curl --request POST \
--url https://api.pomerado.ai/v1/logins \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"site_url": "<string>",
"label": "<string>",
"username": "<string>",
"email": "<string>",
"phone": "<string>",
"account_number": "<string>",
"password": "<string>",
"date_of_birth": "<string>",
"zip": "<string>",
"authenticator_secret": "<string>",
"recovery_codes": [
"<string>"
],
"deliver": "dashboard"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
site_url: '<string>',
label: '<string>',
username: '<string>',
email: '<string>',
phone: '<string>',
account_number: '<string>',
password: '<string>',
date_of_birth: '<string>',
zip: '<string>',
authenticator_secret: '<string>',
recovery_codes: ['<string>'],
deliver: 'dashboard'
})
};
fetch('https://api.pomerado.ai/v1/logins', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/logins"
payload = {
"site_url": "<string>",
"label": "<string>",
"username": "<string>",
"email": "<string>",
"phone": "<string>",
"account_number": "<string>",
"password": "<string>",
"date_of_birth": "<string>",
"zip": "<string>",
"authenticator_secret": "<string>",
"recovery_codes": ["<string>"],
"deliver": "dashboard"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"dashboard_url": "<string>"
}{
"id": "login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"label": "<string>",
"site": {
"url": "<string>",
"name": "<string>"
},
"username_masked": "<string>",
"identifier_type": "username",
"sign_in": "password",
"saved_fields": [
"email"
],
"two_factor": {
"authenticator": true,
"sms_number": "none"
},
"status": "unverified",
"needs_attention": {
"field": "username"
},
"locked": true,
"created_at": "<string>",
"updated_at": "<string>",
"verified_at": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Save a website login
Save a website login, and answer its metadata only. The values pass through this client and its model provider: warn the user first, or pass deliver “dashboard” with site_url (and label) for a Dashboard page where the person types the login instead. A Personal account keeps one login per website, locked to its identity after the first verified sign-in; a Business account keeps several.
curl --request POST \
--url https://api.pomerado.ai/v1/logins \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"site_url": "<string>",
"label": "<string>",
"username": "<string>",
"email": "<string>",
"phone": "<string>",
"account_number": "<string>",
"password": "<string>",
"date_of_birth": "<string>",
"zip": "<string>",
"authenticator_secret": "<string>",
"recovery_codes": [
"<string>"
],
"deliver": "dashboard"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
site_url: '<string>',
label: '<string>',
username: '<string>',
email: '<string>',
phone: '<string>',
account_number: '<string>',
password: '<string>',
date_of_birth: '<string>',
zip: '<string>',
authenticator_secret: '<string>',
recovery_codes: ['<string>'],
deliver: 'dashboard'
})
};
fetch('https://api.pomerado.ai/v1/logins', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.pomerado.ai/v1/logins"
payload = {
"site_url": "<string>",
"label": "<string>",
"username": "<string>",
"email": "<string>",
"phone": "<string>",
"account_number": "<string>",
"password": "<string>",
"date_of_birth": "<string>",
"zip": "<string>",
"authenticator_secret": "<string>",
"recovery_codes": ["<string>"],
"deliver": "dashboard"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"dashboard_url": "<string>"
}{
"id": "login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190",
"label": "<string>",
"site": {
"url": "<string>",
"name": "<string>"
},
"username_masked": "<string>",
"identifier_type": "username",
"sign_in": "password",
"saved_fields": [
"email"
],
"two_factor": {
"authenticator": true,
"sms_number": "none"
},
"status": "unverified",
"needs_attention": {
"field": "username"
},
"locked": true,
"created_at": "<string>",
"updated_at": "<string>",
"verified_at": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"retryable": true,
"docs_url": "<string>",
"details": {}
}
}Authorization: Bearer <token> with Dashboard session, Pomerado MCP OAuth token, API key.
Permission: logins:manage.
Effect: Write: creates or changes something in your account.
Errors: invalid_request (400), unauthorized (401), reauthentication_required (401), forbidden (403), site_login_exists (409), login_identity_conflict (409), legacy_duplicate_saved_logins (409), saved_login_unsettled (409), login_in_use (409), login_save_in_progress (409), request_too_large (413), invalid_credential (422), internal_error (500), acceptance_unknown (503), temporarily_unavailable (503). Every error has the same envelope.Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
The website: anthem.com, www.anthem.com or a pasted URL, kept as its HTTPS origin
2048a string at most 200 character(s) long
1 - 200a string at most 1024 character(s) long
1 - 1024a string at most 320 character(s) long
3 - 320a string at most 64 character(s) long
3 - 64a string at most 128 character(s) long
1 - 128The identifier it signs in with; else the first it holds in this order
username, email, phone, account_number a string at most 16384 character(s) long
1 - 16384code: the site sends a code each sign-in, so no password is saved
password, code a string matching the pattern ^\d{4}-(?:0[1-9]|1[0-2])-(?:0[1-9]|[12]\d|3[01])$
^\d{4}-(?:0[1-9]|1[0-2])-(?:0[1-9]|[12]\d|3[01])$a string at most 10 character(s) long
3 - 10a string at most 4096 character(s) long
1 - 4096an array of at most 20 item(s)
1 - 20 elementsa string at most 64 character(s) long
4 - 64A two-factor method: sms, call, email, authenticator, push or recovery_code
sms, call, email, authenticator, push, recovery_code Answer a Dashboard page where the person types the login instead, so no secret reaches this client
dashboard Response
With deliver dashboard: where to finish
A signed-in Dashboard page where the person finishes this and sees the secret once