An AI agent that works in your browser sometimes reaches a sign-in page. With Vallkey, it asks; you approve in Vallkey’s extension; the extension fills the form. The agent never sees the password.
Set it up
-
Log the computer in with the command line, and start a session for the agent:
vallkey unlock --raw --minutes 480That prints the session’s key.
-
Add Vallkey to your agent’s MCP servers, with that key:
{ "mcpServers": { "vallkey": { "command": "vallkey", "args": ["mcp"], "env": { "VALLKEY_SESSION": "…" } } } } -
Keep Vallkey’s extension unlocked in the browser the agent uses.
When the agent asks
Vallkey’s button shows a count, and its popup asks: An AI agent asks to sign in to example.com, with the agent’s name, its reason, and your logins for that site.
- Fill it in fills the login into the tab open on that site.
- Refuse tells the agent no.
A request waits for two minutes.
What the agent gets
Which logins you have for a page, by title and username, and how its request ended: filled, refused, or approved with no form to fill. Never a password.
What to know
- Only the login’s own site. The extension fills only a page whose address the login matches. An agent that asks for one site’s login while on another gets nothing.
- The agent names itself, and gives its own reason. Read them as its claims.
- An agent that controls your whole screen could press the extension’s button itself.
- We see neither the agent nor the site. Each request is encrypted with your account’s keys.
- In an organization, a login filled from one of its vaults goes in its audit log.
- Only the browser extension answers agents.
Last updated October 4, 2026