Test on 1password.com. The development environment,
b5dev.eu, can’t show approval prompts with current 1Password app builds.Accounts and setup
| Symptom | Cause | Fix |
|---|---|---|
| Integrations has no OAuth Application option | You aren’t an owner, an administrator, or in the Security group, or the option isn’t turned on for the account | Sign in as an owner or administrator. If the option still isn’t there, send your contact the email address of an account owner or administrator so 1Password can turn it on. If it was just turned on, sign out and back in. |
| The OAuth Application form doesn’t offer the Read credentials scope | You’re signed in to a different account from the one 1Password set up, or the feature isn’t turned on for this account | Sign in to your company’s Business account. If the scope is still missing, ask your contact to check the account. |
| Calls that worked in development fail on production | Tokens and integration keys from b5dev.eu don’t work on production | Connect the test user again on 1password.com, and store the new integration key. |
Connect
| Symptom | Cause | Fix |
|---|---|---|
| After sign-in, the browser shows the 1Password home page, not the consent screen | The authorize path has /v1, or the account type doesn’t get the consent screen | Use {web origin}/oauth/authorize with no version prefix. Test users need Individual or Family accounts. Business accounts don’t get the consent screen, so don’t test with your company’s Business account. |
| An error page mentions the redirect URI | redirect_uri differs from the URI registered on the client | Send it exactly as registered, character for character. |
The callback has error=access_denied | The person declined the consent screen | Let them connect again. |
| The consent screen shows your name but no icon | The client was registered without an icon | Register a new client with an icon. You can’t add one after a client is created. |
No integration_key in the fragment | The person already has an active key for your client | Keep the key you stored. If you don’t have one, revoke the connection and connect again. |
curl asks “Enter host password for user” | zsh changed "$VAR:..." in the -u argument | Write "${VAR1}:${VAR2}", with braces. |
Token exchange and refresh
| Symptom | Cause | Fix |
|---|---|---|
| The token call returns 404 | The path is missing /v1, or you called the web origin | POST {api origin}/v1/oauth/token |
400 invalid_request: missing client credentials | No HTTP Basic header | Send Authorization: Basic base64(client_id:client_secret). |
400 invalid_request: multiple client authentication methods are not allowed | client_id is in the form body as well as the Basic header | Remove client_id from the body. |
401 invalid_client: client authentication failed | Wrong client ID or secret, or a client from the other environment | Use the ID and secret of the client registered in the same environment. |
400 invalid_grant on the code exchange | The code was already used or expired, or the code verifier or redirect URI doesn’t match the authorize request | Start the connect flow again, and exchange the code right away. |
400 invalid_grant on refresh | The refresh token was already rotated, or the connection was revoked or expired | Use the latest refresh token. If it still fails, ask the person to connect again. |
Access requests
| Symptom | Cause | Fix |
|---|---|---|
authenticationFailed | The access token expired after 15 minutes, or belongs to another connection | Refresh on your backend, and pass the new token. |
internal from createAccessRequest | The request broke a limit, such as a goal over 140 characters or more than five entries, or the integration key is damaged or belongs to another connection | Check the field limits. |
createAccessRequest returns immediately with no prompt and a fixed test login | An old mock build of the extension is loaded | Load the current development build that 1Password sent you. |
rateLimitExceeded | You exceeded the rate limit | Retry with backoff. Wait a few seconds between status checks rather than checking in a tight loop. |
forbidden | This connection isn’t allowed to access the resource | Use the right person’s connection. Don’t retry unchanged. |
Extension and CDP
| Symptom | Cause | Fix |
|---|---|---|
api is not defined | You evaluated in a web page instead of the extension’s service worker | Attach to chrome-extension://<id>/background/background.js. |
api.agenticAutofill or api.agenticMode is undefined after initialization | The installed extension build, or its configuration, doesn’t make this API available | Load the development build that 1Password sent you. |
| Calls fail right after the browser starts | The extension hasn’t finished initializing | Wait for api.initialization.v1.whenSettled() to resolve to "ready" before your first call. |
whenSettled() resolves to "failed" | The extension couldn’t initialize. That’s final for the running service worker. | Restart the browser. If it fails again, send your contact the extension logs. |
| The service worker target never appears | The extension isn’t loaded, or a branded Google Chrome build ignored --load-extension | Use Chromium or Chrome for Testing, and check chrome://extensions. |
| The extension ID doesn’t match the channel | You installed a different channel, or loaded an unpacked copy without a manifest key | Use the ID chrome://extensions shows for the build you loaded. |
| Polling stops working midway | The service worker suspended between checks, or your websocket timed out | Keep one CDP session attached for the whole task. |
tab_unavailable from agenticMode.v1.enable | Another agent controls the tab or the whole browser | Don’t take control from the other agent. Retry after it releases the tab. |
tab_invalid from agenticMode.v1.enable or disable | You turned on a scope you already control, or tried to turn off one tab while whole-browser mode is on | Avoid duplicate enable calls. To release one tab, turn off whole-browser mode, then turn it on again for the tabs you still need. |
Approval
| Symptom | Cause | Fix |
|---|---|---|
No approval prompt appears on b5dev.eu | The development environment can’t show approval prompts with current 1Password app builds | Test on 1password.com. |
| Opening the link does nothing | The 1Password desktop app isn’t installed or running, or isn’t on the Nightly channel | Install the app, switch it to Nightly, and sign it in to the test account. Open the link on the computer where the app runs. |
| The app opens but shows no approval prompt | The app isn’t signed in to the account the person connected, or a prompt for the same request is already open | Add the test account to the app. Opening the link again while that request is already open has no effect. |
The prompt disappeared, and the status stays pending | The unlock and approval prompts close after 2 minutes | Create a new request and approve within 2 minutes. |
| The approval prompt fails | The Business account that holds your OAuth client may be inactive. The prompt looks up your client there. | Keep that Business account active. |
The request ends in denied | The person declined | Create a new request if the task still needs the login. |
| The login you expected isn’t suggested | It’s in a shared vault, or its website differs from the one you requested | Save it in the person’s own vault with that website. The person can also search for it in the prompt. |
| The prompt shows your name but no icon | The client was registered without an icon | Register a new client with an icon. See Register your production OAuth client. |
Fill
| Symptom | Cause | Fix |
|---|---|---|
invalidRequest | You passed the reference object as resourcePath instead of the string inside it, or a non-number tabId | Pass grant.reference.reference and the numeric tab ID. |
agenticModeNotEnabled | Agentic Mode doesn’t cover the tab | Turn on Agentic Mode for the tab or the whole browser with api.agenticMode.v1.enable, then fill again. |
invalidTabId | You passed a CDP target ID, or the tab closed | Look up the tab with chrome.tabs.query in the service worker. |
fillFailed | An expired access token, a revoked or placeholder reference, or a reference from another connection | Refresh the token first. Use a reference from this connection. If it still fails, create a new request. |
autosubmitFailed | 1Password filled the form but couldn’t submit it, and cleared the values | Report the website to 1Password. |
fill_submitted, but the agent isn’t signed in | The website rejected the login or requested another step, such as a passkey, social sign-in, or a verification step that 1Password doesn’t handle | Check the page. Passkeys and social sign-in aren’t supported yet. |
Revoke
| Symptom | Cause | Fix |
|---|---|---|
| 403 with an empty body | The access token isn’t current | Refresh, then revoke. |