Ask the user to set a login Bowmark will need
request_secretCreate a named, empty slot for a secret and get back a link the user opens to fill it in. They type the value on a Bowmark page and choose how long it lives, from 5 minutes to never. It is encrypted in their own browser before it leaves, so nothing on the way — this connection included — ever sees it.
Give the user the link. Never ask them to type a password, API key or one-time code to you. A secret in this conversation is in your context, in the transcript and in the logs.
Name it for the person, not for your script. The name you pass is the heading on the page they open and the row they see in their secret list months later, so make it <site>_<what it is>: letterboxd_password, stripe_api_key, acme_totp_seed. A run id, a timestamp, a uuid or a bare password is refused.
Call list_secrets first: if the name already exists and is set, use it instead. name is lowercase letters, digits, _, . and -. hosts narrows where the value may be used and is worth passing — a secret is refused against any other site.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Lowercase name, `<site>_<what it is>` — `letterboxd_password`, `stripe_api_key`, `acme_totp_seed`. Letters, digits, _ . - only. THE USER READS THIS: it is the heading on the page they open and the row in their credential list months later, so use words, never a run id, a timestamp or a bare `password`. | |
| type | Yes | What kind of value the person will be asked for. | |
| hosts | No | Hosts the value may be used against, e.g. ["acme.com"]. Refused elsewhere. |