Skip to content
Showcase
DemoLogins

Log in with a password and an authenticator code, then resume

The agent logs in to a site with two-factor authentication without ever seeing the password or the code, saves the session, and a later run skips the login.

This is a demo we wrote from the product's capabilities, not a customer story. The steps are the tools an agent calls; your agent may take a slightly different path.

The prompt

The prompt

Prompt

Log in to the site with my stored account, open my account page and tell me the name on it. Save the session as "demo" so the next run does not need to log in.

What the agent does

  1. 01browser_vault_listnames only: the site, the username and the field names (password, totp)
  2. 02browser_openact tab on the login page: logging in is a write
  3. 03browser_loginthe server types the username and password, computes the TOTP code and fills it
  4. 04browser_read_textthe account page, as untrusted text
  5. 05browser_session_savecookies and local storage, encrypted like the passwords
  6. 06browser_session_loadnext run, in a fresh tab: already signed in

Why it is hard

  • The secret never enters the model's context, so no page can talk the agent into revealing it.
  • Authenticator 2FA usually needs a person with a phone. With the setup key in the vault entry, the server computes the code itself.
  • Saved sessions make the second run faster and avoid the new-device prompts that repeated logins trigger.

Try it

Add a login with its authenticator key in the console's Vault page, then give your agent the prompt with your site's name. The open repository's examples/python/vault_login.py does the same against a local test site.

Give your agent a browser that remembers.

Start with the free trial. Connect Claude Code, Cursor, Codex or your own code in a minute.