1Password
1Password is a password manager. This connector brings in the users of your 1Password account, including whether each is active or suspended.
Beta. This connector was built from 1Password’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact support@chartingcyber.com.
At a glance
| Data provided | Users |
|---|---|
| Authentication | OAuth application (client ID + client secret) with the list users scope |
| Where to configure | Connectors → Add a Connector → 1Password |
Before you start
- You need a 1Password Enterprise Password Manager account (the Business tier) and permission to manage integrations (an owner, an administrator, or a member of the Security group).
- The 1Password Users API is a public preview. 1Password states that its functionality may be added, changed or removed at any time. If it changes, this connector may need an update.
- Not supported with automated provisioning. 1Password’s own documentation says the Users API can’t be used if your account uses automated provisioning (for example an identity-provider integration or the SCIM bridge). In that case your users are managed by your identity provider, which Navigator can connect to directly.
- 1Password’s other products, SaaS Manager and Extended Access Management, are separate and are not covered by this connector.
Required permissions
Create the OAuth application with only the list users scope. Navigator never suspends or reactivates users.
Setup
- Sign in to your 1Password account and select Integrations in the sidebar (then Directory, if you’ve set up other integrations).
- Select OAuth Application and give it a name such as
Navigator. - Enter an HTTPS Redirect URL (1Password requires one; Navigator does not use it, so any valid HTTPS URL works).
- Under Scopes, select only List users.
- Select Generate credentials. Copy the client ID and client secret now — the secret is only shown once. (1Password offers to save them to a vault.)
- Find your 1Password account ID. It appears in your API paths (
/v1beta1/accounts/<account_id>/users); the 1Password CLI reports it as theidfromop account get. - In Navigator, go to Connectors → Add a Connector → 1Password.
- Enter your Region (
comfor 1Password.com,cafor 1Password.ca,eufor 1Password.eu), your account ID, the client ID and the client secret, then save.
1Password’s own guide: Get started with the Users API.
The OAuth application’s settings can’t be edited after creation; to change its scopes, create a new one and update the credentials here.
What data this connector provides
- Users: each user’s email, display name, and whether the account is active or suspended.
Known limitations
- The Users API returns only identity and state. Role, two-factor status, last sign-in and devices are not available, so they are not shown for 1Password users.
- Rate limit: 100 requests per minute. Navigator fetches up to 1,000 users per request, so this is not a concern in practice.
- Access tokens last 15 minutes; Navigator requests a fresh one for every sync.