CloutLabs

The Clout guide

3. Bringing your profiles across

Clout reads profiles out of five other tools, and one screen does all five. Import profiles in the fleet toolbar, in the Create menu, or on the empty fleet, opens the same panel: everything found on this computer, vendor by vendor, group by group, with the profiles under them.

VendorWhere its profiles liveWhat it needs from you
AdsPowerA service on your machine, plus your signed-in accountNothing. The session already on the machine is used
KameleoFiles on your disk. No app running, no loginNothing at all. There is no account to sign in to
MultiloginThe vendor's cloudA signed-in Multilogin on this machine
Dolphin AntyThe vendor's cloudAn API token from your Dolphin account, pasted in
GoLoginThe vendor's cloudA signed-in GoLogin on this machine, or an API token

Three of the five are cloud-first and cannot be imported offline. "Bring your profiles" is an account integration for those three, not a file wizard. Read How your data is held before you hand over a token, because that is a real decision.


What the screen does

Every vendor is probed at once and the answers arrive as one list you can search, expand and tick across products. You never pick a vendor first, which is the point: somebody who cannot remember which product a set of profiles came from used to be stuck at the first step.

Three rules it keeps, and each one is worth knowing before you use it:

Nothing is fetched from anyone's cloud to draw the list

Detection makes no vendor API call. Counting your profiles at AdsPower or Dolphin means making an authenticated request with your session, and asking your vendors about you is something you opt into rather than a side effect of opening a screen. Where a count could only come from the vendor, the screen says nothing rather than 0.

"Installed but not signed in" is a different answer from "not installed", and both are different from "we have a token the vendor rejects". Each state has its own remedy, which is why they are separated:

VendorA real answer, from this Mac
AdsPowerSigned in to AdsPower. The session is live; the app is not running, but the saved session is still valid
KameleoFound 3 profiles in Kameleo. Read from your workspace across 2 workspaces
MultiloginSigned in to Multilogin. The profiles opened on this Mac are listed; the account may hold more
Dolphin AntyDolphin Anty is here, but we have no API token for your account. Create one at anty.dolphin.ru.com/panel/#/api and paste it
GoLoginGoLogin is installed but not signed in here. Open GoLogin and sign in, or paste a GoLogin API token

AdsPower

The one vendor whose profiles arrive from an account rather than from files. Press the vendor's tick or pick the profiles you want, and Clout pulls them from the AdsPower session already on the machine. No export folder, no API key.

The pull reports three phases, because listing an account with a thousand profiles in it is a long run of paced requests that finishes before a single profile is saved. A second pull cannot start while one is running.

If AdsPower is installed but not running, the panel says so and offers a re-check rather than failing at you:

AdsPower Global is installed but not running. Open it and sign in.


Kameleo

Nothing to sign in to and nothing to paste. Kameleo keeps its profiles as files on your disk, which makes it the only vendor whose import needs no credential from you at all. Clout reads the workspace, lists what is in it, and imports what you tick.

Your Kameleo installation is not touched. The import copies out; it does not write back, and a file by file checksum of a Kameleo workspace before, during and after an import came back identical.

A Kameleo profile stays in Kameleo's format and runs on Kameleo's own engine, so you need Kameleo installed on the machine to open it. See The two engines, which is the chapter that explains why.


Multilogin, Dolphin and GoLogin

All three are read through the vendor's own API with your credentials, and all three import from this screen.

Multilogin uses the session signed in on the machine. A live account has been walked end to end (workspaces, folders, profiles, fingerprints), and a profile pulled that way was converted, launched, and reported the imported identity rather than anything of the donor's.

Dolphin Anty needs a token, and only a token. Dolphin's own saved session cannot be reused: it is sealed to the machine's keychain and scoped to Dolphin's app. Create a token at anty.dolphin.ru.com/panel/#/api and paste it into the panel. A wrong token draws a real 401 from Dolphin and is reported as rejected rather than accepted and left to fail later.

GoLogin needs either a sign-in on this machine or an API token. One thing was fixed here rather than papered over: GoLogin's detector used to report "authenticated" for any non-empty token without ever asking GoLogin. It asks now, and an unverified token says it is unverified instead of claiming an account it does not have.

When these three import, their profiles are converted to the AdsPower format and run on SunBrowser, with the canvas, WebGL and audio cost described in The two engines.


What comes across

For every vendor, the importer runs five stages: detect, acquire, map, materialize, verify. What survives the trip:

Every vendor studied stores its cookies in plaintext or something close to it, on your own disk. That sounds alarming and is the reason cookie migration works at all without asking anybody for a key. It is also a fact about your current tools, today, whether or not you ever use Clout.


Bringing back a profile Clout exported

The same screen imports a profile file this app wrote. It previews first, and the preview is where a real decision is made: an id that is not in this store means importing adds a profile, and an id that is already here means importing replaces a row that may hold a live signed-in session. The second is refused unless you say so by name.


A thing to decide before you import from a cloud vendor

For Dolphin, GoLogin and Multilogin, you are handing us credentials to a competitor's account that holds your profiles. Whether we should hold those credentials at all, rather than using them once at import time and never storing them, is an open question the owner has not answered. Until it is answered, assume the conservative reading: give us a token you can revoke, revoke it when the import is done, and do not give us your vendor password.

The same thing without the app

cloutctl detect                     # all five vendors, no API calls
cloutctl adspower-pull              # from the signed-in account
cloutctl adspower-preview --dir …   # dry-run an export directory
cloutctl adspower-import --dir …    # import it
cloutctl kameleo-detect             # is there a Kameleo workspace worth importing
cloutctl kameleo-preview            # dry run, copies nothing
cloutctl kameleo-import             # --id, --limit, --group
cloutctl kameleo-verify             # check an imported profile has what a launch needs

There is no kameleo-pull and there never will be: Kameleo has no cloud to pull from. There is no kameleo-launch either, because an imported Kameleo profile launches with the ordinary launch verb and the engine picks Chroma from the profile's own format.