> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rundesert.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 1Password

> Let your automations sign in to sites that have no API.

Plenty of the web has no API. When an automation needs something that only exists behind a
login, it has to sign in the way you would.

Until now that meant you: the agent opened a browser you could watch, and waited for you to
type the password in yourself. That works, and it means an automation only really runs when
you are awake and looking at your screen.

Connect 1Password and the agent handles the login itself.

## What it can do

* **Sign in to sites with no API.** The agent asks for the credential at the moment it
  reaches the sign-in form.
* **Get through two-factor.** If your 1Password item has a one-time code, we compute the
  current code and hand it over. Sites with 2FA stop being a dead end.
* **Save new logins back.** If an automation signs you up for something, it can put the
  password it generated straight into your vault, where you would look for it.

## Connecting it

1Password has no "connect this app" screen the way Google does. Instead you create a key
and paste it in once.

<Steps>
  <Step title="Make a vault for your automations">
    In 1Password, create a new vault and move the logins you want your automations to use
    into it.

    <Warning>
      This step is not optional, and skipping it is the reason most first attempts do not
      work. 1Password does not let a service account into your Private vault or your
      default Shared vault, which is where most people keep everything. A key can never see
      a login that is still sitting in either one.
    </Warning>
  </Step>

  <Step title="Create a service account">
    In 1Password, create a service account, grant it the vault you just made, and choose
    whether it may only read, or also write. Read is enough for signing in. Add write if
    you want automations to save new logins.
  </Step>

  <Step title="Paste the token">
    1Password shows the token once and never again. Copy it, open **Integrations** in the
    dashboard, and paste it into 1Password.

    We check it against 1Password before saving, and then tell you which vaults it reaches.
    If that says none, go back to step one.
  </Step>
</Steps>

## Where your key lives

The key is encrypted the moment it arrives and stored that way. Two things follow from
that, and both are deliberate.

**You cannot read it back.** Not from the dashboard, not anywhere. Once it is saved you can
replace it or remove it, and that is all. There is no screen that shows it because there is
no code that can. If you lose your copy, make a new key in 1Password and replace this one.

**Your workspaces never receive it.** This is the part that matters most. The agent does
not get your key and then look things up. It asks us for one credential, and we return that
one answer. So a workspace never holds anything it could reuse, and nothing about your
vault survives in it after the run.

Every lookup is recorded: which workspace asked, and which item. The value itself is never
logged.

## What the agent can reach

Exactly the vaults you granted the key, and nothing else. That is enforced by 1Password,
not by us, which is the reason it is worth setting up properly: **the vault you create is
the boundary.** Put in what you want automated, leave out what you do not.

You can see what the key reaches on the 1Password page under **Integrations**, along with
whether it may write to each vault.

## Removing it

Remove the key under **Integrations** and your automations lose access straight away.

<Note>
  Also revoke the service account in 1Password. Their API gives us no way to retire a key
  on your behalf, so removing our copy stops us using it but does not destroy it. Revoking
  it in 1Password is what makes it dead everywhere.
</Note>

## Limits worth knowing

1Password caps how many requests an account can make. On a personal or Families plan that
is **1,000 a day for the whole account**, and Teams and Business are higher.

We work around this rather than spending it. The list of what is in your vaults is cached
and refreshed about once an hour, so an agent checking what it can do costs nothing. Only
actually fetching a credential counts, and a full login is one request, not three.

If you add a login and want to use it right away, hit **Refresh** on the 1Password page
rather than waiting for the cache.

If you do hit the limit, nothing breaks permanently. We stop sending requests until it
lifts, which keeps the situation from getting worse, and automations pick up again on their
own.

## What to tell the agent

Nothing about 1Password. Describe the job.

> Every morning, log into our supplier portal and pull yesterday's orders into a page.

> Check the council planning site each week for anything on our street and email me.

The agent checks whether a credential exists before it promises anything, and asks you to
log in by hand if there isn't one.
