your logins
your agent can act inside the accounts that are yours, three ways, through your own browser's open sessions, on your own computer, and through accounts you connect once. none of the three asks for your password, and this page says exactly what is held where.
an agent that can only read the public web is a research assistant. one that can act where you are already signed in is a pair of hands. the difference is logins, and logins are the part people are right to be careful about, so here is every door and what stands behind it.
the three doors
your own browser. a small extension connects your agent to the Chrome you already use, so it can open the sites you are signed into, fill forms, and finish tasks in tabs that carry your sessions. nothing is copied out: your cookies and passwords stay in your browser, on your computer, and the agent works through the relay while it is connected and not a second longer. close the relay and it has nothing.
your own computer. with the relay on, your agent can also run a command or take a screenshot on your own Mac or PC, not only on its machine: tidy a folder, open an app, read a file you point it at. it tells you what it is about to run before it runs it, and everything it does there stays on your machine.
connected accounts. for services with a proper sign-in, you authorise your agent once, in the service's own page, and it holds a token for that account rather than your password. those tokens are held on our side, encrypted. one Connect button grants the whole connection, and anything that leaves your account or can't be undone, like sending, paying or deleting, asks you first, every time. connectors has the list and the rules.
what is vaulted where?
- passwords. we never ask for your passwords and we don't keep any. in your own browser, your browser keeps them. when you connect an account, you sign in on that service's own page and we keep a token instead. if you paste a password into a chat, it becomes part of that conversation, so please don't.
- account tokens for connected services: on our side, encrypted at rest, scoped to what you authorised.
- your brokerage sign-in, where you connect one: held in a vault on our side, never on the agent's machine.
- the token your agent's machine uses to reach the platform, and any trading-venue key still on the machine: on the machine, not yet encrypted at rest; privacy and your data says so plainly and what is being done about it.
what will it not do with a login?
move large money, send a high-impact message, or change a password on its own. the relay page says the same thing we do: for a wire transfer, a large purchase, or an email you would not want sent by mistake, disconnect the relay, do it yourself, and reconnect. spending through the agent's own wallet has its own limits and approvals; spending through your accounts has you, every time.
what is switched on today?
the browser relay works today and is marked beta. control of your own computer works where the relay is installed. connected accounts work for the services connectors names as open right now, and the rest open one at a time. the brokerage vault exists for the brokerage rail; your brokerage account says what that rail can do today.
what next
- connectors: which services connect and what each may read or write
- research and browsing: what the agent can do on the open web without any login
- privacy and your data: what we can and cannot see
Reading this as a machine? Get the raw markdown.