Skip to main content

1Password

1Password is a password manager. This connector brings in the users of your 1Password account, including whether each is active or suspended.

Beta. This connector was built from 1Password’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact [email protected].

At a glance

Data providedUsers
AuthenticationOAuth application (client ID + client secret) with the list users scope
Where to configureConnectors → Add a Connector → 1Password

Before you start

  • You need a 1Password Enterprise Password Manager account (the Business tier) and permission to manage integrations (an owner, an administrator, or a member of the Security group).
  • The 1Password Users API is a public preview. 1Password states that its functionality may be added, changed or removed at any time. If it changes, this connector may need an update.
  • Not supported with automated provisioning. 1Password’s own documentation says the Users API can’t be used if your account uses automated provisioning (for example an identity-provider integration or the SCIM bridge). In that case your users are managed by your identity provider, which Navigator can connect to directly.
  • 1Password’s other products, SaaS Manager and Extended Access Management, are separate and are not covered by this connector.

Required permissions

Create the OAuth application with only the list users scope. Navigator never suspends or reactivates users.

Setup

  1. Sign in to your 1Password account and select Integrations in the sidebar (then Directory, if you’ve set up other integrations).
  2. Select OAuth Application and give it a name such as Navigator.
  3. Enter an HTTPS Redirect URL (1Password requires one; Navigator does not use it, so any valid HTTPS URL works).
  4. Under Scopes, select only List users.
  5. Select Generate credentials. Copy the client ID and client secret now — the secret is only shown once. (1Password offers to save them to a vault.)
  6. Find your 1Password account ID. It appears in your API paths (/v1beta1/accounts/<account_id>/users); the 1Password CLI reports it as the id from op account get.
  7. In Navigator, go to Connectors → Add a Connector → 1Password.
  8. Enter your Region (com for 1Password.com, ca for 1Password.ca, eu for 1Password.eu), your account ID, the client ID and the client secret, then save.

1Password’s own guide: Get started with the Users API.

The OAuth application’s settings can’t be edited after creation; to change its scopes, create a new one and update the credentials here.

What data this connector provides

  • Users: each user’s email, display name, and whether the account is active or suspended.

Known limitations

  • The Users API returns only identity and state. Role, two-factor status, last sign-in and devices are not available, so they are not shown for 1Password users.
  • Rate limit: 100 requests per minute. Navigator fetches up to 1,000 users per request, so this is not a concern in practice.
  • Access tokens last 15 minutes; Navigator requests a fresh one for every sync.