
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
whatsapp-messaging-api-mcp
Advanced tools
MCP server for sending WhatsApp messages from Claude and other MCP clients. No Meta Business approval, no WhatsApp Business account — scan a QR code and send.
Send WhatsApp messages from Claude, Cursor, or any MCP client. Create a session, scan a QR code, and send text, images and files — no Meta Business approval and no WhatsApp Business account required.
Wraps the WhatsApp Messaging API.
Get a free API key from RapidAPI — no credit card.
Add this to your MCP client config (Claude Desktop: claude_desktop_config.json):
{
"mcpServers": {
"whatsapp": {
"command": "npx",
"args": ["-y", "whatsapp-messaging-api-mcp"],
"env": {
"WHATSAPP_API_KEY": "your-rapidapi-key"
}
}
}
}
Restart the client. Ask it to create a WhatsApp session and show you the QR code.
Nothing to install or build — npx fetches the package on first run.
| Tool | Description |
|---|---|
list_sessions | List all sessions on this API key |
create_session | Create a new session |
get_session_status | Check a session's current status |
get_qr_code | Get the QR code to authenticate a session |
request_pairing_code | Get an 8-digit pairing code instead of a QR |
check_contact_exists | Check if a phone number is on WhatsApp before sending |
send_text_message | Send a text message |
send_image | Send an image via URL |
send_file | Send a file (PDF, document) via URL |
create_session → get_qr_code → scan with WhatsApp (Settings → Linked Devices)get_session_status until it reports WORKINGcheck_contact_exists, then send_text_message / send_image / send_fileSessions stay authenticated between runs, so steps 1-2 are one-time per number.
| Variable | Required | Description |
|---|---|---|
WHATSAPP_API_KEY | yes | Your RapidAPI key. The server exits on startup if it is missing. |
The key is read from the environment and sent only to the API host. It is never logged.
git clone https://github.com/jevil25/whatsapp-messaging-api-mcp.git
cd whatsapp-messaging-api-mcp
npm install
npm run dev # runs src/index.ts directly via tsx, no build step
npm run build # compile to dist/
npm test # boots the built server and drives a real MCP handshake
npm test needs no credentials — it passes a dummy key, which gets far enough to
list tools because nothing in the handshake makes an API call.
To point an MCP client at your local build, use "command": "node" with
"args": ["/absolute/path/to/dist/index.js"].
See DEVELOPING.md for the release process.
io.github.jevil25/whatsapp-messaging-api-mcpMIT
FAQs
MCP server for sending WhatsApp messages from Claude and other MCP clients. No Meta Business approval, no WhatsApp Business account — scan a QR code and send.
The npm package whatsapp-messaging-api-mcp receives a total of 26 weekly downloads. As such, whatsapp-messaging-api-mcp popularity was classified as not popular.
We found that whatsapp-messaging-api-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.