Skip to main content
With Agentic Autofill, your agent signs in to websites on a person’s behalf using the logins they already keep in 1Password. The person reviews each access request in 1Password on their own device and chooses which logins, if any, to grant. The 1Password browser extension then fills sign-in forms with those logins, so neither your platform nor the model handles credential values.
This guide is for partners building against Agentic Autofill before general availability. Endpoints, response shapes, and dates can change. Check with your 1Password contact before you rely on anything this guide marks as not yet available.

How it works

Connect once

The person selects Connect 1Password in your product. They sign in to 1Password on the web and approve a consent screen. You receive OAuth tokens and an integration key for that person. You can now ask them for logins, but you can’t read anything yet.

Ask for the logins a task needs

When a task needs to sign in somewhere, your agent creates an access request: a goal for the task and up to five logins, each with a website and a reason.

The person approves in 1Password

You send the approval link to the person’s device. Their 1Password app opens, shows who is asking and why, and lets them pick the exact logins to grant. This is the last time the person needs to be present.

Fill and continue the task

Your agent asks the 1Password extension in its browser to fill a granted login. The extension fetches the login from 1Password, fills the form, and submits it. The values never reach your code or the model.

Build on the browser extension

Your agent works with 1Password through the 1Password browser extension. It creates access requests, waits for the person’s decision, and fills granted logins into the page. Your code never handles credential values. If your product needs the 1Password SDK instead, for example to ask for access before a browser exists, contact 1Password before you build with it. We can review the security requirements with you. See Use the SDK.

What you build

Test the flow end to end

Register your OAuth client, connect a test user on 1password.com, approve a request, and fill a login.

Connect a user

Run the OAuth authorization code flow with PKCE and receive the integration key.

Store keys and tokens

Hold the integration key and tokens per user, and give each browser session only what it needs.

Create an access request

Describe the task and the logins it needs, within the field limits.

Get the user's approval

Deliver the approval link to the user’s device and wait for their decision.

Fill with the browser extension

Load the extension, call it over CDP, and fill a granted login into a tab.

Supported today

Get help

Ask your 1Password contact in your shared Slack channel. The FAQ answers the questions partners ask most, and Errors and troubleshooting lists the error messages you’re likely to see while you build.