Kaption WhatsApp (Cloud)

io.github.Kaption-AIv1.0.0更新於 Oct 5, 2026

Use WhatsApp from AI apps through the Kaption extension. OAuth 2.1 relay that cannot read messages.

已驗證Streamable HTTP可網頁執行Productivity & WorkflowCommunication & Collaboration

概覽

AI 產生的概覽

讓 AI 助理透過瀏覽器擴充功能讀取與管理 WhatsApp 對話、聯絡人、標籤、提醒和排程訊息。

功能
這是一個雲端中繼,把 MCP 工具呼叫轉送給 Kaption 瀏覽器擴充功能,由擴充功能在 WhatsApp Web 分頁中實際執行。十六個公開工具涵蓋:查詢對話、聯絡人、訊息與轉錄內容;產生對話摘要;管理 WhatsApp Business 標籤與聯絡人備註;下載媒體;封存、釘選、靜音、標示已讀;以及管理提醒、排程訊息、聊天清單、聯絡人、群組、聯絡人匯出與活動分析。中繼本身不執行這些工具,並聲明無法讀取訊息內容。
適用情境
當助理需要操作既有 WhatsApp 帳號時適合加入,例如搜尋與摘要聊天、整理標籤與清單、匯出聯絡人、安排排程訊息,且不想在本機執行橋接程序。使用前必須安裝並連線該瀏覽器擴充功能,因此較適合已經在使用 Kaption 的使用者,而非通用的 WhatsApp 整合方案。
執行需求
遠端端點 mcp.kaptionai.com,支援 Streamable HTTP 或 SSE,不需要本機執行環境或安裝套件。需要 OAuth 2.1 授權,在授權步驟以 WhatsApp 一次性驗證碼登入,並在 WhatsApp Web 分頁中安裝並連線 Kaption 瀏覽器擴充功能。用戶端未宣告任何環境變數或標頭。
安裝前請注意
授權依賴 WhatsApp 一次性驗證碼,完成該步驟的人即可存取所連線帳號的對話。多個工具會寫入或傳送資料:manage_labels、manage_notes、manage_chat、manage_reminders、manage_scheduled_messages 與 manage_lists 會變更帳號狀態,本機模式下的排程訊息可從使用者自己的號碼發出,包括傳到群組。工具呼叫與結果會先經過第三方雲端中繼,再送達擴充功能。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Kaption WhatsApp (Cloud),將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "mcp-extension-remote": {
      "type": "http",
      "url": "https://mcp.kaptionai.com/mcp"
    }
  }
}

README

kaption-mcp-remote

Cloud MCP relay for WhatsApp — lets AI assistants (Claude, ChatGPT, Cursor, etc.) interact with your WhatsApp conversations through the Model Context Protocol.

Setup guide: kaptionai.com/mcp — connect WhatsApp to Claude, ChatGPT or Cursor.

Live at: mcp.kaptionai.com (canonical) and mcp-ext.kaptionai.com (backward-compatible alias for existing connections)

The relay cannot read your messages. It forwards MCP tool calls between the AI client and the Kaption browser extension, which processes everything locally in your browser. Its source code is public (BUSL-1.1), so you can verify it yourself.

Architecture

AI Client (Claude/ChatGPT/Cursor)    │    │ OAuth 2.1 + SSE/Streamable HTTP    ▼┌─────────────────────────────────────┐│  Cloudflare Worker                  ││  mcp.kaptionai.com                 ││                                     ││  ┌────────────┐  ┌──────────────┐  ││  │ OAuthProv  │  │ Next.js      │  ││  │ /sse /mcp  │  │ /authorize   │  ││  │ /token     │  │ /ext-auth    │  ││  │ /register  │  │ / (landing)  │  ││  └─────┬──────┘  └──────────────┘  ││        │                            ││  ┌─────▼──────┐  ┌──────────────┐  ││  │ RelayMCP   │  │ Deployment   │  ││  │ (DO)       │  │ ChainDO      │  ││  └─────┬──────┘  └──────────────┘  ││        │                            ││  ┌─────▼──────┐                    ││  │ RelayRoom  │ ◄── WebSocket ──┐  ││  │ (DO/accountRef) │            │  ││  └────────────┘                 │  │└─────────────────────────────────┼──┘                                  │                          Browser Extension                          (WhatsApp Web tab)

Durable Objects

DOKeyed ByPurpose
RelayMCPOAuth sessionMcpAgent — registers tools, relays JSON-RPC to RelayRoom
RelayRoomOpaque accountRefWebSocket bridge to extension, auth handshake, request/response matching
DeploymentChainDO"main"Append-only hash chain for deployment transparency

Request Flow

  1. AI client discovers the MCP server via /.well-known/oauth-authorization-server
  2. Client registers dynamically via POST /register (RFC 7591)
  3. User authenticates with WhatsApp OTP at /authorize
  4. Client exchanges code for token at /token
  5. Client sends tool calls via SSE (/sse) or Streamable HTTP (/mcp)
  6. RelayMCP DO receives the call, routes to RelayRoom for the accountRef
  7. RelayRoom forwards JSON-RPC to the extension over WebSocket
  8. Extension executes in WhatsApp Web context, returns result
  9. Result flows back: RelayRoom → RelayMCP → AI client

Routing Table

PathMethodAuthHandler
/GET—Next.js landing page
/authorizeGET—Next.js OTP form (HMAC-signed oauthReqInfo)
/authorize/send-otpPOST—Next.js API route → rest-api
/authorize/verifyGET/POST—Next.js OTP verify → OAuthProvider completeAuthorization
/authorize/reviewer-loginPOSTStatic review credentialsPassword completion for the configured synthetic review phone
/registerPOST—OAuthProvider (RFC 7591 dynamic client registration)
/tokenPOST—OAuthProvider (token exchange)
/sseGETOAuth tokenRelayMCP DO (SSE transport)
/mcpPOSTOAuth tokenRelayMCP DO (Streamable HTTP)
/ws/extGETJWT/token in auth msgRelayRoom DO (WebSocket upgrade)
/ext-auth/*Various—Next.js extension auth pages + API
/transparencyGET—DeploymentChainDO (chain history)
/transparency/latestGET—DeploymentChainDO (latest entry)
/transparency/verifyGET—DeploymentChainDO (chain integrity)
/transparency/gapsGETCF tokenCross-reference CF deploys with chain
/transparency/appendPOSTDEPLOY_API_KEYAppend entry (CI only)

MCP Tools

16 public tools are forwarded to the extension (the relay does not execute them):

ToolDescription
queryQuery conversations, contacts, messages, transcriptions, labels, communities, sessions
summarize_conversationGet or generate a conversation summary
manage_labelsAdd/remove/create/delete WhatsApp Business labels
manage_notesGet/set contact notes (Business accounts)
download_mediaDownload image/video/audio/document from a message
manage_chatArchive, pin, mute, mark read/unread, set/clear draft
manage_remindersCreate/list/complete/delete personal reminders
manage_scheduled_messagesSchedule messages for future delivery — from Kaption's number (bot, default) or from your own number on this computer (mode: "local", also to groups)
manage_listsManage personal chat lists (custom categories)
list_contacts, get_contact, get_contact_groupsRead contacts and their group memberships
list_groups, get_groupRead cached or live group metadata
export_contactsExport contacts as CSV or JSON
get_analyticsAnalyze WhatsApp activity, rankings, response times, and exports

get_api_info is local-only and is deliberately excluded from the cloud surface because it returns private REST connection credentials.

Deployment Security

Every deployment is cryptographically signed and recorded in a tamper-evident transparency chain. See SECURITY.md for full details.

Pipeline

GitHub Actions (push to main)    │    ├─ 1. Run tests    ├─ 2. Build worker (OpenNext + wrap)    ├─ 3. SHA-256 manifest every generated code and asset file    ├─ 4. Pre-deploy: Sigstore sign the manifest → Rekor log    ├─ 5. Deploy to Cloudflare    ├─ 6. Post-deploy: verify hash unchanged, sign attestation → Rekor    └─ 7. Append to transparency chain (hash-linked)

Daily heartbeat redeploys (6am UTC) ensure the chain stays active even without code changes.

Deploys are gated — do NOT run wrangler deploy locally

All production deploys go through GitHub Actions. Multiple layers enforce this:

  1. wrangler.jsonc is gitignored; scripts/build-config.mjs renders it from wrangler.template.jsonc and refuses to run unless GITHUB_ACTIONS=true + GITHUB_RUN_ID are set (or KAPTIONAI_LOCAL_DEV=1 for dev).
  2. npm run predeploy aborts unless those same CI env vars are present.
  3. main is branch-protected: requires a reviewed PR + green test, deploy, and verify checks.
  4. CODEOWNERS routes every PR through @kshmir.

To ship a change: open a PR → review + CI green → merge to main → Actions builds, signs (Sigstore), deploys, and appends to the transparency chain. npx wrangler deploy from a laptop will fail at step 1 because there is no wrangler.jsonc to deploy.

Verify a Deployment

bash
# 1. Check the transparency chaincurl -s https://mcp.kaptionai.com/transparency/latest | jq .
# 2. Verify chain integritycurl -s https://mcp.kaptionai.com/transparency/verify | jq .
# 3. Verify Sigstore signature (requires cosign)COMMIT=$(curl -s https://mcp.kaptionai.com/transparency/latest | jq -r '.event.commitSha')cosign verify-blob \  --bundle build-manifest.sigstore.json \  --certificate-identity-regexp "https://github.com/Kaption-AI/mcp-extension-remote/.*" \  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \  build-manifest.json

API Endpoints

Transparency API (public, no auth)

bash
# Full chain history (paginated)GET /transparency?limit=50&offset=0
# Latest deploymentGET /transparency/latest
# Verify chain integrityGET /transparency/verify

MCP (OAuth-protected)

bash
# SSE transport (for Claude Code, Cursor)GET /sse
# Streamable HTTP transportPOST /mcp

Development

bash
# Install dependenciesnpm install
# Run testsnpm test
# Dev server (Next.js only — no Worker routing)npm run dev
# Build the full worker (OpenNext + custom wrapper)npm run build:worker

Project Structure

src/  index.ts            # Worker entry — Hono routing, OAuthProvider composition  relay-mcp.ts        # RelayMCP Durable Object (McpAgent)  relay-room.ts       # RelayRoom Durable Object (WebSocket bridge)  deployment-chain.ts # DeploymentChainDO (transparency log)  otp.ts              # OTP generation, verification, JWT, HMAC, rate limiting  schemas.ts          # Zod schemas for API request validation  tools.ts            # MCP tool definitions (forwarded, not executed)  types.ts            # TypeScript interfaces (Env, DeploymentEvent, etc.)app/  page.tsx            # Landing page (multilingual, client-side i18n)  layout.tsx          # Root layout  i18n.ts             # i18next init (8 languages)  locales/            # Translation JSON files  authorize/          # OAuth OTP flow pages + API routes  ext-auth/           # Extension auth pages + API routesscripts/  wrap-worker.mjs     # Post-build: wraps OpenNext output with custom routing

Environment Variables

Vars (wrangler.jsonc)

VariableDescription
INTERNAL_API_BASE_URLBackend API base URL
BUILD_HASHSHA-256 of worker bundle (set by CI)
COMMIT_SHAGit commit SHA (set by CI)

Secrets (wrangler secret put)

SecretDescription
INTERNAL_API_KEYAPI key for rest-api OTP endpoint
DEPLOY_API_KEYAPI key for transparency chain append
JWT_SECRETShared JWT signing secret (same as rest-api, schedule, metadata workers)
PHONE_REF_SECRETHMAC secret used to derive opaque durable account references from phone numbers
EPHEMERAL_STATE_SECRETEncryption secret for short-lived login hints, verify tickets, and encrypted session phone payloads
OPENAI_APPS_CHALLENGE_TOKENExact domain-verification token issued by the OpenAI plugin portal
OPENAI_REVIEW_PASSWORD_SHA256Lowercase SHA-256 hex digest of the high-entropy reviewer password
OPENAI_REVIEW_PHONEPhone number used as the dedicated review username and to derive the synthetic account's opaque reference

The three OPENAI_* values are also configured as GitHub Actions repository secrets. Add all three together, then run the manual Test, Build & Deploy workflow. CI writes them to an ephemeral mode-0600 file and passes that file to wrangler deploy --secrets-file, so the review configuration ships in the same signed, attested Worker version as the code. The workflow fails closed if only part of the three-value set is present and deletes the temporary file immediately after deployment. Existing Worker secrets not listed in that file are preserved.

Related Projects

License

BUSL-1.1

來源:README.md,提交 ba9ed57

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 5, 2026