
Logins and Browser Profiles in the Vault.
User-owned or Agent-owned: whose accounts does the agent use?
Two settings on this page, Browser profile and 1Password, ask the same question: when someone runs the agent, whose accounts does it use? You answer it with the same choice each time.
The same choice appears on the Browser profile and 1Password settings.
- User-owned (default)
- Agent-owned
- Browser profile: each person’s own saved sign-ins.
- 1Password: each person’s own service account.
Logins
A login is a website username, password, and optional 2FA authenticator key, stored encrypted in your Vault. When the agent signs in, it names the login and Gumloop types the values into the page after checking the site. The password and 2FA key never reach the agent or its sandbox environment.How do I add a login?
Open your Vault
Choose Login for a website

Fill in the login

Click Create
How do I give an agent a login?
In the agent’s Browser section, click + Login. In Add login to agent, choose a Name for the agent to use, then a Source: an Existing login from your Vault, or a New login created on the spot.
Where can a login be typed?
Every fill is checked before anything is typed. The page field’s scheme and port must match the login’s website, and its host must match the Type the password on setting:github.io or herokuapp.com count each subdomain as its own site, so a login for alice.github.io never types on bob.github.io.
If the check fails, nothing is typed and the agent is told to ask you with a handoff instead.
How do I save a login from a handoff?
When the agent asks you to sign in with a handoff card, tick Save login for<site> before you click Continue. If the agent is in a team, choose who can use it: Only me or My team.

THE_INTERNET_HEROKUAPP_COM. The card then reads Saved the login for <site> as <NAME> and sent it to the agent, and next time the agent signs in without asking.
Browser profiles
A browser profile is how the agent’s browser remembers which websites it is signed in to. It works like your own Chrome: sign in to a site once, and next time you open the browser you are still signed in. Without a profile, every task would start with a fresh browser that is signed out of everything.How does a profile keep the agent signed in?
The agent signs in once
Gumloop saves the sign-in
The next task starts signed in
What’s the difference between a profile and a login?
Who owns a browser profile?
A profile belongs to a person or a team, never to an agent. An agent that uses a profile can use every site that profile is signed in to.Can everyone who runs the agent share one profile?
Yes, with Agent-owned. By default the profile is User-owned, so everyone uses their own sign-ins. Change it from the Browser profile row in the agent’s Browser section. See User-owned or Agent-owned for which to pick.
- User-owned: Everyone uses their own profile. Each person’s personal Default profile is used.
- Agent-owned: Everyone uses the profile you pick. Picking a profile in Profile switches the agent to Agent-owned.
How do I bring my own sign-ins into a profile?
Import the cookies from a browser on your computer, so agents open those sites already signed in. Open Import logins from the profile menu in the agent’s Browser profile view, from Import in a profile’s menu in the Vault, or from Add on the Vault’s Browser Profiles row.
- From the terminal
- From this browser
- From the API
gumloop browser profiles list (add --team <team_id> for a team’s).- Imports bring cookies only, not local storage.
- An import can carry up to 20,000 cookies. A profile holds up to 25,000 cookies or 24 MB.
- Importing while a task is running is safe: the import and the task’s end-of-turn save are merged, not overwritten.
- Only people who manage team secrets can import into a team profile. Only a personal profile’s owner can import into it.
How do I manage profiles?
In the Vault’s Browser Profiles section, Add opens Import logins, and each profile’s menu has Import, Rename, and Delete.1Password
Connect 1Password and the agent can sign in with the logins in your 1Password vaults, including 2FA codes. You don’t copy anything into Gumloop, and the agent never sees the passwords.How does 1Password work with the agent?
Gumloop lists the logins it may use
The agent searches for the right login
github.com, and finds the matching item.Gumloop types it in
How do I set up 1Password?
Prepare a vault in 1Password
Create a service account
ops_ token. 1Password shows it only once.Connect it in Gumloop
Turn it on for the agent
Choose whose service account and which vaults
How does the agent find the right login?
Each 1Password Login item becomes a login namedOP_<TITLE>, for example OP_GITHUB. The agent finds items by searching:
github.com search, because matching uses the item’s website, not its title.
What are the 1Password limits?
What else should I know?
- If 1Password is unavailable or rate-limits the service account, that turn runs without 1Password logins and the task continues.
- If a Vault login and a 1Password item have the same name, the Vault login is used. Two 1Password items with the same title get
_2,_3, and so on. - Keep agent vaults small. An agent can sign in with any login in the vaults you give it.
- Agent-owned 1Password is not used while the agent is shared with Anyone.
FAQ
The agent says it can't type my login on this page. Why?
The agent says it can't type my login on this page. Why?
login.acme.com), the form is inside an embedded frame from a different site, or the scheme or port differs. Edit the login and set Type the password on to Any page of this site, or let the agent ask you with a handoff.Can the agent handle SMS or email 2FA codes?
Can the agent handle SMS or email 2FA codes?
How do I change a saved password?
How do I change a saved password?
Do my teammates get my sign-ins?
Do my teammates get my sign-ins?
I deleted the agent's profile. Why didn't it fall back to mine?
I deleted the agent's profile. Why didn't it fall back to mine?
