globalThis.api on its background service worker at chrome-extension://<extension-id>/background/background.js. Call it over the Chrome DevTools Protocol (CDP). See Call the extension over CDP.
Each capability has its own version namespace:
api.agenticAutofill.v1 has three independent operations:
The extension and the SDK work together. You can create and check a request with the SDK, then pass the granted reference to the extension to fill.
Install the extension
Load the development build of the 1Password extension that 1Password sends you, or install it with the extension installation mechanism your browser stack uses. 1Password will announce in your partner channel when Agentic Autofill is available in Nightly, Beta, or Stable, and when to switch.Wait for the extension to be ready
api.initialization.v1 is available as soon as the service worker starts. Its state property is "initializing", "ready", or "failed". Wait with whenSettled() instead of polling state:
whenSettled() resolves to "ready" or "failed". A "failed" result is final for the current service worker lifetime.
After initialization, check that api.agenticMode and api.agenticAutofill are present. If either is missing, the installed extension build or its current configuration doesn’t make this API available.
Turn on Agentic Mode
Agentic Mode stops normal 1Password browser behavior, such as inline suggestions and save prompts, from exposing the person’s state in pages your agent controls. Turn it on every time your agent starts working in the browser.fillCredential fails with agenticModeNotEnabled in a tab that Agentic Mode doesn’t cover.
Turn it on for one tab when the agent starts working in that tab:
enable and disable return this envelope:
success before you continue. Turning on a tab you already control returns tab_invalid. Turning on a tab that another agent controls returns tab_unavailable.
Response envelope
Every Agentic Autofill operation takes the person’s current access token and their integration key, and resolves to an envelope rather than throwing:success before you read result or error.
createAccessRequest
Creates an access request for one to five logins. The result contains the created request and an app link that presents it to the person in 1Password.Parameters
string
required
The current OAuth access token for the person’s connection.
string
required
The integration key for the same connection.
object
required
The request content.
Result
string
The request ID. Pass it to
getAccessRequestStatus as accessRequestUUID.string
The ID 1Password assigned to each entry. Use it to match grants to entries.
string
Opens the request in 1Password. Open it on a device that has 1Password installed. Treat it as opaque: don’t parse it, change it, or build it yourself, and don’t log it or pass it through a model.
getAccessRequestStatus to learn the outcome.
getAccessRequestStatus
Returns the request’s current state and, once it’s resolved, the logins the person granted. The call returns right away: it doesn’t wait for the person to decide. Your code owns polling, backoff, and timeouts.Parameters
string
required
The current OAuth access token for the person’s connection.
string
required
The integration key for the same connection.
string
required
The
accessRequest.id returned when the request was created.Result
While the person hasn’t decided:string
pending, resolved, denied, or failed. resolved, denied, and failed are final: stop checking once you see one.object[]
One item per granted login. Empty unless
state is resolved.entryId, never by position or type:
fillCredential
Fills and submits one granted login in a browser tab. Call it on the page with the username and password fields, not an earlier page that only asks the person to choose a sign-in method. Agentic Mode must cover the tab.Parameters
string
required
The current OAuth access token for the person’s connection. Refresh it before you fill: an expired token is reported as
fillFailed.string
required
The integration key for the same connection.
string
required
The credential reference from a resolved request: the string inside its reference object,
grant.reference.reference. That’s the same whether you checked the request with the extension or the SDK.number
required
The Chrome tab ID of the tab to fill, from
chrome.tabs.query. A CDP target ID doesn’t work.Result
string
fill_submitted: 1Password filled the login and submitted the form. It doesn’t guarantee that the website accepted the login or finished signing in. Check the page before the agent continues.fillFailed and autosubmitFailed, 1Password clears what it filled.