MoreLogin Local API Skill
Manage browser profiles and cloud phones via MoreLogin official Local API, supporting full lifecycle control, automation connections (CDP/ADB), and resource management (proxy/group/tag/app/file).
Official Sources
Trigger Scenarios
Prefer this Skill when:
- User mentions
MoreLogin, envId, uniqueId, cloudphone
- Creating/starting/closing browser profiles
- Refreshing fingerprints, clearing cache, or deleting profiles
- Cloud phone power on/off, ADB, app management, file upload
- API management of proxy, groups, tags
Pre-flight Checklist
Before any operation:
- Confirm MoreLogin desktop app is running and logged in.
- Confirm API is reachable:
http://127.0.0.1:40000.
- Confirm requests originate from localhost (Local API does not support remote access).
- For cloud phone command execution, confirm ADB is available (
adb installed).
Execution Principles
- Treat
local-api.yaml + API-CONTRACT.md as the canonical parameter source before constructing payloads.
- Do not infer field names from memory; verify required keys/types first (especially
id vs ids, object vs array bodies).
- Use
POST by default (except tag query GET /api/envtag/all).
- Uniform request header:
Content-Type: application/json.
- Check
code first: 0 means success, non-zero use msg for error handling.
- Prefer
envId for resource lookup; fall back to uniqueId when missing (browser profiles).
- For batch endpoints (
/batch), always pass arrays and record changed objects.
API Capability Mapping
Browser Profile
| Endpoint |
Purpose |
POST /api/env/create/quick |
Quick create profile |
POST /api/env/create/advanced |
Advanced create (full fingerprint params) |
POST /api/env/fingerprint/refresh |
Refresh device fingerprint |
POST /api/env/start |
Start profile and return debug info |
POST /api/env/close |
Close running profile |
POST /api/env/status |
Get run status and debug info |
POST /api/env/page |
Paginated profile list |
POST /api/env/detail |
Get single profile detail |
POST /api/env/removeLocalCache |
Clear local cache (cookies/localStorage etc.) |
POST /api/env/removeToRecycleBin/batch |
Batch delete to recycle bin |
Cloud Phone
| Endpoint |
Purpose |
POST /api/cloudphone/create |
Create cloud phone |
POST /api/cloudphone/powerOn |
Power on |
POST /api/cloudphone/powerOff |
Power off |
POST /api/cloudphone/page |
Paginated list |
POST /api/cloudphone/info |
Get detail (including ADB info) |
POST /api/cloudphone/edit/batch |
Batch edit config |
POST /api/cloudphone/delete/batch |
Batch delete |
POST /api/cloudphone/newMachine |
One-click new device |
POST /api/cloudphone/updateAdb |
Enable/disable ADB |
Cloud Phone File & App
| Endpoint |
Purpose |
POST /api/cloudphone/uploadFile |
Upload file to cloud phone |
POST /api/cloudphone/uploadUrl |
Query upload status |
POST /api/cloudphone/setKeyBox |
Set Keybox |
POST /api/cloudphone/app/install |
Install app |
POST /api/cloudphone/app/page |
Query app market list |
POST /api/cloudphone/app/installedList |
Query installed apps |
POST /api/cloudphone/app/start |
Start app |
POST /api/cloudphone/app/restart |
Restart app |
POST /api/cloudphone/app/stop |
Stop app |
POST /api/cloudphone/app/uninstall |
Uninstall app |
Proxy / Group / Tag
| Endpoint |
Purpose |
POST /api/proxyInfo/page |
Query proxy list |
POST /api/proxyInfo/add |
Add proxy |
POST /api/proxyInfo/update |
Update proxy |
POST /api/proxyInfo/delete |
Delete proxy |
POST /api/envgroup/page |
Query groups |
POST /api/envgroup/create |
Create group |
POST /api/envgroup/edit |
Edit group |
POST /api/envgroup/delete |
Delete group |
GET /api/envtag/all |
Get all tags |
POST /api/envtag/create |
Create tag |
POST /api/envtag/edit |
Edit tag |
POST /api/envtag/delete |
Delete tag |
Standard Workflows
Workflow A: Browser Profile Automation
- Get
envId from create/quick or page.
- Call
start to launch the profile.
- Call
status to verify run state and debugPort.
- Use CDP (Puppeteer/Playwright) for automation.
- Call
close when done.
Workflow B: Cloud Phone Automation
- Call
page or create to obtain cloud phone id.
- Call
powerOn to start.
- Call
info to get ADB connection params.
- Call
updateAdb when needed to enable ADB.
- Run supported cloud phone management endpoints only (no direct command execution).
- Call
powerOff when done.
Quick Examples (Official API)
# 1) Quick create browser profile
curl -X POST "http://127.0.0.1:40000/api/env/create/quick" \
-H "Content-Type: application/json" \
-d '{"browserTypeId":1,"operatorSystemId":1,"quantity":1}'
# 2) Start profile
curl -X POST "http://127.0.0.1:40000/api/env/start" \
-H "Content-Type: application/json" \
-d '{"envId":"<envId>"}'
# 3) Cloud phone power on
curl -X POST "http://127.0.0.1:40000/api/cloudphone/powerOn" \
-H "Content-Type: application/json" \
-d '{"id":"<cloudPhoneId>"}'
# 4) Query cloud phone detail (including ADB info)
curl -X POST "http://127.0.0.1:40000/api/cloudphone/info" \
-H "Content-Type: application/json" \
-d '{"id":"<cloudPhoneId>"}'
CLI Usage (This Project)
Prefer project-wrapped commands; fall back to curl when needed:
Entry equivalence note: openclaw morelogin ... and node bin/morelogin.js ... are fully equivalent (same arguments, same behavior, same exit code). Use either one based on your runtime environment.
# Browser profile
openclaw morelogin browser list
openclaw morelogin browser start --env-id <envId>
openclaw morelogin browser status --env-id <envId>
openclaw morelogin browser close --env-id <envId>
# Cloud phone
openclaw morelogin cloudphone list
openclaw morelogin cloudphone start --id <cloudPhoneId>
openclaw morelogin cloudphone info --id <cloudPhoneId>
## Response & Error Handling
Parse responses with the following structure:
```json
{
"code": 0,
"msg": null,
"data": {},
"requestId": "..."
}
Handling rules:
code == 0: Proceed, extract data.
code != 0: Output msg, mark failed step, suggest next fix.
- For
start/powerOn operations, call status/info again before subsequent steps to confirm.
Security & Limits
- Local API listens on localhost only; no remote access.
- Can be called only when MoreLogin account is logged in.
- Do not expose account, proxy passwords, ADB keys, or other sensitive data in logs or code.
- Double-check target ID lists before batch delete, cache clear, or app uninstall.
Security Notice
This skill no longer provides local ADB/SSH connection methods (adb-connect, adb-disconnect, adb-devices).
Command execution safeguards:
- Restricted to local automation context (localhost workflows and local API).
- Remote cloud phone
exec is disabled by default and must be explicitly enabled.
exec command content is validated against a safe allowlist and blocks shell metacharacters.
- Generic
api passthrough is endpoint-allowlisted by default.
When Not to Use This Skill
- MoreLogin is not installed, not running, or not logged in.
- Requirements are for regular browser automation (no MoreLogin environment isolation).
- Requirements depend on remote access to Local API over the network.
Related Files
bin/morelogin.js
lib/api.js
local-api.yaml
API-CONTRACT.md
README-OFFICIAL-API.md
1---2name: morelogin3description: Manage MoreLogin anti-detect browser profiles and cloud phones through the official Local API (http://127.0.0.1:40000), including browser profile lifecycle, fingerprint refresh, cloud phone power/file/app operations, and proxy/group/tag management. Use when the user mentions MoreLogin, envId/uniqueId, cloud phone, CDP, ADB, or multi-account automation.4---56# MoreLogin Local API Skill78Manage browser profiles and cloud phones via MoreLogin official Local API, supporting full lifecycle control, automation connections (CDP/ADB), and resource management (proxy/group/tag/app/file).910## Official Sources1112- Local API documentation: https://guide.morelogin.com/api-reference/local-api13- Base URL: `http://127.0.0.1:40000`14- Requirements: MoreLogin Desktop `v2.15.0+`, logged-in local account1516## Trigger Scenarios1718Prefer this Skill when:1920- User mentions `MoreLogin`, `envId`, `uniqueId`, `cloudphone`21- Creating/starting/closing browser profiles22- Refreshing fingerprints, clearing cache, or deleting profiles23- Cloud phone power on/off, ADB, app management, file upload24- API management of proxy, groups, tags2526## Pre-flight Checklist2728Before any operation:29301. Confirm MoreLogin desktop app is running and logged in.312. Confirm API is reachable: `http://127.0.0.1:40000`.323. Confirm requests originate from localhost (Local API does not support remote access).334. For cloud phone command execution, confirm ADB is available (`adb` installed).3435## Execution Principles3637- Treat `local-api.yaml` + `API-CONTRACT.md` as the canonical parameter source before constructing payloads.38- Do not infer field names from memory; verify required keys/types first (especially `id` vs `ids`, object vs array bodies).39- Use `POST` by default (except tag query `GET /api/envtag/all`).40- Uniform request header: `Content-Type: application/json`.41- Check `code` first: `0` means success, non-zero use `msg` for error handling.42- Prefer `envId` for resource lookup; fall back to `uniqueId` when missing (browser profiles).43- For batch endpoints (`/batch`), always pass arrays and record changed objects.4445## API Capability Mapping4647### Browser Profile4849| Endpoint | Purpose |50|---|---|51| `POST /api/env/create/quick` | Quick create profile |52| `POST /api/env/create/advanced` | Advanced create (full fingerprint params) |53| `POST /api/env/fingerprint/refresh` | Refresh device fingerprint |54| `POST /api/env/start` | Start profile and return debug info |55| `POST /api/env/close` | Close running profile |56| `POST /api/env/status` | Get run status and debug info |57| `POST /api/env/page` | Paginated profile list |58| `POST /api/env/detail` | Get single profile detail |59| `POST /api/env/removeLocalCache` | Clear local cache (cookies/localStorage etc.) |60| `POST /api/env/removeToRecycleBin/batch` | Batch delete to recycle bin |6162### Cloud Phone6364| Endpoint | Purpose |65|---|---|66| `POST /api/cloudphone/create` | Create cloud phone |67| `POST /api/cloudphone/powerOn` | Power on |68| `POST /api/cloudphone/powerOff` | Power off |69| `POST /api/cloudphone/page` | Paginated list |70| `POST /api/cloudphone/info` | Get detail (including ADB info) |71| `POST /api/cloudphone/edit/batch` | Batch edit config |72| `POST /api/cloudphone/delete/batch` | Batch delete |73| `POST /api/cloudphone/newMachine` | One-click new device |74| `POST /api/cloudphone/updateAdb` | Enable/disable ADB |7576### Cloud Phone File & App7778| Endpoint | Purpose |79|---|---|80| `POST /api/cloudphone/uploadFile` | Upload file to cloud phone |81| `POST /api/cloudphone/uploadUrl` | Query upload status |82| `POST /api/cloudphone/setKeyBox` | Set Keybox |83| `POST /api/cloudphone/app/install` | Install app |84| `POST /api/cloudphone/app/page` | Query app market list |85| `POST /api/cloudphone/app/installedList` | Query installed apps |86| `POST /api/cloudphone/app/start` | Start app |87| `POST /api/cloudphone/app/restart` | Restart app |88| `POST /api/cloudphone/app/stop` | Stop app |89| `POST /api/cloudphone/app/uninstall` | Uninstall app |9091### Proxy / Group / Tag9293| Endpoint | Purpose |94|---|---|95| `POST /api/proxyInfo/page` | Query proxy list |96| `POST /api/proxyInfo/add` | Add proxy |97| `POST /api/proxyInfo/update` | Update proxy |98| `POST /api/proxyInfo/delete` | Delete proxy |99| `POST /api/envgroup/page` | Query groups |100| `POST /api/envgroup/create` | Create group |101| `POST /api/envgroup/edit` | Edit group |102| `POST /api/envgroup/delete` | Delete group |103| `GET /api/envtag/all` | Get all tags |104| `POST /api/envtag/create` | Create tag |105| `POST /api/envtag/edit` | Edit tag |106| `POST /api/envtag/delete` | Delete tag |107108## Standard Workflows109110### Workflow A: Browser Profile Automation1111121. Get `envId` from `create/quick` or `page`.1132. Call `start` to launch the profile.1143. Call `status` to verify run state and `debugPort`.1154. Use CDP (Puppeteer/Playwright) for automation.1165. Call `close` when done.117118### Workflow B: Cloud Phone Automation1191201. Call `page` or `create` to obtain cloud phone `id`.1212. Call `powerOn` to start.1223. Call `info` to get ADB connection params.1234. Call `updateAdb` when needed to enable ADB.1245. Run supported cloud phone management endpoints only (no direct command execution).1256. Call `powerOff` when done.126127## Quick Examples (Official API)128129```bash130# 1) Quick create browser profile131curl -X POST "http://127.0.0.1:40000/api/env/create/quick" \132 -H "Content-Type: application/json" \133 -d '{"browserTypeId":1,"operatorSystemId":1,"quantity":1}'134135# 2) Start profile136curl -X POST "http://127.0.0.1:40000/api/env/start" \137 -H "Content-Type: application/json" \138 -d '{"envId":"<envId>"}'139140# 3) Cloud phone power on141curl -X POST "http://127.0.0.1:40000/api/cloudphone/powerOn" \142 -H "Content-Type: application/json" \143 -d '{"id":"<cloudPhoneId>"}'144145# 4) Query cloud phone detail (including ADB info)146curl -X POST "http://127.0.0.1:40000/api/cloudphone/info" \147 -H "Content-Type: application/json" \148 -d '{"id":"<cloudPhoneId>"}'149```150151## CLI Usage (This Project)152153Prefer project-wrapped commands; fall back to `curl` when needed:154155Entry equivalence note: `openclaw morelogin ...` and `node bin/morelogin.js ...` are fully equivalent (same arguments, same behavior, same exit code). Use either one based on your runtime environment.156157```bash158# Browser profile159openclaw morelogin browser list160openclaw morelogin browser start --env-id <envId>161openclaw morelogin browser status --env-id <envId>162openclaw morelogin browser close --env-id <envId>163164# Cloud phone165openclaw morelogin cloudphone list166openclaw morelogin cloudphone start --id <cloudPhoneId>167openclaw morelogin cloudphone info --id <cloudPhoneId>168169## Response & Error Handling170171Parse responses with the following structure:172173```json174{175 "code": 0,176 "msg": null,177 "data": {},178 "requestId": "..."179}180```181182Handling rules:183184- `code == 0`: Proceed, extract `data`.185- `code != 0`: Output `msg`, mark failed step, suggest next fix.186- For `start/powerOn` operations, call `status/info` again before subsequent steps to confirm.187188## Security & Limits189190- Local API listens on localhost only; no remote access.191- Can be called only when MoreLogin account is logged in.192- Do not expose account, proxy passwords, ADB keys, or other sensitive data in logs or code.193- Double-check target ID lists before batch delete, cache clear, or app uninstall.194195## Security Notice196197This skill no longer provides local ADB/SSH connection methods (`adb-connect`, `adb-disconnect`, `adb-devices`).198199Command execution safeguards:200201- Restricted to local automation context (localhost workflows and local API).202- Remote cloud phone `exec` is disabled by default and must be explicitly enabled.203- `exec` command content is validated against a safe allowlist and blocks shell metacharacters.204- Generic `api` passthrough is endpoint-allowlisted by default.205206## When Not to Use This Skill207208- MoreLogin is not installed, not running, or not logged in.209- Requirements are for regular browser automation (no MoreLogin environment isolation).210- Requirements depend on remote access to Local API over the network.211212## Related Files213214- `bin/morelogin.js`215- `lib/api.js`216- `local-api.yaml`217- `API-CONTRACT.md`218- `README-OFFICIAL-API.md`