Skip to main content
Plenty of the web has no API. When an automation needs something that only exists behind a login, it has to sign in the way you would. Until now that meant you: the agent opened a browser you could watch, and waited for you to type the password in yourself. That works, and it means an automation only really runs when you are awake and looking at your screen. Connect 1Password and the agent handles the login itself.

What it can do

  • Sign in to sites with no API. The agent asks for the credential at the moment it reaches the sign-in form.
  • Get through two-factor. If your 1Password item has a one-time code, we compute the current code and hand it over. Sites with 2FA stop being a dead end.
  • Save new logins back. If an automation signs you up for something, it can put the password it generated straight into your vault, where you would look for it.

Connecting it

1Password has no “connect this app” screen the way Google does. Instead you create a key and paste it in once.
1

Make a vault for your automations

In 1Password, create a new vault and move the logins you want your automations to use into it.
This step is not optional, and skipping it is the reason most first attempts do not work. 1Password does not let a service account into your Private vault or your default Shared vault, which is where most people keep everything. A key can never see a login that is still sitting in either one.
2

Create a service account

In 1Password, create a service account, grant it the vault you just made, and choose whether it may only read, or also write. Read is enough for signing in. Add write if you want automations to save new logins.
3

Paste the token

1Password shows the token once and never again. Copy it, open Integrations in the dashboard, and paste it into 1Password.We check it against 1Password before saving, and then tell you which vaults it reaches. If that says none, go back to step one.

Where your key lives

The key is encrypted the moment it arrives and stored that way. Two things follow from that, and both are deliberate. You cannot read it back. Not from the dashboard, not anywhere. Once it is saved you can replace it or remove it, and that is all. There is no screen that shows it because there is no code that can. If you lose your copy, make a new key in 1Password and replace this one. Your workspaces never receive it. This is the part that matters most. The agent does not get your key and then look things up. It asks us for one credential, and we return that one answer. So a workspace never holds anything it could reuse, and nothing about your vault survives in it after the run. Every lookup is recorded: which workspace asked, and which item. The value itself is never logged.

What the agent can reach

Exactly the vaults you granted the key, and nothing else. That is enforced by 1Password, not by us, which is the reason it is worth setting up properly: the vault you create is the boundary. Put in what you want automated, leave out what you do not. You can see what the key reaches on the 1Password page under Integrations, along with whether it may write to each vault.

Removing it

Remove the key under Integrations and your automations lose access straight away.
Also revoke the service account in 1Password. Their API gives us no way to retire a key on your behalf, so removing our copy stops us using it but does not destroy it. Revoking it in 1Password is what makes it dead everywhere.

Limits worth knowing

1Password caps how many requests an account can make. On a personal or Families plan that is 1,000 a day for the whole account, and Teams and Business are higher. We work around this rather than spending it. The list of what is in your vaults is cached and refreshed about once an hour, so an agent checking what it can do costs nothing. Only actually fetching a credential counts, and a full login is one request, not three. If you add a login and want to use it right away, hit Refresh on the 1Password page rather than waiting for the cache. If you do hit the limit, nothing breaks permanently. We stop sending requests until it lifts, which keeps the situation from getting worse, and automations pick up again on their own.

What to tell the agent

Nothing about 1Password. Describe the job.
Every morning, log into our supplier portal and pull yesterday’s orders into a page.
Check the council planning site each week for anything on our street and email me.
The agent checks whether a credential exists before it promises anything, and asks you to log in by hand if there isn’t one.