Reveal a saved login's values
curl --request POST \
--url https://api.pomerado.ai/v1/logins/{id}/reveal \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.pomerado.ai/v1/logins/{id}/reveal', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/logins/{id}/reveal"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"username": "<string>",
"password": "<string>",
"email": "<string>",
"phone": "<string>",
"account_number": "<string>",
"date_of_birth": "<string>",
"zip": "<string>",
"preferred_method": "sms",
"recovery_codes": {
"saved": 123,
"unused": 123,
"low": true
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Logins
Reveal a saved login's values
Every value a saved login holds but its authenticator secret, and how many recovery codes it has left. Only on the Dashboard, behind the Logins PIN on a Personal account and a recent sign-in on a Business one: elsewhere this answers the Dashboard page that reveals it.
POST
/
v1
/
logins
/
{id}
/
reveal
Reveal a saved login's values
curl --request POST \
--url https://api.pomerado.ai/v1/logins/{id}/reveal \
--header 'Authorization: Bearer <token>'const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.pomerado.ai/v1/logins/{id}/reveal', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/logins/{id}/reveal"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text){
"username": "<string>",
"password": "<string>",
"email": "<string>",
"phone": "<string>",
"account_number": "<string>",
"date_of_birth": "<string>",
"zip": "<string>",
"preferred_method": "sms",
"recovery_codes": {
"saved": 123,
"unused": 123,
"low": true
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Authentication:
Authorization: Bearer <token> with Dashboard session, Pomerado MCP OAuth token, API key.
Permission: logins:manage.
Effect: Read: changes nothing.
Errors: invalid_request (400), reauthentication_required (401), unauthorized (401), forbidden (403), not_found (404), internal_error (500), temporarily_unavailable (503). Every error has the same envelope.Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
a saved login ID: login_ and 32 lowercase hex digits
Example:
"login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"
Response
On the Dashboard: the values; Elsewhere: the page that reveals it
- Option 1
- Option 2
A two-factor method: sms, call, email, authenticator, push or recovery_code
Available options:
sms, call, email, authenticator, push, recovery_code Show child attributes
Show child attributes