Read only No injection Offline No risk control

CROSS-PLATFORM · LOCAL WECHAT KEY READER

Read its memory,
WeChat never notices.

No injection, no private-function calls, not a single byte changed — nothing for WeChat risk control to trip on. Recover the current account and the database, image and emoticon keys in under a second, with the same read-only boundary on macOS, Windows and Linux.

READ ONLY · 0 INJECTION · 0 NETWORK
wecha-key · read result
wechatIdwxid_demo••••
uin2056••••
dbMasterKeya1b2••••••••••••c3d4
imageAesKey5e6f••••••••••••7081
emoticonKey2c4d••••••••••••8e90
extendedKeys 20/20 LOCAL ONLY
0.4s read time
0 injection / network calls
3 operating systems
20/20 database keys verified

WHAT IT DOES / WHAT IT READS

WeChat is running.
The answer is in memory.

No injection, no WeChat private functions, and nothing sent to any server. One authorization, and the whole login context is clear in under a second.

Account context

Nickname, WeChat ID, alias and UIN — all tied to the account currently signed in.

Database keys

Read the master key, and verify each SQLCipher database under db_storage one by one.

Media keys

Image AES, emoticon AES and the XOR key — everything you need for local parsing later.

Quick copy

Copy items one by one or all at once. Keys are hidden by default to avoid shoulder-surfing.

HOW IT WORKS

One authorization,
the whole context in view.

From process discovery to key verification: a single pass over on-disk signatures, done in under a second, entirely in your local terminal or native UI — and fully scriptable.

  1. 1

    Find the WeChat process

    Locate the running WeChat and its PID automatically — no paths to type in.

  2. 2

    Locate the login context, read-only

    Read UIN, WeChat ID, nickname and keys from static signatures and memory structures.

  3. 3

    Verify the database keys

    Optionally scan db_storage and verify every database key against a SQLCipher page.

wecha-key / bash
# Example output: sensitive fields redacted
$ sudo wecha-key -x

keys
  dbMasterKey  : a1b2••••••••••••c3d4
  imageAesKey  : 5e6f••••••••••••7081
  xorKey       : 0x••

account
  wechatApp    : /Applications/WeChat.app
  databaseDir  : ~/Library/.../wxid_demo••/db_storage
  uin          : 2056••••
  wechatId     : wxid_demo••••
  alias        : demo_user
  nickname     : Demo User
  phone        : 13••••••07
  smallHeadUrl : https://wx.qlogo.cn/mmhead/.../••••/132

extendedKeys
  dbDir        : ~/Library/.../wxid_demo••/db_storage
  format       : sqlCipher4
  matched      : 20/20
  contact.db   : encKey c9••••••49 · salt c4••••••28 · ok
  message_0.db : encKey 79••••••13 · salt 7a••••••6e · ok
  ... 18 more database keys redacted ...

$ sudo wecha-key
keys  dbMasterKey a1b2••••••••••••c3d4 · imageAesKey 5e6f••••••••••••7081 · xorKey 0x••
account  wechatId wxid_demo•••• · uin 2056•••• · nickname Demo User

CHOOSE YOUR SURFACE

Three systems,
one read-only boundary.

macOS, Windows and Linux share the same read-only mechanism and output format. The desktop gives you a native reader; servers and dev boxes keep the familiar command-line flow.

01 / MACOS

A familiar native reader

Finds WeChat automatically and reads extended database keys on demand. Admin rights go only to a one-shot helper; the app itself always runs as the current user.

  • Apple Silicon & Intel
  • Native SwiftUI interface
  • Installs straight from DMG

WHY IT STAYS INVISIBLE

WeChat never knows
you read it.

Risk control watches for injection, hooks and abnormal network behavior. Wecha Key only reads memory from outside the process and touches none of those paths — there is nothing to detect, so nothing trips risk control or triggers a ban.

READ ONLY

Read-only access to the WeChat process: no memory writes, no database writes — WeChat's own state is untouched.

NO INJECTION

No dylib injection, no hooks, no WeChat private-function calls — none of the behaviors risk control looks for.

NO NETWORK

No upload path at all. Results stay in the current process memory, cleared when you close the window — nothing written to disk.

SAME ACCOUNT

Only resolves keys for the account already signed in on your machine; it never changes the login state or interferes with normal WeChat use.

READY WHEN WECHAT IS

Pick your build.

macOS Apple Silicon / Intel · DMG arm64 x64
Windows x64 · ZIP · 136 KB Download
Linux Single-file CLI x64 arm64
SHA-256 checksums
macOS arm64
dfd465ea467d8003f78407512676d4789e5b55be67110721ab773d70bc79c26b
macOS x64
b9a24a47af19eadb6bc93b5616c81d02c28ff7736eae01fa6f6d8553cda51ef8
Windows x64
4dff5a7ec46b4295d1572799f4ad9a28e19c185dc6e9a4c1933fa76353b173c6
Linux x64
6f843586da485bdd141fb657b5905d71361a7f58c8386ffacf47ace2816739a5
Linux arm64
67db47ddbfb5323c15c3e6cc0ce7e5ed7819ead4e94a491a152f9cc1b5e1acc0

BEFORE YOU READ

FAQ

Will it trip WeChat risk control or get my account banned?

No. Risk control mainly detects injection, hooks, memory tampering and abnormal network behavior. Wecha Key reads memory from outside the WeChat process — no injection, no hooks, no private-function calls, not a single byte changed, and no network requests. There is nothing for risk control to detect, and WeChat's login state and status stay exactly the same.

Why does it need admin rights?

Operating systems forbid an ordinary process from reading another process's memory by default. Wecha Key requests admin rights only while reading, and never receives or stores your system password.

Does it modify WeChat or the databases?

No. The probe only reads the WeChat process, and reads just the first database page for key verification — it never injects code into WeChat and never writes to the databases.

How fast is it?

From on-disk signature scanning to key resolution in a single pass — sub-second in practice (about 0.4s on macOS). Keys are printed before the account details, so you don't wait for everything to finish.

Are the results uploaded?

No. The desktop app makes no network requests; results stay only in the current window and process memory.

When should I use it?

Only on devices, accounts and data you are authorized to access. Follow your local laws, platform terms and your organization's data-security requirements.