> ## Documentation Index
> Fetch the complete documentation index at: https://www.1password.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Quickstart: test the flow end to end

> Register your OAuth client, connect a test user on 1password.com, approve an access request in the 1Password desktop app, then fill the granted login with the 1Password extension.

export const StatusBadge = ({children}) => <span className="op-status-badge not-prose">{children}</span>;

<StatusBadge>Partner preview</StatusBadge>

You test on 1password.com, against production. This page walks you through a complete test fill in about half an hour. Your product will later perform the same steps in code; here you run them by hand.

<Note>
  The development environment, `b5dev.eu`, can't show approval prompts with current 1Password app builds. Test on 1password.com. Tokens and integration keys from `b5dev.eu` don't work on production, so connect your test user again there.
</Note>

<Warning>
  Keep secrets out of logs, chats, and AI tools. The steps below produce a client secret, OAuth tokens, an integration key, and login values. Run the commands in your own terminal, and don't paste their output into a model, a ticket, or a Slack message.
</Warning>

## What works on production today

* OAuth connect, token exchange, refresh, and revoke on 1password.com.
* Approval in the 1Password desktop app on the Nightly release channel.

## Before you start

You need:

* Your company's 1Password Business account on 1password.com, for your OAuth client.
* A separate 1Password Individual or Family account on 1password.com, in the US, to act as your test user.
* A Mac, Windows, or Linux computer for the 1Password desktop app.
* `openssl`, `curl`, and Node.js, to build the authorization URL.
* A Chromium browser, and the development build of the 1Password extension that 1Password sends you.

## Set up

<Steps>
  <Step title="Register your OAuth client">
    Your client lives in your company's 1Password Business account on 1password.com. If you don't have one, [sign up for 1Password Business](https://1password.com/pricing/business). Choose Business, not Teams.

    1. Sign in to the Business account as an owner, an administrator, or a member of the Security group.
    2. Go to **Integrations** > **OAuth Application** and select **OAuth Application**. If the option isn't there, send your 1Password contact the email address of an account owner or administrator, and 1Password turns it on.
    3. Enter the name people should see, and upload an icon: PNG, JPEG, or GIF, up to 1 MB. The consent screen and the approval prompt show both. You can't add an icon after the client is created.
    4. Enter your redirect URL: your HTTPS callback, exactly as you'll send it in `redirect_uri`. Custom URL schemes and `localhost` are rejected.
    5. For **Grant type**, choose **Authorization code**.
    6. For **Select scope**, choose **Read credentials**.
    7. Select **Generate credentials**, and store the client ID and client secret in your secret store. The secret is shown once. Never share it, including with 1Password.

    Write down the redirect URL exactly as you typed it. The console doesn't show it again, and authorization fails unless the `redirect_uri` you send matches it character for character. You don't need to send 1Password your client ID. See [Go to production](/agentic-autofill/partners/production#register-your-production-oauth-client).

    <Tip>
      To run the manual connect below, register a separate test client whose redirect URL no page handles, such as a path on a host you control that returns 404. The browser then stops on that URL with the code and the integration key still in the address bar.
    </Tip>
  </Step>

  <Step title="Choose a test user">
    Use a 1Password Individual or Family account on 1password.com, in the US. An existing personal account works, or sign up for a new one.

    Don't use your Business account as the test user. Business accounts don't get the consent screen. Your client in the Business account and your test user in a separate account is the normal setup.
  </Step>

  <Step title="Install the 1Password desktop app on the Nightly channel">
    The person approves requests in their 1Password app, so you need the app to test. Install [1Password for Mac, Windows, or Linux](https://1password.com/downloads), then open **Settings** > **Advanced** and set **Release channel** to **Nightly**. See [Use 1Password beta or nightly releases](https://support.1password.com/betas/#install-a-prerelease-version-of-the-1password-app).

    Sign in to your test account in the app.
  </Step>

  <Step title="Save a test login">
    In the test account, save a login in the person's own vault, with the website you'll request, for example `https://example.com`. That's the Personal vault in an Individual account, or the Private vault in a Family account. Logins in shared vaults aren't offered in the approval prompt.
  </Step>
</Steps>

## Connect the test user

Your product runs this flow behind its **Connect 1Password** button. See [Connect a user](/agentic-autofill/partners/connect) for the full reference. To test by hand, run these commands in zsh or bash. Keep the braces in `${VAR}`: in zsh, `"$VAR:..."` applies a modifier and changes the value.

```bash Build the authorization URL theme={null}
# Set first: OP_OAUTH_CLIENT_ID, OP_OAUTH_CLIENT_SECRET, OP_OAUTH_REDIRECT_URI (exactly as registered)
CODE_VERIFIER=$(openssl rand -base64 48 | tr -d '=+/\n' | cut -c1-64)
CODE_CHALLENGE=$(printf %s "${CODE_VERIFIER}" | openssl dgst -sha256 -binary | openssl base64 -A | tr '+/' '-_' | tr -d '=')
STATE=$(openssl rand -hex 16)
echo "https://my.1password.com/oauth/authorize?response_type=code&client_id=${OP_OAUTH_CLIENT_ID}&redirect_uri=$(node -p 'encodeURIComponent(process.argv[1])' "${OP_OAUTH_REDIRECT_URI}")&scope=brokered-credentials%3Arequest-access%20brokered-credentials%3Aread&state=${STATE}&code_challenge=${CODE_CHALLENGE}&code_challenge_method=S256"
```

Open the printed URL in a private browser window, so the browser isn't still signed in to the Business account. Sign in as the test user and approve the consent screen. The browser stops on your redirect URL.

In the address bar, check that `state` matches `${STATE}`. Then copy `code` from the query string and `integration_key` from after the `#`. Store the integration key somewhere safe now: it's delivered only once. The code is single use and expires quickly, so exchange it right away:

```bash Exchange the code for tokens theme={null}
read -rs CODE   # paste the code value; input is hidden
curl -s -X POST https://api.1password.com/v1/oauth/token \
  -u "${OP_OAUTH_CLIENT_ID}:${OP_OAUTH_CLIENT_SECRET}" \
  --data-urlencode grant_type=authorization_code \
  --data-urlencode "code=${CODE}" \
  --data-urlencode "redirect_uri=${OP_OAUTH_REDIRECT_URI}" \
  --data-urlencode "code_verifier=${CODE_VERIFIER}"
```

The response has an `access_token` that expires in 900 seconds (15 minutes) and a `refresh_token`. Authenticate with HTTP Basic only: sending `client_id` in the body as well is rejected.

## Request, approve, and fill with the extension

To test the extension before you write any CDP code, use its service worker console.

<Steps>
  <Step title="Load the extension">
    Unzip the development build of the 1Password extension that 1Password sent you. Go to `chrome://extensions`, turn on **Developer mode**, select **Load unpacked**, and choose the unzipped folder. Note the extension ID on its card. 1Password will announce in your partner channel when to switch to the Chrome Web Store.
  </Step>

  <Step title="Open the service worker console">
    On the 1Password card in `chrome://extensions`, select the **service worker** link. In the DevTools window that opens, use the **Console** tab. Wait for the extension to finish starting up:

    ```js theme={null}
    await api.initialization.v1.whenSettled();
    ```

    It returns `"ready"` when the extension is ready. `"failed"` means it won't recover until the service worker restarts.
  </Step>

  <Step title="Create a request">
    Paste your own values into the console:

    ```js theme={null}
    const accessToken = "<access_token>";
    const integrationKey = "<integration_key>";
    const created = await api.agenticAutofill.v1.createAccessRequest({
      accessToken,
      integrationKey,
      requests: {
        version: 2,
        goal: "Test sign-in",
        entries: [
          {
            type: "login",
            parameters: { website: "https://example.com" },
            reason: "Check the fill flow",
          },
        ],
      },
    });
    created.result.appLink;
    ```

    Open the returned `appLink` on the computer where the Nightly desktop app runs, and approve. The prompt closes after 2 minutes.
  </Step>

  <Step title="Check the decision">
    ```js theme={null}
    let status = await api.agenticAutofill.v1.getAccessRequestStatus({
      accessToken,
      integrationKey,
      accessRequestUUID: created.result.accessRequest.id,
    });
    status.result.state;
    ```

    The call returns right away. If `state` is still `pending`, run it again after you approve.
  </Step>

  <Step title="Turn on Agentic Mode and fill">
    Open the page with the username and password form for your test login in a tab. Turn on Agentic Mode for that tab, then fill it:

    ```js theme={null}
    const [tab] = await chrome.tabs.query({ url: "https://example.com/*" });
    await api.agenticMode.v1.enable({ tabId: tab.id });
    await api.agenticAutofill.v1.fillCredential({
      accessToken,
      integrationKey,
      resourcePath: status.result.resolved[0].reference.reference,
      tabId: tab.id,
    });
    ```

    A successful fill returns `{ success: true, result: { status: "fill_submitted" } }`.
  </Step>
</Steps>

## Check the result

* After 1Password web sign-in, the browser shows the consent screen instead of the 1Password home page.
* The first connect returns an `integration_key` in the URL fragment.
* The approval prompt appears in the Nightly app within a few seconds of opening the link.
* The status call returns `resolved` with one reference, and the fill returns `fill_submitted`.

If something doesn't match, see [Errors and troubleshooting](/agentic-autofill/partners/troubleshooting).

## Next steps

<CardGroup cols={2}>
  <Card title="Connect a user" icon="link" href="/agentic-autofill/partners/connect">
    Build the connect flow into your product.
  </Card>

  <Card title="Fill with the browser extension" icon="window-maximize" href="/agentic-autofill/partners/fill">
    Call the extension from your orchestrator over CDP.
  </Card>
</CardGroup>


## Related topics

- [1Password partner quickstart](/get-started/partner-quickstart.md)
- [Tutorial: Get started with 1Password SDKs and 1Password Service Accounts](/sdks/setup-tutorial.md)
- [Use service accounts with 1Password SDKs](/service-accounts/setup-tutorial.md)
