curl --request POST \
--url https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"product_id": "1p-msp-us",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
}
}
'const url = 'https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements';
const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
product_id: '1p-msp-us',
contact_info: {email: 'admin@acme-corp.com', company_name: 'Acme Corporation'}
})
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));import requests
url = "https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements"
payload = {
"product_id": "1p-msp-us",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements"
payload := strings.NewReader("{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}using RestSharp;
var options = new RestClientOptions("https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("Authorization", "Bearer <token>");
request.AddJsonBody("{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}", false);
var response = await client.PostAsync(request);
Console.WriteLine("{0}", response.Content);
HttpResponse<String> response = Unirest.post("https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}")
.asString();<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'product_id' => '1p-msp-us',
'contact_info' => [
'email' => 'admin@acme-corp.com',
'company_name' => 'Acme Corporation'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}$headers=@{}
$headers.Add("Authorization", "Bearer <token>")
$headers.Add("Content-Type", "application/json")
$response = Invoke-WebRequest -Uri 'https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements' -Method POST -Headers $headers -ContentType 'application/json' -Body '{
"product_id": "1p-msp-us",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
}
}'require 'uri'
require 'net/http'
url = URI("https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}"
response = http.request(request)
puts response.read_body{
"path": "distributor-customers/cust_789xyz/entitlements/ent_abc123def456",
"id": "ent_abc123def456",
"customer_id": "cust_789xyz",
"product_id": "1p-msp-us",
"status": "pending",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
},
"create_time": "2026-09-15T10:30:00Z"
}{
"code": "invalid_argument",
"message": "The 'email' field must be a valid email address."
}{
"code": "unauthenticated",
"message": "Authentication required. Please provide a valid bearer token."
}{
"code": "not_found",
"message": "The requested resource was not found."
}{
"code": "already_exists",
"message": "An entitlement for this product already exists."
}"Too Many Requests"{
"code": "internal",
"message": "An internal error occurred. Please try again later."
}Create an entitlement
Provision a new 1Password product entitlement for a distributor customer.
curl --request POST \
--url https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"product_id": "1p-msp-us",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
}
}
'const url = 'https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements';
const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
product_id: '1p-msp-us',
contact_info: {email: 'admin@acme-corp.com', company_name: 'Acme Corporation'}
})
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));import requests
url = "https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements"
payload = {
"product_id": "1p-msp-us",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements"
payload := strings.NewReader("{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}using RestSharp;
var options = new RestClientOptions("https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements");
var client = new RestClient(options);
var request = new RestRequest("");
request.AddHeader("Authorization", "Bearer <token>");
request.AddJsonBody("{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}", false);
var response = await client.PostAsync(request);
Console.WriteLine("{0}", response.Content);
HttpResponse<String> response = Unirest.post("https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}")
.asString();<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'product_id' => '1p-msp-us',
'contact_info' => [
'email' => 'admin@acme-corp.com',
'company_name' => 'Acme Corporation'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}$headers=@{}
$headers.Add("Authorization", "Bearer <token>")
$headers.Add("Content-Type", "application/json")
$response = Invoke-WebRequest -Uri 'https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements' -Method POST -Headers $headers -ContentType 'application/json' -Body '{
"product_id": "1p-msp-us",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
}
}'require 'uri'
require 'net/http'
url = URI("https://api.1password.eu/v1/distributor-customers/{distributor-customer}/entitlements")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"product_id\": \"1p-msp-us\",\n \"contact_info\": {\n \"email\": \"admin@acme-corp.com\",\n \"company_name\": \"Acme Corporation\"\n }\n}"
response = http.request(request)
puts response.read_body{
"path": "distributor-customers/cust_789xyz/entitlements/ent_abc123def456",
"id": "ent_abc123def456",
"customer_id": "cust_789xyz",
"product_id": "1p-msp-us",
"status": "pending",
"contact_info": {
"email": "admin@acme-corp.com",
"company_name": "Acme Corporation"
},
"create_time": "2026-09-15T10:30:00Z"
}{
"code": "invalid_argument",
"message": "The 'email' field must be a valid email address."
}{
"code": "unauthenticated",
"message": "Authentication required. Please provide a valid bearer token."
}{
"code": "not_found",
"message": "The requested resource was not found."
}{
"code": "already_exists",
"message": "An entitlement for this product already exists."
}"Too Many Requests"{
"code": "internal",
"message": "An internal error occurred. Please try again later."
}pending until the customer activates it.
Creating an entitlement works as follows:
- The entitlement is created with a status of
pending. - 1Password sends an email to the customer with an activation link. The email includes your distributor name and the product name.
- The customer selects the activation link and sets up their new 1Password account, which activates the entitlement and transitions it to
active.
pending until the customer activates it or you cancel it. Only pending entitlements can be updated.If an entitlement for the product already exists for the customer, the request fails with a 409 error unless it has a cancelled or expired status.If the existing entitlement is cancelled or expired, it’s reactivated with a status of pending.A reactivated entitlement keeps its original id and create_time, with the contact details from the new request.distributor-customer ID in the request path is your own identifier for the customer, as defined in your system, and isn’t validated when you create an entitlement. Make sure your integration passes customer IDs consistently.
Retrieve a list of available 1Password products to find the product_id value to use when creating an entitlement.Authorizations
Bearer token authentication. When a distributor is registered, they receive an opaque bearer token (prefixed op_b_). Include it in the Authorization header of every request as Bearer <token>.
Path Parameters
The customer ID, as defined in the distributor's own system.
Body
The entitlement resource to create.
Response
The newly created entitlement, with status pending.
A provisioned 1Password product entitlement for a distributor customer.
The canonical resource path of the entitlement (for example, "distributor-customers/{customer_id}/entitlements/{id}"). Use the IDs in this path to update or cancel the entitlement.
The unique identifier for this entitlement.
The ID of the marketplace customer who owns this entitlement. This is the distributor-defined ID from the request path that created the entitlement.
The ID of the 1Password product. Required on create; immutable thereafter.
The entitlement lifecycle state.
pending, active, cancelling, cancelled, expired, suspended The customer's contact details for account setup.
Show child attributes
Show child attributes
The date and time the entitlement was created.
The date and time the entitlement expires. Set only for change-of-channel entitlements created by linking an entitlement, and omitted for standard entitlements. Customers have 5 days to claim the emailed entitlement code against their existing 1Password account. Claiming the code completes the link; otherwise, the entitlement transitions to expired at this time.
Was this page helpful?