> ## Documentation Index
> Fetch the complete documentation index at: https://www.1password.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Go to production

> Register your production OAuth client with the name and icon people see, test on 1password.com, and check your integration before your users connect.

export const StatusBadge = ({children}) => <span className="op-status-badge not-prose">{children}</span>;

<StatusBadge>Partner preview</StatusBadge>

Production is live, and it's where you test. Your OAuth client lives in your own company's 1Password Business account, and your users connect their Individual and Family accounts on 1password.com.

What works on production today:

* OAuth connect, token exchange, refresh, and revoke on 1password.com.
* Approval in the 1Password desktop app on the Nightly release channel.

<Note>
  The development environment, `b5dev.eu`, can't show approval prompts with current 1Password app builds. Move your testing to 1password.com.
</Note>

## Register your production OAuth client

<Steps>
  <Step title="Get a Business account for your company">
    Your OAuth client lives in a 1Password Business account on 1password.com. If your company doesn't have one, [sign up for 1Password Business](https://1password.com/pricing/business). Choose Business, not Teams. You can use an account for your product team; it doesn't need to cover your whole company. The account determines the identifiers used for your integration.
  </Step>

  <Step title="Turn on OAuth Application">
    Sign in and go to **Integrations**. If there's no **OAuth Application** option, send your 1Password contact the email address of an account owner or administrator, and 1Password turns it on. The person who creates the client must be an owner, an administrator, or in the Security group. After it's turned on, sign out and back in.
  </Step>

  <Step title="Register the client">
    1. Go to **Integrations** > **OAuth Application** and select **OAuth Application**.
    2. Enter the name users should see, and upload an icon: PNG, JPEG, or GIF, up to 1 MB. The consent screen and the approval prompt show both.
    3. Enter your production redirect URL: your HTTPS callback, exactly as you'll send it in `redirect_uri`. Custom URL schemes and `localhost` are rejected.
    4. For **Grant type**, choose **Authorization code**.
    5. For **Select scope**, choose **Read credentials**.
    6. Select **Generate credentials**, and store the client ID and secret in your secret store. The secret is shown once. **Never share the client secret**, including with 1Password.

    Record the redirect URL exactly. Register a separate client for each of your own environments, such as staging and production, so each has its own redirect URL and secret.

    <Warning>
      You can't add an icon after a client is created. If you registered a production client without an icon, register a new one.
    </Warning>
  </Step>

  <Step title="Keep the Business account active">
    You don't need to send 1Password your client ID. The 1Password app reads your integration's name and icon from your client registration.

    Keep the Business account that holds your client active. The approval prompt looks up your client there to show your name and icon, and approval can fail if the account is inactive.
  </Step>
</Steps>

## Move from development to production

| | Development | Production |
| - | - | - |
| Web origin | `https://my.b5dev.eu` | `https://my.1password.com` |
| API origin | `https://api.b5dev.eu` | `https://api.1password.com` |
| OAuth client | In your development Business account | In your company's Business account |
| Test users | Your development accounts | An Individual or Family account on 1password.com, in the US. Not your Business account: Business accounts don't get the consent screen. |
| Approval | Can't show approval prompts with current 1Password app builds | The 1Password desktop app for Mac, Windows, or Linux, on the Nightly release channel |
| Extension | The development build 1Password sends you | The development build, until 1Password announces Nightly, Beta, or Stable in your partner channel |

The connect flow is the same, with production origins. Tokens and integration keys from development don't work on production, so connect your test user again and store the new key.

The extension needs no host setting. It uses the API host named in each person's integration key, so a person connected in production uses the production API.

## Launch scope

| Area | At launch |
| - | - |
| Accounts | Individual and Family accounts on 1password.com, in the US |
| Vaults | The person's own vault |
| Credentials | Logins: username, password, and one-time password |
| Browsers | Chromium builds that support extensions, remote or local |
| Approval | The 1Password app on the person's device |
| Grant lifetime | 30 days |
| Revocation | The entire connection, from your backend |

Not at launch: Business accounts as end users, shared vaults, passkeys, social sign-in, payment cards, addresses, revoking a single login, revoking from inside 1Password, and regions outside the US.

## Before your users connect

**Connect and disconnect**

* [ ] **Connect 1Password** starts the authorization code flow with PKCE and a fresh `state`.
* [ ] Your callback reads, stores, then clears the integration key, and treats a missing key as normal.
* [ ] Tokens and integration keys live in a per-user secret store, and nothing logs them.
* [ ] Refresh-token rotation is atomic, with one refresher per person.
* [ ] A reconnect path handles `invalid_grant` and expired connections.
* [ ] **Disconnect 1Password** revokes the connection and deletes secrets only after success.

**Requests and approval**

* [ ] Each task batches its logins into one request, with a clear goal and reasons in the person's language.
* [ ] Request text contains no personal names, account identifiers, or secrets.
* [ ] The approval link goes to the person's device in code, never through the model, and never into a log.
* [ ] You handle `denied`, `failed`, a status timeout, and an approval prompt that closed after 2 minutes.
* [ ] You match grants on `entryId`, and handle missing entries and logins you didn't ask for.

**Fill**

* [ ] Browser sessions get a current access token and the integration key in memory, one person per browser.
* [ ] The model and agent can't read the page until `fillCredential` returns.
* [ ] Your agent checks the page after `fill_submitted`.
* [ ] You refresh the access token before it expires, instead of waiting for `fillFailed`.

**Production setup**

* [ ] Your production client shows the name and icon people should see.
* [ ] The Business account that holds your client is active.
* [ ] You've confirmed with your contact which extension channel to use.
* [ ] You've tested the full flow on 1password.com with an Individual or Family test account, connected on production.


## Related topics

- [Go](/sdks/languages/golang.md)
- [1Password SDKs](/sdks.md)
- [Secure CI/CD and deployments with 1Password](/get-started/secure-deployment.md)
