Skip to main content
Production is live, and it’s where you test. Your OAuth client lives in your own company’s 1Password Business account, and your users connect their Individual and Family accounts on 1password.com. What works on production today:
  • OAuth connect, token exchange, refresh, and revoke on 1password.com.
  • Approval in the 1Password desktop app on the Nightly release channel.
The development environment, b5dev.eu, can’t show approval prompts with current 1Password app builds. Move your testing to 1password.com.

Register your production OAuth client

1

Get a Business account for your company

Your OAuth client lives in a 1Password Business account on 1password.com. If your company doesn’t have one, sign up for 1Password Business. Choose Business, not Teams. You can use an account for your product team; it doesn’t need to cover your whole company. The account determines the identifiers used for your integration.
2

Turn on OAuth Application

Sign in and go to Integrations. If there’s no OAuth Application option, send your 1Password contact the email address of an account owner or administrator, and 1Password turns it on. The person who creates the client must be an owner, an administrator, or in the Security group. After it’s turned on, sign out and back in.
3

Register the client

  1. Go to Integrations > OAuth Application and select OAuth Application.
  2. Enter the name users should see, and upload an icon: PNG, JPEG, or GIF, up to 1 MB. The consent screen and the approval prompt show both.
  3. Enter your production redirect URL: your HTTPS callback, exactly as you’ll send it in redirect_uri. Custom URL schemes and localhost are rejected.
  4. For Grant type, choose Authorization code.
  5. For Select scope, choose Read credentials.
  6. Select Generate credentials, and store the client ID and secret in your secret store. The secret is shown once. Never share the client secret, including with 1Password.
Record the redirect URL exactly. Register a separate client for each of your own environments, such as staging and production, so each has its own redirect URL and secret.
You can’t add an icon after a client is created. If you registered a production client without an icon, register a new one.
4

Keep the Business account active

You don’t need to send 1Password your client ID. The 1Password app reads your integration’s name and icon from your client registration.Keep the Business account that holds your client active. The approval prompt looks up your client there to show your name and icon, and approval can fail if the account is inactive.

Move from development to production

The connect flow is the same, with production origins. Tokens and integration keys from development don’t work on production, so connect your test user again and store the new key. The extension needs no host setting. It uses the API host named in each person’s integration key, so a person connected in production uses the production API.

Launch scope

Not at launch: Business accounts as end users, shared vaults, passkeys, social sign-in, payment cards, addresses, revoking a single login, revoking from inside 1Password, and regions outside the US.

Before your users connect

Connect and disconnect
  • Connect 1Password starts the authorization code flow with PKCE and a fresh state.
  • Your callback reads, stores, then clears the integration key, and treats a missing key as normal.
  • Tokens and integration keys live in a per-user secret store, and nothing logs them.
  • Refresh-token rotation is atomic, with one refresher per person.
  • A reconnect path handles invalid_grant and expired connections.
  • Disconnect 1Password revokes the connection and deletes secrets only after success.
Requests and approval
  • Each task batches its logins into one request, with a clear goal and reasons in the person’s language.
  • Request text contains no personal names, account identifiers, or secrets.
  • The approval link goes to the person’s device in code, never through the model, and never into a log.
  • You handle denied, failed, a status timeout, and an approval prompt that closed after 2 minutes.
  • You match grants on entryId, and handle missing entries and logins you didn’t ask for.
Fill
  • Browser sessions get a current access token and the integration key in memory, one person per browser.
  • The model and agent can’t read the page until fillCredential returns.
  • Your agent checks the page after fill_submitted.
  • You refresh the access token before it expires, instead of waiting for fillFailed.
Production setup
  • Your production client shows the name and icon people should see.
  • The Business account that holds your client is active.
  • You’ve confirmed with your contact which extension channel to use.
  • You’ve tested the full flow on 1password.com with an Individual or Family test account, connected on production.