Credentials
Credentials are saved logins you can authorize for a Stairway browser session. They are meant for agent-driven logins and the remote Login control — not for autofilling every page you open.
Open Credentials from the header when signed in.
What you store
For each credential you typically set:
- Label — a name you recognize (for example “Corp wiki”)
- Domain — the site the login is for
- Username and secret (password)
- Optional notes and team attribution
Secrets are encrypted at rest. After you save, the secret is never shown again in the UI.
How login works
- Add the credential on Credentials.
- When you create a new browser, authorize the credentials that session may use.
- In the remote browser, open the site’s login page, then either:
- Press Login on the stream toolbar, or
- Have an agent call the MCP login tool (
browser_login)
Stairway does not autofill credentials on page load. You (or the agent) choose when to apply them.
Sharing
You can share a credential with a team so teammates can authorize it on their sessions (according to your team’s practices). Prefer team-scoped credentials for shared research accounts; keep personal credentials personal when the secret should not leave your account.
Tips
- Authorize only what that session needs — you can always create another session with a different set.
- Rotate secrets in Stairway when you rotate them at the site.
- Deleting a credential does not remove it from sessions that already authorized it; start a new session if you need a clean set.