your logins
your agent can act inside the accounts that are yours, three ways: through your own browser's open sessions, on your own computer, and through accounts you connect once. each way keeps the password out of the agent's hands, and this page says exactly what is held where.
an agent that can only read the public web is a research assistant. one that can act where you are already signed in is a pair of hands. the difference is logins, and logins are the part people are right to be careful about, so here is every door and what stands behind it.
the three doors
your own browser. a small extension connects your agent to the Chrome you already use, so it can open the sites you are signed into, fill forms, and finish tasks in tabs that carry your sessions. nothing is copied out: your cookies and passwords stay in your browser, on your computer, and the agent works through the relay while it is connected and not a second longer. close the relay and it has nothing.
your own computer. with the relay on, your agent can also run a command or take a screenshot on your own Mac or PC, not only on its machine: tidy a folder, open an app, read a file you point it at. it tells you what it is about to run before it runs it, and everything it does there stays on your machine.
connected accounts. for services with a proper sign-in, you authorise your agent once, in the service's own page, and it holds a token for that account rather than your password. those tokens are held on our side, encrypted, and every connected account starts read-only: writing to it, sending, paying, deleting, waits for your approval of that exact action. connectors has the list and the rules.
what is vaulted where?
- passwords: never with the agent. the browser keeps them; the connected-account sign-in never shows them to us.
- account tokens for connected services: on our side, encrypted at rest, scoped to what you authorised.
- your brokerage sign-in, where you connect one: held in a vault on our side, never on the agent's machine.
- the token your agent's machine uses to reach the platform, and any trading-venue key still on the machine: on the machine, not yet encrypted at rest; privacy and your data says so plainly and what is being done about it.
what will it not do with a login?
move large money, send a high-impact message, or change a password on its own. the relay page says the same thing we do: for a wire transfer, a large purchase, or an email you would not want sent by mistake, disconnect the relay, do it yourself, and reconnect. spending through the agent's own wallet has its own limits and approvals; spending through your accounts has you, every time.
what is switched on today?
the browser relay works today and is marked beta. control of your own computer works where the relay is installed. connected accounts work for the services listed on connectors as live, and the others say coming. the brokerage vault exists for the brokerage rail; your brokerage account says what that rail can do today.
what next
- connectors: which services connect and what each may read or write
- research and browsing: what the agent can do on the open web without any login
- privacy and your data: what we can and cannot see
Reading this as a machine? Get the raw markdown.