All docs

Agent website logins

Configure website credentials for the agent browser and understand their limits.

Ophio isn’t released yet. These docs describe the development version; app downloads are not available.

Settings → Agent logins holds usernames and passwords that coding Work tasks may use in Ophio’s own browser. It is separate from Accounts, which supplies service and tool credentials.

The feature starts off. Read the disclaimer, select its acknowledgement and tap Turn on Agent logins, then confirm with your phone’s secure screen lock. A changed disclaimer requires acceptance again. On the computer, ophio agent-logins enable requires typing yes.

What you are allowing

A signed-in agent may act as you, including sending messages, posting, buying or deleting. Login controls are not approval for each later website action. Keep banking and payment accounts out of this store. Do not rely on it to prevent every leak or unwanted action.

A compatible Chromium-family browser must be installed on the computer. Ophio uses a separate headless browser profile, not your normal browsing profile. It does not expose a network debugging port. Ask and Plan do not have this browser. For new coding Work, check Browser in task review.

Add a login

Tap Add a login, then fill in:

  • Name: a label you will recognize.
  • Sites: the main site first, then other required sites, one per line. Filling is limited to those sites and their subdomains.
  • Username and Password.
  • 2FA setup key (optional): an authenticator setup key or its otpauth:// link. Saving it gives Ophio both factors. Leave it out for important accounts.
  • Notes for the agent: ordinary instructions. They are not secret.
  • Who can use it: select the permitted projects and launcher agents.
  • How: choose automatic use or a request first.

Generate creates a 20-character password. Save it in your own password manager too. A generated or replaced password must also be set on the website; storing it in Ophio does not change the site’s password.

Under Projects, Every project allows all projects; Only these projects limits the selection. Under Agents, Any agent allows any task agent; Only these agents means tasks started from the selected launcher entries, not simply any Claude Code or Codex run.

Use whenever needed allows matching tasks to use the login without asking. Ask me first requests permission for use in a run. Confirm on the unlocked phone. A chat message cannot approve it. This login permission is separate from coding launch flags.

Tell me each time it’s used enables usage notices. Tap Add login to save. Passwords and authenticator keys are sent once over the paired connection. They are not stored as unsent task commands on the phone.

Fill a code or take over

Ophio fills a password or authenticator code itself. It does not return the value to the agent. Filling requires the expected HTTPS site, frame and visible input.

If the site needs an email or text-message code, the phone offers a private Sign-in code request. Enter Code, then tap Fill code. Do not put it in task chat. If you cannot verify the request, choose No code…, optionally enter Reason (optional), then Deny.

For a passkey, CAPTCHA or security-key challenge, open Control → Screens, select the agent browser target and take over. This pauses agent tab input while you complete the challenge. Review before handing control back.

Manage a saved login

Open a login to use Edit, Replace password, Add a 2FA key, or Replace or remove the 2FA key. Show password requires phone confirmation and hides it again after 30 seconds.

  • Pause blocks future filling and opening of that login’s sites, and clears already-open site tabs. The tasks themselves keep running.
  • Resume permits use under the saved rules again.
  • Pause all and Resume all control all logins. Computer CLI equivalents are also available.
  • Sign the agent browser out clears the site’s browser data, including subdomains and ports. It resets the browser and can close tabs belonging to other tasks too.
  • Delete permanently removes the login after sign-out succeeds. If sign-out fails, the saved entry is kept for you to resolve it.

Used by and History show usage. The computer retains up to 500 history entries; the phone shows up to 50. Logins do not sync between computers and have no import or export workflow.

Protection limits

Screenshots are withheld while password or code entry is open. Known exact secrets are masked from agent-visible text. That does not cover every encoded value, script-based exfiltration or picture on a later page.

Adding, changing, revealing or deleting credentials requires account access and the phone’s secure screen lock. Account access must be granted from the computer. Read any reported storage fallback or locked-keyring problem before saving secrets.