Safety & control

Vault

Logins for your team's browsers, encrypted on your Mac. Agents sign in without ever seeing a password.

The Vault holds logins for the sites your team works on: a username, a password and, optionally, an authenticator setup key so two-factor sign-ins don’t stop them.

Adding a login to the Vault

How it’s kept

  • Logins are encrypted with AES-GCM. The key lives in your Keychain on this Mac; the database only holds ciphertext.
  • Revealing or copying a password needs Touch ID.
  • Every use is logged.

Who can use a login

When you add or edit a login, choose who can sign in with it. Turn on Ask me each time to approve every use from your Inbox.

How agents sign in

Agents never handle the secret. They open the site’s sign-in page in their browser and call:

Tool What it does
vault_list The logins they can use, and ones they can ask for — sites and usernames only, never passwords
browser_login Reigh fills the username and password into the page itself
browser_fill_code Reigh fills the current verification code from the authenticator key

Reigh only fills a login on that login’s own sites, and only over HTTPS. Page snapshots the agent reads mask filled fields, so no password or code ever reaches the model.

Separate browsers

Each employee’s browser has its own cookies and storage, so a sign-in is only ever theirs. Taking a login away signs them out of its sites, and letting someone go clears their browser.