Level up your business security with free, on-demand training and certification. Explore 1Password Academy today →
best practices
266 TopicsFeature request - Force 1password to sync
I would like, like many requests before, an option to force the sync. I know I can lock/unlock and everything should sync but that is not efficient. I have seen this asked before and everyone answers that it should just happen and/or lock/unlock the Mac desktop app. Please just add a sync now button! The automatic syncing is great but does not always work. It is probably related to the app going to sleep in the background such as due to time, Mac sleeping, etc.... Just add the button!72Views4likes2CommentsShow the requested credential
I'm heavily using 1password now for agentic usage. All of my business is set up on it now, and all of my credentials are locally using op://, or service accounts. I've put in a lot of effort to try and isolate systems using least privilege, but one problem is that when agents (or applications) request a credential from the system, it doesn't say WHAT credential is being requested. Half the time it doesn't even say the correct name for the application making the request, either. This is a big problem, because I'm starting to get into the habit of just spamming "Accept" blindly. But the whole reason I have set up this whole pipeline is so I can catch malicious programs trying to gain access - for example, supply chain attack infections. Without seeing what credential is being requested, and the process information that is requesting it, I'm finding it's not actually adding much protection at all, because it's putting me into a false sense of security and promoting bad habits. If I'm running multiple agents in parallel, which is often the case, it might just say "Terminal requests access to your vault" or something similar. Which terminal is that? What is the underlying entity being requested? What credential? What is the process ID or terminal title, so I can isolate it to a terminal/agent? Etc. I think this is something that urgently needs to be added. Otherwise, as it stands, it's not really offering much protection because users will just go "oh, it's probably just that agent running - I'm sure it's fine" and accept everything. If that agent happened to have installed a malicious npm package, you'd probably catch it too late.25Views0likes3CommentsUnable to use Yubikey with 1Password desktop client in Ubuntu 26.04
Hello all, I'm not able to use my Yubikey to sign into the 1Password desktop app running on Ubuntu 26.04. I've tried installing the client using the instructions for setting up apt and installing it that way but haven't been able to get it working. I've also installed it using the RPM as a direct download. I don't see any guides on the site that explain how to do the PAM config but I've done a number of versions of that config with no luck as well. There is no "Unlock using system authentication" option in Settings either. I just get prompted to touch my Yubikey and it doesn't flash and when I touch it nothing happens. I'm also not prompted for my UV pin. I can sign into my 1Pass account in a browser with no issue and use my Yubikey with everything but the 1Password app which I'm trying to get going so I can use the browser extension. Is there anyone that can offer help or point me to detailed technical documentation about how 1Password expects systems to be configured to support the same authentication methods the website supports? I've tried the following three authentication flows on the desktop app. QR code scanned with my mobile device Clicking the "Sign in on 1password.com" option Manually typing my login credentials, etc. 1Password version in all attempts is 8.12.21.27Views0likes1CommentPlease make the system tray icon customizable to comply with OS design standards (monochrome)
1Password has been flip-flopping between colorful and monochrome system tray icons and is now in an inconsistent state across operating systems. Please let us select between the colorful icon and the monochrome one. By catering to one set of users, you have isolated others. Your "evolving our design language across 1Password to create a more consistent experience." reasoning is flawed by the mere fact that you do not have a consistent design across OSes. A more "cohesive and predictable experience" would be an app that actually looks like it belongs in the OS you are using, rather than standing out as the sole exception. Regarding consistency, on MacOS, you follow the OS standard of a monochrome tray icon which looks native: But on Linux and Windows, we are forced to use the colorful option, which at least on KDE does not align with the design standards. Frankly the colorful icon does not comply with Windows design standards either: While we're on the topic of native integration, the Safari plugin also ditches the native monochrome icon, again diverting from OS design standards, which was a strange decision considering it used to be compliant on older versions: Current: Compliant: This was the behavior of 1Password 7, but ever since 8 you have forced the full color icon down our throats, design guidelines be damned. This was brought up years ago, but for some reason my account was deactivated, so my comment is now marked as "anonymous". Choices are good, for those who would rather focus on visibility they can opt-in to the color icon, for those who prefer consistent design, the monochrome icon should be available - arguably by default.36Views0likes1Commentop from a remote docker container?
Hi, We're using (linux) ssh remotely to connect to an on-prem bastion. Behind the bastion is a docker container we use for ansible deployment. There are several playbooks that need environment variables exported in order to run. It would be nice to pull these in on the remote container using op instead of the current cut/paste workflow. Is it possible to authorize the terminal locally with op signin and then schmooze that authorization into the remote docker container with ssh -A or something to allow the container to do something like: TOKEN=$(op read "op://Dev Secrets/GitHub Token/password") ? Our 1P accounts are issued through an enterprise and we use SSO for login with our on-prem IDP so there may be some restrictions with methods available (eg: service account token)Solved37Views0likes1CommentFirefox extension not being updated or mainted
Is there going to be any updates coming to firefox extension soon? It's been two months since the extension has been updated and chrome was updated two days ago. It would be nice if the firefox extension got a little bit more love like chrome and was updated more promptly to match current version of everything else in the ecosystem. Thank for the help in advance!Solved166Views1like8CommentsMigrate Family Account into Private account
I am currently the owner of a family account, but am the only family member that is using it nowadays. So I want to move my passwords to a private account, without losing the entries. All passwords are already in the private vault. I can't find anywhere how you can do this. There is a lot of info on moving private to family, but not the other way around. Can anyone guide me on this one?23Views0likes1CommentUnable to set up Teams Starter Pack
The President of our 4 person company, subscribed to the Teams Starter Pack and made me an admin. When I look at the Team (So far it's only the two of us), I can see his personal vault, but not his work vault, which is the opposite of what he intended. He has asked me to figure out what's wrong and I've tried looking but can't find a way to address this. HELP.60Views0likes6CommentsUpcoming 1Password webinars
Hi folks, Here's an overview of all the webinars we have coming up in the next several weeks. I hope we'll see you there! Thursday, May 21st at 9 AM PDT / 12 PM EDT (60 minutes): The unmanaged stack: Governing SaaS apps and AI tools outside SSO In this webinar, we'll explore how IT and security teams can gain full visibility into the apps, credentials and OAuth connections that live outside of SSO, and what governance looks like in an environment where AI tools are the new shadow IT. Wednesday, May 27th at 10 AM BST / 11 AM CEST / 12 PM EEST (60 minutes): The unmanaged stack: Governing SaaS apps and AI tools outside SSO This is the same webinar, but scheduled to be more convenient for Europe, the Middle East, and Africa. Tuesday, June 2nd at 9 AM PDT / 12 PM EDT (60 minutes): What's new? The 1Password quarterly security spotlight and roadmap review In this webinar, you can look forward to learning about our recent product releases, a glimpse into our product roadmap, upcoming events with 1Password, a deep dive into actionable ways 1Password can support your business' security goals. Thursday, June 4th at 11 AM BST / 12 PM CEST / 1 PM EEST (60 minutes): What's new? The 1Password quarterly security spotlight and roadmap review This is the same webinar, but scheduled to be more convenient for Europe, the Middle East, and Africa. Wednesday, June 10th at 9 AM PDT / 12 PM EDT (60 minutes): Discover built-in developer security in 1Password EPM In this session, we’ll show you how to extend the value of your 1Password deployment to developer workflows, and help you enable your engineers to build quickly and securely without added friction.30Views0likes0Comments