Account context
Nickname, WeChat ID, alias and UIN — all tied to the account currently signed in.
CROSS-PLATFORM · LOCAL WECHAT KEY READER
No injection, no private-function calls, not a single byte changed — nothing for WeChat risk control to trip on. Recover the current account and the database, image and emoticon keys in under a second, with the same read-only boundary on macOS, Windows and Linux.
WHAT IT DOES / WHAT IT READS
No injection, no WeChat private functions, and nothing sent to any server. One authorization, and the whole login context is clear in under a second.
Nickname, WeChat ID, alias and UIN — all tied to the account currently signed in.
Read the master key, and verify each SQLCipher database under db_storage one by one.
Image AES, emoticon AES and the XOR key — everything you need for local parsing later.
Copy items one by one or all at once. Keys are hidden by default to avoid shoulder-surfing.
HOW IT WORKS
From process discovery to key verification: a single pass over on-disk signatures, done in under a second, entirely in your local terminal or native UI — and fully scriptable.
Locate the running WeChat and its PID automatically — no paths to type in.
Read UIN, WeChat ID, nickname and keys from static signatures and memory structures.
Optionally scan db_storage and verify every database key against a SQLCipher page.
# Example output: sensitive fields redacted
$ sudo wecha-key -x
keys
dbMasterKey : a1b2••••••••••••c3d4
imageAesKey : 5e6f••••••••••••7081
xorKey : 0x••
account
wechatApp : /Applications/WeChat.app
databaseDir : ~/Library/.../wxid_demo••/db_storage
uin : 2056••••
wechatId : wxid_demo••••
alias : demo_user
nickname : Demo User
phone : 13••••••07
smallHeadUrl : https://wx.qlogo.cn/mmhead/.../••••/132
extendedKeys
dbDir : ~/Library/.../wxid_demo••/db_storage
format : sqlCipher4
matched : 20/20
contact.db : encKey c9••••••49 · salt c4••••••28 · ok
message_0.db : encKey 79••••••13 · salt 7a••••••6e · ok
... 18 more database keys redacted ...
$ sudo wecha-key
keys dbMasterKey a1b2••••••••••••c3d4 · imageAesKey 5e6f••••••••••••7081 · xorKey 0x••
account wechatId wxid_demo•••• · uin 2056•••• · nickname Demo User
CHOOSE YOUR SURFACE
macOS, Windows and Linux share the same read-only mechanism and output format. The desktop gives you a native reader; servers and dev boxes keep the familiar command-line flow.
01 / MACOS
Finds WeChat automatically and reads extended database keys on demand. Admin rights go only to a one-shot helper; the app itself always runs as the current user.
02 / WINDOWS
Recognizes multiple WeChat processes, starts an admin worker when needed, and returns the result safely to the current window.
01 process found
02 login context located
03 keys verified
03 / LINUX
No runtime required — do process discovery, key reading and database verification right in the terminal. Supports x86_64 and arm64.
WHY IT STAYS INVISIBLE
Risk control watches for injection, hooks and abnormal network behavior. Wecha Key only reads memory from outside the process and touches none of those paths — there is nothing to detect, so nothing trips risk control or triggers a ban.
Read-only access to the WeChat process: no memory writes, no database writes — WeChat's own state is untouched.
No dylib injection, no hooks, no WeChat private-function calls — none of the behaviors risk control looks for.
No upload path at all. Results stay in the current process memory, cleared when you close the window — nothing written to disk.
Only resolves keys for the account already signed in on your machine; it never changes the login state or interferes with normal WeChat use.
READY WHEN WECHAT IS
BEFORE YOU READ
No. Risk control mainly detects injection, hooks, memory tampering and abnormal network behavior. Wecha Key reads memory from outside the WeChat process — no injection, no hooks, no private-function calls, not a single byte changed, and no network requests. There is nothing for risk control to detect, and WeChat's login state and status stay exactly the same.
Operating systems forbid an ordinary process from reading another process's memory by default. Wecha Key requests admin rights only while reading, and never receives or stores your system password.
No. The probe only reads the WeChat process, and reads just the first database page for key verification — it never injects code into WeChat and never writes to the databases.
From on-disk signature scanning to key resolution in a single pass — sub-second in practice (about 0.4s on macOS). Keys are printed before the account details, so you don't wait for everything to finish.
No. The desktop app makes no network requests; results stay only in the current window and process memory.
Only on devices, accounts and data you are authorized to access. Follow your local laws, platform terms and your organization's data-security requirements.