APL tester setup
APL (All Purpose Login) gives agents one login layer over Google, Microsoft 365, WhatsApp, GitHub and the browser. This page gets it running on your machine in about 10 minutes so you can test it. No npm, no source code: one installer.
You will need: your own Google account (you will create your own Google Cloud project and OAuth app, free) and optionally your
@reqsume.com mailbox. Nothing in this setup uses anyone else's account or app.1Prerequisites
brew install node # only for the browser agent; skip if you have node
python3 --version # comes with Xcode command line toolssudo apt install -y curl nodejs python3
# optional, to sign in to websites from your laptop (step 7):
sudo apt install -y xvfb x11vnc novnc websockify
# + cloudflared: https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/downloads/
Install as your normal user, not root. The browser part refuses to run as root.
2Install
curl -fsSL https://hel1.your-objectstorage.com/publicassets/apl-kit/install.sh | sh
This puts apl, wacli (WhatsApp) and chrome-agent (browser) in ~/.local/bin and the browser engine (~170 MB) in ~/.local/share/chrome-agent. It also installs chrome-agent's site recipes (LinkedIn, X, Reddit, YouTube, HN, Medium, Substack and more, 54 verbs) into ~/chromeagent/recipes, and links the agent skills apl-skill and chrome-agent into Claude Code / Codex (~/.claude/skills, ~/.agents/skills) when those exist. Your own existing copies are never overwritten. Every file is checked against a SHA-256 list before install. Re-run any time to upgrade.
If the installer says so, add the folder to your PATH and open a new terminal:
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.zshrc # Linux bash: ~/.bashrc
apl version # should print apl v0.5.x
3Create your own Google app and connect Google
APL signs in through an OAuth app that you own, in your own Google Cloud project. apl setup google creates all of it for you (project, APIs, consent screen, OAuth client); it needs the gcloud CLI.
brew install --cask google-cloud-sdk# https://cloud.google.com/sdk/docs/install#deb (apt repo), then open a new terminalgcloud auth login # sign in with YOUR Google account
apl setup google # follow the prompts; it prints the handle label at the end
apl login google:<label> # e.g. google:work
On "Google hasn't verified this app", click Advanced → Go to … (unsafe) → Continue. It's your own app, unverified, which is expected.
Stop tokens expiring after 7 days (do this once)
- Open Google Auth Platform → Branding in your project. Fill in app name, support email and developer contact email. Save. Don't upload a logo (a logo forces Google's review).
- Go to Audience → Publish app → Confirm. Status should read In production.
- Sign in again so you get a long-lived token:
apl login google:<label> --force
Already have an OAuth client of type Desktop app? Download its JSON and run apl setup google --client-secret-file ~/Downloads/client_secret.json instead.
4Connect your reqsume mailbox (Microsoft 365, optional)
apl setup ms registers an app for you in your Microsoft tenant and grants it Graph permissions (mail, calendar, Teams, files). It needs the Azure CLI.
brew install azure-cli # Linux: https://learn.microsoft.com/cli/azure/install-azure-cli
az login # sign in with your @reqsume.com account
apl setup ms
apl login ms:<label>
If it says you're not allowed to register apps in the tenant, ask a reqsume admin. Don't borrow someone else's app.
5Check everything
apl accounts --check
Every line should say ok and name the right email. Anything else prints the exact fix in the last column. wrong_account means you picked a different account in the browser: run apl login <handle> --force and choose the right one.
6Try it
| What | Command |
|---|---|
| Search all your mail + Teams at once | apl find "invoice" |
| Who is this person, everywhere | apl contacts refresh then apl contacts resolve <name> |
| Raw Gmail API call | apl call google:<label> GET https://gmail.googleapis.com/gmail/v1/users/me/profile |
| Your Outlook profile | apl call ms:<label> GET https://graph.microsoft.com/v1.0/me |
| Today's calendar | apl call google:<label> GET "https://www.googleapis.com/calendar/v3/calendars/primary/events?maxResults=5&orderBy=startTime&singleEvents=true&timeMin=$(date -u +%Y-%m-%dT00:00:00Z)" |
7Browser agent (optional)
chrome-agent up https://www.linkedin.com # opens the agent's own browser window
# sign in to the sites you want the agent to use, by hand, then:
chrome-agent auth linkedin.com # should say signed_in: trueOn a server there is no screen. share gives you a private, time-limited link to the server's browser so you can sign in from your laptop:
chrome-agent share start --ttl 30m # prints a one-time link; open it on your laptop
chrome-agent share stop # or let it expire
Logins stay in the server's profile after the link expires.
8Send us your result
Paste the output of these two to Muthu (they contain no passwords or tokens):
apl version; uname -sm
apl accounts --check
And anything that confused you, even small. That's the point of this test.
Remove everything
apl forget google:<label>; apl forget ms:<label> # removes logins from THIS machine only
rm -rf ~/.local/bin/{apl,wacli,chrome-agent} ~/.local/share/chrome-agent ~/.config/apl
Use forget, not logout: logout revokes the login at Google/Microsoft everywhere.