> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Saved logins and protected input

Enter website credentials in Pomerado's protected browser forms. Keep passwords, TOTP seeds and durable tokens out of prompts and MCP tool arguments.

A saved connection belongs to the account. Authorized clients can use it according to their permissions.

## Choose a saved login

Use `list_connections` on an endpoint that advertises it. An optional `site_origin` filters the results to an exact website origin.

```json theme={null}
{
  "site_origin": "https://example.com"
}
```

The response contains metadata only.

```json theme={null}
{
  "connections": [
    {
      "id": "33333333-3333-4333-8333-333333333333",
      "label": "My example login",
      "siteOrigin": "https://example.com",
      "maskedUsername": "a***",
      "authMode": "password",
      "smsCodeNumberLinked": false
    }
  ]
}
```

Pass the selected ID as `connected_account_id` to `run_tool` or `build_tool`. Follow each generated tool's advertised schema for its connection selector.

* Choose the intended login before starting a write.
* Use an HTTPS origin without a path, query or embedded credentials.
* Keep the connection ID separate from the integration ID and job ID.

## Follow the account's login policy

| Account | Saved logins per site | Editing policy |
| - | - | - |
| Personal Free | One | Locked after the first verified sign-in |
| Personal Premium | One | Locked after the first verified sign-in |
| Business | Multiple | Editable with the required permissions |

* Correct an unverified Personal login before its first successful sign-in.
* Expect updates to be refused while the login is in active use.
* Treat the Personal login lock as permanent after verified sign-in.
* Treat deletion as credential removal, not a way to unlock or replace a verified Personal login.

Deleting a verified Personal login does not free its site slot. Premium uses the same login policy as Free.

## Open a protected management page

Call `manage_connection` to get a browser URL. The tool accepts action metadata only.

```json theme={null}
{
  "action": "create"
}
```

For an existing connection, include its ID.

```json theme={null}
{
  "action": "update",
  "connection_id": "33333333-3333-4333-8333-333333333333"
}
```

Supported action names are `create`, `import`, `update`, `reveal` and `totp`. The last three require `connection_id`.

`import` opens a protected page that takes up to 1000 logins as a JSON array, each with the fields a single saved login takes (`label`, `siteOrigin`, `username`, `password` and optional `totpSeed`). It reports each login's outcome.

A successful management request returns `status` of `protected_input_required` and a `url`.

* Open the returned URL in your browser.
* Sign in to the account that owns the connection.
* Complete any required PIN or fresh authentication check.
* Enter or view sensitive values only on the protected page.

The URL does not grant access by itself. A browser session also does not replace the MCP client's permissions.

`reveal` opens a protected view of a saved login. `totp` opens a protected view of a current TOTP code. Neither action returns those secrets through MCP.

## Supply credentials to a waiting job

When a job's login is missing, rejected by the website or expired, the job asks for it in place. `get_job` shows a pending request with one `credential` question. Its `reason` is `missing_credentials`, `invalid_credentials` or `credentials_expired`, its `fields` is `username_password` or `password`, and `allowSave` says whether the login may be saved.

* Open the request's `protected_input_path` to enter the login there, or call `provide_input` with `job_id` alone to get its URL.
* A rejected or expired login keeps its username; you replace only the password.
* The job signs in again on the same browser once you answer. If the website still rejects the login, the job fails.
* Without an answer the job ends with `failure_reason` set to `no_response`.

Sending a login through `provide_input` answers are visible to your client and its model provider. Use the protected page to keep them out of the conversation.

## Handle website challenges

Codes, sign-in choices and native website dialogs arrive the same way, as questions in a pending request. Answer them on the protected page or with `provide_input`; see [jobs](jobs.md). A code sent through `provide_input` may be visible to your client or its model provider.

Passwords, TOTP seeds and durable tokens never belong in `provide_input`.

## Delete a saved connection

Call `delete_connection` with the selected connection ID.

```json theme={null}
{
  "connection_id": "33333333-3333-4333-8333-333333333333"
}
```

The response has `status` of `deleted` or `deletion_pending`.

* Treat the connection as revoked once deletion is requested.
* Expect related jobs and saved sessions to be invalidated.
* Retry deletion for the same connection if cleanup remains pending.
* Preserve the Personal site-slot restriction after verified login deletion.

Deletion removes saved access. It does not reverse actions already performed on the website.

See [jobs and results](jobs.md) for resuming work and [authentication](authentication.md) for permissions.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.