Skip to main content
Your agent’s browser can sign in to websites in three ways: it restores a browser profile that is already signed in, it types a saved login (username, password, and optional 2FA) that Gumloop fills in for it, or it hands the browser to you to sign in. In every case, the agent never sees the password.
Your Vault page with 1Password, Secrets, Logins, and Browser Profiles sections, showing one saved login and a Default browser profile

Logins and Browser Profiles in the Vault.


User-owned or Agent-owned: whose accounts does the agent use?

Two settings on this page, Browser profile and 1Password, ask the same question: when someone runs the agent, whose accounts does it use? You answer it with the same choice each time.
Whose profile toggle with User-owned, Everyone uses their own profile, and Agent-owned, Everyone uses the profile you pick

The same choice appears on the Browser profile and 1Password settings.

Everyone acts as themselves. Each person who runs the agent uses their own accounts. If ten people use the agent, it works in ten different accounts. Shown as User/Team-owned on team agents.
  • Browser profile: each person’s own saved sign-ins.
  • 1Password: each person’s own service account.
Use it when people work in their own accounts, for example a research agent your team shares where each person signs in to their own LinkedIn.
Agent-owned works the same way it does for connectors. On organizations it needs the Agent-owned credentials feature on your custom role, and it can’t be used while the agent is shared with Anyone. Choosing Agent-owned on an Anyone-shared agent offers to change its sharing first.

Logins

A login is a website username, password, and optional 2FA authenticator key, stored encrypted in your Vault. When the agent signs in, it names the login and Gumloop types the values into the page after checking the site. The password and 2FA key never reach the agent or its sandbox environment.

How do I add a login?

1

Open your Vault

Go to gumloop.com/personal/vault for your own logins, or your team’s Vault for shared ones. Click Add.
2

Choose Login for a website

Username, password and optional 2FA. The agent types them into the site without seeing them.
What are you adding? dialog with API key or value and Login for a website options
3

Fill in the login

Add Login form with Name, Website, Username, Password, and an Advanced section with Authenticator key and Type the password on
4

Click Create

The login appears under Logins in your Vault.

How do I give an agent a login?

In the agent’s Browser section, click + Login. In Add login to agent, choose a Name for the agent to use, then a Source: an Existing login from your Vault, or a New login created on the spot.
Add login to agent dialog with Name, Source with Existing login and New login, and a Login picker
Gumloop also lists the agent’s logins in its instructions, so the agent knows which sites it can sign in to and as which username. A binding you remove is revoked from the next turn, even in a running chat.

Where can a login be typed?

Every fill is checked before anything is typed. The page field’s scheme and port must match the login’s website, and its host must match the Type the password on setting: The check uses the frame the field actually lives in, not just the top page, so a login form embedded from another site is refused. Shared hosting domains such as github.io or herokuapp.com count each subdomain as its own site, so a login for alice.github.io never types on bob.github.io. If the check fails, nothing is typed and the agent is told to ask you with a handoff instead.

How do I save a login from a handoff?

When the agent asks you to sign in with a handoff card, tick Save login for <site> before you click Continue. If the agent is in a team, choose who can use it: Only me or My team.
Handoff card with Username and Password fields and a Save login checkbox
Gumloop saves the login to the matching Vault and names it after the site, for example THE_INTERNET_HEROKUAPP_COM. The card then reads Saved the login for <site> as <NAME> and sent it to the agent, and next time the agent signs in without asking.

Browser profiles

A browser profile is how the agent’s browser remembers which websites it is signed in to. It works like your own Chrome: sign in to a site once, and next time you open the browser you are still signed in. Without a profile, every task would start with a fresh browser that is signed out of everything.

How does a profile keep the agent signed in?

1

The agent signs in once

It signs in with a saved login, or you sign in for it with a handoff.
2

Gumloop saves the sign-in

At the end of the agent’s turn, the sign-in is saved to the browser profile.
3

The next task starts signed in

The next time the agent opens the browser, even in a brand-new chat, it is already signed in to that site.
You do not need to set anything up. Your personal Default profile is created automatically the first time a task saves a sign-in.

What’s the difference between a profile and a login?

They work best together. The profile keeps the agent signed in from task to task. When a site eventually signs it out, the agent uses the login to sign back in, and the profile saves the new session.

Who owns a browser profile?

A profile belongs to a person or a team, never to an agent. An agent that uses a profile can use every site that profile is signed in to.

Can everyone who runs the agent share one profile?

Yes, with Agent-owned. By default the profile is User-owned, so everyone uses their own sign-ins. Change it from the Browser profile row in the agent’s Browser section. See User-owned or Agent-owned for which to pick.
Browser profile settings with Whose profile options User-owned and Agent-owned, and a Profile section
  • User-owned: Everyone uses their own profile. Each person’s personal Default profile is used.
  • Agent-owned: Everyone uses the profile you pick. Picking a profile in Profile switches the agent to Agent-owned.
The profile menu also has Import from browser and Manage browser profiles (opens the Vault). Incognito chats never restore or save a profile.

How do I bring my own sign-ins into a profile?

Import the cookies from a browser on your computer, so agents open those sites already signed in. Open Import logins from the profile menu in the agent’s Browser profile view, from Import in a profile’s menu in the Vault, or from Add on the Vault’s Browser Profiles row.
Import logins dialog with From the terminal and From this browser sections
Copy the command from the dialog and run it on your computer. The dialog fills in the target profile for you.
Terminal
macOS may ask for Keychain access. Windows is not supported yet.With the Gumloop CLI installed, you can run the import directly:
Terminal
List your profiles and the sites they hold with gumloop browser profiles list (add --team <team_id> for a team’s).
  • Imports bring cookies only, not local storage.
  • An import can carry up to 20,000 cookies. A profile holds up to 25,000 cookies or 24 MB.
  • Importing while a task is running is safe: the import and the task’s end-of-turn save are merged, not overwritten.
  • Only people who manage team secrets can import into a team profile. Only a personal profile’s owner can import into it.

How do I manage profiles?

In the Vault’s Browser Profiles section, Add opens Import logins, and each profile’s menu has Import, Rename, and Delete. When an agent switches profiles, or its profile is deleted, the browser is reset before the next step so no session carries over from one profile to another.

1Password

Connect 1Password and the agent can sign in with the logins in your 1Password vaults, including 2FA codes. You don’t copy anything into Gumloop, and the agent never sees the passwords.

How does 1Password work with the agent?

1

Gumloop lists the logins it may use

The first time the agent uses its browser in a turn, Gumloop reads the list of Login items in the vaults you allowed. It reads only each item’s title and website, never the password.
2

The agent searches for the right login

The agent searches that list for the site it is on, for example github.com, and finds the matching item.
3

Gumloop types it in

Gumloop fetches just that one item from 1Password and types the username, password, and current 2FA code into the page, after checking it is the item’s site. 1Password logs each read.

How do I set up 1Password?

1

Prepare a vault in 1Password

1Password service accounts can’t see Private vaults, so give agents a vault of their own, such as Gumloop Agents. Add the logins agents will use. Each login needs its website filled in, plus 2FA where the site asks for it.
2

Create a service account

In 1Password Developer Tools, create a Service Account with read-only access to that vault. Copy the ops_ token. 1Password shows it only once.
3

Connect it in Gumloop

In your Vault (or your team’s Vault), click Add on the 1Password row and paste the token.
4

Turn it on for the agent

In the agent’s Browser section, open 1Password and click Turn on under Use 1Password. The agent’s Browser must be on first.
5

Choose whose service account and which vaults

Whose service account: User-owned uses each person’s own default service account (or the team’s default on team agents); Agent-owned uses one service account you pick for everyone. See User-owned or Agent-owned.Vaults: All vaults the service account can read, or up to 10 specific vaults.
Gumball needs no setup. Once you connect 1Password, it can use every vault your default connection can read.

How does the agent find the right login?

Each 1Password Login item becomes a login named OP_<TITLE>, for example OP_GITHUB. The agent finds items by searching: A login named “GitHub” but saved for a different website does not match a github.com search, because matching uses the item’s website, not its title.

What are the 1Password limits?

What else should I know?

  • If 1Password is unavailable or rate-limits the service account, that turn runs without 1Password logins and the task continues.
  • If a Vault login and a 1Password item have the same name, the Vault login is used. Two 1Password items with the same title get _2, _3, and so on.
  • Keep agent vaults small. An agent can sign in with any login in the vaults you give it.
  • Agent-owned 1Password is not used while the agent is shared with Anyone.

FAQ

The page failed the site check. Common causes: the login is set to This exact address only and the form is on another subdomain (for example login.acme.com), the form is inside an embedded frame from a different site, or the scheme or port differs. Edit the login and set Type the password on to Any page of this site, or let the agent ask you with a handoff.
Only authenticator-app codes can be generated automatically, from the login’s Authenticator key. For codes sent by SMS or email, the agent hands the browser to you with a one-time code field.
Edit the login in the Vault. Leave Password or Authenticator key blank to keep the current value.
Not with the default User-owned setting: each person uses their own profile and their own logins. With an Agent-owned profile or a team login, everyone who runs the agent uses the same sessions or credentials.
An agent-owned profile stays pinned even after it is deleted, so the browser starts signed out rather than silently using someone else’s sessions. Pick a new profile, or switch Whose profile back to User-owned.
Check that you imported into the profile the agent uses (see Browser profile in the agent’s Browser section), and that the site’s session had not expired in your own browser. Some sites also tie sessions to local storage, which imports do not copy. In that case, save a login so the agent can sign in itself.

Agent Browser

Turn on the browser, watch it live, replay steps, and answer handoffs.

Code Sandbox & Secrets

The Vault, secrets, and the sandbox the browser runs in.

CLI

Install the Gumloop CLI to import sign-ins from your terminal.

Custom Roles

Control who can give agents a browser.