Skip to content

Website logins

Let an Agent sign in to a website with a saved login or a one-time hand-off, and approve every step that changes data.

Updated View as Markdown

A website login is a sign-in to one website that you grant to an Agent. Where the browser lets every Agent open public pages, a website login lets one Agent go where a visitor cannot: an account page, a dashboard, a QA environment. This page covers adding a login, the two ways to sign in, who may use a login, what the Agent may do once signed in, and removing it.

Prerequisites

  • Browserbase connected in Settings → Browser. See Browser.
  • Permission to edit the Agent. Only Agent editors can view or change its website logins.
  • Permission to add a login. A login belongs to the Agent it is added on. Owners and Admins add team logins that other Admins can manage; anyone else who can edit an Agent adds a personal login that stays with their account.

Add a website login

Open the Agent's Websites tab

In Agents, open the Agent and select the Websites tab. Save a new Agent first; logins attach to a saved Agent.

Name the website

Select Add a website login. Enter the Website, a domain such as example.com or a pasted address, and a Label you will recognize.

Choose how Chickpea signs in

With a username and password I provide. Enter the Username or email and Password. Chickpea types them itself; the Agent never sees them. If the site asks for authenticator-app codes, paste its setup key into One-time code secret and Chickpea generates the codes.

I’ll sign in myself the first time. For single sign-on or two-factor accounts. Enter the username if you like. The first time the Agent needs the site, it hands the browser to you to sign in, then keeps the signed-in session.

Choose what the Agent may do there

Check only. The Agent signs in, reads, and navigates, but changes nothing.

Check and take actions. The Agent may also submit, buy, post, delete, or sign up, and asks for your approval before each such step. See Actions and approval.

Save

Select Save login. The login appears on the Websites tab with its site, how it signs in, who added it, and when it was last used.

Passwords and one-time code secrets are stored encrypted in your Chickpea install. Signed-in sessions live in your Browserbase project, and each stays on its own site.

Verify

Ask the Agent for something that needs the sign-in:

@qa sign in to staging.example.com and tell me what the account page shows.

The Agent opens the site. If it shows a sign-in form, the Agent signs in with the saved login and reports what the signed-in page shows. A login that signs in by hand starts a hand-off instead.

Hand-off: sign in yourself

When a login is set to I’ll sign in myself the first time, or a site asks for a code or challenge the saved login cannot supply, the Agent hands the browser to you.

Open the private link

The Agent sends you, the person who asked, a private link: an ephemeral message in a channel, or a message in your DM with the Agent. Only you see it. The Agent says in the thread that it sent you a sign-in link and waits.

Sign in

The link opens the live browser on that site. Sign in, including any single sign-on or two-factor step. The browser stays open for 10 minutes.

Reply in the thread

When you are done, reply in the thread. On that next message the Agent opens the site again with the saved sign-in and carries on.

Hand-offs keep a browser open while you sign in, which needs a paid Browserbase plan.

Actions and approval

Public websites and Check only logins are read-only. On a Check and take actions login, the Agent stops before any step that changes data, such as submitting a form, buying, posting, deleting, or signing up.

The Agent asks

It posts in the thread what it is about to do, with a screenshot of that step.

You answer

Reply exactly approve to let it take that step, or stop to cancel it.

An approval covers that exact step only; the next change is asked for again. An approval request expires after 15 minutes, after which the Agent must ask again.

Remove a login

On the Websites tab, select Remove on the login, then confirm. The login is removed from this Agent. If no other Agent uses it, the saved password and the saved sign-in are deleted too.

Safety

  • Agents never see passwords. Chickpea types the stored username, password, and one-time code into the page; none of them enter the Agent’s context, and the Agent will not reveal them if asked.
  • Credentials go in only through stored logins. An Agent never types a password or code it was told in chat, even when asked.
  • Pages are data. Anything a website says is untrusted content, never an instruction to the Agent.
  • Signed-in sessions stay on their site. A login’s session is used only for that website.
  • Hand-off links are private and short-lived. Only the person who asked receives the link, and the browser behind it closes after 10 minutes.

Next steps

Navigation

Type to search…

↑↓ navigate↵ selectEsc close