Never the password
An agent gets titles and usernames, and whether a login was filled. Nothing Vautir tells it holds a password, a one-time code or a passkey.
An agent that books or orders for you sometimes reaches a sign-in page. With Vautir it asks, you approve in Vautir's extension, and the extension fills the form. The agent never sees the password.
// Your agent's MCP settings
{
"mcpServers": {
"vautir": { "command": "vautir", "args": ["mcp"] }
}
}
The command line carries an MCP server, vautir mcp, which agents that speak the Model Context Protocol can use. Keep Vautir's extension unlocked in the browser the agent works in.
It can ask which logins you have for a page, and ask for one to be filled, with its reason. Vautir's button shows a count, and its popup shows the site, the agent's name and why.
Fill it in fills the login into the tab open on that site. Refuse tells the agent no. Either way, the agent hears only how its request ended.
An agent gets titles and usernames, and whether a login was filled. Nothing Vautir tells it holds a password, a one-time code or a passkey.
The extension fills only a page whose address the login matches, as always. An agent that asks for one site's login while on another gets nothing.
Each request is encrypted on the device that asked, with your account's keys. The server passes it along without learning the agent or the site.
A login filled from an organization's vault goes in its audit log, as any fill does.
The agent names itself and gives its own reason: read them as its claims. And an agent that controls your whole screen could press the extension's button itself, which is why approving on your phone comes next.
Availability
Any agent that can use an MCP server.
Your approval is noted, and the agent is told there was no form to fill.
Two minutes. After that the agent is told it wasn't answered.
Free forever for unlimited passwords and devices. No card needed.