Agent skill

Cloudbase Platform

by TencentCloudBase in TencentCloudBase/CloudBase-AI-Toolkit

CloudBase platform overview and routing guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

MITAuto-check passedBackend & APIs

Install Cloudbase Platform

skills CLI
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit cloudbase-platform --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/config/source/skills/cloudbase-platform .claude/skills/cloudbase-platform && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudbase-platform
GitHub stars
1.1k
Used in
1 other repo
Token cost
~8.1k tokens
SKILL.md length
3,544 words
Files
5 (incl. references)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

CloudBase platform overview and routing guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

  • Works in 4 steps: Understand platform differences → Follow best practices → Use correct SDKs and APIs → …
  • Backend & APIs work in your project
  • SKILL.md covers Sibling skills (local only), Activation Contract, When to use this skill and How to use this skill (for a…, plus 9 more sections
  • Reaches docs.cloudbase.net and cloud.tencent.com

What it does

Cloudbase Platform is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. CloudBase platform overview and routing guide. This skill should be used when users need high-level capability selection, platform concepts, console navigation, realtime (broadcast / presence / live database changes), or cross-platform best practices before choosing a more specific implementation skill.

Its SKILL.md is about 8.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/protocols/change-safety-protocol.md`, `references/protocols/deployment-gate.md` and `references/protocols/deployment-share.md`).

It sits in Backend & APIs. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/cloudbase-platform”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Understand platform differences
  2. Follow best practices
  3. Use correct SDKs and APIs
  4. Use the canonical CloudBase MCP setup from the main cloudbase guideline

What it can do on your machine

Read from SKILL.md and the folder at commit 21af91c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.cloudbase.net
    • cloud.tencent.com
    • env-xxx.tcb.qcloud.la
    • tcb.cloud.tencent.com
    • console.cloud.tencent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudbase Platform loads about 8.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 81 tokens; SKILL.md has 3,544 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~8.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit 21af91c, republished under its MIT licence (© TencentCloudBase). 3,544 words, ~8,149 tokens.

Download SKILL.mdSave it as .claude/skills/cloudbase-platform/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
cloudbase-platform
description
CloudBase platform overview and routing guide. This skill should be used when users need high-level capability selection, platform concepts, console navigation, realtime (broadcast / presence / live database changes), or cross-platform best practices before choosing a more specific implementation skill.
version
2.34.8
alwaysApply
false

Sibling skills (local only)

Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.

If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.

Cross-cutting protocols (required before code changes or deployments):

  • Change Safety Protocol: references/protocols/change-safety-protocol.md
  • Deployment Gate: references/protocols/deployment-gate.md
  • Sensitive Runtime Data Protection: references/protocols/sensitive-runtime-data-protection.md

Post-deployment (optional, non-intrusive): after a deployment is verified successful, you may offer at most once to generate anonymized shareables and, in that same offer, optionally submit the work to the case wall (Deployment Share) — see references/protocols/deployment-share.md. Never follow up if declined; never publish or submit on the user's behalf.

Activation Contract

Use this first when
  • The user asks which CloudBase capability, service, or tool to use, or needs a high-level understanding of hosting, storage, authentication, cloud functions, or database options.
  • The task is about console navigation, cross-platform differences, permission models, or platform-level best practices before implementation.
Read before writing code if
  • It is still unclear whether the task belongs to Web, mini program, cloud functions, storage, MySQL / NoSQL, or auth.
  • The response needs platform selection, conceptual explanation, or control-plane navigation more than direct implementation steps.
Then also read
  • Minimal Web + database demo (BaaS-first, no cloud functions by default) -> ../minimal-web-baas-demo/SKILL.md
    • Stack order for 最小前后端 / Lovable-like demos: Web SDK CRUD > MCP schema > template warmup during credential wait > cloud functions (default count = 0). Capability sniff: connector ready → queryEnv → lock one DB plane → MCP schema → @cloudbase/js-sdk CRUD → preview.
  • Web app implementation -> ../web-development/SKILL.md
  • Web auth and provider setup -> ../auth-tool-cloudbase/SKILL.md, ../auth-web-cloudbase/SKILL.md
  • Mini program development -> ../miniprogram-development/SKILL.md
  • WeChat Pay, Official Account OAuth, JSAPI Pay, or Native QR-code Pay through CloudBase Integration Center -> ../cloudbase-wechat-integration/SKILL.md (official docs: https://docs.cloudbase.net/integration/introduce.md)
  • Cloud functions -> ../cloud-functions/SKILL.md
  • Official HTTP API clients -> ../http-api-cloudbase/SKILL.md
  • Document database -> ../cloudbase-document-database-web-sdk/SKILL.md or ../cloudbase-document-database-in-wechat-miniprogram/SKILL.md
  • CloudBase PostgreSQL / PG -> ../postgresql-development-cloudbase/SKILL.md
  • Realtime / live push / channels / live table change subscriptions / multiplayer sync -> ../postgresql-development-cloudbase/references/realtime.md
    • PG mode only. Run its Step 0 environment probe before writing any realtime code; if the environment has no realtime schema, stop and report rather than working around it.
    • app.realtime() (Broadcast / Presence / Postgres CDC) is not document-database collection.watch(). Do not answer a realtime request with watch() code, or the reverse.
  • MySQL relational database / data modeling -> ../relational-database-mcp-cloudbase/SKILL.md or ../data-model-creation/SKILL.md
  • Cloud storage -> ../cloud-storage-web/SKILL.md
Do NOT use for
  • Direct implementation of web pages, auth flows, functions, or database operations when a more specific skill already fits.
  • Low-level API parameter references or SDK recipes that belong in specialized skills.
Common mistakes / gotchas
  • Treating this general skill as the default entry point for all CloudBase development.
  • Staying here after the correct implementation skill is already clear.
  • Mixing platform overview with platform-specific API shapes or SDK details.
  • Using this overview skill as a detour in an existing application where the active auth, storage, and data files are already obvious.
  • Making code or configuration changes without first following the Change Safety Protocol (cloudbase-platform/references/protocols/change-safety-protocol.md).
  • Starting any deployment, publish, custom domain, or CloudRun work without first completing the checks in cloudbase-platform/references/protocols/deployment-gate.md.
  • Echoing x-cloudbase-context, full req.headers, or process.env from Cloud Functions / CloudRun (including httpbin-style debug images) — follow references/protocols/sensitive-runtime-data-protection.md.
  • Confusing security domains with custom domains: these are two different tools for different purposes. See the "Domain Management Tools" table below for the authoritative split.

When to use this skill

Use this skill for CloudBase platform knowledge when you need to:

  • Understand CloudBase storage and hosting concepts
  • Compare platform capabilities before implementation
  • Understand cross-platform auth differences (Web vs Mini Program)
  • Understand database permissions and access control
  • Access CloudBase console management pages

This skill provides foundational knowledge that applies to all CloudBase projects, regardless of whether they are Web, Mini Program, or backend services.


How to use this skill (for a coding agent)

  1. Understand platform differences

    • Web and Mini Program have completely different authentication approaches
    • Must strictly distinguish between platforms
    • Never mix authentication methods across platforms
    • If the workspace is already an application with TODOs or prebuilt handlers, do not stay in platform overview mode. Move quickly to the concrete implementation skill and the existing files that own the flow.
  2. Follow best practices

    • Use SDK built-in authentication features (Web)
    • Understand natural login-free feature (Mini Program)
    • Configure appropriate database permissions
    • Prefer @cloudbase/js-sdk direct DB access for browser CRUD; use cloud functions only for secrets, scheduled/background jobs, or elevated cross-collection logic that security rules / RLS cannot express (see ../minimal-web-baas-demo/SKILL.md for the demo default)
  3. Use correct SDKs and APIs

    • Different platforms require different SDKs for data models
    • MySQL data models must use models SDK, not collection API
    • PostgreSQL / CloudBase PG work must route to postgresql-development-cloudbase; do not reuse NoSQL app.database() / db.collection(...) snippets or MySQL queryMysqlDatabase / manageMysqlDatabase for PG data paths
    • Use queryEnv tool to get environment ID
    • In an existing Web application with fixed structure, inspect the existing src/lib/backend.*, src/lib/auth.*, src/lib/*service.*, and bound page handlers before broad concept reading.
  4. Use the canonical CloudBase MCP setup from the main cloudbase guideline

    • This platform overview intentionally does not duplicate the full MCP / mcporter config block
    • For the canonical config snippet, CLI commands, and auth examples, read the main cloudbase guideline first
    • Keep the same core rules here: prefer MCP when tools are available in this session; if not, configure MCP for next session and use tcb CLI now (../cloudbase-cli/SKILL.md, ../cloudbase/references/tooling-fallback.md). Inspect tool schemas before MCP execution. Do not hard-code Secret ID / Secret Key / Env ID in config
    • Keep the auth split explicit: management-side login uses auth, while application-side auth configuration uses queryAppAuth / manageAppAuth

CloudBase Platform Knowledge

Domain Management Tools: Clear Distinction

When working with domain-related tasks, use the correct tool based on the requirement:

RequirementToolParametersPurpose
Security Domain (安全域名)manageEnv(action="addSecurityDomain" | "removeSecurityDomain")domains (array of host:port strings)CORS/request source validation for browser uploads. No certificate involved. (Deprecated alias: envDomainManagement.)
Reuse existing Custom DomainqueryGateway(listCustomDomains) → manageGateway(createRoute)domain = existing custom domain; route fieldsExpose a service/path on an already-bound custom domain. No certificateId. Prefer this when a custom domain already exists.
Bind new Custom Domain (自定义域名)manageGateway(action="bindCustomDomain")domain (string), certificateId (string)First-time bind of a new public HTTPS domain. Requires certId from SSL console.
Delete Custom DomainmanageGateway(action="deleteCustomDomain")domain (string)Remove custom domain binding (only after routes on that domain are deleted).
Disable / enable gateway routemanageGateway(action="disableRoute" | "enableRoute")path (required), prefer explicit domainToggle Routes[].Enable via ModifyHTTPServiceRoute (not ModifyGatewayRoute).
Disable static hosting default domainqueryGateway(listRoutes) → manageGateway(disableRoute)domain = *.tcloudbaseapp.com (DomainType=STATIC_STORE, IsDefault=true), usually path="/"Turns off public access on the shared hosting CDN default host. Do not use manageHosting.

Key indicators for choosing the right tool:

  • Task mentions "自定义域名访问" but env already has a custom domain → listCustomDomains then createRoute(domain=...) (no certificateId)
  • Task mentions "certificate ID" or "SSL" and needs to bind a new domain → manageGateway(action="bindCustomDomain")
  • Task mentions "浏览器上传" or "CORS" or "安全域名" → Use manageEnv(action="addSecurityDomain" / "removeSecurityDomain")
  • Task mentions "public access" or "HTTPS" with domain → Prefer reuse via createRoute when possible; only bindCustomDomain for first-time domain bind
  • Task mentions "关闭/禁用静态托管默认域名" / *.tcloudbaseapp.com → queryGateway(listRoutes) then manageGateway(disableRoute) with that STATIC_STORE domain; never invent ModifyGatewayRoute
  • Task asks about the whole onboarding flow (能不能绑、要等多久、解析怎么配、备案是不是前置) or a bound domain is not reachable → follow ../cloud-api-operations/references/recipes/custom-domain.md: run the read-only VerifyHTTPServiceRoute pre-check first, then bind, then poll Status / DNSStatus. That recipe also covers why domain registration / DNS / ICP calls may return UnauthorizedOperation for an account-level identity.
Error Code Troubleshooting: Route Through Official Docs

When a CloudBase tool call fails and the error message contains a specific error code (pattern Category.Code, e.g. OperationDenied.FreePackageDenied, ResourceNotFound.*), always route through the official docs before acting — do not guess the meaning, do not hardcode fix recipes here:

  1. Extract the error code from the error message.
  2. Look it up: searchKnowledgeBase(mode="docs", action="searchDocs", query="<错误码>") — official docs search covers error-code pages. Act on the documented meaning and the fix steps the doc prescribes (plan limits → upgrade guidance, misconfiguration → config fix, etc.).
  3. If docs search returns nothing, fall back to the canonical error-code pages:
    • Error code basics & self-service troubleshooting: https://docs.cloudbase.net/error-code/basic
    • Control-plane cloud API error codes: https://cloud.tencent.com/document/product/876/34823
  4. Never assert capability-per-plan or error-code semantics from memory — official docs and the console plan comparison are the only authoritative sources. Example: for Web 安全域名 plan requirements, cite https://cloud.tencent.com/document/product/876/127357 rather than assuming which tier unlocks it.
Recording Operation Results

When a task explicitly requires recording operation steps or results to a file (e.g., RESULT.json): perform the tool calls first, then write a complete record containing every attempt (action, success/failure, message) plus a summary with total / succeeded / failed counts. Do not write the file from memory before the calls finish.

Storage and Hosting

  1. Static Hosting vs Cloud Storage:

    • CloudBase static hosting and cloud storage are two different buckets
    • Generally, publicly accessible files can be stored in static hosting, which provides a public web address
    • Static hosting supports custom domain configuration (requires console operation)
    • Cloud storage is suitable for files with privacy requirements, can get temporary access addresses via temporary file URLs
    • If the task needs COS SDK polling, file metadata lookup, or temporary URLs for an uploaded object, use cloud storage tools (manageStorage / queryStorage), not manageHosting(action="upload")
  2. Static Hosting Domain:

    • CloudBase static hosting domain and website document config can be obtained via queryHosting(action="websiteConfig")
    • Combine with static hosting file paths to construct final access addresses
    • Default shared host looks like <envId>-<appId>.tcloudbaseapp.com (DomainType=STATIC_STORE, often IsDefault=true in queryGateway(listRoutes))
    • To disable that default public host: manageGateway(action="disableRoute", domain="<that-host>", path="/") (or updateRoute with enable=false). Re-enable with enableRoute. Do not look for a manageHosting disable-default-domain action; do not call non-existent ModifyGatewayRoute — the API is ModifyHTTPServiceRoute
    • Important: If access address is a directory, it must end with /
  3. Cloud Storage Public URL:

    • CRITICAL: manageStorage(action=upload) and queryStorage(action=url) return temporaryUrl which is a temporary signed URL that expires (default 1 hour). Do NOT use this as a permanent public URL.
    • To get the permanent public access URL for a cloud storage object:
      1. Call queryEnv(action=info) to get environment details
      2. Extract the storage CDN domain from EnvInfo.Storages[0].CdnDomain (e.g., your-env-id.tcb.qcloud.la)
      3. Construct the public URL: https://{CdnDomain}/{cloudPath}
    • Example: If CdnDomain is env-xxx.tcb.qcloud.la and cloudPath is uploads/avatar.jpg, the public URL is https://env-xxx.tcb.qcloud.la/uploads/avatar.jpg
    • Note: The public URL is accessible only if the storage bucket ACL allows public read (default is PRIVATE which requires signed URLs)
  4. Shared-Bucket (ExternalStorage) Environments:

    • Some environments keep files in a COS bucket shared with other environments, each isolated under its own directory prefix (BasePath). Detect it with queryEnv(action="info"): cloud storage uses a shared bucket when EnvInfo.Storages[0].Bucket is empty and Storages[0].ExternalStorage.Enabled === true; check static hosting the same way on EnvInfo.StaticStorages[0]. Storage and hosting can use different buckets and BasePaths.
    • Paths stay logical. Storage and hosting tools add the BasePath themselves, so pass cloudPath exactly as in a normal environment and never prepend the BasePath or bucket name. Example: with BasePath tenant-a, upload with cloudPath="images/a.png", not "tenant-a/images/a.png" (that nests the file under tenant-a/tenant-a/). Build hosting and CDN URLs from the logical path too — the domain resolves the BasePath, and adding it to a hosting URL returns 404.
    • manageHosting(action="setWebsiteDocument") changes a bucket-level setting that would affect every environment in the bucket, so it fails on shared-bucket hosting. Reading with queryHosting(action="websiteConfig") still works. Tell the user this setting is managed by the platform instead of retrying.
    • Storage security rules are maintained per environment, not as a COS bucket ACL, so read and update them the same way as in a normal environment.
    • What happens to files when a shared-bucket environment is deleted is decided by the platform. Do not promise that its BasePath directory is kept or removed.
Show full SKILL.md (1,691 more words)Show less

Environment and Authentication

  1. SDK Initialization:

    • CloudBase SDK initialization requires environment ID
    • Can query environment ID via queryEnv tool
    • If the user only provides an environment alias, nickname, or other short form, resolve it with queryEnv(action="list", alias=..., aliasExact=true) first and use the returned full EnvId
    • Do not pass alias-like short forms directly into SDK init, auth.set_env, console URLs, or generated config files
    • For Web, always initialize synchronously:
      • import cloudbase from "@cloudbase/js-sdk"; const app = cloudbase.init({ env: "your-full-env-id" });
      • Do not use dynamic imports like import("@cloudbase/js-sdk") or async wrappers such as initCloudBase() with internal initPromise
    • Then proceed with login using a verified method (username/password, phone, email, or WeChat)
  2. Environment Management (via manageEnv): The manageEnv tool provides full lifecycle management for CloudBase environments.

    ActionDescriptionKey Parameters
    listPackagesQuery available plans(none)
    createCreate new environment (needs confirm)alias, packageId, resources, duration, region, externalStorage
    modifyPlanChange plan (upgrade/downgrade, needs confirm)envId, packageId
    renewRenew environment (needs confirm)envId, duration

    Creating an environment with specific resources:

    manageEnv(action="create", alias="my-env", packageId="baas_personal",
              resources=["storage","function","postgresql"], confirm="yes")
    • resources (optional, create only): controls which CloudBase capabilities to enable:
      • storage — Cloud Storage
      • function — Cloud Functions
      • postgresql — PostgreSQL relational database (PG mode)
    • Defaults to all three when omitted. MCP always sends non-empty Resources to CreateEnv.
    • flexdb (document database) is not offered: new environments are created without a NoSQL tenant. Do not pass it — it is rejected by the schema. To find out whether an environment actually has NoSQL, read queryEnv(action="info") → EnvInfo.RuntimeBackends rather than assuming.
    • Region is selectable: pass region (e.g. region="ap-shanghai") to choose where the environment is created. It is applied as the X-TC-Region request context, not as a CreateEnv body field — so do not put Region inside params. Omit it to use the current session region (cloudBaseOptions.region → TCB_REGION → project config / rc binding → site default: ap-shanghai for the domestic site, ap-singapore for the intl site). Equivalent CLI: tcb env create --region ap-shanghai.
    • ⚠️ If you pass region, repeat the same value on the confirming call together with confirm="yes"; otherwise the second call falls back to the session region and the environment may be created somewhere other than the summary you confirmed.
    • externalStorage (optional, create only): { bucketName, region, basePath } creates the environment's cloud storage on an existing shared COS bucket instead of a dedicated one, isolating its files under basePath (must be unique within the bucket). All three fields are required when the object is passed. Use it only when the user provides the bucket — typically a platform creating many environments under one account, where one bucket per environment would hit the account's COS bucket quota; never invent bucket names. It does not cover static hosting: the hosting bucket is chosen by the platform when hosting is enabled and cannot be set through this tool.
    • ⚠️ Like region, repeat the same externalStorage on the confirm="yes" call. The confirming call reads only its own arguments, so leaving it out creates the environment with a dedicated bucket instead.
    manageEnv(action="create", alias="tenant-a", packageId="baas_personal",
              externalStorage={ bucketName: "shared-bucket-1250000000", region: "ap-shanghai", basePath: "tenant-a" },
              confirm="yes")
    • ⚠️ All paid operations (create / modifyPlan / renew) require confirm="yes".

    Querying available packages before creating:

    manageEnv(action="listPackages")

    Changing plan (e.g. personal → standard):

    manageEnv(action="modifyPlan", envId="your-env-id", packageId="baas_pf_standard", confirm="yes")

    Renewing an environment:

    manageEnv(action="renew", envId="your-env-id", duration=1, confirm="yes")

Authentication Best Practices

Important: Authentication methods for different platforms are completely different, must strictly distinguish!

Web Authentication
  • Must use SDK built-in authentication: CloudBase Web SDK provides complete authentication features
  • Recommended method: SMS login with auth.getVerification(), for detailed, refer to web auth related docs
  • Forbidden behavior: Do not use cloud functions to implement login authentication logic
  • Session management: For route guards and login proof, use auth.getSession() and require data.session; do not use deprecated getLoginState() or auth.getUser() / auth.getCurrentUser() as proof of real login.
  • Provider and login-method setup: Use queryAppAuth / manageAppAuth, not the MCP auth tool
  • Anonymous login is disabled by default. Publishable accessKey alone does not create a gateway-authenticated anonymous session. With @cloudbase/js-sdk 3.x, call await auth.signInAnonymously() (or an equivalent authenticated session) before NoSQL app.database() CRUD, or the gateway returns 401. If the app uses AuthGuard or RLS for access control, ensure is_anonymous checks are in place when anonymous access is allowed.
  • ⚠️ PG RLS: Use auth.uid(), NOT current_user. When writing RLS policies for CloudBase PostgreSQL, the user identity must use auth.uid() (returns the JWT sub / actual user ID as text, not uuid — unlike Supabase). Prefer owner columns as varchar(64) / text; if the column is uuid, cast with auth.uid()::uuid or you get operator does not exist: uuid = text. Do NOT use current_user or current_setting(...) — these PostgreSQL built-in functions return the database role name (e.g. authenticated), not the CloudBase auth user ID. CloudBase PG provides four auth helper functions: auth.uid(), auth.role(), auth.email(), auth.jwt(). Verify availability with SELECT proname FROM pg_proc WHERE pronamespace = 'auth'::regnamespace.
Mini Program Authentication
  • Login-free feature: Mini program CloudBase is naturally login-free, no login flow needed
  • User identifier: In cloud functions, get wxContext.OPENID via wx-server-sdk
  • User management: Manage user data in cloud functions based on openid
  • Forbidden behavior: Do not generate login pages or login flow code

Cloud Functions

  1. Node.js Cloud Functions:
    • Node.js cloud functions need to include package.json, declaring required dependencies
    • Can use manageFunctions(action="createFunction") to create functions
    • Use manageFunctions(action="updateFunctionCode") to deploy cloud functions
    • Prioritize cloud dependency installation, do not upload node_modules
    • functionRootPath refers to the parent directory of function directories, e.g., cloudfunctions directory

Database Permissions

⚠️ CRITICAL: Always configure permissions BEFORE writing database operation code!

  1. Permission Model:

    • CloudBase database access has permissions
    • Default basic permissions include:
      • READONLY: Everyone can read, only creator/admin can write
      • PRIVATE: Only creator/admin can read/write
      • ADMINWRITE: Everyone can read, only admin can write (⚠️ NOT for Web SDK write!)
      • ADMINONLY: Only admin can read/write
      • CUSTOM: Fine-grained control with custom rules
  2. Platform Compatibility (CRITICAL):

    • ⚠️ Web SDK cannot use ADMINWRITE or ADMINONLY for write operations
    • ✅ For user-generated content in Web apps, use CUSTOM rules
    • ✅ For admin-managed data (products, settings), use READONLY
    • ✅ Cloud functions have full access regardless of permission type
  3. Configuration Workflow:

    Create collection → Configure security rules → Write code → Test
    • Use managePermissions(action="updateResourcePermission") to configure resource permissions
    • If permissions were just changed, retry after a few seconds (typically within ~30s). Do not blind-wait 2-5 minutes. If it still fails, re-check the actual rule shape and active client write pattern first — most failures are misconfigured rules, not cache.
    • See no-sql-web-sdk/security-rules.md for detailed resourceType="noSqlDatabase" examples only; do not treat doc._openid, auth.openid, query-subset validation, or create / update / delete JSON templates as generic rules for functions, storage, or SQL tables
    • Official references:
      • General security rules overview: https://cloud.tencent.com/document/product/876/41802
      • NoSQL database security rules: https://docs.cloudbase.net/database/security-rules
      • Cloud function security rules: https://docs.cloudbase.net/cloud-function/security-rules
      • Storage security rules: https://docs.cloudbase.net/storage/security-rules

Compatibility note:

  • Canonical plugin name: permissions
  • Legacy plugin aliases security-rule, security-rules, secret-rule, secret-rules, and access-control still resolve to the permissions plugin
  • Legacy tools readSecurityRule / writeSecurityRule are removed; prefer queryPermissions / managePermissions
  1. Common Scenarios:

    • E-commerce products: READONLY (admin manages via cloud functions)
    • Shopping carts: CUSTOM with auth.uid check (users manage their own)
    • Orders: CUSTOM with ownership validation
    • System logs: PRIVATE or ADMINONLY
  2. Cross-Collection Operations:

    • Prefer security rules / RLS and client SDK when the permission model allows it
    • Use cloud functions when the operation needs elevated privileges, server secrets, or multi-collection logic that rules cannot express
    • For minimal Web demos (Todo / Notes / Kanban / 最小前后端), do not introduce cloud functions for CRUD — follow ../minimal-web-baas-demo/SKILL.md

Role Management (MCP)

CloudBase MCP provides role management via queryPermissions and managePermissions (CLI equivalent: tcb role). See each tool's schema for the full action list.

⚠️ CRITICAL: Role policies and resource permissions are two independent systems with NO automatic synchronization.

  • Resource permissions (security rules) control access to specific resources (tables, collections, functions, storage)
  • Roles (identity dimension) control policy bundles and member assignments

Query (queryPermissions): listRoles, getRole (by roleId / roleIdentity / roleName). Manage (managePermissions): createRole, updateRole, deleteRoles, addRoleMembers, removeRoleMembers, addRolePolicies, removeRolePolicies.

managePermissions(action="createRole", roleName="Developer", roleIdentity="developer",
                  policies=["FunctionsAccess"], memberUids=["user-uid-1"])

⚠️ Only custom roles can be deleted. System roles are read-only.

See also: CLI equivalent commands in cloudbase-cli/references/permission.md

  1. Cloud Function Optimization:
    • Browser CRUD should not default to a cloud-function middleware layer; prefer @cloudbase/js-sdk → database (see ../minimal-web-baas-demo/SKILL.md)
    • When cloud functions are truly required, keep the count minimal and scope each function to secrets, elevated privilege, or background work

Data Models

  1. Get Data Model Operation Object:

    • Mini Program: Need @cloudbase/wx-cloud-client-sdk, initialize const client = initHTTPOverCallFunction(wx.cloud), use client.models
    • Cloud Function: Need @cloudbase/node-sdk@3.10+, initialize const app = cloudbase.init({env}), use app.models
    • Web: Need @cloudbase/js-sdk, initialize const app = cloudbase.init({env}), after login use app.models
  2. Data Model Query:

    • Can call MCP manageDataModel tool to:
      • Query model list
      • Get model detailed information (including Schema fields)
      • Get specific models SDK usage documentation
  3. MySQL Data Model Invocation Rules:

    • MySQL data models cannot use collection method invocation, must use data model SDK
    • Wrong: db.collection('model_name').get()
    • Correct: app.models.model_name.list({ filter: { where: {} } })
    • Use manageDataModel tool's docs method to get specific SDK usage

Console Management

After creating/deploying resources, provide corresponding console links. All console URLs follow the pattern: https://tcb.cloud.tencent.com/dev?envId=${envId}#/{path} — replace ${envId} with the real EnvId resolved via queryEnv (resolve aliases first; see Environment and Authentication below), and resource names with actual values.

The CloudBase console is updated frequently. If a live, logged-in console shows a different hash path from this list, prefer the live console path over stale documentation and then update this skill to match.

Entry points (one line each)
  • Overview: #/overview
  • Template Center: #/cloud-template/market
  • Document Database: #/db/doc · Collections #/db/doc/collection/${collectionName} · Models #/db/doc/model/${modelName}
  • MySQL Database: #/db/mysql · Tables #/db/mysql/table/default/ (must be enabled in console first)
  • PostgreSQL Database: #/db/postgres · Data editor #/db/postgres/data-editor · SQL editor #/db/postgres/sql-editor · Settings #/db/postgres/setting (instance spec, account password) · Tasks #/db/postgres/tasks (async task list: spec change, share-to-dedicated upgrade) · Backups #/db/postgres/backups · Migrations #/db/postgres/migrations
  • Cloud Functions: #/scf · Detail #/scf/detail?id=${functionName}&NameSpace=${envId}
  • CloudRun: #/platform-run (a per-environment capability that must be provisioned first — manageCloudRun(action="initEnv"), then poll queryCloudRun(action="envStatus") until normal; an env can exist without CloudRun, and in that case CloudRun APIs still return success with empty fields)
  • Cloud Storage: #/storage
  • AI+: #/ai
  • Static Hosting: #/static-hosting (alt: https://console.cloud.tencent.com/tcb/hosting)
  • Identity Authentication: #/identity · Login management #/identity/login-manage · Token management #/identity/token-management
  • Weida Low-Code: #/lowcode/apps
  • Logs & Monitoring: #/devops/log
  • Environment Settings: #/env/env-setting (env info, QPS overage, preview state)
  • HTTP Access: #/env/http-access (security domains, CORS, env vars, quotas)
  • ICP Filing: #/env/filing-manage (whether this env qualifies as a filing resource: package tier, remaining validity > 6 months, CloudRun fixed IP; unmet items carry their own "renew" / "enable fixed IP" buttons)

For configuration pages (like login management), guide users through the setup process rather than only dropping a link.

Reference index

All packaged reference files (required for skill lint reachability):

© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in config/source/skills/cloudbase-platform of TencentCloudBase/CloudBase-AI-Toolkit.

  • SKILL.md
  • references/protocols/change-safety-protocol.md
  • references/protocols/deployment-gate.md
  • references/protocols/deployment-share.md
  • references/protocols/sensitive-runtime-data-protection.md

Open the folder on GitHubat commit 21af91c

Used in 1 other repository

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in TencentCloudBase/CloudBase-AI-Toolkit, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudbase Platform next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudbase Platform compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudbase Platform this skillTencentCloudBase/CloudBase-AI-Toolkit1.1k1 repos~8.1kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api43k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    43k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from TencentCloudBase/CloudBase-AI-Toolkit

All 49 skills in this repo
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 3 repos~5k tokens
    Auto-check passed
  • HTTP API Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

    1.1k GitHub starsUsed in 3 repos~2.1k tokens
    Auto-check passed
  • Cloud API Recipe Authoring

    TencentCloudBase/CloudBase-AI-Toolkit

    Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).

    1.1k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Manage Local Skills

    TencentCloudBase/CloudBase-AI-Toolkit

    Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.

    1.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Cloudbase Agent Python

    TencentCloudBase/CloudBase-AI-Toolkit

    Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…

    1.1k GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check: notes
  • Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…

    1.1k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed

Categories

Questions about Cloudbase Platform

What does Cloudbase Platform do?

CloudBase platform overview and routing guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Cloudbase Platform is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. CloudBase platform overview and routing guide.

When should I use Cloudbase Platform?

Cloudbase Platform fits situations like: backend & APIs work in your project.

How do I install Cloudbase Platform in Claude Code?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a claude-code`. Or copy the skill folder (config/source/skills/cloudbase-platform in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/cloudbase-platform in your project. Claude Code loads it when a task matches its description.

How do I install Cloudbase Platform in Codex?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a codex`. Or copy the skill folder (config/source/skills/cloudbase-platform in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/cloudbase-platform in your project. Codex loads it when a task matches its description.

Can I use Cloudbase Platform in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloudbase-platform -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudbase-platform, .gemini/skills/cloudbase-platform, .github/skills/cloudbase-platform and .opencode/skills/cloudbase-platform in your project.

What does Cloudbase Platform need to run?

SKILL.md names no scripts, command-line tools or credentials: Cloudbase Platform is instructions for the agent only.

Does Cloudbase Platform access the network?

SKILL.md names 5 domains. In commands or code: docs.cloudbase.net, cloud.tencent.com, env-xxx.tcb.qcloud.la, tcb.cloud.tencent.com and console.cloud.tencent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Cloudbase Platform safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudbase Platform use?

Cloudbase Platform is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudbase Platform use?

About 8.1k tokens (SKILL.md is roughly 33k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Cloudbase Platform?

Skills that share tags, products or a category with Cloudbase Platform: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 43k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudbase Platform?

TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,133 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 7, 2026.

Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.