Choose a saved login
Uselist_connections on an endpoint that advertises it. An optional site_origin filters the results to an exact website origin.
connected_account_id to run_tool or build_tool. Follow each generated tool’s advertised schema for its connection selector.
- Choose the intended login before starting a write.
- Use an HTTPS origin without a path, query or embedded credentials.
- Keep the connection ID separate from the integration ID and job ID.
Follow the account’s login policy
- Correct an unverified Personal login before its first successful sign-in.
- Expect updates to be refused while the login is in active use.
- Treat the Personal login lock as permanent after verified sign-in.
- Treat deletion as credential removal, not a way to unlock or replace a verified Personal login.
Open a protected management page
Callmanage_connection to get a browser URL. The tool accepts action metadata only.
create, import, update, reveal and totp. The last three require connection_id.
import opens a protected page that takes up to 1000 logins as a JSON array, each with the fields a single saved login takes (label, siteOrigin, username, password and optional totpSeed). It reports each login’s outcome.
A successful management request returns status of protected_input_required and a url.
- Open the returned URL in your browser.
- Sign in to the account that owns the connection.
- Complete any required PIN or fresh authentication check.
- Enter or view sensitive values only on the protected page.
reveal opens a protected view of a saved login. totp opens a protected view of a current TOTP code. Neither action returns those secrets through MCP.
Supply credentials to a waiting job
When a job’s login is missing, rejected by the website or expired, the job asks for it in place.get_job shows a pending request with one credential question. Its reason is missing_credentials, invalid_credentials or credentials_expired, its fields is username_password or password, and allowSave says whether the login may be saved.
- Open the request’s
protected_input_pathto enter the login there, or callprovide_inputwithjob_idalone to get its URL. - A rejected or expired login keeps its username; you replace only the password.
- The job signs in again on the same browser once you answer. If the website still rejects the login, the job fails.
- Without an answer the job ends with
failure_reasonset tono_response.
provide_input answers are visible to your client and its model provider. Use the protected page to keep them out of the conversation.
Handle website challenges
Codes, sign-in choices and native website dialogs arrive the same way, as questions in a pending request. Answer them on the protected page or withprovide_input; see jobs. A code sent through provide_input may be visible to your client or its model provider.
Passwords, TOTP seeds and durable tokens never belong in provide_input.
Delete a saved connection
Calldelete_connection with the selected connection ID.
status of deleted or deletion_pending.
- Treat the connection as revoked once deletion is requested.
- Expect related jobs and saved sessions to be invalidated.
- Retry deletion for the same connection if cleanup remains pending.
- Preserve the Personal site-slot restriction after verified login deletion.