Identities & sign-ins
An identity is the person an Astari acts as: its logins, its documents, its saved sessions.
Most useful work needs to be signed in. An identity holds the logins and files an Astari uses, so you set them up once instead of per job.
You can have more than one — a personal identity and a work identity, or one per brand — and point different Astarii at different ones. Sessions never mix between them.
Two ways to connect an account
| Saved login | You store a username and password for a site. The Astari types them in like you would. Works anywhere. |
| Connected app | You authorise Gmail, Outlook, Calendar, Drive, Sheets, Slack, Notion, GitHub and others once. The Astari then uses the app directly instead of driving its website — faster and far more reliable. |
Prefer a connected app where one exists. Driving Gmail's website works, but reading mail through the connection is quicker and does not break when the page layout changes.
Scope
A connected app can be attached to one identity or shared account-wide. Account-wide suits things like your calendar; per-identity suits a brand's own mailbox.
Staying signed in
After the first successful sign-in an Astari keeps that session, so later runs skip the login entirely. If a session expires it signs in again from the saved login. Sites that force a code by email or SMS will park the run and ask you for that one step rather than failing.
Where credentials live
- Passwords are encrypted and only ever decrypted on our server, at the moment of typing them into the site they belong to.
- They are never sent to your browser, the extension, the desktop app or your phone — not even during a smart-routed run, which receives cookies only.
- An Astari is told never to reveal them, and run transcripts have them stripped out.
For anything you would not want touched by mistake — a primary bank or a main email — give an Astari its own account rather than yours. This is ordinary hygiene for automation, not a limitation of Astarii.