Load the extension
The extension runs in Chromium builds that support extensions, in a cloud browser or on a local machine. Nobody signs in to it, and in pages that Agentic Mode covers it shows no 1Password interface.- Load the development build of the 1Password extension that 1Password sends you, or install it with the extension installation mechanism your browser stack uses. Unzip it and load the folder unpacked.
- Switch to Nightly, Beta, or Stable from the Chrome Web Store when 1Password announces it in your partner channel, and keep it up to date.
Branded Google Chrome builds ignore
--load-extension. If you load the extension unpacked from the command line, use Chromium or Chrome for Testing.
After you load it, check the extension ID in
chrome://extensions, and use that ID to find the service worker. An unpacked extension whose manifest has no key gets an ID derived from its folder path instead.
In a cloud browser, load the extension when you create the browser, not in the middle of a task. On some providers, adding an extension restarts the browser. Run one person per browser.
Call the extension over CDP
The extension exposes its API asglobalThis.api on its background service worker, with a version namespace per capability: api.initialization.v1, api.agenticMode.v1, and api.agenticAutofill.v1. See the API reference. Web pages can’t see it, so page.evaluate won’t find it.
Attach to the service worker target at:
api.initialization.v1.whenSettled() to resolve to "ready", because the extension may still be starting up. Pass the token and integration key as arguments, not by building them into a script string, and never log CDP traffic, because it carries both.
Find the tab ID
fillCredential takes a Chrome tab ID, the number the chrome.tabs API uses. It isn’t a CDP target ID, and Playwright and Puppeteer don’t expose it. Look it up inside the same service worker, with chrome.tabs.query:
Turn on Agentic Mode
Agentic Mode stops normal 1Password browser behavior, such as inline suggestions and save prompts, from exposing the person’s state in pages your agent controls. Turn it on every time your agent starts working in the browser, for the tab it works in or for the whole browser. A fill in a tab that Agentic Mode doesn’t cover fails withagenticModeNotEnabled.
success in the response. Turn Agentic Mode off with api.agenticMode.v1.disable(), with the same argument, when the agent gives up control. See Turn on Agentic Mode for the errors.
Fill a granted login
Callapi.agenticAutofill.v1.fillCredential with the tab and the reference of the granted login to fill. Your agent decides which granted login to use for which page. Each resolved grant carries a reference object: pass the string inside it, grant.reference.reference, as resourcePath. That’s the same whether you checked the request with the extension or the SDK.
Before you fill, navigate the tab to the page with the username and password form. Sign-in pages that first ask the person to pick a method, such as a social sign-in choice, aren’t supported yet.
Playwright
fill_submitted. That means 1Password filled and submitted the form, and the filled values are no longer present on the page. It doesn’t mean the website accepted the login or finished signing in, so check the page after the call returns.
On fillFailed and autosubmitFailed, 1Password clears what it filled before it returns.
A multi-page sign-in, such as a username page followed by a password page and a one-time code page, fills the same reference again on each page. Every fill is a fresh request to 1Password, so a revoked or expired grant fails at the next fill.
Keep the model off the page during a fill
Between fill and submit, the values are in the page. The extension removes them beforefillCredential returns, but until then anything that can read the page can read them.
- Don’t let the model or agent read the DOM, take screenshots, or send other CDP commands to that tab until
fillCredentialreturns. - One approach is to keep the browser on a different machine from the model and pause agent actions until the call returns. A lock in your orchestrator also works. In either case, prevent the model and agent from reading the page while secrets are present.
- Don’t run other extensions you don’t trust in the same browser. An extension with access to the page can read it.
Errors
See Errors and troubleshooting for more.