Set Up WeChat

View as Markdown

WeChat support is experimental and uses Tencent’s iLink gateway. The supported mode in this release is personal WeChat with bot_type=3. WeChat Official Account and WeCom or Enterprise WeChat are not wired up.

Understand the Pairing Flow

NemoClaw runs QR login on the host during nemoclaw onboard or channels add wechat because the bot token exists only after a successful iLink handshake. Scan the QR with WeChat on your phone through Discover and Scan, then confirm the login. NemoClaw captures the token, accountId, baseUrl, and userId from the iLink response. The QR flow accepts only Tencent’s two static iLink hosts or an account-specific idc-<number>.weixin.qq.com origin returned during pairing. NemoClaw rejects HTTP, ports, paths, credentials, and unrecognized redirect hosts before it contacts them or saves the login result. If pairing reports an invalid IDC redirect host, restart the QR flow. If the error repeats, preserve the error text without sharing tokens or verbose diagnostics and file an issue.

NemoClaw registers the token as the <sandbox>-wechat-bridge OpenShell provider and supplies a revision-scoped OpenShell credential placeholder inside the sandbox. The token does not land in the image or on disk inside the running container.

NemoClaw writes the non-secret WECHAT_ACCOUNT_ID, WECHAT_BASE_URL, and WECHAT_USER_ID metadata into the image’s channel configuration. Together with the credential placeholder, this metadata lets the bridge start without another QR handshake.

Configure Access

WeChat is DM-only with allowIdsMode: "dm". NemoClaw adds the operator who scanned the QR to WECHAT_ALLOWED_IDS automatically.

You can append more comma-separated WeChat user IDs through the same variable. If you want to suppress host-side QR-login diagnostics, set NEMOCLAW_WECHAT_QUIET=1 before nemoclaw onboard or nemoclaw <sandbox> channels add wechat. This setting suppresses [wechat] poll diagnostics, including status updates and recoverable errors, but not host-side IDC redirect notices or in-sandbox WeChat diagnostics.

Tencent’s iLink gateway is a third-party service. Review your organization’s terms-of-service, compliance, and data-residency constraints before enabling WeChat.

Continue with Enable Channels During Onboarding or Add Channels After Onboarding.