kaption-mcp-remote
OfficialEnables AI assistants to interact with a user's WhatsApp account through a browser extension that processes data locally in WhatsApp Web. Provides tools to query conversations, contacts, messages, transcriptions, labels, communities, and sessions; get or generate conversation summaries; manage WhatsApp Business labels and contact notes; download media (images, videos, audio, documents) from messages; archive, pin, mute, mark read/unread, and set drafts on chats; create and manage reminders, scheduled messages (from Kaption's bot number or the user's own number, including to groups), and personal chat lists; read contacts, contact groups, and group metadata; export contacts as CSV or JSON; and analyze WhatsApp activity, rankings, response times, and exports.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@kaption-mcp-remotesummarize my conversation with John from yesterday"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
kaption-mcp-remote
Cloud MCP relay for WhatsApp — lets AI assistants (Claude, ChatGPT, Cursor, etc.) interact with your WhatsApp conversations through the Model Context Protocol.
Setup guide: kaptionai.com/mcp — connect WhatsApp to Claude, ChatGPT or Cursor.
Live at: mcp.kaptionai.com (canonical) and mcp-ext.kaptionai.com (backward-compatible alias for existing connections)
The relay cannot read your messages. It forwards MCP tool calls between the AI client and the Kaption browser extension, which processes everything locally in your browser. Its source code is public (BUSL-1.1), so you can verify it yourself.
Architecture
AI Client (Claude/ChatGPT/Cursor)
│
│ OAuth 2.1 + SSE/Streamable HTTP
▼
┌─────────────────────────────────────┐
│ Cloudflare Worker │
│ mcp.kaptionai.com │
│ │
│ ┌────────────┐ ┌──────────────┐ │
│ │ OAuthProv │ │ Next.js │ │
│ │ /sse /mcp │ │ /authorize │ │
│ │ /token │ │ /ext-auth │ │
│ │ /register │ │ / (landing) │ │
│ └─────┬──────┘ └──────────────┘ │
│ │ │
│ ┌─────▼──────┐ ┌──────────────┐ │
│ │ RelayMCP │ │ Deployment │ │
│ │ (DO) │ │ ChainDO │ │
│ └─────┬──────┘ └──────────────┘ │
│ │ │
│ ┌─────▼──────┐ │
│ │ RelayRoom │ ◄── WebSocket ──┐ │
│ │ (DO/accountRef) │ │ │
│ └────────────┘ │ │
└─────────────────────────────────┼──┘
│
Browser Extension
(WhatsApp Web tab)Durable Objects
DO | Keyed By | Purpose |
RelayMCP | OAuth session | McpAgent — registers tools, relays JSON-RPC to RelayRoom |
RelayRoom | Opaque accountRef | WebSocket bridge to extension, auth handshake, request/response matching |
DeploymentChainDO |
| Append-only hash chain for deployment transparency |
Related MCP server: WhatsApp MCP Server
Request Flow
AI client discovers the MCP server via
/.well-known/oauth-authorization-serverClient registers dynamically via
POST /register(RFC 7591)User authenticates with WhatsApp OTP at
/authorizeClient exchanges code for token at
/tokenClient sends tool calls via SSE (
/sse) or Streamable HTTP (/mcp)RelayMCP DO receives the call, routes to RelayRoom for the accountRef
RelayRoom forwards JSON-RPC to the extension over WebSocket
Extension executes in WhatsApp Web context, returns result
Result flows back: RelayRoom → RelayMCP → AI client
Routing Table
Path | Method | Auth | Handler |
| GET | — | Next.js landing page |
| GET | — | Next.js OTP form (HMAC-signed oauthReqInfo) |
| POST | — | Next.js API route → rest-api |
| GET/POST | — | Next.js OTP verify → OAuthProvider completeAuthorization |
| POST | Static review credentials | Password completion for the configured synthetic review phone |
| POST | — | OAuthProvider (RFC 7591 dynamic client registration) |
| POST | — | OAuthProvider (token exchange) |
| GET | OAuth token | RelayMCP DO (SSE transport) |
| POST | OAuth token | RelayMCP DO (Streamable HTTP) |
| GET | JWT/token in auth msg | RelayRoom DO (WebSocket upgrade) |
| Various | — | Next.js extension auth pages + API |
| GET | — | DeploymentChainDO (chain history) |
| GET | — | DeploymentChainDO (latest entry) |
| GET | — | DeploymentChainDO (chain integrity) |
| GET | CF token | Cross-reference CF deploys with chain |
| POST | DEPLOY_API_KEY | Append entry (CI only) |
MCP Tools
16 public tools are forwarded to the extension (the relay does not execute them):
Tool | Description |
| Query conversations, contacts, messages, transcriptions, labels, communities, sessions |
| Get or generate a conversation summary |
| Add/remove/create/delete WhatsApp Business labels |
| Get/set contact notes (Business accounts) |
| Download image/video/audio/document from a message |
| Archive, pin, mute, mark read/unread, set/clear draft |
| Create/list/complete/delete personal reminders |
| Schedule messages for future delivery — from Kaption's number (bot, default) or from your own number on this computer ( |
| Manage personal chat lists (custom categories) |
| Read contacts and their group memberships |
| Read cached or live group metadata |
| Export contacts as CSV or JSON |
| Analyze WhatsApp activity, rankings, response times, and exports |
get_api_info is local-only and is deliberately excluded from the cloud
surface because it returns private REST connection credentials.
Deployment Security
Every deployment is cryptographically signed and recorded in a tamper-evident transparency chain. See SECURITY.md for full details.
Pipeline
GitHub Actions (push to main)
│
├─ 1. Run tests
├─ 2. Build worker (OpenNext + wrap)
├─ 3. SHA-256 manifest every generated code and asset file
├─ 4. Pre-deploy: Sigstore sign the manifest → Rekor log
├─ 5. Deploy to Cloudflare
├─ 6. Post-deploy: verify hash unchanged, sign attestation → Rekor
└─ 7. Append to transparency chain (hash-linked)Daily heartbeat redeploys (6am UTC) ensure the chain stays active even without code changes.
Deploys are gated — do NOT run wrangler deploy locally
All production deploys go through GitHub Actions. Multiple layers enforce this:
wrangler.jsoncis gitignored;scripts/build-config.mjsrenders it fromwrangler.template.jsoncand refuses to run unlessGITHUB_ACTIONS=true+GITHUB_RUN_IDare set (orKAPTIONAI_LOCAL_DEV=1for dev).npm run predeployaborts unless those same CI env vars are present.mainis branch-protected: requires a reviewed PR + greentest,deploy, andverifychecks.CODEOWNERS routes every PR through @kshmir.
To ship a change: open a PR → review + CI green → merge to main → Actions builds, signs (Sigstore), deploys, and appends to the transparency chain. npx wrangler deploy from a laptop will fail at step 1 because there is no wrangler.jsonc to deploy.
Verify a Deployment
# 1. Check the transparency chain
curl -s https://mcp.kaptionai.com/transparency/latest | jq .
# 2. Verify chain integrity
curl -s https://mcp.kaptionai.com/transparency/verify | jq .
# 3. Verify Sigstore signature (requires cosign)
COMMIT=$(curl -s https://mcp.kaptionai.com/transparency/latest | jq -r '.event.commitSha')
cosign verify-blob \
--bundle build-manifest.sigstore.json \
--certificate-identity-regexp "https://github.com/Kaption-AI/mcp-extension-remote/.*" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
build-manifest.jsonAPI Endpoints
Transparency API (public, no auth)
# Full chain history (paginated)
GET /transparency?limit=50&offset=0
# Latest deployment
GET /transparency/latest
# Verify chain integrity
GET /transparency/verifyMCP (OAuth-protected)
# SSE transport (for Claude Code, Cursor)
GET /sse
# Streamable HTTP transport
POST /mcpDevelopment
# Install dependencies
npm install
# Run tests
npm test
# Dev server (Next.js only — no Worker routing)
npm run dev
# Build the full worker (OpenNext + custom wrapper)
npm run build:workerProject Structure
src/
index.ts # Worker entry — Hono routing, OAuthProvider composition
relay-mcp.ts # RelayMCP Durable Object (McpAgent)
relay-room.ts # RelayRoom Durable Object (WebSocket bridge)
deployment-chain.ts # DeploymentChainDO (transparency log)
otp.ts # OTP generation, verification, JWT, HMAC, rate limiting
schemas.ts # Zod schemas for API request validation
tools.ts # MCP tool definitions (forwarded, not executed)
types.ts # TypeScript interfaces (Env, DeploymentEvent, etc.)
app/
page.tsx # Landing page (multilingual, client-side i18n)
layout.tsx # Root layout
i18n.ts # i18next init (8 languages)
locales/ # Translation JSON files
authorize/ # OAuth OTP flow pages + API routes
ext-auth/ # Extension auth pages + API routes
scripts/
wrap-worker.mjs # Post-build: wraps OpenNext output with custom routingEnvironment Variables
Vars (wrangler.jsonc)
Variable | Description |
| Backend API base URL |
| SHA-256 of worker bundle (set by CI) |
| Git commit SHA (set by CI) |
Secrets (wrangler secret put)
Secret | Description |
| API key for rest-api OTP endpoint |
| API key for transparency chain append |
| Shared JWT signing secret (same as rest-api, schedule, metadata workers) |
| HMAC secret used to derive opaque durable account references from phone numbers |
| Encryption secret for short-lived login hints, verify tickets, and encrypted session phone payloads |
| Exact domain-verification token issued by the OpenAI plugin portal |
| Lowercase SHA-256 hex digest of the high-entropy reviewer password |
| Phone number used as the dedicated review username and to derive the synthetic account's opaque reference |
The three OPENAI_* values are also configured as GitHub Actions repository
secrets. Add all three together, then run the manual Test, Build & Deploy
workflow. CI writes them to an ephemeral mode-0600 file and passes that file
to wrangler deploy --secrets-file, so the review configuration ships in the
same signed, attested Worker version as the code. The workflow fails closed if
only part of the three-value set is present and deletes the temporary file
immediately after deployment. Existing Worker secrets not listed in that file
are preserved.
Related Projects
Kaption Extension — Chrome/Edge/Firefox browser extension (the other side of the relay)
@kaptionai/mcp-extension — Local MCP bridge (runs on your machine, no cloud relay)
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Let Claude or ChatGPT search, read and send your WhatsApp messages over MCP. OAuth sign-in.
WhatsMCP connects Claude and other MCP-compatible AI agents directly to WhatsApp. Send and receive text, images, documents, and voice notes; manage groups (create, add/remove members, promote admins); look up contacts and profiles; follow channels; and read call and message history — all through a standard MCP interface. For voice use cases, WhatsMCP offers SIP-based calling plans (inbound-only, or full inbound/outbound) so AI voice agents can answer and place WhatsApp calls, plus low-latency WebSocket integrations with voice agent providers like ElevenLabs. Multiple WhatsApp accounts can be paired and managed per workspace, with webhook support for real-time inbound message delivery to your own infrastructure.
WhatsApp CRM for AI agents: search contacts, read chats, manage the sales pipeline, send messages.
Run WhatsApp Business campaigns from any AI assistant: contacts, segments, and broadcasts.
Related MCP Servers
- AlicenseCqualityFmaintenanceA Model Context Protocol server that connects your personal WhatsApp account to AI agents like Claude, enabling them to search messages, view contacts, retrieve chat history, and send messages via WhatsApp.714 npm74ISC
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to interact with your personal WhatsApp account, allowing them to search messages and contacts, retrieve chat history, and send messages to individuals or groups. Uses WhatsApp Web API with local data storage for privacy and security.14 npmISC
- FlicenseNot gradedqualityNot gradedmaintenanceEnables seamless integration with WhatsApp through the Model Context Protocol, featuring multi-user support and Supabase cloud storage for persistent message history and media. Users can send messages, search chat records, and manage contacts across platforms like Claude Desktop, Cursor, and OpenClaw.-
- AlicenseAqualityBmaintenanceEnables Claude to interact with WhatsApp on macOS through the Model Context Protocol. It allows reading messages, searching contacts, listing chats, and sending replies via natural conversation.2840 PyPI2MIT