Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
CloudBase platform overview and routing guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-platform --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/config/source/skills/cloudbase-platform .claude/skills/cloudbase-platform && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloudbase-platform" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/cloudbase-platform into .claude/skills/cloudbase-platform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudbase-platform", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/cloudbase-platformType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-platform --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/config/source/skills/cloudbase-platform .agents/skills/cloudbase-platform && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloudbase-platform" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/cloudbase-platform into .agents/skills/cloudbase-platform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudbase-platform", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-platform --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/config/source/skills/cloudbase-platform .cursor/skills/cloudbase-platform && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloudbase-platform" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/cloudbase-platform into .cursor/skills/cloudbase-platform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudbase-platform", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git --path config/source/skills/cloudbase-platform--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-platform --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/config/source/skills/cloudbase-platform .gemini/skills/cloudbase-platform && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloudbase-platform" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/cloudbase-platform into .gemini/skills/cloudbase-platform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudbase-platform", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-platformInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/config/source/skills/cloudbase-platform .github/skills/cloudbase-platform && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloudbase-platform" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/cloudbase-platform into .github/skills/cloudbase-platform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudbase-platform", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-platform --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/config/source/skills/cloudbase-platform .opencode/skills/cloudbase-platform && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloudbase-platform" agent skill from https://github.com/TencentCloudBase/CloudBase-AI-Toolkit/tree/main/config/source/skills/cloudbase-platform into .opencode/skills/cloudbase-platform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudbase-platform", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloudbase-platformCloudBase platform overview and routing guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
Cloudbase Platform is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. CloudBase platform overview and routing guide. This skill should be used when users need high-level capability selection, platform concepts, console navigation, realtime (broadcast / presence / live database changes), or cross-platform best practices before choosing a more specific implementation skill.
Its SKILL.md is about 8.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/protocols/change-safety-protocol.md`, `references/protocols/deployment-gate.md` and `references/protocols/deployment-share.md`).
It sits in Backend & APIs. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 21af91c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
docs.cloudbase.netcloud.tencent.comenv-xxx.tcb.qcloud.latcb.cloud.tencent.comconsole.cloud.tencent.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cloudbase Platform loads about 8.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 81 tokens; SKILL.md has 3,544 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit 21af91c, republished under its MIT licence (© TencentCloudBase). 3,544 words, ~8,149 tokens.
.claude/skills/cloudbase-platform/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.
If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.
Cross-cutting protocols (required before code changes or deployments):
references/protocols/change-safety-protocol.mdreferences/protocols/deployment-gate.mdreferences/protocols/sensitive-runtime-data-protection.mdPost-deployment (optional, non-intrusive): after a deployment is verified successful, you may offer at most once to generate anonymized shareables and, in that same offer, optionally submit the work to the case wall (Deployment Share) — see references/protocols/deployment-share.md. Never follow up if declined; never publish or submit on the user's behalf.
../minimal-web-baas-demo/SKILL.mdqueryEnv → lock one DB plane → MCP schema → @cloudbase/js-sdk CRUD → preview.../web-development/SKILL.md../auth-tool-cloudbase/SKILL.md, ../auth-web-cloudbase/SKILL.md../miniprogram-development/SKILL.md../cloudbase-wechat-integration/SKILL.md (official docs: https://docs.cloudbase.net/integration/introduce.md)../cloud-functions/SKILL.md../http-api-cloudbase/SKILL.md../cloudbase-document-database-web-sdk/SKILL.md or ../cloudbase-document-database-in-wechat-miniprogram/SKILL.md../postgresql-development-cloudbase/SKILL.md../postgresql-development-cloudbase/references/realtime.mdrealtime schema, stop and report rather than working around it.app.realtime() (Broadcast / Presence / Postgres CDC) is not document-database collection.watch(). Do not answer a realtime request with watch() code, or the reverse.../relational-database-mcp-cloudbase/SKILL.md or ../data-model-creation/SKILL.md../cloud-storage-web/SKILL.mdcloudbase-platform/references/protocols/change-safety-protocol.md).cloudbase-platform/references/protocols/deployment-gate.md.x-cloudbase-context, full req.headers, or process.env from Cloud Functions / CloudRun (including httpbin-style debug images) — follow references/protocols/sensitive-runtime-data-protection.md.Use this skill for CloudBase platform knowledge when you need to:
This skill provides foundational knowledge that applies to all CloudBase projects, regardless of whether they are Web, Mini Program, or backend services.
Understand platform differences
Follow best practices
@cloudbase/js-sdk direct DB access for browser CRUD; use cloud functions only for secrets, scheduled/background jobs, or elevated cross-collection logic that security rules / RLS cannot express (see ../minimal-web-baas-demo/SKILL.md for the demo default)Use correct SDKs and APIs
postgresql-development-cloudbase; do not reuse NoSQL app.database() / db.collection(...) snippets or MySQL queryMysqlDatabase / manageMysqlDatabase for PG data pathsqueryEnv tool to get environment IDsrc/lib/backend.*, src/lib/auth.*, src/lib/*service.*, and bound page handlers before broad concept reading.Use the canonical CloudBase MCP setup from the main cloudbase guideline
cloudbase guideline firsttcb CLI now (../cloudbase-cli/SKILL.md, ../cloudbase/references/tooling-fallback.md). Inspect tool schemas before MCP execution. Do not hard-code Secret ID / Secret Key / Env ID in configauth, while application-side auth configuration uses queryAppAuth / manageAppAuthWhen working with domain-related tasks, use the correct tool based on the requirement:
| Requirement | Tool | Parameters | Purpose |
|---|---|---|---|
| Security Domain (安全域名) | manageEnv(action="addSecurityDomain" | "removeSecurityDomain") | domains (array of host:port strings) | CORS/request source validation for browser uploads. No certificate involved. (Deprecated alias: envDomainManagement.) |
| Reuse existing Custom Domain | queryGateway(listCustomDomains) → manageGateway(createRoute) | domain = existing custom domain; route fields | Expose a service/path on an already-bound custom domain. No certificateId. Prefer this when a custom domain already exists. |
| Bind new Custom Domain (自定义域名) | manageGateway(action="bindCustomDomain") | domain (string), certificateId (string) | First-time bind of a new public HTTPS domain. Requires certId from SSL console. |
| Delete Custom Domain | manageGateway(action="deleteCustomDomain") | domain (string) | Remove custom domain binding (only after routes on that domain are deleted). |
| Disable / enable gateway route | manageGateway(action="disableRoute" | "enableRoute") | path (required), prefer explicit domain | Toggle Routes[].Enable via ModifyHTTPServiceRoute (not ModifyGatewayRoute). |
| Disable static hosting default domain | queryGateway(listRoutes) → manageGateway(disableRoute) | domain = *.tcloudbaseapp.com (DomainType=STATIC_STORE, IsDefault=true), usually path="/" | Turns off public access on the shared hosting CDN default host. Do not use manageHosting. |
Key indicators for choosing the right tool:
listCustomDomains then createRoute(domain=...) (no certificateId)manageGateway(action="bindCustomDomain")manageEnv(action="addSecurityDomain" / "removeSecurityDomain")createRoute when possible; only bindCustomDomain for first-time domain bind*.tcloudbaseapp.com → queryGateway(listRoutes) then manageGateway(disableRoute) with that STATIC_STORE domain; never invent ModifyGatewayRoute../cloud-api-operations/references/recipes/custom-domain.md: run the read-only VerifyHTTPServiceRoute pre-check first, then bind, then poll Status / DNSStatus. That recipe also covers why domain registration / DNS / ICP calls may return UnauthorizedOperation for an account-level identity.When a CloudBase tool call fails and the error message contains a specific error code (pattern Category.Code, e.g. OperationDenied.FreePackageDenied, ResourceNotFound.*), always route through the official docs before acting — do not guess the meaning, do not hardcode fix recipes here:
searchKnowledgeBase(mode="docs", action="searchDocs", query="<错误码>") — official docs search covers error-code pages. Act on the documented meaning and the fix steps the doc prescribes (plan limits → upgrade guidance, misconfiguration → config fix, etc.).https://docs.cloudbase.net/error-code/basichttps://cloud.tencent.com/document/product/876/34823https://cloud.tencent.com/document/product/876/127357 rather than assuming which tier unlocks it.When a task explicitly requires recording operation steps or results to a file (e.g., RESULT.json): perform the tool calls first, then write a complete record containing every attempt (action, success/failure, message) plus a summary with total / succeeded / failed counts. Do not write the file from memory before the calls finish.
Static Hosting vs Cloud Storage:
manageStorage / queryStorage), not manageHosting(action="upload")Static Hosting Domain:
queryHosting(action="websiteConfig")<envId>-<appId>.tcloudbaseapp.com (DomainType=STATIC_STORE, often IsDefault=true in queryGateway(listRoutes))manageGateway(action="disableRoute", domain="<that-host>", path="/") (or updateRoute with enable=false). Re-enable with enableRoute. Do not look for a manageHosting disable-default-domain action; do not call non-existent ModifyGatewayRoute — the API is ModifyHTTPServiceRoute/Cloud Storage Public URL:
manageStorage(action=upload) and queryStorage(action=url) return temporaryUrl which is a temporary signed URL that expires (default 1 hour). Do NOT use this as a permanent public URL.queryEnv(action=info) to get environment detailsEnvInfo.Storages[0].CdnDomain (e.g., your-env-id.tcb.qcloud.la)https://{CdnDomain}/{cloudPath}CdnDomain is env-xxx.tcb.qcloud.la and cloudPath is uploads/avatar.jpg, the public URL is https://env-xxx.tcb.qcloud.la/uploads/avatar.jpgPRIVATE which requires signed URLs)Shared-Bucket (ExternalStorage) Environments:
queryEnv(action="info"): cloud storage uses a shared bucket when EnvInfo.Storages[0].Bucket is empty and Storages[0].ExternalStorage.Enabled === true; check static hosting the same way on EnvInfo.StaticStorages[0]. Storage and hosting can use different buckets and BasePaths.cloudPath exactly as in a normal environment and never prepend the BasePath or bucket name. Example: with BasePath tenant-a, upload with cloudPath="images/a.png", not "tenant-a/images/a.png" (that nests the file under tenant-a/tenant-a/). Build hosting and CDN URLs from the logical path too — the domain resolves the BasePath, and adding it to a hosting URL returns 404.manageHosting(action="setWebsiteDocument") changes a bucket-level setting that would affect every environment in the bucket, so it fails on shared-bucket hosting. Reading with queryHosting(action="websiteConfig") still works. Tell the user this setting is managed by the platform instead of retrying.SDK Initialization:
queryEnv toolqueryEnv(action="list", alias=..., aliasExact=true) first and use the returned full EnvIdauth.set_env, console URLs, or generated config filesimport cloudbase from "@cloudbase/js-sdk"; const app = cloudbase.init({ env: "your-full-env-id" });import("@cloudbase/js-sdk") or async wrappers such as initCloudBase() with internal initPromiseEnvironment Management (via manageEnv):
The manageEnv tool provides full lifecycle management for CloudBase environments.
| Action | Description | Key Parameters |
|---|---|---|
listPackages | Query available plans | (none) |
create | Create new environment (needs confirm) | alias, packageId, resources, duration, region, externalStorage |
modifyPlan | Change plan (upgrade/downgrade, needs confirm) | envId, packageId |
renew | Renew environment (needs confirm) | envId, duration |
Creating an environment with specific resources:
manageEnv(action="create", alias="my-env", packageId="baas_personal",
resources=["storage","function","postgresql"], confirm="yes")resources (optional, create only): controls which CloudBase capabilities to enable:storage — Cloud Storagefunction — Cloud Functionspostgresql — PostgreSQL relational database (PG mode)Resources to CreateEnv.flexdb (document database) is not offered: new environments are created without a NoSQL tenant. Do not pass it — it is rejected by the schema. To find out whether an environment actually has NoSQL, read queryEnv(action="info") → EnvInfo.RuntimeBackends rather than assuming.region (e.g. region="ap-shanghai") to choose where the environment is created. It is applied as the X-TC-Region request context, not as a CreateEnv body field — so do not put Region inside params. Omit it to use the current session region (cloudBaseOptions.region → TCB_REGION → project config / rc binding → site default: ap-shanghai for the domestic site, ap-singapore for the intl site). Equivalent CLI: tcb env create --region ap-shanghai.region, repeat the same value on the confirming call together with confirm="yes"; otherwise the second call falls back to the session region and the environment may be created somewhere other than the summary you confirmed.externalStorage (optional, create only): { bucketName, region, basePath } creates the environment's cloud storage on an existing shared COS bucket instead of a dedicated one, isolating its files under basePath (must be unique within the bucket). All three fields are required when the object is passed. Use it only when the user provides the bucket — typically a platform creating many environments under one account, where one bucket per environment would hit the account's COS bucket quota; never invent bucket names. It does not cover static hosting: the hosting bucket is chosen by the platform when hosting is enabled and cannot be set through this tool.region, repeat the same externalStorage on the confirm="yes" call. The confirming call reads only its own arguments, so leaving it out creates the environment with a dedicated bucket instead.manageEnv(action="create", alias="tenant-a", packageId="baas_personal",
externalStorage={ bucketName: "shared-bucket-1250000000", region: "ap-shanghai", basePath: "tenant-a" },
confirm="yes")confirm="yes".Querying available packages before creating:
manageEnv(action="listPackages")Changing plan (e.g. personal → standard):
manageEnv(action="modifyPlan", envId="your-env-id", packageId="baas_pf_standard", confirm="yes")Renewing an environment:
manageEnv(action="renew", envId="your-env-id", duration=1, confirm="yes")Important: Authentication methods for different platforms are completely different, must strictly distinguish!
auth.getVerification(), for detailed, refer to web auth related docsauth.getSession() and require data.session; do not use deprecated getLoginState() or auth.getUser() / auth.getCurrentUser() as proof of real login.queryAppAuth / manageAppAuth, not the MCP auth toolaccessKey alone does not create a gateway-authenticated anonymous session. With @cloudbase/js-sdk 3.x, call await auth.signInAnonymously() (or an equivalent authenticated session) before NoSQL app.database() CRUD, or the gateway returns 401. If the app uses AuthGuard or RLS for access control, ensure is_anonymous checks are in place when anonymous access is allowed.auth.uid(), NOT current_user. When writing RLS policies for CloudBase PostgreSQL, the user identity must use auth.uid() (returns the JWT sub / actual user ID as text, not uuid — unlike Supabase). Prefer owner columns as varchar(64) / text; if the column is uuid, cast with auth.uid()::uuid or you get operator does not exist: uuid = text. Do NOT use current_user or current_setting(...) — these PostgreSQL built-in functions return the database role name (e.g. authenticated), not the CloudBase auth user ID. CloudBase PG provides four auth helper functions: auth.uid(), auth.role(), auth.email(), auth.jwt(). Verify availability with SELECT proname FROM pg_proc WHERE pronamespace = 'auth'::regnamespace.wxContext.OPENID via wx-server-sdkpackage.json, declaring required dependenciesmanageFunctions(action="createFunction") to create functionsmanageFunctions(action="updateFunctionCode") to deploy cloud functionsfunctionRootPath refers to the parent directory of function directories, e.g., cloudfunctions directory⚠️ CRITICAL: Always configure permissions BEFORE writing database operation code!
Permission Model:
Platform Compatibility (CRITICAL):
ADMINWRITE or ADMINONLY for write operationsConfiguration Workflow:
Create collection → Configure security rules → Write code → TestmanagePermissions(action="updateResourcePermission") to configure resource permissionsno-sql-web-sdk/security-rules.md for detailed resourceType="noSqlDatabase" examples only; do not treat doc._openid, auth.openid, query-subset validation, or create / update / delete JSON templates as generic rules for functions, storage, or SQL tableshttps://cloud.tencent.com/document/product/876/41802https://docs.cloudbase.net/database/security-ruleshttps://docs.cloudbase.net/cloud-function/security-ruleshttps://docs.cloudbase.net/storage/security-rulesCompatibility note:
permissionssecurity-rule, security-rules, secret-rule, secret-rules, and access-control still resolve to the permissions pluginreadSecurityRule / writeSecurityRule are removed; prefer queryPermissions / managePermissionsCommon Scenarios:
READONLY (admin manages via cloud functions)CUSTOM with auth.uid check (users manage their own)CUSTOM with ownership validationPRIVATE or ADMINONLYCross-Collection Operations:
../minimal-web-baas-demo/SKILL.mdCloudBase MCP provides role management via queryPermissions and managePermissions (CLI equivalent: tcb role). See each tool's schema for the full action list.
⚠️ CRITICAL: Role policies and resource permissions are two independent systems with NO automatic synchronization.
Query (queryPermissions): listRoles, getRole (by roleId / roleIdentity / roleName).
Manage (managePermissions): createRole, updateRole, deleteRoles, addRoleMembers, removeRoleMembers, addRolePolicies, removeRolePolicies.
managePermissions(action="createRole", roleName="Developer", roleIdentity="developer",
policies=["FunctionsAccess"], memberUids=["user-uid-1"])⚠️ Only custom roles can be deleted. System roles are read-only.
See also: CLI equivalent commands in cloudbase-cli/references/permission.md
@cloudbase/js-sdk → database (see ../minimal-web-baas-demo/SKILL.md)Get Data Model Operation Object:
@cloudbase/wx-cloud-client-sdk, initialize const client = initHTTPOverCallFunction(wx.cloud), use client.models@cloudbase/node-sdk@3.10+, initialize const app = cloudbase.init({env}), use app.models@cloudbase/js-sdk, initialize const app = cloudbase.init({env}), after login use app.modelsData Model Query:
manageDataModel tool to:MySQL Data Model Invocation Rules:
db.collection('model_name').get()app.models.model_name.list({ filter: { where: {} } })manageDataModel tool's docs method to get specific SDK usageAfter creating/deploying resources, provide corresponding console links. All console URLs follow the pattern: https://tcb.cloud.tencent.com/dev?envId=${envId}#/{path} — replace ${envId} with the real EnvId resolved via queryEnv (resolve aliases first; see Environment and Authentication below), and resource names with actual values.
The CloudBase console is updated frequently. If a live, logged-in console shows a different hash path from this list, prefer the live console path over stale documentation and then update this skill to match.
#/overview#/cloud-template/market#/db/doc · Collections #/db/doc/collection/${collectionName} · Models #/db/doc/model/${modelName}#/db/mysql · Tables #/db/mysql/table/default/ (must be enabled in console first)#/db/postgres · Data editor #/db/postgres/data-editor · SQL editor #/db/postgres/sql-editor · Settings #/db/postgres/setting (instance spec, account password) · Tasks #/db/postgres/tasks (async task list: spec change, share-to-dedicated upgrade) · Backups #/db/postgres/backups · Migrations #/db/postgres/migrations#/scf · Detail #/scf/detail?id=${functionName}&NameSpace=${envId}#/platform-run (a per-environment capability that must be provisioned first — manageCloudRun(action="initEnv"), then poll queryCloudRun(action="envStatus") until normal; an env can exist without CloudRun, and in that case CloudRun APIs still return success with empty fields)#/storage#/ai#/static-hosting (alt: https://console.cloud.tencent.com/tcb/hosting)#/identity · Login management #/identity/login-manage · Token management #/identity/token-management#/lowcode/apps#/devops/log#/env/env-setting (env info, QPS overage, preview state)#/env/http-access (security domains, CORS, env vars, quotas)#/env/filing-manage (whether this env qualifies as a filing resource: package tier, remaining validity > 6 months, CloudRun fixed IP; unmet items carry their own "renew" / "enable fixed IP" buttons)For configuration pages (like login management), guide users through the setup process rather than only dropping a link.
All packaged reference files (required for skill lint reachability):
© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in config/source/skills/cloudbase-platform of TencentCloudBase/CloudBase-AI-Toolkit.
Open the folder on GitHubat commit 21af91c
We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in TencentCloudBase/CloudBase-AI-Toolkit, which our catalogue first saw on October 7, 2026.
Cloudbase Platform next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloudbase Platform this skillTencentCloudBase/CloudBase-AI-Toolkit | 1.1k | 1 repos | ~8.1k | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Nestjs Best Practicesrolling-scopes/rsschool-app | 10k | 6 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Sub2API AdminWei-Shaw/sub2api | 43k | 1 repos | ~717 | Automated safety check: Pass | LGPL-3.0 | |
| Firecrawl Build Onboardingfirecrawl/firecrawl | 190k | 1 repos | ~1.4k | Automated safety check: Notes | ISC | |
| Obsidian BasesAtmosphere/atmosphere | 3.8k | 22 repos | ~3.2k | Automated safety check: Pass | Apache-2.0 |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
rolling-scopes/rsschool-app
NestJS best practices and architecture patterns for building production-ready applications.
Wei-Shaw/sub2api
Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.
firecrawl/firecrawl
Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.
Atmosphere/atmosphere
Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.
TencentCloudBase/CloudBase-AI-Toolkit
CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
TencentCloudBase/CloudBase-AI-Toolkit
Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).
TencentCloudBase/CloudBase-AI-Toolkit
Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.
TencentCloudBase/CloudBase-AI-Toolkit
Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…
Categories
CloudBase platform overview and routing guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Cloudbase Platform is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. CloudBase platform overview and routing guide.
Cloudbase Platform fits situations like: backend & APIs work in your project.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a claude-code`. Or copy the skill folder (config/source/skills/cloudbase-platform in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/cloudbase-platform in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a codex`. Or copy the skill folder (config/source/skills/cloudbase-platform in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/cloudbase-platform in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudbase-platform, .gemini/skills/cloudbase-platform, .github/skills/cloudbase-platform and .opencode/skills/cloudbase-platform in your project.
SKILL.md names no scripts, command-line tools or credentials: Cloudbase Platform is instructions for the agent only.
SKILL.md names 5 domains. In commands or code: docs.cloudbase.net, cloud.tencent.com, env-xxx.tcb.qcloud.la, tcb.cloud.tencent.com and console.cloud.tencent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cloudbase Platform is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.1k tokens (SKILL.md is roughly 33k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cloudbase Platform: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 43k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,133 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 7, 2026.
Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.