How to let an AI log in without sharing your password

Pasting passwords into ChatGPT or Claude leaves them in chat history and on someone else's servers. Here's a safer way for AI agents to log in, including 2FA codes.

The first time an AI agent hits a login page, most people do the obvious thing: they paste the password into the chat. It works. It's also one of the riskiest habits in AI today. Here's why, and what to do instead.

Why pasting passwords into a chat is risky

  • It's stored. The password now sits in your chat history, and possibly in the AI company's logs, for as long as they keep them.
  • It's shared. Anyone with access to that chat, or a shared project, can read it.
  • It travels. If the AI is tricked by a page it reads (a "prompt injection"), it may repeat what's in its context somewhere it shouldn't.
  • It's not revocable. You can't take back what a model has already seen.

The goal is simple: the AI should be able to type the password, but never read it.

The vault approach

A secrets vault for AI works like a password manager with one twist: the AI can ask the vault to type a secret into the screen, but the vault never hands the value back to the AI.

In AgentDaftar it looks like this:

  1. You save the secret once in the panel: a name (insta_client), the username, the website and a note on when to use it.
  2. The AI sees only that name and the note: insta_client (password, user @client_store).
  3. At the login page, the AI clicks the password field and calls type_secret("insta_client").
  4. The vault types the value straight into the field. The AI's chat only ever contains the name.

The value lives on your company's own server, readable by the system only. It's never sent to the AI company.

What about 2FA codes?

Two-step login is where most AI agents give up and ask you for the code. If you save the authenticator key (the setup key behind the QR code) as a 2FA secret, the vault can type the current 6-digit code, and the AI can finish the login on its own.

That's convenient, and it's real access, so treat it like giving a trusted employee your authenticator. For the most sensitive accounts, use the next step.

Lock the sensitive ones

Some logins should never be used without you knowing: your bank, your payment gateway, your domain registrar. Mark those vault entries ask first. The vault then refuses to type them until you approve that specific use, from a Yes/No message on Telegram.

You can also mark whole websites as guarded, so any action there waits for your approval.

A checklist

  • Never paste passwords, API keys or 2FA codes into an AI chat.
  • Give each AI employee only the secrets it needs for its job.
  • Use 2FA secrets for routine accounts; mark money-related accounts ask first.
  • Check the activity log: every use of a secret is recorded with its name and time.
  • Rotate a password if you ever suspect it was exposed.

Read more about the AgentDaftar vault, or how approvals keep risky actions in your hands.