Showcase
DemoLogins
Log in with a password and an authenticator code, then resume
The agent logs in to a site with two-factor authentication without ever seeing the password or the code, saves the session, and a later run skips the login.
The prompt
The prompt
Prompt
Log in to the site with my stored account, open my account page and tell me the name on it. Save the session as "demo" so the next run does not need to log in.What the agent does
- 01
browser_vault_listnames only: the site, the username and the field names (password, totp) - 02
browser_openact tab on the login page: logging in is a write - 03
browser_loginthe server types the username and password, computes the TOTP code and fills it - 04
browser_read_textthe account page, as untrusted text - 05
browser_session_savecookies and local storage, encrypted like the passwords - 06
browser_session_loadnext run, in a fresh tab: already signed in
Why it is hard
- The secret never enters the model's context, so no page can talk the agent into revealing it.
- Authenticator 2FA usually needs a person with a phone. With the setup key in the vault entry, the server computes the code itself.
- Saved sessions make the second run faster and avoid the new-device prompts that repeated logins trigger.
Try it
Add a login with its authenticator key in the console's Vault page, then give your agent the prompt with your site's name. The open repository's examples/python/vault_login.py does the same against a local test site.
Give your agent a browser that remembers.
Start with the free trial. Connect Claude Code, Cursor, Codex or your own code in a minute.