Skip to main content
A login profile holds everything a workflow needs to sign in and act as one identity. The API calls a profile an agentProfile and a profile group an agentProfilePool. A profile carries:
  • attached secrets (usernames and passwords with optional TOTP seeds, API keys, cards, custom secrets)
  • an Email Inbox
  • a sticky IP
  • browser cache and session state
A profile is reusable. Many workflows can share one profile, and one workflow can run with a different profile on every execution. Proxy, captcha solving, stealth, cookies and extensions live on the environment the workflow runs on, not on the profile. Older profiles created through the API may still carry these settings. They apply only when the environment has no settings of its own.

In the platform

Open Logins in the sidebar. It has four tabs. Click Create a login profile to add one. The form walks through Details, Secrets, Email Inbox and Sticky IP. Click Ask someone for a login to send a request instead. Click a profile to open its drawer. It has four sections: Click Edit in the drawer header to turn every section into its form, then save once. Starting cookies apply only to runs with no custom environment. Sticky IP applies to browsers only, and is set when the profile is created.

Choosing a profile for a run

An execution uses at most one profile. In the builder, open the environment control in the bottom bar. Runs as lists the profiles and profile groups the workflow may use. With one entry, runs never ask. With several, the run form asks which one to use. The Runs as list belongs to the workflow’s environment. Other workflows on the same environment share it. Click Copy environment for this workflow to give one workflow its own list. See Profile rows. On the API, pass the profile ID (agentProfileId):
Pass a profile group (agentProfilePoolId) instead to let Asteroid choose a profile from a profile group.
agentProfileId and agentProfilePoolId are mutually exclusive. Pass one or the other, never both.
See Call a workflow from your code for the full execute call.

Profile configuration

Every profile gets an inbox at {prefix}@agentmail.asteroid.ai. The default prefix is the profile’s UUID. Set a prefix to get a readable address. Set it as Inbox address when you create or edit the profile. See Workflow emails.
Create and manage profiles on the platform, through the API, or through the SDKs. See the API reference.
Deleting a profile affects every workflow that references it. Check that no live automation depends on it first.

Credentials and 2FA

A profile does not store secret values itself. It attaches secrets from the organization’s Secrets tab. The profile then exposes ##ITEM_KEY.FIELD## placeholders. A profile cannot attach two secrets that share a key. On the API, attach secrets (vaultItemIds) on create or update. On MCP, create them with vaultItemsCreate and attach them with agentProfileUpdate. Profile credentials* fields are deprecated. The same secret can attach to many profiles. See Secrets & 2FA for secret kinds, placeholders, and TOTP seeds.

Profile groups

A profile group holds interchangeable logins for one portal, with the same permissions. You point a run at the group, and Asteroid picks a profile from it. Profile groups solve four problems:
  • Credential conflicts: stop two executions using one account at the same time.
  • Rate limits: spread requests across several accounts.
  • Availability: fall back to another profile when one is busy.
  • Manual selection: remove the choice from every execute call.
Create a group on the Profile groups tab with New profile group. The form walks through Details and Members. The group’s drawer has Members and Settings sections.

Selection strategies

A profile group uses one of two strategies. The drawer shows it as Picks. Least recently used rotates fairly. With profiles A, B and C, an execution after B picks whichever of A or C idled longest. Most recently used concentrates work on fewer profiles. It keeps browser state and authenticated sessions warm.

Concurrent use

allowConcurrentUse decides whether a busy profile can be picked again. The drawer shows it as Shared use.
With allowConcurrentUse: false, a request fails immediately when every profile in the group is busy. The error says no profile is available. Add more profiles, allow concurrent use, or send "onCapacityLimit": "queue" on the execute call. The execution is then accepted as queued and starts when a profile frees. See Queue when capacity is full.

Group constraints

An execute call takes agentProfileId or agentProfilePoolId, never both.
  • Every profile in a group belongs to the same organization.
  • A group name is unique within an organization.
  • A profile from another organization cannot join the group.
  • A group needs at least one profile before an execution can use it.
  • Remove the last profile and no new execution can use the group.
Match the group size to your parallelism. Five simultaneous runs need at least five profiles. Add one or two spare profiles for peak load.
A profile group works with every profile feature: attached secrets, TOTP seeds, Email Inbox, and browser state. The selected profile’s configuration applies exactly as if you had named it yourself.

Call a workflow

Pass a profile or a profile group on the execute call

Secrets & 2FA

How Asteroid stores and uses secrets

Workflow emails

The Email Inbox each profile owns

Environments

Where the workflow runs, and its browser settings

Security

How Asteroid protects stored credentials