APL tester setup

APL (All Purpose Login) gives agents one login layer over Google, Microsoft 365, WhatsApp, GitHub and the browser. This page gets it running on your machine in about 10 minutes so you can test it. No npm, no source code: one installer.

Supported: macOS on Apple Silicon (M1–M4) · Linux x86_64 (Ubuntu 22.04+, Debian 12+).
You will need: your own Google account (you will create your own Google Cloud project and OAuth app, free) and optionally your @reqsume.com mailbox. Nothing in this setup uses anyone else's account or app.

1Prerequisites

brew install node      # only for the browser agent; skip if you have node
python3 --version      # comes with Xcode command line tools

2Install

curl -fsSL https://hel1.your-objectstorage.com/publicassets/apl-kit/install.sh | sh

This puts apl, wacli (WhatsApp) and chrome-agent (browser) in ~/.local/bin and the browser engine (~170 MB) in ~/.local/share/chrome-agent. It also installs chrome-agent's site recipes (LinkedIn, X, Reddit, YouTube, HN, Medium, Substack and more, 54 verbs) into ~/chromeagent/recipes, and links the agent skills apl-skill and chrome-agent into Claude Code / Codex (~/.claude/skills, ~/.agents/skills) when those exist. Your own existing copies are never overwritten. Every file is checked against a SHA-256 list before install. Re-run any time to upgrade.

If the installer says so, add the folder to your PATH and open a new terminal:

echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.zshrc   # Linux bash: ~/.bashrc
apl version     # should print apl v0.5.x

3Create your own Google app and connect Google

APL signs in through an OAuth app that you own, in your own Google Cloud project. apl setup google creates all of it for you (project, APIs, consent screen, OAuth client); it needs the gcloud CLI.

brew install --cask google-cloud-sdk
gcloud auth login                 # sign in with YOUR Google account
apl setup google                  # follow the prompts; it prints the handle label at the end
apl login google:<label>          # e.g. google:work

On "Google hasn't verified this app", click Advanced → Go to … (unsafe) → Continue. It's your own app, unverified, which is expected.

Stop tokens expiring after 7 days (do this once)

  1. Open Google Auth Platform → Branding in your project. Fill in app name, support email and developer contact email. Save. Don't upload a logo (a logo forces Google's review).
  2. Go to Audience → Publish app → Confirm. Status should read In production.
  3. Sign in again so you get a long-lived token: apl login google:<label> --force

Already have an OAuth client of type Desktop app? Download its JSON and run apl setup google --client-secret-file ~/Downloads/client_secret.json instead.

4Connect your reqsume mailbox (Microsoft 365, optional)

apl setup ms registers an app for you in your Microsoft tenant and grants it Graph permissions (mail, calendar, Teams, files). It needs the Azure CLI.

brew install azure-cli            # Linux: https://learn.microsoft.com/cli/azure/install-azure-cli
az login                          # sign in with your @reqsume.com account
apl setup ms
apl login ms:<label>

If it says you're not allowed to register apps in the tenant, ask a reqsume admin. Don't borrow someone else's app.

5Check everything

apl accounts --check

Every line should say ok and name the right email. Anything else prints the exact fix in the last column. wrong_account means you picked a different account in the browser: run apl login <handle> --force and choose the right one.

6Try it

WhatCommand
Search all your mail + Teams at onceapl find "invoice"
Who is this person, everywhereapl contacts refresh then apl contacts resolve <name>
Raw Gmail API callapl call google:<label> GET https://gmail.googleapis.com/gmail/v1/users/me/profile
Your Outlook profileapl call ms:<label> GET https://graph.microsoft.com/v1.0/me
Today's calendarapl call google:<label> GET "https://www.googleapis.com/calendar/v3/calendars/primary/events?maxResults=5&orderBy=startTime&singleEvents=true&timeMin=$(date -u +%Y-%m-%dT00:00:00Z)"

7Browser agent (optional)

chrome-agent up https://www.linkedin.com     # opens the agent's own browser window
# sign in to the sites you want the agent to use, by hand, then:
chrome-agent auth linkedin.com               # should say signed_in: true

8Send us your result

Paste the output of these two to Muthu (they contain no passwords or tokens):

apl version; uname -sm
apl accounts --check

And anything that confused you, even small. That's the point of this test.

Remove everything

apl forget google:<label>; apl forget ms:<label>          # removes logins from THIS machine only
rm -rf ~/.local/bin/{apl,wacli,chrome-agent} ~/.local/share/chrome-agent ~/.config/apl

Use forget, not logout: logout revokes the login at Google/Microsoft everywhere.