Getting started
How is this different from giving my agent a service account?
How is this different from giving my agent a service account?
- The person connects with a standard web OAuth flow at 1password.com. There’s no token for them to create or paste.
- The person approves specific logins, for a stated goal, in their 1Password app. Your integration can use only those.
- With extension fill, your platform and the model never handle the values. The extension fills the page.
- The person’s items stay end-to-end encrypted, and your integration never holds their vault keys.
Do I need the 1Password app or a Linux client in my agent's environment?
Do I need the 1Password app or a Linux client in my agent's environment?
Which accounts do I build and test with?
Which accounts do I build and test with?
b5dev.eu, can’t show approval prompts with current 1Password app builds. See the Quickstart.Why do I need a Business account?
Why do I need a Business account?
Do I need to send 1Password my client ID?
Do I need to send 1Password my client ID?
Which 1Password app do I test approvals with?
Which 1Password app do I test approvals with?
Where do I get the extension?
Where do I get the extension?
Can I use the SDK instead of the extension?
Can I use the SDK instead of the extension?
Connecting users
Why do I land on the 1Password home page instead of the consent screen?
Why do I land on the 1Password home page instead of the consent screen?
/oauth/authorize, with no /v1. At launch, the consent screen appears only for Individual and Family accounts. In development, it’s also available for Business accounts.Why didn't my callback include an integration key?
Why didn't my callback include an integration key?
How do I get a fresh integration key while testing?
How do I get a fresh integration key while testing?
self:revoke, then connect again. The new consent returns a new key. A person can’t revoke from inside 1Password, so there’s no screen for it in the account. See Disconnect a user.How do I match a returning person to the key I stored?
How do I match a returning person to the key I stored?
path inside the integration key: it names one OAuth client, account, and user. The token response can include user_id. Compare it with the user in the stored key’s path. If they don’t match, the person connected a different account and you don’t have a key for it: revoke and have them connect again. Treat token strings as opaque rather than parsing IDs out of them.What if the person doesn't have a 1Password account yet?
What if the person doesn't have a 1Password account yet?
Can a person connect from the 1Password app on their iPhone?
Can a person connect from the 1Password app on their iPhone?
Can my mobile app use a custom URL scheme or localhost as its redirect URI?
Can my mobile app use a custom URL scheme or localhost as its redirect URI?
https. Use a universal link or app link, or a web page that hands the result back to your app. Your callback also has to read the URL fragment in a browser, because the integration key arrives there.Why does the token exchange return 400 invalid_request?
Why does the token exchange return 400 invalid_request?
client_id in the form body as well as the HTTP Basic header. Authenticate with HTTP Basic only. See Token exchange and refresh.Should my cloud browser provider own the OAuth client, or should I?
Should my cloud browser provider own the OAuth client, or should I?
Where do I store the tokens and the integration key?
Where do I store the tokens and the integration key?
Requests and approval
Why do access requests go through the extension instead of an HTTP API?
Why do access requests go through the extension instead of an HTTP API?
Does the browser need to stay open while the person approves?
Does the browser need to stay open while the person approves?
Can approval happen in my app, or count the OAuth connection as approval?
Can approval happen in my app, or count the OAuth connection as approval?
How long does an approval last? Does it end with the chat session?
How long does an approval last? Does it end with the chat session?
Can my agent run scheduled or background tasks?
Can my agent run scheduled or background tasks?
Is mobile approval supported?
Is mobile approval supported?
Where does the approval prompt get my name and icon?
Where does the approval prompt get my name and icon?
What if the person picks a different login than I asked for, or grants nothing?
What if the person picks a different login than I asked for, or grants nothing?
entryId because the person added one you didn’t ask for. Match on entryId, never on position. See Read what the person granted.Is the request text end-to-end encrypted?
Is the request text end-to-end encrypted?
Filling
What do I get from 1Password, and how does it reach the extension?
What do I get from 1Password, and how does it reach the extension?
//api.1password.com/credential-broker/accounts/<account>/capability/login/configurations/<id>. It’s a pointer, not a credential and not an encrypted payload, and you don’t transport any secret material. When you call fillCredential with the reference, the extension fetches the login from 1Password’s credential broker over an attested, encrypted session, fills the form, and submits it. See Security model.What does the browser need, and can I give it a short-lived key instead?
What does the browser need, and can I give it a short-lived key instead?
Does this work with cloud browser providers?
Does this work with cloud browser providers?
What is Agentic Mode, and do I have to turn it on?
What is Agentic Mode, and do I have to turn it on?
api.agenticMode.v1.enable every time your agent starts working in the browser, for one tab or the whole browser. A fill in a tab it doesn’t cover fails with agenticModeNotEnabled. See Turn on Agentic Mode.Do I have to disconnect my agent from the browser during a fill?
Do I have to disconnect my agent from the browser during a fill?
fillCredential returns, because the values are in the page between fill and submit. How you do it is up to you. If the browser runs on a different machine from the model, holding agent actions until the call returns is enough. A lock in your orchestrator that blocks DOM reads, screenshots, and other CDP commands to the tab also works.Are passwords or codes left on the page after a fill?
Are passwords or codes left on the page after a fill?
fillCredential returns fill_submitted, the form was submitted and the filled values are no longer present on the page. When it returns fillFailed or autosubmitFailed, 1Password clears what it filled before it returns.Does fill_submitted mean the agent is signed in?
Does fill_submitted mean the agent is signed in?
Can several of my agents use one person's access?
Can several of my agents use one person's access?
Can I keep the token and integration key out of the agent's browser entirely?
Can I keep the token and integration key out of the agent's browser entirely?
Scope and roadmap
What's supported at launch?
What's supported at launch?
Can I revoke access to a single login?
Can I revoke access to a single login?
Can a person revoke access from inside 1Password?
Can a person revoke access from inside 1Password?
Can I use this outside the browser, for example in CLI tools?
Can I use this outside the browser, for example in CLI tools?
Going to production
When can I test with real 1Password accounts?
When can I test with real 1Password accounts?
Why can't I see OAuth Application or the Read credentials scope in my production account?
Why can't I see OAuth Application or the Read credentials scope in my production account?
Can I register redirect URLs for my staging and development environments?
Can I register redirect URLs for my staging and development environments?
I registered my production client without an icon. What do I do?
I registered my production client without an icon. What do I do?