Paste a credential you already hold. Sign in to the target yourself, then copy the session cookie from your browser's developer tools, or paste an API bearer token. A credential you do not save is sent with this one assessment, used in memory, and never written anywhere.
A test user you save is encrypted on the server and visible only to this account. It is never stored in this browser. Give it a label and it is reusable for this domain; remove it with the × and it is gone.
Authorization: Bearer …. Use this instead of, or as well as, a cookie.
These take the JSON the API documents. Leave them empty for a single-identity assessment. See the API reference for the shape of each.