Sessions & HITL
Decide how the agent makes new accounts
Sign up with Google or GitHub (in your order) when the site offers it, the email to register with, and the password — the defaults a sign-up follows for whatever the prompt leaves out.
set_new_account_defaults
What it is
The job: Decide what the agent signs up with when you did not say.
`signUpWith` is the ORDERED list of providers a sign-up may take — `["github", "google"]` tries GitHub first, then Google. The run takes the first one the page offers that this workspace can sign in with: a captured session (POST /connect/sessions for the provider’s sign-in host) or a saved login for it. There is no password to keep; the method is remembered for the site so the next sign-in takes the same door. `"password"` or `[]` always fills the form, as does a site that offers none of them.
`email` is the address a sign-up uses when the prompt names none. It should be an inbox you have connected, because most sites confirm a new account by email; the answer reports `emailInboxConnected`, and a run prefers that inbox for its codes. `password` sets the default password; with none, each site gets its own strong generated one, readable afterwards with reveal_account. A method, email or password in the prompt always wins.
The call
Call it exactly like this.
Copied from the tool's registration and the route handler — not paraphrased.
// MCP tool call — server "twin-browser"
{
"tool": "set_new_account_defaults",
"arguments": {
"signUpWith": ["github", "google"],
"email": "signups@example.com"
}
}curl -X PUT https://twin-browser.com/api/v1/accounts/signup-defaults \
-H "Authorization: Bearer $TWIN_API_KEY" \
-H "content-type: application/json" \
-d '{"providers":["github","google"],"email":"signups@example.com"}'With “save secrets automatically” turned off for the workspace, no password is generated — a password nobody keeps is one nobody holds — so a sign-up without a default password asks for one instead.
| Parameter | Type | What it does |
|---|---|---|
| signUpWith | string[] | "password" | Ordered providers ("google", "github") to sign up with when offered and usable; "password" or [] always fills the form. |
| string | null | Default address for new accounts; null clears it. | |
| password | string | Default password, 8–128 characters (PUT /accounts/new-account-password). |
| clearPassword | boolean | Remove the default password: each site gets a generated one. |
Returns
{ "defaults": { "providers": [
{ "id": "github", "on": true, "ready": true, "session": true, "login": false },
{ "id": "google", "on": true, "ready": false, "session": false, "login": false } ],
"email": "signups@example.com", "emailInboxConnected": true },
"password": { "set": false, "whenUnset": "generated per site" } }What it costs
Free
Settings writes. Values are stored encrypted where secret and never returned.
See the full rate cardWhich one
When a different tool is the right call.
The honest answer is often the neighbouring tool. These are the trades.
reveal_accountLeave the password unset for a unique one per site, then read the one you need with reveal_account.
reveal_accountconnect_accountconnect_account { host: "accounts.google.com" } is how the Google session that makes Google sign-up one click gets captured.
connect_accountKeep going
The rest of the tool set.
reveal_accountGive the owner of a newly provisioned account the login the agent signed up with.
list_accountsAnswer “can I get into this site, and as whom?” before starting a run.
connect_accountGet logged into a site that an agent is not going to be allowed to log into.
run_goalDo one thing on one site, right now, and block until you know whether it worked.