---
title: "tool si.act.hold_identity"
description: "the platform, the scopes the rows declare: a browser session for the person; then the credential with its vault entry."
section: reference
address: /reference/tools/si-act-hold_identity
contract: 0476e35e6e275db5
---

# tool si.act.hold_identity

the platform, the scopes the rows declare: a browser session for the person; then the credential with its vault entry.

[figure: Over MCP, si.act.hold_identity takes HoldIdentityInput and returns a card whose body is SignedInIdentity.]

a browser session for the person; then the credential with its vault entry. The call needs the act grant at the tenant rung.



| | |
|---|---|
| input | [HoldIdentityInput](/concepts/holdidentityinput) |
| result | a card whose body is [SignedInIdentity](/concepts/signedinidentity) |
| read-only | no |
| destructive | yes |
| card address | `ui://scale-intelligence/cards/SignedInIdentity` |
| HTTP route | [`/v1/act/hold_identity`](/reference/act/hold_identity) |





| field | type | required | note |
|---|---|---|---|
| `platform` | `text` | yes | the platform's slug, a row of the platform domains |
| `label` | `text` | yes | the person's name for this identity, unique within the tenant and platform |
| `wait_seconds` | `count` | no | how long the platform waits for the sign-in; the parameter row's value when absent |
| `session` | `id` | no | an open browsing session with a live view in which the person signed in; the platform reads the session's cookies as the session given, so nothing leaves any browser; the web version's way that lasts |
| `cookies` | [HeldCookie](/concepts/heldcookie) | no | the session's cookies given as data, read from the person's own browser by the platform's own extension or pasted by the person, for the web version where no window of the platform can open beside the person; when given, no window opens, and the platform keeps the cookies of the platform's domains and probes them |
