> ## Documentation Index
> Fetch the complete documentation index at: https://www.1password.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Errors and troubleshooting

> Common Agentic Autofill integration errors, what causes them, and how to fix them.

export const StatusBadge = ({children}) => <span className="op-status-badge not-prose">{children}</span>;

<StatusBadge>Partner preview</StatusBadge>

Find the stage and symptom that match your problem. Text in code formatting matches what appears in a response or exception.

<Note>
  Test on 1password.com. The development environment, `b5dev.eu`, can't show approval prompts with current 1Password app builds.
</Note>

## Accounts and setup

| Symptom | Cause | Fix |
| - | - | - |
| **Integrations** has no **OAuth Application** option | You aren't an owner, an administrator, or in the Security group, or the option isn't turned on for the account | Sign in as an owner or administrator. If the option still isn't there, send your contact the email address of an account owner or administrator so 1Password can turn it on. If it was just turned on, sign out and back in. |
| The OAuth Application form doesn't offer the **Read credentials** scope | You're signed in to a different account from the one 1Password set up, or the feature isn't turned on for this account | Sign in to your company's Business account. If the scope is still missing, ask your contact to check the account. |
| Calls that worked in development fail on production | Tokens and integration keys from `b5dev.eu` don't work on production | Connect the test user again on 1password.com, and store the new integration key. |

## Connect

| Symptom | Cause | Fix |
| - | - | - |
| After sign-in, the browser shows the 1Password home page, not the consent screen | The authorize path has `/v1`, or the account type doesn't get the consent screen | Use `{web origin}/oauth/authorize` with no version prefix. Test users need Individual or Family accounts. Business accounts don't get the consent screen, so don't test with your company's Business account. |
| An error page mentions the redirect URI | `redirect_uri` differs from the URI registered on the client | Send it exactly as registered, character for character. |
| The callback has `error=access_denied` | The person declined the consent screen | Let them connect again. |
| The consent screen shows your name but no icon | The client was registered without an icon | Register a new client with an icon. You can't add one after a client is created. |
| No `integration_key` in the fragment | The person already has an active key for your client | Keep the key you stored. If you don't have one, revoke the connection and connect again. |
| `curl` asks "Enter host password for user" | zsh changed `"$VAR:..."` in the `-u` argument | Write `"${VAR1}:${VAR2}"`, with braces. |

## Token exchange and refresh

| Symptom | Cause | Fix |
| - | - | - |
| The token call returns 404 | The path is missing `/v1`, or you called the web origin | `POST {api origin}/v1/oauth/token` |
| 400 `invalid_request`: `missing client credentials` | No HTTP Basic header | Send `Authorization: Basic base64(client_id:client_secret)`. |
| 400 `invalid_request`: `multiple client authentication methods are not allowed` | `client_id` is in the form body as well as the Basic header | Remove `client_id` from the body. |
| 401 `invalid_client`: `client authentication failed` | Wrong client ID or secret, or a client from the other environment | Use the ID and secret of the client registered in the same environment. |
| 400 `invalid_grant` on the code exchange | The code was already used or expired, or the code verifier or redirect URI doesn't match the authorize request | Start the connect flow again, and exchange the code right away. |
| 400 `invalid_grant` on refresh | The refresh token was already rotated, or the connection was revoked or expired | Use the latest refresh token. If it still fails, ask the person to connect again. |

## Access requests

| Symptom | Cause | Fix |
| - | - | - |
| `authenticationFailed` | The access token expired after 15 minutes, or belongs to another connection | Refresh on your backend, and pass the new token. |
| `internal` from `createAccessRequest` | The request broke a limit, such as a goal over 140 characters or more than five entries, or the integration key is damaged or belongs to another connection | Check the [field limits](/agentic-autofill/partners/access-requests#the-request). |
| `createAccessRequest` returns immediately with no prompt and a fixed test login | An old mock build of the extension is loaded | Load the current development build that 1Password sent you. |
| `rateLimitExceeded` | You exceeded the rate limit | Retry with backoff. Wait a few seconds between status checks rather than checking in a tight loop. |
| `forbidden` | This connection isn't allowed to access the resource | Use the right person's connection. Don't retry unchanged. |

## Extension and CDP

| Symptom | Cause | Fix |
| - | - | - |
| `api is not defined` | You evaluated in a web page instead of the extension's service worker | Attach to `chrome-extension://<id>/background/background.js`. |
| `api.agenticAutofill` or `api.agenticMode` is undefined after initialization | The installed extension build, or its configuration, doesn't make this API available | Load the development build that 1Password sent you. |
| Calls fail right after the browser starts | The extension hasn't finished initializing | Wait for `api.initialization.v1.whenSettled()` to resolve to `"ready"` before your first call. |
| `whenSettled()` resolves to `"failed"` | The extension couldn't initialize. That's final for the running service worker. | Restart the browser. If it fails again, send your contact the extension logs. |
| The service worker target never appears | The extension isn't loaded, or a branded Google Chrome build ignored `--load-extension` | Use Chromium or Chrome for Testing, and check `chrome://extensions`. |
| The extension ID doesn't match the channel | You installed a different channel, or loaded an unpacked copy without a manifest `key` | Use the ID `chrome://extensions` shows for the build you loaded. |
| Polling stops working midway | The service worker suspended between checks, or your websocket timed out | Keep one CDP session attached for the whole task. |
| `tab_unavailable` from `agenticMode.v1.enable` | Another agent controls the tab or the whole browser | Don't take control from the other agent. Retry after it releases the tab. |
| `tab_invalid` from `agenticMode.v1.enable` or `disable` | You turned on a scope you already control, or tried to turn off one tab while whole-browser mode is on | Avoid duplicate `enable` calls. To release one tab, turn off whole-browser mode, then turn it on again for the tabs you still need. |

## Approval

| Symptom | Cause | Fix |
| - | - | - |
| No approval prompt appears on `b5dev.eu` | The development environment can't show approval prompts with current 1Password app builds | Test on 1password.com. |
| Opening the link does nothing | The 1Password desktop app isn't installed or running, or isn't on the Nightly channel | Install the app, switch it to Nightly, and sign it in to the test account. Open the link on the computer where the app runs. |
| The app opens but shows no approval prompt | The app isn't signed in to the account the person connected, or a prompt for the same request is already open | Add the test account to the app. Opening the link again while that request is already open has no effect. |
| The prompt disappeared, and the status stays `pending` | The unlock and approval prompts close after 2 minutes | Create a new request and approve within 2 minutes. |
| The approval prompt fails | The Business account that holds your OAuth client may be inactive. The prompt looks up your client there. | Keep that Business account active. |
| The request ends in `denied` | The person declined | Create a new request if the task still needs the login. |
| The login you expected isn't suggested | It's in a shared vault, or its website differs from the one you requested | Save it in the person's own vault with that website. The person can also search for it in the prompt. |
| The prompt shows your name but no icon | The client was registered without an icon | Register a new client with an icon. See [Register your production OAuth client](/agentic-autofill/partners/production#register-your-production-oauth-client). |

## Fill

| Symptom | Cause | Fix |
| - | - | - |
| `invalidRequest` | You passed the reference object as `resourcePath` instead of the string inside it, or a non-number `tabId` | Pass `grant.reference.reference` and the numeric tab ID. |
| `agenticModeNotEnabled` | Agentic Mode doesn't cover the tab | Turn on Agentic Mode for the tab or the whole browser with `api.agenticMode.v1.enable`, then fill again. |
| `invalidTabId` | You passed a CDP target ID, or the tab closed | Look up the tab with `chrome.tabs.query` in the service worker. |
| `fillFailed` | An expired access token, a revoked or placeholder reference, or a reference from another connection | Refresh the token first. Use a reference from this connection. If it still fails, create a new request. |
| `autosubmitFailed` | 1Password filled the form but couldn't submit it, and cleared the values | Report the website to 1Password. |
| `fill_submitted`, but the agent isn't signed in | The website rejected the login or requested another step, such as a passkey, social sign-in, or a verification step that 1Password doesn't handle | Check the page. Passkeys and social sign-in aren't supported yet. |

## Revoke

| Symptom | Cause | Fix |
| - | - | - |
| 403 with an empty body | The access token isn't current | Refresh, then revoke. |

## Still stuck

Send your 1Password contact the step you're on, the environment, the exact error text, and the time it happened. Never send tokens, the integration key, the client secret, approval links, or credential values.


## Related topics

- [Sync secrets from 1Password to AWS Secrets Manager (beta)](/environments/aws-secrets-manager.md)
- [Troubleshooting](/ssh/agent/troubleshooting.md)
- [1Password Shell Plugins troubleshooting](/cli/shell-plugins/troubleshooting.md)
