Skip to main content
The 1Password browser extension exposes a public API as globalThis.api on its background service worker at chrome-extension://<extension-id>/background/background.js. Call it over the Chrome DevTools Protocol (CDP). See Call the extension over CDP. Each capability has its own version namespace: api.agenticAutofill.v1 has three independent operations: The extension and the SDK work together. You can create and check a request with the SDK, then pass the granted reference to the extension to fill.

Install the extension

Load the development build of the 1Password extension that 1Password sends you, or install it with the extension installation mechanism your browser stack uses. 1Password will announce in your partner channel when Agentic Autofill is available in Nightly, Beta, or Stable, and when to switch.

Wait for the extension to be ready

api.initialization.v1 is available as soon as the service worker starts. Its state property is "initializing", "ready", or "failed". Wait with whenSettled() instead of polling state:
whenSettled() resolves to "ready" or "failed". A "failed" result is final for the current service worker lifetime. After initialization, check that api.agenticMode and api.agenticAutofill are present. If either is missing, the installed extension build or its current configuration doesn’t make this API available.

Turn on Agentic Mode

Agentic Mode stops normal 1Password browser behavior, such as inline suggestions and save prompts, from exposing the person’s state in pages your agent controls. Turn it on every time your agent starts working in the browser. fillCredential fails with agenticModeNotEnabled in a tab that Agentic Mode doesn’t cover. Turn it on for one tab when the agent starts working in that tab:
Leave out the argument to turn it on for the whole browser, including tabs opened later:
Turn it off when the agent gives up control:
Turning off the whole-browser scope releases every tab that agent controls. You can’t turn off a single tab while whole-browser Agentic Mode is on. enable and disable return this envelope:
Check success before you continue. Turning on a tab you already control returns tab_invalid. Turning on a tab that another agent controls returns tab_unavailable.

Response envelope

Every Agentic Autofill operation takes the person’s current access token and their integration key, and resolves to an envelope rather than throwing:
Check success before you read result or error.

createAccessRequest

Creates an access request for one to five logins. The result contains the created request and an app link that presents it to the person in 1Password.

Parameters

string
required
The current OAuth access token for the person’s connection.
string
required
The integration key for the same connection.
object
required
The request content.
Describe what your agent needs, not a specific 1Password item. 1Password asks the person to pick the login that satisfies each entry.

Result

string
The request ID. Pass it to getAccessRequestStatus as accessRequestUUID.
string
The ID 1Password assigned to each entry. Use it to match grants to entries.
Opens the request in 1Password. Open it on a device that has 1Password installed. Treat it as opaque: don’t parse it, change it, or build it yourself, and don’t log it or pass it through a model.
Creating or opening a request doesn’t return the person’s decision. Use getAccessRequestStatus to learn the outcome.

getAccessRequestStatus

Returns the request’s current state and, once it’s resolved, the logins the person granted. The call returns right away: it doesn’t wait for the person to decide. Your code owns polling, backoff, and timeouts.

Parameters

string
required
The current OAuth access token for the person’s connection.
string
required
The integration key for the same connection.
string
required
The accessRequest.id returned when the request was created.

Result

While the person hasn’t decided:
After they approve:
string
pending, resolved, denied, or failed. resolved, denied, and failed are final: stop checking once you see one.
object[]
One item per granted login. Empty unless state is resolved.
Match grants to your entries by entryId, never by position or type:

fillCredential

Fills and submits one granted login in a browser tab. Call it on the page with the username and password fields, not an earlier page that only asks the person to choose a sign-in method. Agentic Mode must cover the tab.

Parameters

string
required
The current OAuth access token for the person’s connection. Refresh it before you fill: an expired token is reported as fillFailed.
string
required
The integration key for the same connection.
string
required
The credential reference from a resolved request: the string inside its reference object, grant.reference.reference. That’s the same whether you checked the request with the extension or the SDK.
number
required
The Chrome tab ID of the tab to fill, from chrome.tabs.query. A CDP target ID doesn’t work.

Result

string
fill_submitted: 1Password filled the login and submitted the form. It doesn’t guarantee that the website accepted the login or finished signing in. Check the page before the agent continues.
On fillFailed and autosubmitFailed, 1Password clears what it filled.

Error codes