## TL;DR

Generate a unique random password per account, store all of them in one secure vault your scripts can read, and never reuse a password across sites. The vault is the only place passwords live; scripts fetch at runtime and never log them. This sounds obvious, but the moment you have thirty accounts, ad-hoc password handling breaks down fast.

```text
password management across dozens of agent accounts
```

## Use this when

- You operate accounts on dozens of sites and need a system
- Passwords are currently in spreadsheets, notes, or scripts
- You need to rotate passwords across many accounts

## Not for this skill when

- You have one or two accounts (a password manager app is enough)
- You need SSO or passkey strategy instead
- You want to share credentials between people

## Steps

1. Pick one vault. Use a real secret store: a local encrypted vault, a cloud secret manager, or the platform's secure credential store. Expected: exactly one place holds passwords.
2. Generate unique passwords per site. Sixteen-plus random characters, generated at account creation, never reused. Expected: a breach on one site compromises nothing else.
3. Name entries consistently. Use a scheme like forum-slug plus account handle so scripts can look up the right entry. Expected: lookups work without guessing.
4. Have scripts read at runtime. The script fetches the password from the vault when it needs it and keeps it in memory only. Expected: no passwords in code, logs, or config files.
5. Rotate on a schedule or on incident. Change passwords quarterly for high-value accounts, immediately if a site reports a breach. Expected: stale credentials dont linger.
6. Audit periodically. Check for duplicates, weak entries, and accounts whose passwords live outside the vault. Expected: the vault stays the single source of truth.

## Variant phrasings

### managing passwords for many bot accounts

Same system: unique generated passwords, one vault, runtime-only access.

### secure credential storage for agent fleets

The vault plus consistent naming plus no-logging rules covers the fleet case.

### password rotation across many accounts

Script the rotation: generate, update on the site, write to vault, verify login.

## Why it happens

Password reuse is how one breached forum takes down your accounts on twenty others. And plain-text passwords in scripts leak through logs, repos, and backups. A vault with unique passwords per site removes both failure modes at once.

## Edge cases

- Some sites restrict password characters or length; generate per site rules, not one global format.
- Shared team access to the vault needs its own access control; dont hand the whole vault to every script.
- If a script must run somewhere untrusted, prefer short-lived tokens over long-lived passwords.
- Losing vault access locks you out of everything; keep an offline backup of the vault itself.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_iLiZOZS4f9G4hBYEDZrLgw
