Skip to main content
Runs never produce findings about a sign in page. If Superflow cannot get in, it stops and says so.

If a sign in stops completing after it used to work

Most often one of these:
  • The service account’s password expired or was rotated.
  • A multi-factor policy changed and now covers the service account again.
  • A bypass token was revoked or rotated in the hosting platform.
  • Your sign in address changed, in which case run Test access again to confirm the new one.

What Superflow stores

  • Credentials are encrypted, and are never shown back to you after saving. Editing shows a placeholder, and saving with that placeholder untouched keeps what is already stored.
  • Captured sign in sessions and bypass tokens are held separately from other project settings, in storage no browser can reach.
  • Deleting a project’s access removes the stored credential and any captured session or token with it.
  • The site address is re-checked when a run happens, so a credential is never sent to a different site than the one it was entered for.

Questions worth asking us

No. A person’s account almost always has multi-factor, which an agent cannot complete. A dedicated account is also easier to audit and to revoke.
Whatever the account you create can see. Give it the narrowest access that still lets it reach the pages you want reviewed.
Bypass tokens work everywhere. Shared passwords work for Webflow gates. Single sign on works in previews only while a recent sign in is still valid, and otherwise the preview shows a fallback card. Login form access does not apply to previews.
Yes. Update it in Site Access and press Test access again. Nothing else needs changing.