Use case · 2FA
The site sends a code.You type it. The job goes on.
One-time codes by e-mail or SMS, authenticator prompts, approval screens: a second factor is a step only the account owner can finish. Kaabist pauses the job there, emails a link to you (or the teammate or customer who owns the account), and resumes the program the moment the code is typed.
The problem
A headless script cannot read your phone. Teams either switch the second factor off, which security will not accept, or babysit every run, which defeats the automation.
How it works
01
Wait for the code, in the program
await_input names what the job needs and how long it may wait. The value arrives as a variable the next step types in.
example{ "await_input": { "name": "otp", "type": "secret", "collect": "hosted", "hosted": { "notify": "email", "to": "{{inputs.approver}}" } } }, { "fill": "#otp", "value": "{{vars.otp}}" }02
A link, not an account
The address you set in the step (yours, a teammate's or your customer's) gets an e-mail with a link to a page on app.kaab.ist. It shows what the job is waiting for and a field for the code. No Kaabist account needed.
03
Or answer from your own code
If the code reaches a system you control, post it to the job yourself. Subscribe to job.awaiting_input to know when one is needed.
examplecurl -X POST https://api.kaab.ist/v1/jobs/job_8KqV2/input \ -H "Authorization: Bearer $KAAB_API_KEY" \ -d '{"otp": "481207"}'04
Ask less often
Save the session after the second factor. Later jobs reuse it and skip the whole login, so you are asked for a code only when the session finally expires.
Questions
Askedbefore you ask.
More use cases
Scrape a website that requires login
Portals, dashboards, supplier sites: the data you need sits behind a sign-in form. Kaabist runs the login as part of a program, keeps the session between jobs, and reads the pages as typed, validated fields.
Forms that must submit exactly once
Some forms change the world when they are sent: an order is placed, money moves, an application is filed. Kaabist records those steps just before and just after they run (a fence), so a crash, a retry or a redeploy can never send them twice.
Turn a website into an API
Describe the flow once as a program with inputs. From then on it is one HTTP call: inputs in, typed JSON out, with versions, aliases and webhooks, as if the site had shipped the API itself.