# Account field reference

Keep a service's website, login and issued secrets on the same Decoy account. An API key is a named Hidden field, separate from its login password. A passwordless service needs no password. Useful task context belongs in [Memories](/agent-memories.md).

<a id="choose-the-field-then-check-the-write-path"></a>
<a id="save-and-update-a-named-secret-current-write-limitation"></a>
## Scope

This page describes account fields in the Decoy app. It is not an agent write procedure: the standard created-only HTTP flow and default MCP tools do not provide supported same-account custom-field saving or editing. Use the [storage guide](/agent-storage.md#3-api-keys-and-other-secret-fields) for the current action and outcome. Do not put an API key in the password slot, create another account or request whole-vault access to bypass a missing writer.

Field kinds describe values inside an encrypted record; they are not plaintext properties to POST to Decoy. A field's concealed appearance is separate from access permission. A supported writer must preserve the exact secret, including meaningful whitespace, and all unrelated record content. Do not use an editor that changes either.

## Single-value field catalog

| App field | kind | Value and use |
| --- | --- | --- |
| Hidden | secret | API key, access token, client secret, webhook signing secret, PIN or recovery code. Keep each distinct credential under a meaningful label; its secret flag is true. |
| Security Question | security-question | Label: the exact question. Value: its answer, concealed with secret true. Keep the answer out of memory. |
| Name | name | The actual name used for this service. |
| Date of Birth | dob | A known date in YYYY-MM-DD form. |
| Email | email | An additional account email, such as a recovery address. Preserve the primary login and linked Decoy address. |
| Phone | phone | A known phone number as text, including its country code. |
| Website | url | An additional URL, such as API documentation. Keep the main service URL in its account field; exclude tokens and keys from URLs. |
| Number | number | A numeric value. A secret PIN belongs in Hidden; an identifier with meaningful leading zeroes belongs in Custom. |
| Date | date | A known date in YYYY-MM-DD form, such as an issued key's expiry. Do not invent an expiry. |
| Custom | custom | A labeled value without a more specific type. Secret values belong in Hidden. |

Values are strings, including numbers and dates. API key, token and password are not custom-field kind values. Use the account's main notes field for service notes; preserve any existing note fields when editing a record.

<a id="api-key-token-and-recovery-code-examples"></a>
## Name separate secrets clearly

Use a distinct label for each purpose, such as API key, Webhook signing secret or Recovery code 1. Add an environment label only when known. Keep the secret separate from its non-secret purpose or expiry. Updating a value reuses its account and field identity; ambiguous duplicate labels need resolution before editing. Saving a replacement in Decoy does not rotate or revoke the credential at its provider.

## Multi-part fields

Address and Credit Card are typed records with separate members, not generic strings. The table describes those members; it does not supply an agent write endpoint.

| Field | kind | Members |
| --- | --- | --- |
| Address | address | streetAddress, apt, city, territory, postalCode, country |
| Credit Card | credit-card | number, fullName, expiryDate, verificationNumber |

Use a known country code and region for addresses and preserve postal codes as strings. Card expiry uses YYYY-MM; card number and verification number are concealed. The app also has a billing-ZIP field; do not infer support for that member in an agent writer. Store only details covered by the person's task. A saved card does not authorize a purchase. Authenticator/TOTP and passkeys use dedicated flows, not these structured-field kinds.

<a id="preserve-existing-fields-and-verify-the-result"></a>
## Preserve and confirm

An editor that replaces a field collection must retain every unrelated entry. Stop if the current collection is unreadable or incomplete; an empty replacement can clear it. Do not infer stable field identities or conflict protection from a field schema.

A successful response or has_password flag does not establish the correct field kind, secret value or app visibility. Confirm stored content with an independent authorized fetch and decryption; confirm an app or extension result only by observing that surface. The original input and local cache are not read-back evidence. If no supported writer is available, report the save as incomplete and follow the storage guide's secure handling instructions.
