Credential Manager
Securely select and fill login forms without exposing stored passwords.
Installation
- Make sure Claude is on your device and in your terminal.
Skills load from
~/.claude/skills/when Claude Code starts up — so you need it on your machine first. If you don't have it yet, install it once with the command below, then runclaudein any terminal to verify.One-time setupnpm i -g @anthropic-ai/claude-codeAlready have it? Skip ahead.
- Paste into Claude Code or into your terminal.
This copies the whole skill folder into
~/.claude/skills/credential-manager-betterwright/— the SKILL.md plus any scripts, reference docs, or templates the skill ships with. Safe default: works for every skill.Faster alternative (instruction-only skills)
Skips the clone and grabs only the SKILL.md file. Don't use this if the skill ships Python scripts, reference markdowns, or asset templates — they won't be downloaded and the skill will fail when it tries to load them.
Quick install (SKILL.md only)Sign up to copy - Restart Claude Code.
Quit and reopen Claude Code (or any other agent that loads from
~/.claude/skills/). New skills are picked up on startup. - Just ask Claude.
Skills auto-activate when your request matches the skill's description — no slash command needed. Trigger phrases live in the skill's own frontmatter; you can read them in the “What this skill does” section above.
Prefer to read the source first? Open on GitHub.
When Claude uses it
Read this before any login, signup, password change, or checkout so the right credential source is used in the right order without ever exposing a secret.
What this skill does
Credential manager
Use metadata to choose an account, then let the password manager detect and fill the form. Never fetch, inspect, transform, or print a stored secret.
Source order
Work down this ladder; stop at the first source that works.
- A configured external manager. If the operator prompt explicitly names
1Password or Bitwarden, use its inline menu and read the matching provider
pack first (
../1password/SKILL.md,../bitwarden/SKILL.md). - BetterWright's built-in vault.
credentials.list()returns matching metadata only: id, username, label, category, saved URL, and match mode. Filter withcredentials.list({text, category}). If one account clearly fits the task, callcredentials.fill({id, submit: true}). BetterWright detects the visible form and resolves/types the secret internally. MCP/Pi'sbrowser_loginand the SDK'sfillCredentialuse the same path. - The page itself. Focus the username field with
human.clickand re-snapshot; a session may already exist, an SSO button may be present, or the user's own password manager may surface. - Ask the user through the host's question mechanism, offering the accounts you found as masked options (e.g. "account ending in 999"). This is the last resort, not the first.
Account choice and staged login
- Search before filling. One clear match may be used directly. If several plausible accounts remain and the task does not disambiguate them, ask with usernames/labels only; never mention a secret.
- On a username-first flow, enter the selected record's public username and
advance. On the password stage call
credentials.fill({id, submit: true}); password-only pages are detected. - Detection uses autocomplete/type/label/form context. If it reports multiple
plausible forms, scope explicit
usernameSelector,passwordSelector,currentPasswordSelector,confirmPasswordSelector, orsubmitSelectorfrom a fresh snapshot. For an ambiguous rotation, pin current, new, and confirmation password roles together. Do not guess selectors before detection fails.
Signup and password rotation
- Call
credentials.generateAndFill({username, submit: true}). Generation returns only an opaque pending id; the encrypted provisional entry is not an active saved login yet. - Verify the site's visible success state. A clicked button or request alone is not proof.
- On success, call
credentials.commitGenerated({pendingId}). On rejection or abandonment, callcredentials.discardGenerated({pendingId}).
If generation fails but returns pendingCredential, do not generate again.
Inspect the visible site outcome, then commit or discard that exact recovery id.
After a complete host restart with no returned id, revisit the signup site and
call credentials.listPending(). Use its secret-free username, label, and
timestamps to identify the attempt; never guess or auto-pick among several.
For rotation, pass the existing credential id to generateAndFill. Commit
only after the site confirms the change; commit updates that item instead of
creating a duplicate. Rotation preserves its URL scope, so update matchMode
separately before rotating when needed. Choose an existing username/email when
the site allows it; never invent an address.
Rules
- An empty
credentials.list()means no enabled item matches this site under its URL policy. Fall through the ladder instead of searching unrelated credentials. - Never read, print, encode, or transmit a password, card number, or one-time
secret. Snapshots and results redact password inputs; keep it that way: no
inputValue(),input.value,evaluate, console, or network probes on secret fields. - A failed fill ("info isn't correct") means the stored secret may be stale: try the next source on the ladder, then ask the user — never brute-force variants.
- Save a task-supplied credential only when the user asks to remember it, and only after the site accepts it.
Related skills
PDF Tools & Editing
anthropics
Read, merge, split, rotate, watermark, encrypt, and extract text from PDF files.
PowerPoint Slide Decks
anthropics
Create, edit, read, and extract content from PowerPoint presentations.
Slack GIF Creator
anthropics
Create animated GIFs optimized for Slack messages and emojis.
Honest Postmortem Analyzer
alirezarezvani
Analyze what went wrong in failures without blame to find real causes.