Website logins and secure links
How the agent asks for a website login, a document or a key through a private link, so nothing sensitive is typed into chat.
Some work happens on websites behind a sign-in, such as a supplier portal or a booking site. Some needs a passport number or an API key. The agent never asks you to type these into Chat. It sends a private link instead. You enter the value on that page, and Auto Lab stores it encrypted for the goal.
Four kinds of link
| Link | The page says | What you hand over | Who uses it |
|---|---|---|---|
| Login link | Sign your agent in to a website | A website sign-in and how its second step works | The browser task agent, which signs in for you |
| Secure link | Hand over a document securely | A document or a number, such as an ID, a passport or a card | A task that fills a form or reads the record by name |
| Secret link | Add a project secret | A key or another value | A connector, or the agent's code |
| Connect link | Connect an app | Your approval on the app's own sign-in page | A connector. See Connectors |
You can open these links without an Auto Lab account. The link itself is the key, so send it only to the person who holds the login or the document. In Auto Lab's Chat, login, secret and connect links show as a card you can open in place. In Slack, Teams, iMessage or email they arrive as a plain link.
Sign the agent in to a website
- The agent reaches a sign-in page. A browser task that finds no saved login for a site stops there. The agent then posts a login link in the thread, or in the channel you asked from.
- You open the link. The page shows the site's address, whether it is a secure
httpssite, which goal asked, and when the link expires. - You enter the login. Fill in the email, username or phone number, the Password, and the Second factor. Add a Note for the agent if the page needs something extra, such as a company code. Select Save login.
- The agent carries on. Chat shows Login for {host} saved, and the agent returns to the task. The browser task types the login into the site from the encrypted store. The password never appears in Chat, and the agent does not read it.
- The site stays signed in. After a sign-in, Auto Lab keeps the site's browser session until its cookies expire, for up to 30 days. The next visit starts signed in, with no new link.
A login link lasts seven days by default. An expired link says This link has expired. Ask the agent for a new one.
During setup, Sign in on a Works with card asks the agent to send a login link for that site.
Second factors
| Second factor | What happens |
|---|---|
| None | The password alone signs in |
| Authenticator app (TOTP) | Paste the setup key under TOTP secret and the agent makes the code itself. Without it, the agent asks you for the code each time |
| SMS code or Email code | The agent asks you for the code in the thread and enters it once |
| Push approval | You approve on your phone. The agent tells you when it is waiting |
When a site asks for a one-time code, the agent asks in the thread with the question One-time code for {site}. Reply with the code. It is used once and then removed from the log, and Chat shows One-time code removed from the log.
When a site pushes back
If a site shows a CAPTCHA or a device check, the agent does not try to get past it. It tells you what the page showed, gives you the quickest way to do the step yourself, and can try once more later. Before it places an order on a site, it shows you what it is about to buy and waits for you to answer Place order.
Approve each use of a saved login
To be asked before a saved login is used, turn on Approve website login use in Settings › Autonomy. The first use of a login in each session then waits for your approval. The approval covers only that login in that session. See Approvals and autonomy.
See, request and revoke saved logins
Saved logins are listed under Website logins in Settings › Secrets, which is also Brain › Secrets. Each row shows the site, its label, the masked sign-in name, the owner, the second factor, when it was last used, and whether a Saved browser state exists. Passwords are never shown.
| Owner | Who can sign in with it |
|---|---|
| Project | Any session in this goal |
| Personal | Only sessions started by the person who submitted the link |
- Request a login makes a link before the agent asks. Fill in Site, an optional Label, Sign-in uses and Owner, then select Create link and send the Link to send to whoever has the login.
- Revoke stops the agent from signing in to that site with the login, and deletes the saved browser state. To hand it over again, send a new link.
Requesting and revoking need permission to manage the goal's secrets.
Hand over a document or a number
The agent never asks for an ID, a passport or a card in Chat. It sends a secure link instead. The page asks for the fields the agent named: text, numbers, dates, or a file (an image or a PDF). Select Save securely.
- The link works once, and lasts 24 hours by default. A used link says This link was already used. Ask the agent for a fresh one if something needs correcting.
- The values are stored encrypted as one named record for the goal. The page says whether everyone on the goal can use it or only sessions you run.
- A browser task fills a form from the record by name. The agent reads it only when a task needs it and never shows it in Chat.
Hand over a key without seeing it
A secret link lets someone enter a key or another value that you never see. The link can only set the values it names. It cannot read any existing secret. It lasts seven days by default and at most 30 days.
A secret link comes from kortix secrets request (see CLI) or from an agent working in a session. By default, the value is kept for connectors and stays on Auto Lab's servers. A link made for the agent's machine stores it as an environment variable, which the agent's commands can read. See Secrets.