
Kaption WhatsApp (Cloud)
io.github.Kaption-AIv1.0.0Updated Oct 5, 2026
Use WhatsApp from AI apps through the Kaption extension. OAuth 2.1 relay that cannot read messages.
Overview
Lets an AI assistant read and manage WhatsApp conversations, contacts, labels, reminders and scheduled messages through a browser extension.
- What it does
- A cloud relay that forwards MCP tool calls to the Kaption browser extension, which runs in a WhatsApp Web tab and does the actual work. Sixteen public tools cover querying conversations, contacts, messages and transcriptions; summarizing conversations; managing WhatsApp Business labels and contact notes; downloading media; archiving, pinning, muting and marking chats read; and managing reminders, scheduled messages, chat lists, contacts, groups, contact exports and activity analytics. The relay itself does not execute the tools and states it cannot read messages.
- When to use it
- Worth adding when an assistant should work with an existing WhatsApp account — searching and summarizing chats, organizing labels and lists, exporting contacts, or scheduling messages — without a local bridge process. The extension must be installed and connected, so it suits users already using Kaption rather than a general-purpose WhatsApp integration.
- Requirements
- A remote endpoint at mcp.kaptionai.com over Streamable HTTP or SSE; no local runtime or package. OAuth 2.1 authorization with a WhatsApp one-time passcode at the authorize step, plus the Kaption browser extension installed and connected in a WhatsApp Web tab. No environment variables or headers are declared for the client.
Installation
In SourceWeft
- Open Kaption WhatsApp (Cloud) in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"mcp-extension-remote": {
"type": "http",
"url": "https://mcp.kaptionai.com/mcp"
}
}
}README
kaption-mcp-remote
Cloud MCP relay for WhatsApp — lets AI assistants (Claude, ChatGPT, Cursor, etc.) interact with your WhatsApp conversations through the Model Context Protocol.
Setup guide: kaptionai.com/mcp — connect WhatsApp to Claude, ChatGPT or Cursor.
Live at: mcp.kaptionai.com (canonical) and mcp-ext.kaptionai.com (backward-compatible alias for existing connections)
The relay cannot read your messages. It forwards MCP tool calls between the AI client and the Kaption browser extension, which processes everything locally in your browser. Its source code is public (BUSL-1.1), so you can verify it yourself.
Architecture
Durable Objects
Request Flow
- AI client discovers the MCP server via
/.well-known/oauth-authorization-server - Client registers dynamically via
POST /register(RFC 7591) - User authenticates with WhatsApp OTP at
/authorize - Client exchanges code for token at
/token - Client sends tool calls via SSE (
/sse) or Streamable HTTP (/mcp) - RelayMCP DO receives the call, routes to RelayRoom for the accountRef
- RelayRoom forwards JSON-RPC to the extension over WebSocket
- Extension executes in WhatsApp Web context, returns result
- Result flows back: RelayRoom → RelayMCP → AI client
Routing Table
MCP Tools
16 public tools are forwarded to the extension (the relay does not execute them):
get_api_info is local-only and is deliberately excluded from the cloud
surface because it returns private REST connection credentials.
Deployment Security
Every deployment is cryptographically signed and recorded in a tamper-evident transparency chain. See SECURITY.md for full details.
Pipeline
Daily heartbeat redeploys (6am UTC) ensure the chain stays active even without code changes.
Deploys are gated — do NOT run wrangler deploy locally
All production deploys go through GitHub Actions. Multiple layers enforce this:
wrangler.jsoncis gitignored;scripts/build-config.mjsrenders it fromwrangler.template.jsoncand refuses to run unlessGITHUB_ACTIONS=true+GITHUB_RUN_IDare set (orKAPTIONAI_LOCAL_DEV=1for dev).npm run predeployaborts unless those same CI env vars are present.mainis branch-protected: requires a reviewed PR + greentest,deploy, andverifychecks.- CODEOWNERS routes every PR through @kshmir.
To ship a change: open a PR → review + CI green → merge to main → Actions builds, signs (Sigstore), deploys, and appends to the transparency chain. npx wrangler deploy from a laptop will fail at step 1 because there is no wrangler.jsonc to deploy.
Verify a Deployment
API Endpoints
Transparency API (public, no auth)
MCP (OAuth-protected)
Development
Project Structure
Environment Variables
Vars (wrangler.jsonc)
Secrets (wrangler secret put)
The three OPENAI_* values are also configured as GitHub Actions repository
secrets. Add all three together, then run the manual Test, Build & Deploy
workflow. CI writes them to an ephemeral mode-0600 file and passes that file
to wrangler deploy --secrets-file, so the review configuration ships in the
same signed, attested Worker version as the code. The workflow fails closed if
only part of the three-value set is present and deletes the temporary file
immediately after deployment. Existing Worker secrets not listed in that file
are preserved.
Related Projects
- Kaption Extension — Chrome/Edge/Firefox browser extension (the other side of the relay)
- @kaptionai/mcp-extension — Local MCP bridge (runs on your machine, no cloud relay)
License
Source: README.md at commit ba9ed57
Tools
0Version history
1- v1.0.0LatestOct 5, 2026
