The development environment,
b5dev.eu, can’t show approval prompts with current 1Password app builds. Test on 1password.com. Tokens and integration keys from b5dev.eu don’t work on production, so connect your test user again there.What works on production today
- OAuth connect, token exchange, refresh, and revoke on 1password.com.
- Approval in the 1Password desktop app on the Nightly release channel.
Before you start
You need:- Your company’s 1Password Business account on 1password.com, for your OAuth client.
- A separate 1Password Individual or Family account on 1password.com, in the US, to act as your test user.
- A Mac, Windows, or Linux computer for the 1Password desktop app.
openssl,curl, and Node.js, to build the authorization URL.- A Chromium browser, and the development build of the 1Password extension that 1Password sends you.
Set up
1
Register your OAuth client
Your client lives in your company’s 1Password Business account on 1password.com. If you don’t have one, sign up for 1Password Business. Choose Business, not Teams.
- Sign in to the Business account as an owner, an administrator, or a member of the Security group.
- Go to Integrations > OAuth Application and select OAuth Application. If the option isn’t there, send your 1Password contact the email address of an account owner or administrator, and 1Password turns it on.
- Enter the name people should see, and upload an icon: PNG, JPEG, or GIF, up to 1 MB. The consent screen and the approval prompt show both. You can’t add an icon after the client is created.
- Enter your redirect URL: your HTTPS callback, exactly as you’ll send it in
redirect_uri. Custom URL schemes andlocalhostare rejected. - For Grant type, choose Authorization code.
- For Select scope, choose Read credentials.
- Select Generate credentials, and store the client ID and client secret in your secret store. The secret is shown once. Never share it, including with 1Password.
redirect_uri you send matches it character for character. You don’t need to send 1Password your client ID. See Go to production.2
Choose a test user
Use a 1Password Individual or Family account on 1password.com, in the US. An existing personal account works, or sign up for a new one.Don’t use your Business account as the test user. Business accounts don’t get the consent screen. Your client in the Business account and your test user in a separate account is the normal setup.
3
Install the 1Password desktop app on the Nightly channel
The person approves requests in their 1Password app, so you need the app to test. Install 1Password for Mac, Windows, or Linux, then open Settings > Advanced and set Release channel to Nightly. See Use 1Password beta or nightly releases.Sign in to your test account in the app.
4
Save a test login
In the test account, save a login in the person’s own vault, with the website you’ll request, for example
https://example.com. That’s the Personal vault in an Individual account, or the Private vault in a Family account. Logins in shared vaults aren’t offered in the approval prompt.Connect the test user
Your product runs this flow behind its Connect 1Password button. See Connect a user for the full reference. To test by hand, run these commands in zsh or bash. Keep the braces in${VAR}: in zsh, "$VAR:..." applies a modifier and changes the value.
Build the authorization URL
state matches ${STATE}. Then copy code from the query string and integration_key from after the #. Store the integration key somewhere safe now: it’s delivered only once. The code is single use and expires quickly, so exchange it right away:
Exchange the code for tokens
access_token that expires in 900 seconds (15 minutes) and a refresh_token. Authenticate with HTTP Basic only: sending client_id in the body as well is rejected.
Request, approve, and fill with the extension
To test the extension before you write any CDP code, use its service worker console.1
Load the extension
Unzip the development build of the 1Password extension that 1Password sent you. Go to
chrome://extensions, turn on Developer mode, select Load unpacked, and choose the unzipped folder. Note the extension ID on its card. 1Password will announce in your partner channel when to switch to the Chrome Web Store.2
Open the service worker console
On the 1Password card in It returns
chrome://extensions, select the service worker link. In the DevTools window that opens, use the Console tab. Wait for the extension to finish starting up:"ready" when the extension is ready. "failed" means it won’t recover until the service worker restarts.3
Create a request
Paste your own values into the console:Open the returned
appLink on the computer where the Nightly desktop app runs, and approve. The prompt closes after 2 minutes.4
Check the decision
state is still pending, run it again after you approve.5
Turn on Agentic Mode and fill
Open the page with the username and password form for your test login in a tab. Turn on Agentic Mode for that tab, then fill it:A successful fill returns
{ success: true, result: { status: "fill_submitted" } }.Check the result
- After 1Password web sign-in, the browser shows the consent screen instead of the 1Password home page.
- The first connect returns an
integration_keyin the URL fragment. - The approval prompt appears in the Nightly app within a few seconds of opening the link.
- The status call returns
resolvedwith one reference, and the fill returnsfill_submitted.
Next steps
Connect a user
Build the connect flow into your product.
Fill with the browser extension
Call the extension from your orchestrator over CDP.