Skip to main content
Sensitive values are redacted by default before ordinary BrowserPair observations leave the connected device. Disclosure requires an explicit user grant that matches current authority.

Redacted first

Protected values stay hidden unless the workflow truly needs them.

Minimum scope

Grants can be limited to one action, one task, or one agent key.

Revocable + auditable

Reusable grants can be revoked and grant events are recorded.

Protected categories

Passwords & passcodes

Authentication secrets and password-like fields.

OTP & verification codes

One-time and verification values.

Payment & card fields

Card numbers and payment-sensitive values.

API keys & secrets

API credentials and secret tokens.

Auth & access tokens

Authorization values exposed in page fields.

Other sensitive fields

Protected values outside the named categories.

Grant lifetimes

A sensitive-data grant never overrides browser scope, website scope, capabilities, or policy-required confirmation.

Reusable agent grant

1

Choose the agent key

Select the exact reusable key.
2

Choose one category

Grant only the data class the workflow needs.
3

Optionally restrict the domain

Narrow the grant further when possible.
4

Review and revoke

Use the dashboard grant list and audit trail.

Permissions

See the broader authority model.

Task semantics

See how durable state protects retries.