Solutions · Login automation
Logins your agent never sees.
Store a site's login and its authenticator key once. The agent says “log in to github.com”; the server types the values, fills the 2FA code and saves the session for next time.
browser_open{url: "https://github.com/login", mode: "act"}
browser_login{site: "github.com"} # username, password and TOTP from the vault
browser_session_save{name: "github"} # cookies and storage, encrypted
# next time: browser_session_load{name: "github"}: no password neededHow it works
01
The vault
You add an entry in the console: the site, the login page, the username, the password and, if the site uses an authenticator app, its setup key. Values are encrypted with AES-256-GCM and can be written but never read back through any API.
When the agent calls browser_login, the server decrypts the values inside the gateway and types them into the page. The agent gets back a status (logged in, hand-off required, failed), not the values.
02
Two-factor without a phone
If the entry has a TOTP key, the server computes the current code and fills it, so authenticator-app 2FA needs no person. SMS, email and push codes cannot be computed: browser_login returns a hand-off link instead, and the person types the code in the live view.
03
Sessions you can resume
After a login, save the session: the site's cookies and local storage are encrypted like passwords. A later run loads it and skips the login. You can also import a cookie export (Cookie-Editor, EditThisCookie, cookies.txt or a Playwright storageState) as a saved session.
FAQ
Questions people ask
Does the agent see my passwords?
No. Logins, card fields and authenticator (TOTP) keys live in your vault, encrypted with AES-256-GCM. The agent names an entry (browser_login{site}) and the server types the values into the page. No API returns a stored value.
Which kinds of 2FA work without me?
Authenticator apps (TOTP), when you store the setup key or otpauth:// link in the entry. SMS, email, push and hardware keys need you: the agent gets a hand-off link and waits until you press Done.
Can I stop the agent logging in to some sites?
Yes. Set a site rule to read-only and logins, secrets, writes and JavaScript are refused there with site_read_only; reading still works. Rules are checked by the server, for MCP and REST alike.
What about card details?
Store card fields as their own vault entry. browser_fill_secret fills a named field into the page; the agent never sees the number. Sensitive actions such as paying are written to the audit log.
Is every login logged?
Yes. Every login, every secret use and every write is in the audit log with the user, the site and the time; values never are.
What if the login page changes?
browser_login finds the username, password and code fields on the page each time, from their type, autocomplete hints and names, not from a stored selector. If it cannot finish, it says why, and for a code or a CAPTCHA it offers a hand-off rather than guessing.
Give your agent a browser that remembers.
Start with the free trial. Connect Claude Code, Cursor, Codex or your own code in a minute.