All docs

Accounts & service credentials

Sign in to services on a computer, supply API keys and pause credentials for future tasks.

Ophio isn’t released yet. These docs describe the development version; app downloads are not available.

Settings → Accounts manages service sign-ins and keys on the selected computer. Every computer has its own accounts. The phone shows their identity and state, not stored keys.

Every active account is provided to every newly started task on that computer, across agents and projects. There is no per-project account selection. Only add accounts you are willing to make available that way.

Website usernames and passwords for an agent browser belong in Agent logins, not Accounts.

Built-in accounts

The built-in services include Claude Code and Codex native sign-ins, GitHub through its CLI, OpenRouter with an API key, and Google Gmail through OAuth.

Claude Code and Codex use their own login stores. Other CLI services use account-specific private storage managed by Ophio. Programs you launch yourself are not automatically switched to those accounts.

Sign in or set a key

  1. Select the computer, then open Settings → Accounts.
  2. Select a service and tap Sign in or Sign in again.
  3. Confirm with the phone’s secure screen lock.
  4. Finish in the computer’s normal browser through Open Desktop control.

For a provider that displays a device code, the sign-in strip in the ordinary desktop or typing view can type that displayed code. It is not shown in the full-screen picture overlay; open Keys for the typing view if needed. Passwords, passkeys and other private challenges remain yours to complete. Cancellation, timeout or failure does not save a successful sign-in.

For an API service, tap Set key or Replace key, enter the key and tap Save key. It is sent once over the encrypted paired connection and stored on the computer. Do not send it as a task message.

Google client setup

Google Gmail requires a Desktop OAuth client that you create. Choose its JSON with Choose the client file, or save it on the computer and run:

ophio accounts set-client google client.json

Then sign in and review Google’s requested access. The OAuth client is not the same thing as a Gmail password.

Password manager

Password manager on this computer opens an extension setup page in the computer’s normal browser. Install your extension there, then tap It’s set up. This helps when you sign in yourself. It does not import passwords into Agent logins.

Add another service

Tap Add a service and enter Name. How it signs in offers:

  • API key: set Environment variable to the variable tasks should receive. Check address (optional) is an HTTPS endpoint that returns status 200 when given the key.
  • OAuth app: enter Sign-in address, Token address, Scopes separated by spaces and Environment variable for fresh access tokens. After adding the service, supply its OAuth client on the computer with ophio accounts set-client ACCOUNT FILE.
  • CLI login: enter Sign-in command, Status command, Sign-out command (optional) and Config folder variable. Commands run on the computer without a shell. Each account gets a separate configuration folder; tasks receive its path in the selected variable.

Security page (optional) is the provider page where you end sessions or revoke keys. Tap Add after checking the fields. Reserved environment variables cannot be replaced by a custom service. Adding a service does not sign it in or supply its key.

Custom service setup does not guarantee that every provider or CLI works. Use Check now after signing in or setting a key to inspect the current result.

Pause, sign out or delete

  • Check now verifies the current sign-in or key.
  • Pause stops the account being given to future tasks and stops its token renewal. Running tasks retain credentials already given to them.
  • Resume makes it available to future tasks again.
  • Pause all pauses every account for future tasks. On the computer, ophio accounts pause-all does the same.
  • Sign out ends the local sign-in where supported.
  • Delete permanently signs out and removes the saved key. Built-in services remain listed as signed out. A custom service is also removed from the list.

Used by identifies running tasks that received the account. History records account changes.

Local sign-out is not always provider-side revocation. GitHub CLI logout, for example, does not revoke the provider token. Complete any remaining revocation in the provider’s security settings.

Permissions and storage

Account access must be granted at the computer. The phone cannot grant itself that permission. Browser sign-in also needs desktop control. Sensitive account changes require a secure Android screen lock and confirmation each time. Pausing remains available without that confirmation.

On Linux, Ophio uses the Secret Service keyring when available. The screen reports a protected-file fallback or a locked-keyring problem. Do not assume a fallback provides the same protection as an unlocked keyring.

Ophio masks known keys and tokens in normal stored and streamed text, including approval views. This is not comprehensive secret protection. Encoded values and unknown native-agent or CLI secrets may not be masked.

Tasks can request fresh Google credentials with ophio token google while active, and only for accounts available when the task started. Removing data during uninstall attempts supported sign-outs and revocations and reports what still needs provider-side cleanup. Native agent sign-ins are retained.