login_, such as login_3f0c8a5e1d2b4c6f8a9b0c1d2e3f4a5b.
Reading logins needs the logins:read permission. Saving, changing, deleting and importing them needs logins:manage.
Choose a saved login
List the logins withGET /v1/logins or, in an MCP client, list_logins. An optional site_url filters the results to one website: a host such as example.com or www.example.com, or a URL on it. Logins anywhere on the site match, so example.com also finds a login saved for https://www.example.com. Page through the results with limit and cursor.
data and a next_cursor that is null on the last page. It contains metadata only. A list never contains a password or other secret.
statusisunverifieduntil a sign-in with the login succeeds,verifiedafter that, andneeds_attentionwhen the website rejected it. Thenneeds_attention.fieldnames the rejected field.sign_inispassword, orcodewhen the website sends a code at each sign-in and no password is saved.saved_fieldsandtwo_factor.authenticatorarenullwhen Pomerado has not recorded what the login holds.lockedistruefor a Personal login after its first verified sign-in.created_atandupdated_atare when the login was saved and last changed, andverified_atis its first verified sign-in, ornullbefore one. All are ISO 8601 UTC times.
GET /v1/logins/{id} returns one login.
A label is optional. A login without one has "label": null; refer to it by its site and masked username, as the Dashboard does: example.org · jo***om. A change keeps the label unless it sends a new label, or "label": null to remove it.
Pass the selected ID as connected_account_id to run_website_tool or build_website_tool, or in a run or build request. Follow each generated tool’s advertised schema for its login selector.
- Choose the intended login before starting a write.
- When saving a login, give its website as a host (
example.com), withwww., or as a pasted URL. Pomerado saves the site’s HTTPS origin. Embedded credentials and other schemes are refused. - Keep the login ID separate from the integration ID and job ID.
Follow the account’s login policy
- Correct an unverified Personal login before its first successful sign-in.
- Expect updates to be refused while the login is in active use.
- Treat the Personal login lock as permanent after verified sign-in.
- Treat deletion as credential removal, not a way to unlock or replace a verified Personal login.
Save a login
POST /v1/logins saves a login and returns 201 with the new login. In an MCP client, call call_pomerado_api with the operation logins.create.
site_urlis required. Send at least one ofusername,email,phoneoraccount_number. The first in that order is the sign-in identifier, unlessprimary_identifiernames another one you sent.- A password login needs
password. For a website that sends a code each time, send"sign_in": "code"and no password. - Optional extras are
date_of_birth,zip,authenticator_secret,recovery_codesandpreferred_method(sms,call,email,authenticator,pushorrecovery_code). - A Personal account can save one login per website. A second save for the same site is refused with
site_login_exists.
"deliver": "dashboard" with only site_url and, if you like, label. The answer is {"dashboard_url": "..."}, a link to the page where you enter the login. Nothing is saved until you submit that page.
Change a login
PATCH /v1/logins/{id} (logins.update) changes a saved login. Every field is optional: a field you leave out keeps its value, and null clears an optional one.
- A password login’s label, identifiers and authenticator secret change only together with its
password, since they are saved with it. Its other fields (date_of_birth,zip,recovery_codes,preferred_method) change on their own. - The website and the sign-in mode never change. Save a new login for another site, or delete and save again to switch between password and code sign-in.
- Send
"deliver": "dashboard"alone to get{"dashboard_url": "..."}for the login’s edit page. - A Personal login that has signed in successfully is locked and refuses changes.
Replace recovery codes
PUT /v1/logins/{id}/recovery-codes (logins.set_recovery_codes) replaces the login’s recovery codes.
Import many logins
POST /v1/logins/import (logins.import) takes up to 1000 logins, each with the fields a single save takes.
{"results": [...]}, one entry per login in order. Each has the index and either the saved login or an error, so one refused login does not stop the others. Send "deliver": "dashboard" instead of logins to get the link to the Dashboard’s import page.
Two-factor sign-in and Pomerado phone numbers
Business accounts can give a login a Pomerado phone number, so Pomerado reads the website’s text-message sign-in codes for you. The number operations are:
Each answer is the number: its
phone_number, status (linked or verified), linked_at, verified_at and, during a verification, verification.expires_at, code_received and code. Showing the number of a login that has none is 404 sms_number_not_linked; an account without the feature gets sms_number_not_allowed. A login’s two_factor.sms_number says none or linked.
An authenticator secret saved with the login lets Pomerado compute authenticator codes during sign-in. Recovery codes are used up as sign-ins need them.
See and reveal secrets on the Dashboard
Showing a saved password, reading the current authenticator code and setting the Logins PIN happen only on the Dashboard. The REST API and MCP answer{"dashboard_url": "..."} for them instead, so that no password or PIN reaches a script or a model provider.
- Reveal a login’s saved values from its Logins page. A reveal shows everything except the authenticator secret, and counts the recovery codes.
- The login’s authenticator code page shows the code that is valid now.
- On a Personal account, both need the Logins PIN. You set, change, reset, unlock and lock it on the Logins page.
- A Business account needs a sign-in within the last five minutes.
Delete a saved login
DELETE /v1/logins/{id} (logins.delete) deletes the login and answers 204.
- Treat the login as revoked once deletion is requested.
- Expect related jobs and saved sessions to be stopped.
- Retry the deletion if a first attempt ends without an answer.
- Preserve the Personal site-slot restriction after verified login deletion.
Use logins from an MCP client
The account MCP has one login tool of its own:list_logins, with site_url, cursor and limit. It returns the same data and next_cursor as the REST list. Every other login operation is reached with call_pomerado_api:
- Call
search_pomerado_apiwith theloginsgroup to find the operations. - Call
describe_pomerado_apiwith an operation, such aslogins.create, to read its input. - Call
call_pomerado_apiwith the operation and its input.
dashboard_url. A client that supports URL elicitation asks you to open it.
Supply credentials to a waiting job
When a job’s login is missing, rejected by the website or expired, the job asks for it in place.get_job shows a pending request with one credential question. Its reason is missing_credentials, invalid_credentials or credentials_expired, its fields is username_password or password, and allowSave says whether the login may be saved.
- Open the request’s
protected_input_pathto enter the login there, or callanswer_jobwithjob_idalone to get its URL. - A rejected or expired login keeps its username; you replace only the password.
- The job signs in again on the same browser once you answer. If the website still rejects the login, the job fails.
- Without an answer the job ends with
failure_reasonset tono_response.
answer_job is visible to your client and its model provider. Use the protected page to keep it out of the conversation.
Handle website challenges
Codes, sign-in choices and native website dialogs arrive the same way, as questions in a pending request. Answer them on the protected page or withanswer_job; see jobs. A code sent through answer_job may be visible to your client or its model provider.
Passwords, authenticator secrets and durable tokens never belong in answer_job.
See jobs and results for resuming work, authentication for permissions and REST API for API keys.