Skip to main content
POST
Save a login
The response shows the site and a masked username (to***h) only. No endpoint, tool or webhook ever returns the password, the authenticator seed or a code. Add totp_secret when the site asks for a code from an authenticator app. The run works out the current code itself when it signs in. There is no MCP tool for this on purpose: a password in a tool call would stay in the AI client’s chat history. Save logins here or in the app’s Vault. See Skills that need a login.

Authorizations

Authorization
string
header
required

API key with the vd_sk_ prefix. Create keys from Settings, API Keys in the dashboard.

Body

application/json
site
string
required

The site's domain or a URL on it.

Example:

"the-internet.herokuapp.com"

username
string
required
Maximum string length: 320
password
string
required

Stored encrypted. Never returned by any endpoint.

Maximum string length: 1024
totp_secret
string | null

Authenticator seed (base32, or the whole otpauth:// URI) for sites that ask for an app code. Never returned.

label
string | null
Maximum string length: 120
notes
string | null
Maximum string length: 500

Response

Saved. The masked login.

A saved login as every endpoint shows it. Never the password, seed or a code.

id
string
site
string | null
username_hint
string
Example:

"to***h"

label
string
notes
string | null
has_totp
boolean
created_at
string<date-time>
updated_at
string<date-time>