- OAuth connect, token exchange, refresh, and revoke on 1password.com.
- Approval in the 1Password desktop app on the Nightly release channel.
The development environment,
b5dev.eu, can’t show approval prompts with current 1Password app builds. Move your testing to 1password.com.Register your production OAuth client
1
Get a Business account for your company
Your OAuth client lives in a 1Password Business account on 1password.com. If your company doesn’t have one, sign up for 1Password Business. Choose Business, not Teams. You can use an account for your product team; it doesn’t need to cover your whole company. The account determines the identifiers used for your integration.
2
Turn on OAuth Application
Sign in and go to Integrations. If there’s no OAuth Application option, send your 1Password contact the email address of an account owner or administrator, and 1Password turns it on. The person who creates the client must be an owner, an administrator, or in the Security group. After it’s turned on, sign out and back in.
3
Register the client
- Go to Integrations > OAuth Application and select OAuth Application.
- Enter the name users should see, and upload an icon: PNG, JPEG, or GIF, up to 1 MB. The consent screen and the approval prompt show both.
- Enter your production redirect URL: your HTTPS callback, exactly as you’ll send it in
redirect_uri. Custom URL schemes andlocalhostare rejected. - For Grant type, choose Authorization code.
- For Select scope, choose Read credentials.
- Select Generate credentials, and store the client ID and secret in your secret store. The secret is shown once. Never share the client secret, including with 1Password.
4
Keep the Business account active
You don’t need to send 1Password your client ID. The 1Password app reads your integration’s name and icon from your client registration.Keep the Business account that holds your client active. The approval prompt looks up your client there to show your name and icon, and approval can fail if the account is inactive.
Move from development to production
The connect flow is the same, with production origins. Tokens and integration keys from development don’t work on production, so connect your test user again and store the new key.
The extension needs no host setting. It uses the API host named in each person’s integration key, so a person connected in production uses the production API.
Launch scope
Not at launch: Business accounts as end users, shared vaults, passkeys, social sign-in, payment cards, addresses, revoking a single login, revoking from inside 1Password, and regions outside the US.
Before your users connect
Connect and disconnect- Connect 1Password starts the authorization code flow with PKCE and a fresh
state. - Your callback reads, stores, then clears the integration key, and treats a missing key as normal.
- Tokens and integration keys live in a per-user secret store, and nothing logs them.
- Refresh-token rotation is atomic, with one refresher per person.
- A reconnect path handles
invalid_grantand expired connections. - Disconnect 1Password revokes the connection and deletes secrets only after success.
- Each task batches its logins into one request, with a clear goal and reasons in the person’s language.
- Request text contains no personal names, account identifiers, or secrets.
- The approval link goes to the person’s device in code, never through the model, and never into a log.
- You handle
denied,failed, a status timeout, and an approval prompt that closed after 2 minutes. - You match grants on
entryId, and handle missing entries and logins you didn’t ask for.
- Browser sessions get a current access token and the integration key in memory, one person per browser.
- The model and agent can’t read the page until
fillCredentialreturns. - Your agent checks the page after
fill_submitted. - You refresh the access token before it expires, instead of waiting for
fillFailed.
- Your production client shows the name and icon people should see.
- The Business account that holds your client is active.
- You’ve confirmed with your contact which extension channel to use.
- You’ve tested the full flow on 1password.com with an Individual or Family test account, connected on production.