agentProfile and a profile group an agentProfilePool.
A profile carries:
- attached secrets (usernames and passwords with optional TOTP seeds, API keys, cards, custom secrets)
- an Email Inbox
- a sticky IP
- browser cache and session state
In the platform
Open Logins in the sidebar. It has four tabs.
Click Create a login profile to add one. The form walks through Details, Secrets,
Email Inbox and Sticky IP. Click Ask someone for a login to send a request instead.
Click a profile to open its drawer. It has four sections:
Click Edit in the drawer header to turn every section into its form, then save once.
Starting cookies apply only to runs with no custom environment. Sticky IP applies to browsers only,
and is set when the profile is created.
Choosing a profile for a run
An execution uses at most one profile. In the builder, open the environment control in the bottom bar. Runs as lists the profiles and profile groups the workflow may use. With one entry, runs never ask. With several, the run form asks which one to use. The Runs as list belongs to the workflow’s environment. Other workflows on the same environment share it. Click Copy environment for this workflow to give one workflow its own list. See Profile rows. On the API, pass the profile ID (agentProfileId):
agentProfilePoolId) instead to let Asteroid choose a profile from a profile group.
See Call a workflow from your code for the full execute call.
Profile configuration
Inbox email prefix
Inbox email prefix
Every profile gets an inbox at
{prefix}@agentmail.asteroid.ai. The default prefix is the profile’s UUID. Set a prefix to get a readable address. Set it as Inbox address when you create or edit the profile. See Workflow emails.Credentials and 2FA
A profile does not store secret values itself. It attaches secrets from the organization’s Secrets tab. The profile then exposes##ITEM_KEY.FIELD## placeholders. A profile cannot
attach two secrets that share a key.
On the API, attach secrets (vaultItemIds) on create or update. On MCP, create them with
vaultItemsCreate and attach them with agentProfileUpdate. Profile credentials* fields are
deprecated.
The same secret can attach to many profiles. See Secrets & 2FA for
secret kinds, placeholders, and TOTP seeds.
Profile groups
A profile group holds interchangeable logins for one portal, with the same permissions. You point a run at the group, and Asteroid picks a profile from it. Profile groups solve four problems:- Credential conflicts: stop two executions using one account at the same time.
- Rate limits: spread requests across several accounts.
- Availability: fall back to another profile when one is busy.
- Manual selection: remove the choice from every execute call.
Selection strategies
A profile group uses one of two strategies. The drawer shows it as Picks.
Least recently used rotates fairly. With profiles A, B and C, an execution after B picks whichever of A or C idled longest.
Most recently used concentrates work on fewer profiles. It keeps browser state and authenticated sessions warm.
Concurrent use
allowConcurrentUse decides whether a busy profile can be picked again. The drawer shows it as
Shared use.
Group constraints
Mutual exclusivity
Mutual exclusivity
An execute call takes
agentProfileId or agentProfilePoolId, never both.Organization scope
Organization scope
- Every profile in a group belongs to the same organization.
- A group name is unique within an organization.
- A profile from another organization cannot join the group.
Availability
Availability
- A group needs at least one profile before an execution can use it.
- Remove the last profile and no new execution can use the group.
Group size
Group size
Match the group size to your parallelism. Five simultaneous runs need at least five profiles. Add one or two spare profiles for peak load.
Call a workflow
Pass a profile or a profile group on the execute call
Secrets & 2FA
How Asteroid stores and uses secrets
Workflow emails
The Email Inbox each profile owns
Environments
Where the workflow runs, and its browser settings
Security
How Asteroid protects stored credentials

