Keyvault
Use the user's saved credentials in a Space, only with their approval.
Use the user's saved credentials in a Space, only with their approval.
| Tool | Description |
|---|---|
request_site_login | Sign in to a site in the Space with the user's saved password. |
Sign in to a site in the Space with the user's saved password.
Signs in to a website in the Space's browser with a password the user saved in the Cua Keyvault (imported from their browser). The first call files a Keyvault request and returns a request_id; the user approves it in Cua (Touch ID or the login password), once per sign-in by default. Call again with the same space, url and request_id: the Keyvault checks the page is on the saved login's exact origin, types the username and password through the Space's cua-driver, submits the form and returns what it did, never the password. Pass the browser tab you opened (session, target_id, tab_id from get_browser_state on the same Space) to sign in there; without one the Keyvault opens its own browser in the Space on url and returns its target_id and tab_id. agent names the persistent agent asking, shown to the user.
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:request_site_login; destructive |
| Requires (spacesd) | driver |
| Swift SDK | space.requestSiteLogin(url:) |
| Rust | site_login::request_site_login |
| Parameter | Type | Default | Description |
|---|---|---|---|
agent | string | none | The persistent agent asking (shown to the user in the approval). |
relay_plaintext_ack | boolean | false | Sends the password over a relay connection that predates end-to-end sealing even though the relay could read it in transit. Default false: such a Space refuses the fill instead (S1). |
request_id | string | none | The request id a previous call returned. Present on the retry after the user approved; absent on the first call. |
session | string | none | cua-driver lifecycle session label of the browser tab to sign in. |
space | string | required | Space id or name. |
tab_id | string | none | cua-driver tab id (from get_browser_state). |
target_id | string | none | cua-driver browser target id (from get_browser_state). |
url | string | required | The site's sign-in page (http or https), for example https://github.com/login. |
username | string | none | Which saved username, when the site has several. |
wait_secs | integer | 20 | Seconds to wait for the user's decision on a retry. Default 20, at most 120. At least 0. |
JSON. First call: status: "pending", a request_id, site and space. Retry with request_id: status: "filled" with site, origin, username_hint (masked), submitted, page_url and the browser target_id/tab_id it signed in; status: "pending" while the user decides; status: "denied" when they declined. Never the password.
invalid_argument, not_found, ambiguous_sandbox, spacesd_not_available, capability_missing, login_refused