WhatsApp MCP
Optionally integrates with Obsidian to pull matching CRM context from a vault when reading a chat.
Optionally integrates with OpenAI's Whisper API for voice note transcription (opt-in).
Integrates with WhatsApp Web to read chats, messages, contacts, and send text messages, reactions, and reply-quotes with a mandatory confirmation step, as well as search messages with accent-insensitive matching.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@WhatsApp MCPsend a message to John saying I'm on my way"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
whatsapp-mcp
A WhatsApp MCP server for Claude, built directly on whatsmeow. Encrypted at rest, prompt-injection-scrubbed, draft-and-confirm on every send, full audit trail, daily CI security gates. Actively maintained.
Why this one?
The most-starred WhatsApp MCP (lharries/whatsapp-mcp, 5.6K stars) is the architectural reference for this pattern, but has not shipped since July 2025 and leaves the lethal-trifecta problem entirely to the user. This implementation closes the gaps:
Canonical | This implementation | |
Last shipped | July 2025 | Active |
DB encryption | Plain SQLite | SQLCipher with key in the platform secret store (macOS Keychain / Windows Credential Manager / libsecret) |
Prompt-injection scrubber | None | Every inbound message |
Send safety | Fires immediately | Mandatory |
Audit log | None | Every tool call, 30-day retention |
Voice notes | Not transcribed |
|
LID alias resolution | Open issue cluster upstream | Shipped, with backfill migration for legacy threads |
CI security | None |
|
Not a fork. The Go bridge is built directly against whatsmeow; the Python MCP layer and SQLite schema are original. Other implementations (lharries, LukasHaas, verygoodplugins) were read as reference only.
Related MCP server: WhatsApp MCP for macOS
What this gives you
Claude can:
Read your WhatsApp chats, messages, and contacts
Search messages with accent-insensitive, typo-tolerant matching
Transcribe voice notes locally via
whisper.cpp(Spanish-tuned by default)Resolve LID (Linked IDentifier) names instead of numeric placeholders
Send text messages, reactions, and reply-quotes, with a mandatory
confirm_sendstep between draft and deliveryPull matching CRM context from your Obsidian vault when reading a chat
See only prompt-injection-scrubbed message text, never raw adversarial input
Everything runs locally on your machine. No cloud sync. No telemetry. Optional OpenAI Whisper backend is opt-in, off by default.
Architecture
Two components, both local:
whatsapp-bridge/(Go). Binds to 127.0.0.1 only. Wrapswhatsmeowfor the WhatsApp Web multidevice protocol. Owns SQLite persistence with SQLCipher encryption. Handles QR and pairing-code auth (live-refreshing terminal QR with Windows-safe rendering, plus a headless auth API —GET /api/auth/qr,POST /api/auth/pair-phone,POST /api/auth/reconnect— so a GUI or supervisor can drive pairing without a terminal), media up/download, session recovery fromStreamReplacedconflicts, call history capture. Exposes a REST API the Python MCP layer consumes.whatsapp-mcp-server/(Python, FastMCP). Consumes the Go bridge REST API. Exposes 11 MCP tools to Claude: full read surface (chats, messages, contacts), accent-insensitive search, presence (typing, online, mark-read), and text-send + reactions + reply-quotes with mandatoryconfirm_send. Runs viauvand stdio transport.
Install
Open Claude Code, paste:
/plugin marketplace add adelaidasofia/whatsapp-mcp
/plugin install whatsapp-mcp@whatsapp-mcpThis installs the Python MCP server side. The Go bridge still needs the one-time QR pairing flow with your phone — see the legacy install block below for those steps.
See SETUP.md for step-by-step install per OS. In short:
Grab a prebuilt bridge binary from Releases (Windows/macOS/Linux — no compiler needed), or build from source (Go 1.24+ and a C toolchain)
Python 3.11+ and
uvfor the MCP server layerClone this repo; verify with
scripts/check_prerequisites.sh(Windows:scripts\check_prerequisites.ps1)Start the bridge:
./bin/whatsapp-bridge(Windows:.\bin\whatsapp-bridge.exe)Scan the QR (it refreshes in place — always scan the one on screen), or pair by typed code with
--pair-phone +15551234567Register the MCP in your Claude Code
.mcp.jsonRestart Claude Code
FFmpeg and whisper.cpp are only needed if you enable voice-note transcription (off by default).
Configuration
All configurable via environment variables. See .env.example for the full list.
Key variables:
Variable | Default | Purpose |
|
| Go bridge REST API port |
|
| Encrypted SQLite database |
|
| Media file storage |
| empty | Absolute path to your vault CRM folder for auto-injection (e.g., Obsidian |
|
|
|
| empty | Required only when backend is |
|
| whisper.cpp model name |
|
| Strip known prompt-injection patterns from incoming messages before Claude sees them |
|
| Log every tool call to |
|
| Enable SQLCipher DB encryption; key in the platform secret store (macOS Keychain / Windows Credential Manager / libsecret) |
| empty | Explicit 64-hex-char SQLCipher key override for headless/CI/custom secret managers (skips the platform store) |
Security
This MCP is the highest-trust component in your Claude stack because every WhatsApp message you receive flows through it. See SECURITY.md for the threat model, tool risk-tier classification, and the full list of hardening decisions.
Short version:
Bridge binds to
127.0.0.1only, never0.0.0.0SQLite encrypted at rest with SQLCipher; key stored in the platform secret store (macOS Keychain / Windows Credential Manager / libsecret), with an explicit
WHATSAPP_DB_KEYescape hatchEvery tool call logged to
audit.logwith 30-day retentionSend tools require an explicit
confirm_sendstep between draft and deliveryIncoming message text passes through a prompt-injection scrubber before Claude sees it
whatsmeowpinned to a specific commit; upgrades require diff reviewNo telemetry, no external API calls by default
Status
v0.1.0, actively maintained.
Shipped: live-refreshing QR (in-place redraw on rotation, Windows-safe rendering, auto fresh batch on expiry) + pairing-code auth (typed 8-char code, Android + iOS) + headless auth API for supervisors, full read surface (chats, messages, contacts), accent-insensitive NFD-normalized search, LID alias resolution with backfill migration for legacy threads, Baileys-store import for one-shot history migration, vault-format markdown export, local whisper.cpp voice transcription, presence (typing, online, mark-read), text-send with mandatory confirm_send, reactions, reply-quotes, prompt-injection scrubber, SQLCipher-encrypted persistence with macOS Keychain key handling, audit log, CI security gates.
Not yet shipped: media-send (image, document), audio-message-send (FFmpeg-Opus path), group broadcast helpers.
See CHANGELOG.md for full history.
MCP Registry
Published on the official MCP Registry under io.github.adelaidasofia/whatsapp-mcp. Two live channels:
.mcpbbundle (canonical, recommended) — one-click install in Claude Desktop / Cursor / any MCPB-aware client. Published as a GitHub release artifact at releases/latest/download/whatsapp-mcp.mcpb. The release manifest carries the SHA256 for tamper detection.PyPI package (
adelaidasofia-whatsapp-mcp) — historical; available viauvx adelaidasofia-whatsapp-mcpfor stdio-installer flows. The unprefixed names (whatsapp-mcp,whatsapp-mcp-server) are taken by unrelated projects on PyPI, hence the username-prefixed namespace.
The verification marker mcp-name: io.github.adelaidasofia/whatsapp-mcp is embedded in this README (HTML comment near the top) so the registry can verify package-to-server ownership at publish time.
Publishing pipeline: built and shipped via the Mycelium MCP publishing pipeline (two-phase: .mcpb bundle build, then gh release + mcp-publisher publish). The same pipeline produced all 16 sibling MCPs in this family.
Related MCPs
Same author, same architecture pattern (FastMCP, draft+confirm on writes where applicable, vault auto-export, MIT):
slack-mcp — multi-workspace Slack
imessage-mcp — macOS iMessage
google-workspace-mcp — Gmail / Calendar / Drive / Docs / Sheets
apollo-mcp — Apollo.io CRM + sequences
substack-mcp — Substack writing + analytics
luma-mcp — lu.ma events
parse-mcp — markitdown / Docling / LlamaParse router
rescuetime-mcp — RescueTime productivity data
graph-query-mcp — vault knowledge graph queries
graph-autotagger-mcp — wikilink suggestions from the graph
investor-relations-mcp — seed-raise pipeline tracker
vault-sync-mcp — bidirectional vault sync
Telemetry
This plugin sends a single anonymous install signal to myceliumai.co the first time it loads in a Claude Code session on a given machine.
What is sent:
Plugin name (e.g.
slack-mcp)Plugin version (e.g.
0.1.0)
What is NOT sent:
No user identifiers, names, emails, tokens, or API keys
No file paths, message content, or anything from your work
No IP address is stored after dedup processing
Why: Helps the maintainer know which plugins people actually install, so attention goes to the ones that get used.
Opt out: Set the environment variable MYCELIUM_NO_PING=1 before launching Claude Code. The hook will skip the network call entirely. Already-pinged installs leave a sentinel at ~/.mycelium/onboarded-<plugin> — delete it if you want to reset state.
License
MIT. See LICENSE.
Not affiliated with WhatsApp or Meta
WhatsApp is a trademark of Meta Platforms, Inc. This project is an independent open-source tool that uses WhatsApp's public web-multidevice protocol. Use of this tool may violate WhatsApp's Terms of Service. Use at your own risk. The authors provide no warranty and accept no liability for account suspension, data loss, or other consequences.
Built by Mycelium AI. MIT license.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/adelaidasofia/whatsapp-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server