Level up your business security with free, on-demand training and certification. Explore 1Password Academy today →
vault management
58 TopicsShow the requested credential
I'm heavily using 1password now for agentic usage. All of my business is set up on it now, and all of my credentials are locally using op://, or service accounts. I've put in a lot of effort to try and isolate systems using least privilege, but one problem is that when agents (or applications) request a credential from the system, it doesn't say WHAT credential is being requested. Half the time it doesn't even say the correct name for the application making the request, either. This is a big problem, because I'm starting to get into the habit of just spamming "Accept" blindly. But the whole reason I have set up this whole pipeline is so I can catch malicious programs trying to gain access - for example, supply chain attack infections. Without seeing what credential is being requested, and the process information that is requesting it, I'm finding it's not actually adding much protection at all, because it's putting me into a false sense of security and promoting bad habits. If I'm running multiple agents in parallel, which is often the case, it might just say "Terminal requests access to your vault" or something similar. Which terminal is that? What is the underlying entity being requested? What credential? What is the process ID or terminal title, so I can isolate it to a terminal/agent? Etc. I think this is something that urgently needs to be added. Otherwise, as it stands, it's not really offering much protection because users will just go "oh, it's probably just that agent running - I'm sure it's fine" and accept everything. If that agent happened to have installed a malicious npm package, you'd probably catch it too late.33Views0likes3CommentsCan't share a vault with a Guest
Hi everyone, I'm hoping someone in the community has run into this before, because I've exhausted what I can try on my side and I'm still waiting on a reply from Support and Success. The situation: I invited a client to my Business account as a Guest. He accepted the invitation, created his account, and I confirmed his access. His status is now Active and he is not assigned to any vault. However, every time I try to add him to a vault, I get this error: Failed to add person to vault. An unexpected error occurred. Error Code: 400 What I've already checked / tried: I'm the only team member on the account and I hold owner/administrator permissions, so I have full rights to manage vaults and people. The guest is not assigned to any other vault. Tried adding him from the vault side (Manage Access) and from the person side (People → user profile → Vaults). Both fail with the same error. Deleted the user entirely and re-invited him from scratch. He accepted again, I confirmed him again, and the error persists. Tried a different browser and an incognito window — same result. Has anyone seen this before? Is there something I might be missing, or a workaround that's worked for you? Thanks in advance for any pointers.43Views0likes2CommentsHow to customize the suggested item name in the auto-save prompt?
Hello. When a user saves a new login on our site (e.g. app.acme.io), the "Save in 1Password" prompt defaults to a name derived from the domain so we get "Acme" instead of "acme.io". It doesn't match our brand. We've already done what compatible-website-design recommends: brand-name <title>, application-name, apple-mobile-web-app-title, og:site_name, manifest.webmanifest (name / short_name), correct autocomplete attributes. None of these influence the suggested name. Questions: Is there a client-side mechanism (meta tag, well-known endpoint, JSON-LD…) we're missing to declare our brand name for the auto-save prompt? If not, what's the official process to submit a domain + brand name + logo to 1password Rich Icons / website database? Thanks.22Views0likes0CommentsDomain Migration/Merge
I am not sure if there was an option, may of the settings became unavailable once 1P was connected to an IDP(Rippling). 1- We are rebranding and migrating from domain W to domain A, is there a way to rename users from user @ w.com to user @ a.org while keeping their access and accounts? 2-I've also seen a few users having both a.org and w.com accounts, is there a way to merge the two under a.org? 3-When a user is offboarded they may have passwords not saved in a shared vault, I would manually login as the user to access those. Is there an admin tool/function to transfer those vault items to their manager? Thanks!39Views0likes2Commentslost most of favorites in 1password after the last 1password update
Hello, Yesterday I updated the 1Password client to the latest version "1Password for Windows 8.12.12". After that I lost most of my personal favorite items pinned in 'Favorites'. My colleagues reported about the opposite consequences - they got the favorites they didn't have before the update. I wonder if someone else got similar issues. Thanks!Solved63Views0likes5CommentsFeature Request: Vault Level MFA Enforcement
Problem Statement Currently, MFA can be enforced at the account level, which applies universally to all vaults and users. While this provides a strong baseline, it lacks granularity for organizations that manage vaults with varying sensitivity levels. Not all vaults contain equally critical data, and enforcing MFA globally may introduce unnecessary friction for lower-risk use cases. Proposed Enhancement Introduce the capability to require MFA specifically for access to designated vaults. This would allow administrators to: Enforce MFA only when accessing high-sensitivity vaults (e.g., privileged credentials, production secrets, break glass) Maintain a more flexible user experience for lower-risk vaults Apply differentiated security policies aligned with data classification Suggested Functionality Admin-configurable MFA requirement at the vault level Conditional prompts: users authenticate with MFA only when accessing protected vaults Audit logging for vault-level MFA enforcement and access attempts Use Cases Segregation of privileged credentials requiring stronger authentication controls Compliance scenarios where specific data sets require step-up authentication Organizations implementing tiered security models across teams or environments Impact / Benefits Improved security posture through granular access controls Reduced user friction by avoiding blanket MFA enforcement Better alignment with enterprise security policies and compliance requirements Thank you for your consideration.Solved24Views0likes1Comment1Password App on Linux doesn't show all Vaults
Hi, I'm using 1password for business and for some reason on my installation the application does only show the Employee vault and another one used by me and a few coworkers. However, login into our company space my-company.1password.com I can see several other Vaults. Is I'm fairly new to 1Password and cannot find any settings to enable the visibility in the application. I'm running Archlinux and installed 1Password using yay. I only have this one company account. Is that an issue with the application or is there something I'm missing? Regards LaPeteSolved39Views0likes3CommentsEmployee Vaults - Access?
Hello all, our business environment requires that all passwords should be visible and reclaimable in the event that the employee leaves. This is fine with a shared vault, as other users have access as they may share them, or for redundancy. However we have a particular team where a shared vault isn't suitable, as each user has their own access to certain data. So in this case the Employee vault would be perfect. Except that I'm almost certain that these vaults can't be accessed by Overwatch roles, like Administrators or Owners, even though I've seen language on various docs from 1password that users with the right permissions can access them. Problem is I can't find these permissions to enable them to be visible when needed. What do you suggest is the best solution for this? Accounts are locked to business email addresses but reclaiming an account just because someone is on holiday and something important is stored in the Employee Vault sounds excessive...Solved1.1KViews0likes2CommentsSlow/unresponsive UI/UX after update to 8.12.10 (Windows Desktop)
Multiple users in our organization are seeing the same regression across browsers on Windows 11. The 1Password desktop app Settings UI remains responsive, but navigation between items/tags in the main vault has a noticeable delay (often 3-7 seconds!!!), especially in our largest vault with many tags. The issue started after updating from 8.12.8 to 8.12.10. A related regression is that after clicking a tag, users can no longer immediately type to narrow/search as they previously could. We also notice similar sluggishness in the 1Password web app. I have tried switching between HW-acceleration, OpenGL and more to no avail. This looks less like a browser-specific problem and more like a Windows desktop/webview or list-view performance/focus regression. Please confirm whether this is a known issue in the recent Windows/MSIX client and whether there is a fix in beta/nightly. We would love a solution to this, since navigating now is painfully slow and unintuitive compared to before. It's a massive step backwards.74Views0likes3Comments"Items in wrong account" - feature request
Hello We have an enterprise account and I see lots of items in my Employee vault that are work related but flagged as being in the wrong account as the email domain is our old company name. Accounts with the login badger@company.com are ok but those with badger@oldcompanyname.com are flagged as in the wrong account in my employee vault. "oldcompanyname.com" and "company.co.uk" (and others) should be considered in the correct account? Is there any way to flag several domains as approved? Is there a way to do this for the enterprise account? If there isn't, can this please be added as a feature requestSolved49Views0likes2Comments