording:
{
"steps": [
{"action": "listDomains", "success": true, "message": "Found 3 domains"},
{"action": "bindDomain", "success": false, "message": "Certificate not found"}
],
"summary": {
"totalAttempted": 2,
"succeeded": 1,
"failed": 1
}
}
manageStorage / queryStorage), not manageHosting(action="upload")queryHosting(action="websiteConfig")/manageStorage(action=upload) and queryStorage(action=url) return temporaryUrl which is a temporary signed URL that expires (default 1 hour). Do NOT use this as a permanent public URL.envQuery(action=info) to get environment detailsEnvInfo.Storages[0].CdnDomain (e.g., your-env-id.tcb.qcloud.la)https://{CdnDomain}/{cloudPath}CdnDomain is env-xxx.tcb.qcloud.la and cloudPath is uploads/avatar.jpg, the public URL is https://env-xxx.tcb.qcloud.la/uploads/avatar.jpgPRIVATE which requires signed URLs)envQuery toolenvQuery(action="list", alias=..., aliasExact=true) first and use the returned full EnvIdauth.set_env, console URLs, or generated config filesimport cloudbase from "@cloudbase/js-sdk"; const app = cloudbase.init({ env: "your-full-env-id" });import("@cloudbase/js-sdk") or async wrappers such as initCloudBase() with internal initPromiseThe manageEnv tool provides full lifecycle management for CloudBase environments.
| Action | Description | Key Parameters |
|--------|-------------|----------------|
| listPackages | Query available plans | (none) |
| create | Create new environment (needs confirm) | alias, packageId, resources, duration |
| modifyPlan | Change plan (upgrade/downgrade, needs confirm) | envId, packageId |
| renew | Renew environment (needs confirm) | envId, duration |
Creating an environment with specific resources:
manageEnv(action="create", alias="my-env", packageId="baas_personal",
resources=["flexdb","storage","function","postgresql"], confirm="yes")
resources (optional, create only): controls which CloudBase capabilities to enable:flexdb — Document database (NoSQL)storage — Cloud Storagefunction — Cloud Functionspostgresql — PostgreSQL relational database (PG mode)Resources to CreateEnv.region: CreateEnv does not accept Region; environment region is determined by account/package.confirm="yes".Querying available packages before creating:
manageEnv(action="listPackages")
Changing plan (e.g. personal → standard):
manageEnv(action="modifyPlan", envId="your-env-id", packageId="baas_pf_standard", confirm="yes")
Renewing an environment:
manageEnv(action="renew", envId="your-env-id", duration=1, confirm="yes")
Important: Authentication methods for different platforms are completely different, must strictly distinguish!
auth.getVerification(), for detailed, refer to web auth related docsauth.getSession() and require data.session; do not use deprecated getLoginState() or auth.getUser() / auth.getCurrentUser() as proof of real login.queryAppAuth / manageAppAuth, not the MCP auth toolaccessKey automatically creates an anonymous session. If the app uses AuthGuard or RLS for access control, ensure is_anonymous checks are in place when anonymous access is allowed.auth.uid(), NOT current_user. When writing RLS policies for CloudBase PostgreSQL, the user identity must use auth.uid() (returns the JWT sub / actual user ID). Do NOT use current_user or current_setting(...) — these PostgreSQL built-in functions return the database role name (e.g. authenticated), not the CloudBase auth user ID. CloudBase PG provides four auth helper functions: auth.uid(), auth.role(), auth.email(), auth.jwt(). Verify availability with SELECT proname FROM pg_proc WHERE pronamespace = 'auth'::regnamespace.wxContext.OPENID via wx-server-sdkpackage.json, declaring required dependenciesmanageFunctions(action="createFunction") to create functionsmanageFunctions(action="updateFunctionCode") to deploy cloud functionsfunctionRootPath refers to the parent directory of function directories, e.g., cloudfunctions directory⚠️ CRITICAL: Always configure permissions BEFORE writing database operation code!
ADMINWRITE or ADMINONLY for write operations Create collection → Configure security rules → Write code → Test
managePermissions(action="updateResourcePermission") to configure resource permissionsno-sql-web-sdk/security-rules.md for detailed resourceType="noSqlDatabase" examples only; do not treat doc._openid, auth.openid, query-subset validation, or create / update / delete JSON templates as generic rules for functions, storage, or SQL tableshttps://cloud.tencent.com/document/product/876/41802https://docs.cloudbase.net/database/security-ruleshttps://docs.cloudbase.net/cloud-function/security-ruleshttps://docs.cloudbase.net/storage/security-rulesCompatibility note:
permissionssecurity-rule, security-rules, secret-rule, secret-rules, and access-control still resolve to the permissions pluginreadSecurityRule / writeSecurityRule are removed; prefer queryPermissions / managePermissionsREADONLY (admin manages via cloud functions)CUSTOM with auth.uid check (users manage their own)CUSTOM with ownership validationPRIVATE or ADMINONLYCloudBase MCP provides role management capabilities through the queryPermissions and managePermissions tools. These are equivalent to the CLI tcb role commands.
⚠️ CRITICAL: Role policies and resource permissions are two independent systems with NO automatic synchronization.
Query Operations (via queryPermissions):
| Action | Description |
|--------|-------------|
| listRoles | List all roles (system and custom) |
| getRole | Get detailed role information by roleId/roleIdentity/roleName |
Management Operations (via managePermissions):
| Action | Description |
|--------|-------------|
| createRole | Create a new custom role |
| updateRole | Update an existing role (add/remove policies or members) |
| deleteRoles | Delete one or more custom roles |
| addRoleMembers | Add members to a role |
| removeRoleMembers | Remove members from a role |
| addRolePolicies | Add policies to a role |
| removeRolePolicies | Remove policies from a role |
List all roles:
queryPermissions(action="listRoles")
Get specific role details:
queryPermissions(action="getRole", roleId="role-xxx")
# or by identity
queryPermissions(action="getRole", roleIdentity="dev_role")
# or by name
queryPermissions(action="getRole", roleName="Developer")
Delete a custom role:
managePermissions(action="deleteRoles", roleIds=["role-xxx"])
Create a custom role:
managePermissions(action="createRole", roleName="Developer", roleIdentity="developer", policies=["FunctionsAccess"], memberUids=["user-uid-1"])
Update a role (add policies):
managePermissions(action="updateRole", roleId="role-xxx", addPolicies=["StoragesAccess"])
> ⚠️ Note: Only custom roles can be deleted. System roles are read-only.
See also: CLI equivalent commands in cloudbase-cli/references/permission.md
@cloudbase/wx-cloud-client-sdk, initialize const client = initHTTPOverCallFunction(wx.cloud), use client.models@cloudbase/[email protected]+, initialize const app = cloudbase.init({env}), use app.models@cloudbase/js-sdk, initialize const app = cloudbase.init({env}), after login use app.modelsmanageDataModel tool to:db.collection('model_name').get()app.models.model_name.list({ filter: { where: {} } })manageDataModel tool's docs method to get specific SDK usageAfter creating/deploying resources, provide corresponding console management page links. All console URLs follow the pattern: https://tcb.cloud.tencent.com/dev?envId=${envId}#/{path}.
The CloudBase console is updated frequently. If a live, logged-in console shows a different hash path from this document, prefer the live console path over stale documentation and then update this skill to match.
https://tcb.cloud.tencent.com/dev?envId=${envId}#/overviewhttps://tcb.cloud.tencent.com/dev?envId=${envId}#/cloud-template/markethttps://tcb.cloud.tencent.com/dev?envId=${envId}#/db/dochttps://tcb.cloud.tencent.com/dev?envId=${envId}#/db/doc/collection/${collectionName}https://tcb.cloud.tencent.com/dev?envId=${envId}#/db/doc/model/${modelName}https://tcb.cloud.tencent.com/dev?envId=${envId}#/db/mysqlhttps://tcb.cloud.tencent.com/dev?envId=${envId}#/db/mysql/table/default/https://tcb.cloud.tencent.com/dev?envId=${envId}#/scfhttps://tcb.cloud.tencent.com/dev?envId=${envId}#/scfhttps://tcb.cloud.tencent.com/dev?envId=${envId}#/scf/detail?id=${functionName}&NameSpace=${envId}https://tcb.cloud.tencent.com/dev?envId=${envId}#/platform-runhttps://tcb.cloud.tencent.com/dev?envId=${envId}#/storagehttps://tcb.cloud.tencent.com/dev?envId=${envId}#/aihttps://tcb.cloud.tencent.com/dev?envId=${envId}#/static-hostinghttps://console.cloud.tencent.com/tcb/hosting10. Identity Authentication (身份认证): https://tcb.cloud.tencent.com/dev?envId=${envId}#/identity
https://tcb.cloud.tencent.com/dev?envId=${envId}#/identity/login-managehttps://tcb.cloud.tencent.com/dev?envId=${envId}#/identity/token-management11. Weida Low-Code (微搭低代码): https://tcb.cloud.tencent.com/dev?envId=${envId}#/lowcode/apps
12. Logs & Monitoring (日志监控): https://tcb.cloud.tencent.com/dev?envId=${envId}#/devops/log
13. Environment Settings (环境配置): https://tcb.cloud.tencent.com/dev?envId=${envId}#/env/http-access
https://tcb.cloud.tencent.com/dev?envId=${envId}#/{path}${envId} with the actual environment ID queried via envQuery toolenvQuery(action="list", alias=..., aliasExact=true) and use the returned EnvId; if the alias is ambiguous or missing, ask the user to confirm before generating linksWhen directing users to console pages:
All packaged reference files (required for skill lint reachability):
Take tencentcloudbase/cloudbase-ai-toolkit-cloudbase-platform from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.