Auth Your Agent
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| AYA_AGENT_ID | No | The agent ID, obtained from adding the agent in the phone app (Agents > Add an agent). | |
| AYA_KEY_FILE | No | Path to the agent key file (e.g. /path/to/agent-key.pem), obtained from adding the agent in the phone app (Agents > Add an agent). | |
| AYA_VAULT_URL | No | URL of the browser vault (e.g. http://127.0.0.1:7801). | |
| AYA_VAULT_TOKEN_FILE | No | Path to the vault token file (e.g. ~/.authyouragent/vault/token). |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| navigateA | Open a URL in the vault's browser and wait for the page to load. Returns the final URL and title, after any redirects (a redirect to a sign-in page means you need check_login_wall, then request_takeover). Only public websites open: local, private-network and internal addresses are refused with an error. The page keeps any session the owner signed in to during a take over. url: the full URL, e.g. "https://example.com/account". |
| clickA | Click an element on the current page and return the page's URL and title afterwards. If the click would commit something (it submits a form, or the button says create, send, save, delete, pay and the like), the vault first asks the owner to approve it on their phone and waits up to about five minutes; a denial returns an error and nothing is clicked. Sign-in and search forms are not interrupted. selector: a CSS or Playwright selector, e.g. "button[type=submit]" or "text=Add Server". |
| type_textA | Type into a form field (replaces its value). Never use this for the owner's passwords or codes: use fill_secret if the owner saved the sign-in, otherwise ask for a take over. selector: the field, e.g. "input[name=url]". text: what to type. submit: press Enter afterwards. |
| list_secretsA | List the sign-ins the owner has made available to you from their password manager: each item's name, the sites it may be used on, and which fields it has (username, password, totp). Values are never shown to you. |
| fill_secretA | Fill a field from the owner's password manager. The vault types the value itself; you never see it. It only fills on a site saved with the item, and only the right kind of field: a password into a password field, a totp code into a one-time code field, a username into a text or email field. Then click the sign-in button as usual. selector: the field, e.g. "input[type=password]". name: the item name from list_secrets. field: username, password or totp. |
| read_pageA | Read the current page: its URL, title and visible text, in reading order. Use it after navigate or click to see what is on screen (no screenshot needed). Text in form fields and hidden elements is not included. max_chars: how much text to return, 200 to 20000 (default 5000). |
| check_login_wallA | Check whether the page is stuck at a sign-in, one-time code (2FA) or sign-in approval step. Reads form fields and page text only. |
| request_takeoverA | Ask your owner to take over the browser from their phone when you are stuck at a login, 2FA code, CAPTCHA or anything only they can do. You are disconnected from the browser while they are in control, and you never see what they type. Returns result: done / cancelled / expired / incomplete, or result: waiting with a takeover_id for wait_for_takeover. reason: one short line shown to the owner, e.g. "Please sign in to example.com". |
| wait_for_takeoverA | Keep waiting for a take over that request_takeover returned as "waiting". Returns the same results as request_takeover: done (continue on the signed-in page), cancelled or expired (stop and tell your user), incomplete (the page still asks for sign-in), or waiting again with the same takeover_id. takeover_id: the id request_takeover returned, e.g. "tk_...". wait_seconds: how long to wait this time (default as request_takeover). |
| end_sessionA | End the owner's session when you are finished with the web: the vault signs out of the sites used, then destroys the browser profile. Always call this when done. (The vault also does it by itself if you stop running or the owner revokes you.) |
| request_approvalA | Ask your owner to approve a sensitive action before you perform it. The owner receives a push notification on their phone showing the site and action. They approve or deny. You should not perform the action until this returns approved. Use this before deleting data, changing settings, making purchases, modifying permissions, or any action that could have irreversible consequences. site: the domain or URL of the site where the action will be performed, e.g. "github.com". action: a short label for the action, e.g. "delete repository", "change password", "purchase subscription". wait_seconds: how long to wait for the owner's response (default 120, max 290). Returns: "approved" or "denied" or "expired" (owner did not respond in time). |
| check_agent_statusA | Check whether your agent is still authorized by the owner. The owner can revoke your access at any time from their phone. Call this periodically (e.g. before starting a new task) to verify you are still active. Returns: active / revoked / error. |
| report_siteA | Report a site where take over did not work correctly, so the team can improve it. Call this whenever check_login_wall misses a login, takeover fails to complete, the handback does not trigger, or anything else goes wrong on a real site. site: the domain or URL, e.g. "reddit.com". kind: one of: shadow_dom, bot_detection, input_not_detected, takeover_failed, handback_failed, session_not_cleared, oauth_blocked, other. detail: one short line describing what happened (optional). url: the full page URL if known (optional). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 13 tools
Most tools target clearly distinct operations (navigate vs click vs type_text vs read_page vs fill_secret). The takeover cluster (check_login_wall, request_takeover, wait_for_takeover) and the two check_* tools risk minor confusion, but the descriptions explicitly explain how they chain together.
Strong snake_case, verb-first convention throughout (list_secrets, fill_secret, read_page, end_session, request_approval, request_takeover). Only minor deviations: bare-verb browser tools (navigate, click) and the verb_prep_noun form of wait_for_takeover, which still stay readable and predictable.
13 tools is well within the ideal 3-15 range and each one earns its place: browser control, secret filling, the login/takeover lifecycle, approval, session teardown, reporting and status all cover distinct needs without redundancy.
The set covers the full auth-agent lifecycle: authorization check, browsing actions, secret filling, login-wall detection, owner takeover, approvals, session cleanup and issue reporting. Minor gaps exist (e.g. no explicit scroll, back-navigation or screenshot), but core agent workflows have no dead ends.