Skip to main content
You test on 1password.com, against production. This page walks you through a complete test fill in about half an hour. Your product will later perform the same steps in code; here you run them by hand.
The development environment, b5dev.eu, can’t show approval prompts with current 1Password app builds. Test on 1password.com. Tokens and integration keys from b5dev.eu don’t work on production, so connect your test user again there.
Keep secrets out of logs, chats, and AI tools. The steps below produce a client secret, OAuth tokens, an integration key, and login values. Run the commands in your own terminal, and don’t paste their output into a model, a ticket, or a Slack message.

What works on production today

  • OAuth connect, token exchange, refresh, and revoke on 1password.com.
  • Approval in the 1Password desktop app on the Nightly release channel.

Before you start

You need:
  • Your company’s 1Password Business account on 1password.com, for your OAuth client.
  • A separate 1Password Individual or Family account on 1password.com, in the US, to act as your test user.
  • A Mac, Windows, or Linux computer for the 1Password desktop app.
  • openssl, curl, and Node.js, to build the authorization URL.
  • A Chromium browser, and the development build of the 1Password extension that 1Password sends you.

Set up

1

Register your OAuth client

Your client lives in your company’s 1Password Business account on 1password.com. If you don’t have one, sign up for 1Password Business. Choose Business, not Teams.
  1. Sign in to the Business account as an owner, an administrator, or a member of the Security group.
  2. Go to Integrations > OAuth Application and select OAuth Application. If the option isn’t there, send your 1Password contact the email address of an account owner or administrator, and 1Password turns it on.
  3. Enter the name people should see, and upload an icon: PNG, JPEG, or GIF, up to 1 MB. The consent screen and the approval prompt show both. You can’t add an icon after the client is created.
  4. Enter your redirect URL: your HTTPS callback, exactly as you’ll send it in redirect_uri. Custom URL schemes and localhost are rejected.
  5. For Grant type, choose Authorization code.
  6. For Select scope, choose Read credentials.
  7. Select Generate credentials, and store the client ID and client secret in your secret store. The secret is shown once. Never share it, including with 1Password.
Write down the redirect URL exactly as you typed it. The console doesn’t show it again, and authorization fails unless the redirect_uri you send matches it character for character. You don’t need to send 1Password your client ID. See Go to production.
To run the manual connect below, register a separate test client whose redirect URL no page handles, such as a path on a host you control that returns 404. The browser then stops on that URL with the code and the integration key still in the address bar.
2

Choose a test user

Use a 1Password Individual or Family account on 1password.com, in the US. An existing personal account works, or sign up for a new one.Don’t use your Business account as the test user. Business accounts don’t get the consent screen. Your client in the Business account and your test user in a separate account is the normal setup.
3

Install the 1Password desktop app on the Nightly channel

The person approves requests in their 1Password app, so you need the app to test. Install 1Password for Mac, Windows, or Linux, then open Settings > Advanced and set Release channel to Nightly. See Use 1Password beta or nightly releases.Sign in to your test account in the app.
4

Save a test login

In the test account, save a login in the person’s own vault, with the website you’ll request, for example https://example.com. That’s the Personal vault in an Individual account, or the Private vault in a Family account. Logins in shared vaults aren’t offered in the approval prompt.

Connect the test user

Your product runs this flow behind its Connect 1Password button. See Connect a user for the full reference. To test by hand, run these commands in zsh or bash. Keep the braces in ${VAR}: in zsh, "$VAR:..." applies a modifier and changes the value.
Build the authorization URL
Open the printed URL in a private browser window, so the browser isn’t still signed in to the Business account. Sign in as the test user and approve the consent screen. The browser stops on your redirect URL. In the address bar, check that state matches ${STATE}. Then copy code from the query string and integration_key from after the #. Store the integration key somewhere safe now: it’s delivered only once. The code is single use and expires quickly, so exchange it right away:
Exchange the code for tokens
The response has an access_token that expires in 900 seconds (15 minutes) and a refresh_token. Authenticate with HTTP Basic only: sending client_id in the body as well is rejected.

Request, approve, and fill with the extension

To test the extension before you write any CDP code, use its service worker console.
1

Load the extension

Unzip the development build of the 1Password extension that 1Password sent you. Go to chrome://extensions, turn on Developer mode, select Load unpacked, and choose the unzipped folder. Note the extension ID on its card. 1Password will announce in your partner channel when to switch to the Chrome Web Store.
2

Open the service worker console

On the 1Password card in chrome://extensions, select the service worker link. In the DevTools window that opens, use the Console tab. Wait for the extension to finish starting up:
It returns "ready" when the extension is ready. "failed" means it won’t recover until the service worker restarts.
3

Create a request

Paste your own values into the console:
Open the returned appLink on the computer where the Nightly desktop app runs, and approve. The prompt closes after 2 minutes.
4

Check the decision

The call returns right away. If state is still pending, run it again after you approve.
5

Turn on Agentic Mode and fill

Open the page with the username and password form for your test login in a tab. Turn on Agentic Mode for that tab, then fill it:
A successful fill returns { success: true, result: { status: "fill_submitted" } }.

Check the result

  • After 1Password web sign-in, the browser shows the consent screen instead of the 1Password home page.
  • The first connect returns an integration_key in the URL fragment.
  • The approval prompt appears in the Nightly app within a few seconds of opening the link.
  • The status call returns resolved with one reference, and the fill returns fill_submitted.
If something doesn’t match, see Errors and troubleshooting.

Next steps

Connect a user

Build the connect flow into your product.

Fill with the browser extension

Call the extension from your orchestrator over CDP.