Laki Agent Docs

Password managers & autofill

Use 1Password or Bitwarden inside Laki Agent today with Universal Autofill (⌘\) — no extension needed, and no in-app vault by design.

Laki Agent deliberately ships no built-in password vault — storing, syncing, and recovering credentials is a liability magnet, and mature products already do it better. Instead, the app is built to work *with* the password manager you already trust.

What works today: Universal Autofill (⌘\)

1Password and Bitwarden on macOS offer *Universal Autofill*: it types into whatever field is focused at the OS accessibility layer, so it is browser-agnostic — it fills Salesforce login pages inside Laki Agent's embedded browser the same way it fills any native app.

  1. In 1Password → Settings → Developer/Autofill, enable Universal Autofill (Bitwarden: Settings → Auto-fill, enable the accessibility integration and grant the macOS permissions it asks for).
  2. In Laki Agent, click into the Username field on your org's login page.
  3. Press ⌘\ (Command-Backslash). Pick the matching login; it fills username + password.

Tip: save your org logins against the org's My Domain URL (e.g. acme.my.salesforce.com) so your password manager offers the right credential on the right org — including sandboxes (…sandbox.my.salesforce.com).

Why there's no 1Password/Bitwarden browser extension

Browser extensions are a Chrome/Firefox distribution channel: modern MV3 extensions can't be hosted inside an embedded Chromium app, and password-manager vendors only allowlist mainstream browsers for their extension integrations. Universal Autofill exists precisely for every other app — which is why it's the supported path here.

What's coming

  • Passkeys — platform WebAuthn (Touch ID / iCloud Keychain) is wired in the app and arrives once the signing profile that authorizes it ships.
  • First-party biometric fill — a deeper integration via the op / bw CLIs (unlock with Touch ID, fill without the clipboard) is on the roadmap.

Hardware security keys (USB FIDO2), authenticator apps, TOTP, and SMS MFA already work in the embedded browser — see Troubleshooting.