agent-access

Login-Anmeldedaten, API-Schlüssel und Geheimnisse (Benutzername, Passwort, TOTP) aus dem Bitwarden-Tresor des Benutzers über aac abrufen. Verwenden, wenn Anmeldedaten zum Anmelden benötigt werden...

npx skills add https://github.com/bitwarden/agent-access --skill agent-access

Use this skill when you need to sign into a website, retrieve a login, look up a password, or get a TOTP code. aac fetches credentials (username, password, TOTP, URI, notes) from the user's Bitwarden vault through a trusted paired device.

When to use this

  • The user asks you to log into a website or service
  • You need a username and/or password for a domain
  • You need a TOTP / 2FA code for authentication
  • You need an API key or secret stored in the vault
  • The user says "get my credentials for X" or "sign into X"

Quick start (agent flow)

Step 1 — Check for an existing session:

aac connections list

Step 2 — Fetch the credential using the website's domain:

aac --domain example.com --output json

If only one session is cached, it auto-selects. With multiple sessions, add --session <HEX> (use a fingerprint or unique prefix from connections list).

Step 3 — Parse the JSON output:

{
  "success": true,
  "domain": "example.com",
  "credential": {
    "username": "user@example.com",
    "password": "s3cret",
    "totp": "123456",
    "uri": "https://example.com/login",
    "notes": "optional notes"
  }
}

Use credential.username and credential.password to sign in. If the site requires 2FA, use credential.totp.

If no session exists

The user must pair with a trusted device first. Ask them to:

  1. Run aac listen on their trusted device
  2. Give you the pairing token (e.g. ABC-DEF-GHI)

Then connect with:

aac --domain example.com --token <CODE> --output json

Alternatively, for PSK tokens (format: <64-hex-psk>_<64-hex-fingerprint>):

aac --domain example.com --token <PSK_TOKEN> --output json

Sessions are cached in ~/.access-protocol/ for future use — subsequent requests don't need a token.

Domain matching

Use the bare domain of the website you need credentials for:

  • github.com (not https://github.com/login)
  • accounts.google.com (not https://accounts.google.com/v3/signin)
  • aws.amazon.com

All options

FlagDescription
--domain <DOMAIN>Website domain to fetch credentials for (required for non-interactive use)
--token <TOKEN>Pairing token — rendezvous or PSK (conflicts with --session)
--session <HEX>Session fingerprint or unique prefix (conflicts with --token)
--relay-url <URL>WebSocket relay address (default: wss://ap.lesspassword.dev)
--output json|textOutput format (default: text; use json for programmatic access)
--no-cacheDon't cache this session
--verify-fingerprintRequire fingerprint verification
-vVerbose logging

Session management

aac connections list                          # List all cached sessions
aac connections clear                         # Clear all sessions and identity keys
aac connections clear sessions                # Clear sessions only, keep identity key

Error handling

On failure, JSON output:

{"success": false, "error": {"message": "...", "code": "connection_failed"}}

Exit codes:

CodeMeaningWhat to do
0SuccessParse credential from output
1General errorCheck stderr for details
2Connection failedRelay may be down; retry or check --relay-url
3Auth/handshake failedSession may be stale; clear cache and re-pair
4Credential not foundNo matching login for that domain in the vault
5Fingerprint mismatchSecurity issue; do not proceed, alert the user

If exit code is 3, try aac connections clear sessions and ask the user for a new token. If exit code is 4, confirm the domain with the user — they may store it under a different name.

Mehr Skills von bitwarden

figma-to-angular
bitwarden
Diese Fähigkeit wandelt eine Figma-Designspezifikation in eine vollständig implementierte Angular-Komponente mit Storybook-Stories im Bitwarden Clients Monorepo um. Die Ausgabe sollte dem Design visuell entsprechen und dabei alle Codebase-Konventionen einhalten.
force-multiplier
bitwarden
Wende eine Absicht auf viele Ziele gleichzeitig an — auf eine Flotte von Repositories im Bitwarden-Ökosystem oder auf viele Projekte in einem Monorepo — als N konsistente,…
analyzing-git-sessions
bitwarden
Analysiert Git-Commits und Änderungen innerhalb eines Zeitrahmens oder Commit-Bereichs und liefert strukturierte Zusammenfassungen für Code-Reviews, Retrospektiven, Arbeitsprotokolle oder Sitzungen…
coordinating-cross-team-breakdown
bitwarden
Koordinierung der teamübergreifenden Überprüfung und Freigabe für eine Bitwarden Tech Breakdown. Verwenden Sie dies, wenn Sie betroffene Teams identifizieren, die Signoff-Tabelle für Teil 3 erstellen, nachfassen…
assessing-jira-issue-relevance
bitwarden
Verwenden Sie dies, wenn der Benutzer einen einzelnen Jira-Issue-Schlüssel angibt und fragt, ob er noch relevant, noch anwendbar, noch offen, noch ein Fehler ist, behoben wurde oder ob er kann…
assessing-test-coverage
bitwarden
Verwenden, wenn ermittelt werden soll, welche Testabdeckung BEREITS für eine bestimmte Änderung existiert (ein PR, Jira-Key, Tech-Breakdown-Dokument, Testmo-CSV, geänderte Pfade oder benannte…
retrospecting
bitwarden
Führt umfassende Analysen von Claude Code-Sitzungen durch, untersucht Git-Verlauf, Konversationsprotokolle, Codeänderungen und sammelt Benutzerfeedback, um…
reviewing-incremental-changes
bitwarden
Verwende diese Fähigkeit beim erneuten Überprüfen eines PR, der bereits Kommentare enthält, oder beim Reagieren auf Entwickleränderungen nach der ersten Überprüfung. Wende sie an, wenn PR-Threads vorhanden sind oder…