Skip to main content
  • 308 Product updates

1Password CLI 2.35.0

These release notes are syndicated from releases.1password.com.You can now authenticate the following CLIs using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to everyone who contributed! Cline CLI, contributed by @eddumelendez CrateDB CLI, contributed by @accraw Cursor CLI, contributed by @eddumelendez Descope CLI, contributed by @scottisloud Exercism CLI, contributed by @dethancosta Expo and EAS CLIs, contributed by @CodeByZach GitHub Copilot CLI, contributed by @eddumelendez Google Gemini AI API CLI, contributed by @fproulx-boostsecurity Jetbrains Junie CLI, contributed by @eddumelendez Kiro CLI, contributed by @eddumelendez OpenCode CLI, contributed by @eddumelendez OpenTofu CLI, contributed by @gargakshit PyPI for twine, flit, and hatch, contributed by @cpierce UpCloud CLI, contributed by @jksolbakken The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured. Thanks @scottisloud! The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning. Thanks @arunsathiya! Tab completion is now supported when using shell plugins with bash and zsh shells. op no longer hangs when running a shell plugin from outside $HOME. Terraform workspace subcommands now trigger authentication when using 1Password Shell Plugins. Thanks @moraisph! The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials. Thanks @owenvoke! The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin. Thanks @jbhannah! The awslogsCLI function has been renamed to capitalize CLI for consistency. Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled.

Related products:Developer tools

1Password CLI Beta 2.37.0-beta.01

These release notes are syndicated from releases.1password.com.You can now authenticate the following CLIs using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to everyone who contributed! Cline CLI, contributed by @eddumelendez CrateDB CLI, contributed by @accraw Cursor CLI, contributed by @eddumelendez Descope CLI, contributed by @scottisloud Exercism CLI, contributed by @dethancosta Expo and EAS CLIs, contributed by @CodeByZach GitHub Copilot CLI, contributed by @eddumelendez Google Gemini AI API CLI, contributed by @fproulx-boostsecurity Jetbrains Junie CLI, contributed by @eddumelendez Kiro CLI, contributed by @eddumelendez OpenCode CLI, contributed by @eddumelendez OpenTofu CLI, contributed by @gargakshit PyPI for twine, flit, and hatch, contributed by @cpierce UpCloud CLI, contributed by @jksolbakken The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured. Thanks @scottisloud! The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning. Thanks @arunsathiya! Tab completion is now supported when using shell plugins with bash and zsh shells. op no longer hangs when running a shell plugin from outside $HOME. Terraform workspace subcommands now trigger authentication when using 1Password Shell Plugins. Thanks @moraisph! The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials. Thanks @owenvoke! The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin. Thanks @jbhannah! The awslogsCLI function has been renamed to capitalize CLI for consistency. Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled.

Related products:Developer tools

1Password SaaS Manager #857

These release notes are syndicated from releases.1password.com.New Workday Procurement – Optional Contract Sync: When connecting the Workday Procurement integration, you can now choose to only sync Spend data, without enabling Contract sync. Previously, both data types were always included with no way to opt out. Organizations using a separate system for contract management can now disable contract sync at setup. Existing connections will continue to sync both Spend and Contracts by default. OpenAI Platform – Setup Guidance: The OpenAI Platform integration now includes inline setup documentation clarifying that an Organization Admin key is required (not a project or service-account key), along with the specific permissions needed for each enabled feature: Users, AI Consumption (closed beta), Account Activity, and Provisioning. This makes it easier to configure the integration correctly on the first try. Humaans – Personal Email Support: The Humaans integration now syncs personal email addresses for users in addition to work email, providing more complete people data for organizations using Humaans as their HRIS. Anthropic Claude Enterprise – Renamed and Updated: The “Claude AI” provider has been renamed to Anthropic Claude Enterprise for consistency with how enterprise AI integrations are named in SaaS Manager (for example, OpenAI ChatGPT Enterprise). Descriptions for both the Anthropic Claude Enterprise and Claude Console providers have also been updated to accurately reflect setup requirements and help direct users to the correct provider for their use case. EPM – Audit Log Events: Policy, credential, and accessor events originating from 1Password EPM (Extended Access Management) are now recorded in the SaaS Manager audit log, providing a complete audit trail for EPM-managed credential activity. Cursor – Connection Details: The Cursor integration now includes updated inline documentation clarifying prerequisites for AI usage tracking (closed beta), noting that activity data covers a rolling 90-day window and refreshes approximately every four hours. (Closed beta) AI Consumption – Dashboard Tabs: The AI Consumption dashboard now features dedicated tabs for Overview and Budgets, making it easier to navigate between consumption data and budget management. (Closed beta) AI Consumption – Drill Down: Clicking on entities in the AI consumption chart or table now applies contextual filters and drills into related data automatically. For example, clicking a day in the chart filters the table to that date’s usage. (Closed beta) AI Consumption – Search in Consumption Table: A search bar has been added above the consumption table on the AI Consumption dashboard. Typing filters rows in real time by the primary identifier for the current view (account name, model, API key, and so on). Clearing the search restores the full table. (Closed beta) AI Consumption – Budget Date Quick Pickers: Setting a budget period is now easier with quick-pick date shortcuts, similar to the period picker on the consumption chart. This makes it faster to define and update budget date ranges without manually entering dates. Fixed Google OIDC Connect – Sign-In: Fixed an issue that could prevent some users from signing in with Google OIDC Connect. The issue was introduced when subdomain support was added. EPM – Credential Policy State Consistency: Fixed several state inconsistency issues in the EPM managed-credentials policy lifecycle. This includes a 404 error that appeared after enforcing a credential for a single user, an inconsistent policy state immediately following reactivation, and a phantom app appearing in the discovered apps list after reactivation. HubSpot – User Profile Collisions: Fixed an issue where HubSpot users without a linked CRM owner record were all assigned the same internal identifier, causing multiple distinct users to be incorrectly merged into a single profile in SaaS Manager. HubSpot – Deprovisioning Step Description: Updated the HubSpot “Delete User” workflow step description to correctly reflect that any user can be deprovisioned, not only users with an associated HubSpot owner record. Tableau – 403 Forbidden Error: Fixed a 403 forbidden error that affected Tableau Server connections. The error was caused by a previous Tableau Cloud fix being incorrectly applied to all connection types. OpenAI Platform – Spend Data Parsing: Fixed a parsing error that prevented AI consumption spend values from being imported correctly for certain OpenAI Platform accounts. AI Consumption – Filter Access for Spend Role: Fixed a 403 error that prevented users with the Spend role from loading filters on the AI Consumption dashboard. Filters now load correctly for this role. AI Consumption – Budget Date Range Validation: Restored a clear validation message when a budget’s configured date range exceeds one year. Previously, this showed a generic error with no explanation. Multiple Provider Instances – Team Data Conflicts: Fixed an issue where connecting multiple instances of the same integration provider caused team and group data to conflict or alternate between instances unpredictably. SaaS Manager now maintains stable, separate team data for each connected instance, and the Settings > People > Teams sources list now shows an entry per instance rather than per provider.

Related products:SaaS Manager

1Password SaaS Manager #780

These release notes are syndicated from releases.1password.com.New App Catalog – Additional Approval Tiers: There is no longer a limit on the number of approval levels that can be configured for access request workflows. This applies to both the default approval settings (Settings > App catalog > Default approval) and per-application access policies (Application > Access policy > Approval). Organizations that need sign-off from a manager, app owner, and IT team can now configure as many approval stages as required. ADP – Cost Center Code Mapping: The ADP integration now correctly maps cost center data using the “Cost Numbers” organizational unit type. This improves accuracy for organizations that use the Business Unit field to store company names rather than cost center codes. Asana – Public Projects Guidance: The Asana integration now includes a clear note explaining that the Create task step only syncs task data for public projects. This is reflected in the integration setup and help documentation, reducing confusion for teams working with private projects. (Closed beta) AI Consumption Chart – Filtering: The AI consumption chart now supports additional filtering options to make it easier to analyze spend and usage data by specific dimensions. Fixed App Catalog – Cancel Access Request: Fixed an issue where users were unable to cancel a pending access request from within the App catalog. App Catalog – Message Task Assignees: Fixed an issue where messages couldn’t be sent to Task assignees from within the App catalog. Temporary Access – Expiry Job: Fixed a bug that caused the temporary access expiry job to fail silently since March 2026. Users granted temporary access were not automatically deprovisioned when their access period ended. Affected access requests have been identified and remediated. Contracts – License Population Delay: Fixed a delay where licenses manually assigned to users did not appear immediately in the Contract UI’s overview or contracts drawer. Licenses now reflect correctly without requiring a page refresh or needing to sign in again. BambooHR – API Migration: Updated the BambooHR integration to use BambooHR’s new Datasets v2 API, replacing the deprecated Custom Report API. This makes sure people data continues to sync reliably. dbt – Connection Fix: Fixed a connection failure that prevented organizations from successfully connecting to the dbt integration. The integration was calling an incorrect API endpoint; requests are now routed correctly. Xero – Spend Transaction Date Parsing: Fixed an issue where certain Xero transaction descriptions with non-standard date range formats weren’t being parsed correctly, resulting in inaccurate spend period data. KrispAI – SCIM URL for Large Accounts: Fixed an issue where KrispAI accounts with more than 100 users received an incorrectly formatted SCIM provisioning URL, which prevented user provisioning from completing successfully. Atlassian – OAuth Refresh Token Handling: Fixed an issue where expired Atlassian OAuth refresh tokens were classified as temporary failures, causing the integration to retry indefinitely rather than prompting for reconnection. Connections with an expired token will now correctly surface a reconnection prompt. Microsoft Entra ID – Directory Roles for Mixed-Case User Principal Names: Fixed an issue where users with directly assigned Entra directory roles (such as Global Administrator) didn’t have those roles reflected in SaaS Manager when Microsoft returned their User Principal Name in mixed case (for example, User@domain.com). GitHub – Improved Organization Slug Validation: Improved handling of invalid or malformed GitHub organization slugs during sync, reducing errors for organizations with atypical slug configurations.

Related products:SaaS Manager

1Password in the browser 8.12.28-17

These release notes are syndicated from releases.1password.com.On verified low-risk sites, the phishing prevention prompt now highlights “Add website and autofill” as the primary action. You can now put double quotes around a search query to look up an exact phrase, including special characters like dots and dashes (for example, "10.1.2.3"). We’ve fixed an issue where managed logins wouldn’t appear in the list of logins you could update if you were changing the password. We’ve fixed an issue where a white screen could appear after you unlocked multiple 1Password accounts. Longer account and vault names in the Accounts & Vaults menu now truncate properly. We’ve fixed an issue where 1Password could lock unexpectedly. We’ve fixed an issue where street addresses could be suggested in some URL input fields. We’ve fixed an issue where automatic sign-in could select the option for a passwordless sign-in code instead of the option to log in with a password. We’ve fixed an issue where automatic sign-in could select the wrong option on login pages with a separate administrator login option. We’ve fixed an issue where automatic sign-in could select the wrong option on login pages if buttons used justify-center or items-center layout classes. We’ve fixed an issue where passwords wouldn’t fill properly on Bank Hapoalim, Sentrient, and ctm.net. We’ve fixed an issue where one-time passwords wouldn’t autofill on the Gosuslugi website. We’ve fixed an issue where a new password would be incorrectly suggested when logging in to app.heyberries.com. We’ve fixed an issue where automatic sign-in could select the passkey option instead of the password login option on some French websites.

Related products:Web extension

1Password in the browser 8.12.26

These release notes are syndicated from releases.1password.com.You can now immediately unlock the 1Password browser extension if the 1Password desktop app isn’t detected, instead of having to wait for an attempted connection. You can now choose “Use system defaults” in the language selector to match your browser’s set language. In Safari, pressing the down arrow in a field now focuses the first suggestion in the inline menu. If you haven’t set up 1Password, and you click the 1Password icon in your browser’s toolbar, you’ll now always be taken to the welcome screen in that same window. We’ve made under-the-hood improvements for detecting changes to policies that affect the 1Password browser extension. Identity items are no longer suggested on dns.google. We’ve fixed an issue where a page could disappear behind the save passkey prompt on some websites. We’ve fixed an issue where the inline menu icon didn’t appear on sites with nested iframes. We’ve fixed an issue where you could see a blank icon for your account in the pop-up to update an item. We’ve fixed issues with signing in and saving accounts on Pottery Barn, West Elm, Williams-Sonoma, Swivel AuthControl Sentry, Zalando Lounge, Adobe, the Hong Kong Jockey Club, fotor.com, sso.greenchoice.nl, secure.e-boekhouden.nl, inloggen.kpn.com, cedeo.fr, and play.typeracer.com. One-time passwords now fill properly on more websites, including Oracle Cloud, AT&T, ServiceNow, ConnectWise Manage, ConnectWise-hosted RMM, Canva, GMX, Fortinet SSO, FortiCloud, PeerBerry, and LinkTech Services RMM. We’ve fixed an issue where 1Password would offer to fill a password instead of suggesting a new one when creating accounts on some French sites. We’ve fixed an issue where the 1Password app wouldn’t appear when you unlocked the 1Password browser extension during an enforced Unlock with SSO migration. We now support body-level data-1p-ignore and data-op-ignore attributes to exclude fields from 1Password.

Related products:Web extension

1Password SaaS Manager #724

These release notes are syndicated from releases.1password.com.New Workflows – 7-Day Expiry Option: A “7 days” option has been added to the workflow inactivity reset dropdown. This joins the existing options (Immediately, 30, 60, 90, and 180 days, and 1 year) and applies across License, App, Asset, Person, and Task filter triggers. OpenAI Platform – Admin Key Requirement Clarified: The OpenAI Platform integration setup description has been updated to clarify that an Admin key is required, not just any API key. This should reduce failed connection attempts when setting up AI consumption tracking. 1Password Integration – Updated SCIM Terminology: References to “SCIM Bridge” in the 1Password integration have been updated to “SCIM” to align with 1Password’s current hosted provisioning model. Field labels and helper text now reflect this change, with updated links to the relevant support documentation. Integrations – Logo Initials Fallback: Integration and provider tiles now display a generated initials badge when no logo is available. This provides a consistent visual experience for integrations that don’t have an uploaded logo. Fixed Devices: Fixed an issue where a device sourced from multiple integrations could be incorrectly editable. Attempting to save a duplicate device name now returns a clear error message rather than a generic failure. Public API – App User Filters: Fixed an issue where filtering app users by email or name through the public API, GET /api/apps/v1/{appId}/users, silently returned empty results. These filters now return the correct matching data. Public API – OpenAPI Documentation: Tightened the OpenAPI specification definitions across Apps, Core, and Workflow responses. This includes a corrected route parameter for the Applications PATCH endpoint ({id} → {appId}) and improved required/nullability annotations for several response fields, bringing the documentation in line with actual API behavior. Google Workspace – Generate User Verification Codes: Fixed an intermittent failure in the “Generate User Verification Codes” workflow step. The step could fail when Google’s API experienced a short propagation delay after generating codes. Automatic retry logic has been added to handle this transparently, so the step should now succeed without requiring manual workflow intervention. Google Workspace – 401 Error Messaging: Improved the error messages shown when a Google Workspace workflow action fails due to insufficient permissions on the connected account. The error now clearly explains that a Super Admin role is required when managing other admin users, and links to the relevant setup documentation. 1Password Integration – Non-ASCII Characters in Bearer Token: Fixed a sync failure that occurred when the 1Password SCIM bearer token contained non-ASCII characters, typically caused by copying the token from a rich-text editor. The token is now automatically sanitized before use. Microsoft Entra ID – Roles Missing for Mixed-Case UPN: Fixed an issue where users with directly assigned Microsoft Entra directory roles did not have those roles reflected in SaaS Manager. This occurred when Microsoft Graph returned the User Principal Name (UPN) in mixed case, for example User@domain.com, causing the role lookup to fail silently. Cursor – Missing User Mappings on First Sync: Fixed an issue where the Cursor AI usage integration reported mapping errors for user emails that were already present in the account. This was preventing the integration from being successfully enabled. 1Password – User Deletion Sync: Fixed an issue where SaaS Manager users were not automatically removed when their corresponding 1Password accounts were deleted (rather than purged). People data will now stay in sync when 1Password accounts are removed directly.

Related products:SaaS Manager