
最近做的企微二开开发团队要求在企微里能远程让 Claude Code 写代码——发条消息给订单接口加个参数校验Claude Code 执行代码修改并回结果。和之前聊的远程控制机器人不同那篇是执行运维命令这篇是 Claude Code 这种编程 Agent 的对接——企微消息触发 Claude Code、代码修改结果回传、代码审查闭环。把怎么对接记下来。Eyun 平台开放的企微 API统一 POSTJSON鉴权用 App Token 加 appidAuthorization: Bearer eyk_xxxx路径{BASE_URL}/wx-api/api/模块/动作响应封套{code, data, detail, message, time}code 为 0 成功。Claude Code 和企微的分工Claude Code 是编程 Agent能读写代码、跑测试、提交 commit。企微是消息通道——开发在企微发指令后端转发给 Claude CodeClaude Code 修改代码后结果回企微。分工明确企微 API消息收发、权限校验、结果推送Claude Code代码理解、修改、测试、提交后端桥接层转发、权限、审计指令接收Webhook 收开发指令开发在企微发给订单接口加参数校验Webhook 回调from flask import Flask, request app Flask(__name__) app.route(/wx-api/webhook/, methods[POST]) def webhook(): event request.headers.get(X-Eyun-Event) if event ! message: return ok payload request.json[data] appid payload[appid] from_uin payload[fromUin] content payload[content] # 权限校验只有开发能发指令 if not is_developer(from_uin): return ok # 转给Claude Code处理 process_coding_task.delay(appid, from_uin, content) return ok回调机制在 Eyun 平台开发文档里有说明。权限是第一道——只有开发能触发编程指令非开发发的消息不处理。Claude Code 调用调 Claude Code 的 API带上代码仓库信息和任务描述import requests CLAUDE_API https://api.anthropic.com/v1/code CLAUDE_KEY sk-ant-xxxx def call_claude_code(task, repo_path): resp requests.post( CLAUDE_API, headers{Authorization: fBearer {CLAUDE_KEY}}, json{ task: task, repo_path: repo_path, constraints: [ 修改前先跑测试确保通过, 提交前做代码审查, 不要修改无关文件 ] }, timeout120 # 编码可能慢 ) return resp.json()constraints约束 Claude Code 的行为——先测试、审查、不乱改。不约束Claude Code 可能改一堆无关文件代码库乱。结果回传调消息接口Claude Code 执行完结果回传到企微import requests BASE https://api.eyun.com HEADERS {Authorization: Bearer eyk_xxxx, Content-Type: application/json} def reply_result(appid, to_uin, result): if result[status] success: text f任务完成\n修改文件{, .join(result[files])}\n测试通过\ncommit{result[commit_id][:8]} else: text f任务失败\n原因{result[error]} requests.post( f{BASE}/wx-api/api/message/sendText, headersHEADERS, json{appid: appid, to: to_uin, content: text} )结果包含修改了哪些文件、测试有没有过、commit ID。开发在企微看到就知道改了什么。代码 diff 发卡片调 sendRichText代码 diff 适合发卡片带链接让开发点进去看def send_diff_card(appid, to_uin, commit_id, files): card { title: f代码修改 {commit_id[:8]}, description: f修改文件{len(files)} 个, url: fhttps://git.example.com/commit/{commit_id}, buttons: [ {text: 查看diff, url: fhttps://git.example.com/commit/{commit_id}}, {text: 回滚, action: revert, data: {commit_id: commit_id}} ] } requests.post( f{BASE}/wx-api/api/message/sendRichText, headersHEADERS, json{appid: appid, to: to_uin, cards: [card]} )卡片带回滚按钮——开发觉得改得不对一点就回滚。不做回滚入口改错了要手动去 Git 操作麻烦。关于消息卡片和交互在Eyun 企业微信 API 平台有说明。权限和审计编程是高危操作权限和审计要严def is_developer(uin): staff get_staff(uin) return staff.get(role) in [developer, tech_lead] # 审计日志 audit_log.create( whofrom_uin, taskcontent, filesresult[files], commitresult[commit_id], timestampnow() )只有 developer 和 tech_lead 角色能发指令。审计日志记谁、什么时候、改了什么、哪个 commit。不做审计代码被乱改不知道谁干的。安全边界Claude Code 能改代码安全边界要明确只能改指定仓库不能碰生产配置不能直接 push 到 main 分支要走 PR敏感文件密钥、配置不能改改完要跑测试测试不过不能提交def call_claude_code_safe(task, repo_path): # 检查仓库是否在白名单 if repo_path not in ALLOWED_REPOS: return {status: error, error: 仓库不在允许列表} result call_claude_code(task, repo_path) # 检查是否改了敏感文件 for f in result[files]: if f.endswith((.env, config.py, credentials)): return {status: error, error: f不允许修改敏感文件 {f}} return result不做安全边界Claude Code 把生产配置改了事故无法挽回。关于接口权限和安全管理在开发文档里有。写在最后连接 Claude Code 这套东西本质是做个桥接层——企微 Webhook 收开发指令、转发给 Claude Code 执行、结果通过 sendText 或 sendRichText 回传、带回滚按钮、审计日志、安全边界。里。把权限做严、安全边界做对、审计做实开发在企微里发条消息就能让 Claude Code 写代码——但每一步可控可追溯。