Skip to main content
A credential starts as unverified and becomes verified the first time a task run authenticates with it. If that first run is a data task you run later, the user may not be around to fix a wrong password or answer an MFA prompt. This guide moves sign-in into its own task. Run it right after the user enters their credentials. The agent signs in and stops at the account view. If the source asks for an MFA code or a security question, the run pauses with an interaction for the user to answer. Verifying credentials as a separate task has a few benefits:
  • A quick finish. The task only signs in, so it usually finishes quickly. The user can leave sooner, you can wrap up the experience in your app, and the rest of your tasks run in the background.
  • The user is still there. If the source rejects the credentials or asks for an MFA code, the user can fix or answer it right away.
  • Clear status. The run’s result tells you whether the credential works, separate from any data task.

Prerequisites

This guide assumes you have an agent and a source; the Quickstart covers those steps. To collect credentials, use the Auth Component or build your own auth flow.

Create the task

The task takes no input and returns login_status. It returns metadata only, so leave storage off. See Tasks for guidance on writing prompts. Use this prompt:
Prompt
Or create the task through the API:
Request

Run it after collecting credentials

With the Auth Component

Pass the task’s ID as taskId. The component runs the task as soon as the credential is stored, shows any interactions in the same UI, and returns the result in onSuccess or onError. See Task linking.

With your own auth flow

After you store the credential, run the task with it:
Request
If the source asks for an MFA code or a security question, the run pauses with interaction_required. Submit the user’s answer to resume the run. See Interactions. When the run completes, the credential becomes verified and Deck sends a credential.verified event:
Response

Continue with task runs

Once the credential is verified, run your other tasks with its credential_id. To skip a second sign-in, pass the verification run’s session_id on the next run. Sessions close after 10 minutes of inactivity. See Reusing a session.
Request
Runs in a new session sign in again. To reduce repeat MFA prompts, enable credential persistence.

Handle failures

If the source rejects the credentials, the run fails with auth_invalid, the credential becomes invalid, and Deck sends a credential.invalid event. Ask the user to update the credential and run the task again. Other failures, like the source being unavailable, don’t change the credential’s status. Run the task again later. See Errors.