What it can do
- Sign in to sites with no API. The agent asks for the credential at the moment it reaches the sign-in form.
- Get through two-factor. If your 1Password item has a one-time code, we compute the current code and hand it over. Sites with 2FA stop being a dead end.
- Save new logins back. If an automation signs you up for something, it can put the password it generated straight into your vault, where you would look for it.
Connecting it
1Password has no “connect this app” screen the way Google does. Instead you create a key and paste it in once.1
Make a vault for your automations
In 1Password, create a new vault and move the logins you want your automations to use
into it.
2
Create a service account
In 1Password, create a service account, grant it the vault you just made, and choose
whether it may only read, or also write. Read is enough for signing in. Add write if
you want automations to save new logins.
3
Paste the token
1Password shows the token once and never again. Copy it, open Integrations in the
dashboard, and paste it into 1Password.We check it against 1Password before saving, and then tell you which vaults it reaches.
If that says none, go back to step one.
Where your key lives
The key is encrypted the moment it arrives and stored that way. Two things follow from that, and both are deliberate. You cannot read it back. Not from the dashboard, not anywhere. Once it is saved you can replace it or remove it, and that is all. There is no screen that shows it because there is no code that can. If you lose your copy, make a new key in 1Password and replace this one. Your workspaces never receive it. This is the part that matters most. The agent does not get your key and then look things up. It asks us for one credential, and we return that one answer. So a workspace never holds anything it could reuse, and nothing about your vault survives in it after the run. Every lookup is recorded: which workspace asked, and which item. The value itself is never logged.What the agent can reach
Exactly the vaults you granted the key, and nothing else. That is enforced by 1Password, not by us, which is the reason it is worth setting up properly: the vault you create is the boundary. Put in what you want automated, leave out what you do not. You can see what the key reaches on the 1Password page under Integrations, along with whether it may write to each vault.Removing it
Remove the key under Integrations and your automations lose access straight away.Also revoke the service account in 1Password. Their API gives us no way to retire a key
on your behalf, so removing our copy stops us using it but does not destroy it. Revoking
it in 1Password is what makes it dead everywhere.
Limits worth knowing
1Password caps how many requests an account can make. On a personal or Families plan that is 1,000 a day for the whole account, and Teams and Business are higher. We work around this rather than spending it. The list of what is in your vaults is cached and refreshed about once an hour, so an agent checking what it can do costs nothing. Only actually fetching a credential counts, and a full login is one request, not three. If you add a login and want to use it right away, hit Refresh on the 1Password page rather than waiting for the cache. If you do hit the limit, nothing breaks permanently. We stop sending requests until it lifts, which keeps the situation from getting worse, and automations pick up again on their own.What to tell the agent
Nothing about 1Password. Describe the job.Every morning, log into our supplier portal and pull yesterday’s orders into a page.
Check the council planning site each week for anything on our street and email me.The agent checks whether a credential exists before it promises anything, and asks you to log in by hand if there isn’t one.