An AI agent that works in your browser sometimes reaches a sign-in page. With Vautir, it asks; you approve in Vautir’s extension; the extension fills the form. The agent never sees the password.
Set it up
-
Log the computer in with the command line, and start a session for the agent:
vautir unlock --raw --minutes 480That prints the session’s key.
-
Add Vautir to your agent’s MCP servers, with that key:
{ "mcpServers": { "vautir": { "command": "vautir", "args": ["mcp"], "env": { "VAUTIR_SESSION": "…" } } } } -
Keep Vautir’s extension unlocked in the browser the agent uses.
When the agent asks
Vautir’s button shows a count, and its popup asks: An AI agent asks to sign in to example.com, with the agent’s name, its reason, and your logins for that site.
- Fill it in fills the login into the tab open on that site.
- Refuse tells the agent no.
A request waits for two minutes.
What the agent gets
Which logins you have for a page, by title and username, and how its request ended: filled, refused, or approved with no form to fill. Never a password.
What to know
- Only the login’s own site. The extension fills only a page whose address the login matches. An agent that asks for one site’s login while on another gets nothing.
- The agent names itself, and gives its own reason. Read them as its claims.
- An agent that controls your whole screen could press the extension’s button itself.
- We see neither the agent nor the site. Each request is encrypted with your account’s keys.
- In an organization, a login filled from one of its vaults goes in its audit log.
- Only the browser extension answers agents.
Last updated October 4, 2026