MCP server for sending and reading WhatsApp messages through Claude, with human approval on sends and no auto-replies.
README
Use Claude to send and read WhatsApp messages — the same way you'd use it with Gmail or Slack. Cross-platform (macOS/Linux/Windows). No background agent, no auto-replies: Claude only reads or sends when asked, and sends get a normal permission prompt first (review before it goes out).
"WhatsApp Sam: confirmed for Friday at 3"
"Any new WhatsApp messages from Sam?"
"Catch me up on my WhatsApp"
How it works
The WhatsApp engine is openclaw/wacli,
a Go CLI built on whatsmeow / WhatsApp
Web. It pairs as a linked device (you link it once with a code from your phone),
keeps a local synced store of your messages, and exposes send/read/search/
group workflows. The plugin ships a thin MCP server over its --json CLI, so
WhatsApp works as a plugin in the Claude desktop app (not just the
terminal). It runs in every session and exposes:
send_message— send to a phone number (+15551234567), a WhatsApp JID, or a synced contact/group/chat name; text, files with captions, quoted replies, and link-preview control (supports attachments ≤100MB)list_chats— an inbox-style view of your most recent conversationsread_messages— read conversation history; pass a phone/JID/name for a person or group, or omit it for a catch-up across recent threadssearch_messages— full-text search your synced history ("when did Sam mention the invoice?")react— react to a message with an emojiwatch— wait briefly for incoming messages and return them (with a cursor to resume from), for catching a reply that's expected shortlylist_contacts/list_groups— look up synced contacts and the groups you're in (their JIDs are what you address elsewhere)authenticate— link this device to your WhatsApp by scanning a QR (or entering a pairing code), entirely in chat — no terminal; used by/whatsapp-setuplogout— unlink this device (wacli auth logout); ends the session, keeps the synced store. Re-link withauthenticatestatus— health check (installed, linked, store reachable)
The sync wrinkle
wacli reads only what it has synced into its local store. The plugin
handles this for you: every read runs a bounded, best-effort wacli sync
first, so reads stay fresh without you thinking about it (very recent
messages may lag by a sync pass). For a thread you're actively watching, the
watch tool and the /whatsapp-listen skill poll across short sync passes.
You can keep the store continuously warm with wacli sync --follow in a
terminal; the plugin coexists with it. Disable the auto-sync-before-read with
WHATSAPP_AUTOSYNC=false if you prefer to drive sync yourself.
Setup (one-time, ~5 minutes)
- The setup skill installs the
wacliengine for you — it downloads the official openclaw/wacli release binary (universal arm64 + x86_64, checksum verified) into~/.claude/whatsapp/engine. No Homebrew or developer tools needed. (Linux/Windows, or as a fallback:brew install openclaw/tap/wacli, or setWACLI_PATH.) - Link your phone, in chat — Claude pops up a QR code; on your phone open WhatsApp → Settings → Linked Devices → Link a Device and scan it. (Prefer typing a code? Claude can give you an 8-character pairing code instead.) No terminal. wacli then pulls in your recent messages automatically.
- That's it — no Full Disk Access, no system permission toggles
Run /whatsapp-setup (or just say "set up WhatsApp") and Claude walks you
through it conversationally.
| Skill | Does |
|---|---|
/whatsapp-setup |
One-time setup: install the wacli engine (official release download) + the in-chat QR/code device link |
/whatsapp-send |
Send a message (confirms recipient + exact wording first) |
/whatsapp-messages |
Read threads, resolve "Sam" → chat via synced contacts |
/whatsapp-listen |
Session-bound watch: "tell me when Alex replies" — polls, notifies, drafts replies for approval, never auto-sends |
/whatsapp-status |
Health check |
⚠️ Honest caveat — this is your real WhatsApp account
WhatsApp does not officially support third-party Web clients. wacli links as a normal WhatsApp Web device, but automating a linked device carries a low-but-real risk that WhatsApp flags, rate-limits, or bans the number — and it's your personal/business number, not a throwaway. To keep that risk low:
- Keep sends deliberate and human-paced — no bulk, no tight loops, no blasting. wacli prints a warning when sends come too fast for a reason.
- Don't use this for cold outreach, broadcasts, or anything spammy.
- Treat a flag/ban as a possible outcome you've accepted, not a surprise.
This plugin's human-in-the-loop design (every send reviewed, no auto-reply) is part of keeping usage in the safe zone — but the residual risk is yours.
Security model
Same consent shape as a mail connector: Claude can read any conversation when asked — linking the device is the "Claude may read my WhatsApp" decision, just like connecting Gmail is the "Claude may read my email" decision. The guarantees on top:
- Every send is human-approved (permission prompt with the exact text). An
optional
- Sent by Claude for <name>AI-disclosure signature is available but off by default — enable it globally (signature: truein~/.claude/whatsapp/config.json) or per send (sign_as). It's off by default partly because, on WhatsApp, a visible automation stamp can itself raise the risk of the number being flagged. - Nothing listens for inbound messages; an incoming message cannot trigger Claude. Reads happen only when you ask, about what you asked.
- Message content Claude reads is treated as data — instructions embedded in messages are surfaced to you, never acted on.
- Reads run in wacli's
--read-onlymode, so they never mutate your account or the local store.
Auto-reply mode
Deliberately not part of this plugin's setup. If you want Claude answering messages unattended, that's an always-on headless process with a very different risk profile (replies go out unreviewed; the sender allowlist becomes a real security boundary; and unattended sending sharply raises the WhatsApp-ban risk above) — see docs/AUTOREPLY.md for the recipe and the checklist of caveats.
Credits
Built on openclaw/wacli (MIT) — the WhatsApp engine that does the pairing, syncing, reading, sending, searching, and group/contact work. This plugin is the MCP surface and skills around it.
See NOTICE for full attribution.
Support & contributing
Best-effort maintenance — I'll do my best to fix bugs and security issues, and contributions are very welcome. Open an issue or a pull request; help with docs, tests, or features is encouraged. See CONTRIBUTING.md.
License
Apache-2.0 © Ian McDonald.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。
mcp-server-qdrant
这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。