The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the HuaweiCloud DevKit (Community Preview) listing page.
中文 | English
Help AI coding agents use Huawei Cloud safely and accurately — a single integration that gives agents cloud knowledge, CLI tooling, and safety guardrails.
Supports OpenCode, Codex, CodeArts Agent, WorkBuddy, DeepSeek Harness (DSH), OfficeAce, Hermes, OpenClaw, and AtomCode.
China mainland users: If you experience slow downloads or connection issues with the default npm registry, configure the Huawei Cloud npm mirror:
Restore the default registry:
npm config delete registryMirror lag: npm mirrors (npmmirror, mirrors.huaweicloud.com) may lag behind the official registry for hours after a new release. If install fails with
ETARGETor you get an older version, install via the official registry instead:
If
--targetis omitted, the installer auto-detects agents on your machine:
- None detected: interactive terminals ask what you want (install to one explicit target / install to all / wire up a generic MCP agent); non-interactive shells error out with the supported target list.
- One detected: installs directly to it.
- Multiple detected: interactive terminals show a multi-select chooser; non-interactive shells error and point at
--target <agent>/--target all. For a one-shot full setup, runnpx --yes huaweicloud-devkit install --target all(Codex is skipped when its CLI is missing).
The commands below are global (they act on every agent):
Restart the session after installation.
Restart the Codex session after installation.
Then mention @huaweicloud-devkit in Codex or describe your Huawei Cloud task directly.
Requires Codex CLI — the
codexcommand must be in PATH. If Codex is installed via WindowsApps (Microsoft Store), use--target codex-desktopinstead. Runcodex --versionto verify CLI availability.
Use this target when the Codex CLI is unavailable or when Codex is installed through WindowsApps on Windows.
Restart the Codex Desktop session after installation.
Then mention @huaweicloud-devkit in a new Codex Desktop task or describe your Huawei Cloud task directly.
Restart the session after installation.
Sandbox mode: CodeArts defaults to sandbox mode which blocks KooCLI.
install-hclouddetects this and shows how to resolve it — install KooCLI outside the sandbox terminal, or disable sandbox mode in CodeArts settings (Settings → Chats → Agents Terminal Command Running Mode → Auto Running).
Restart the session after installation.
CodeArts Work (CodeArts Space, appId:
com.codearts.work) uses user-level config at%USERPROFILE%\.codeartswork\. No project-level.codeartsworkdirectory is created.
Restart the session after installation.
Restart the DSH session after installation.
DSH V1 reuses the existing MCP server through
@deepseek-ai/dsh-mcp-client. If the installer reports that the client is not detected, run:npx @deepseek-ai/dsh plugin --profile web add @deepseek-ai/dsh-mcp-client.
Restart OfficeAce after installation.
Restart the Hermes session after installation.
Uninstall notes: On Linux, run
rm -rf ~/.npm/_npx/* && npm cache clean --forceafter uninstall to ensure a clean slate. On Windows, close all Hermes sessions first to release file locks, then after uninstall check%LOCALAPPDATA%\hermes\config.yamlfor YAML corruption and manually remove%LOCALAPPDATA%\hermes\huaweicloud-pluginsif any files remain. Safety hooks: The installer configures Hermes shell hooks (config.yaml→hooks.pre_tool_call) to intercept unsafe terminal commands such as credential file reads, environment variable dumps, and unapprovedhcloudwrite operations. Hermes shows a consent prompt the first time; approve it or sethooks_auto_accept: trueinconfig.yamlto auto-accept. MCP Python SDK: The installer automatically installs themcpPython package required by Hermes for MCP tool discovery. If you see[FAIL] Hermes MCP Python SDKindoctor, runpip3 install mcpmanually. Windows: See docs/hermes-windows.md for known issues and workarounds.
Restart OpenClaw after installation. If prompted for security risk acknowledgment, add --acknowledge-clawhub-risk.
Restart the AtomCode session after installation.
Any agent that supports MCP can use the standard config:
No installation required — npx handles everything.
For manual MCP registrations like this, do not put credentials in the config.
HW_ACCESS_KEY/HW_SECRET_KEYare reserved for platform/CI-injected accounts (e.g. a DevSpace-managed default account) — configure your own account vianpx huaweicloud-devkit auth init(the single entry point), and switch accounts at runtime with thehuaweicloud_auth_init/huaweicloud_auth_switchMCP tools. Seeplugins/huaweicloud-core/skills/huaweicloud-cli-and-auth/SKILL.mdfor the full credential-resolution priority.
If your agent supports type: "remote" (Streamable HTTP) instead of stdio, start the devkit remote MCP server locally first:
It listens on 127.0.0.1:9528 by default. Then connect with a remote config (opencode example):
Use
--port <port>if 9528 is taken and updateurlaccordingly; add--host 0.0.0.0for LAN access. The remote server has no built-in auth — do not expose it anonymously to the public internet.
Synchronizes AK/SK to KooCLI, OBS, and sandbox APIs in one step — this is the single entry point. Never hard-code AK/SK into agent or shell config.
Account switching at runtime (within an agent session): use the MCP tools huaweicloud_auth_init (in-memory, highest priority) or huaweicloud_auth_switch (actions: temporary / persist / clear). In sandbox/DevSpace environments where a default account is injected via HW_ACCESS_KEY/HW_SECRET_KEY, a plain auth init will not override it — use huaweicloud_auth_switch action=persist to make the session account win.
Credential resolution priority (highest first):
| # | Source | Set by |
|---|---|---|
| 1 | Runtime (session) credentials | huaweicloud_auth_init / huaweicloud_auth_switch action=temporary |
| 2 | S1 global file with configuredBySession: true | huaweicloud_auth_switch action=persist |
| 3 | Environment variables (HW_ACCESS_KEY/HW_SECRET_KEY) | platform/DevSpace-injected default account |
| 4 | CodeArts / CodeArts Work | .codeartsdoer/mcp/mcp_settings.json / .codeartswork/mcp/mcp_settings.json |
| 5 | S1 global file (no session flag) | auth init |
| 6 | KooCLI profile | ~/.hcloud/config.json (KooCLI commands only) |
Security: never put your own AK/SK into the MCP config
envfield — they'd be stored in plaintext and could leak if the config file is committed to git.envis for platform/CI injection only.
Full details: plugins/huaweicloud-core/skills/huaweicloud-cli-and-auth/SKILL.md.
update is incremental — it refreshes installed files without touching your
config. Always keep @latest so npm fetches the newest version instead of a
locally cached older one.
Configures HTTP/HTTPS proxy for connections to Huawei Cloud services (e.g. enterprise intranet environments). Settings are saved to ~/.config/huaweicloud/proxy.json.
Environment variables HTTPS_PROXY, HTTP_PROXY, and NO_PROXY take precedence over the file configuration — use proxy show to inspect the effective settings.
ECS, OBS, VPC, IAM, RDS, GaussDB, FunctionGraph, APIG, CCE, SMN/DMS, ModelArts, Cloud Eye, CTS, DEW, Billing, CBR, WAF/AAD, DDS/DCS, Deployment, and Getting Started guides.
Above is the pre-wired guidance list; the remaining 200+ Huawei Cloud services are still reachable via KooCLI / API / SDK routing (see capability-discovery and cli-and-auth meta-skills).
This project is licensed under the Apache-2.0 License. See LICENSE.