1Password
Use credentials from your 1Password vaults for Managed Auth
Connect 1Password to automatically use credentials from your existing vaults with Managed Auth. No need to manually create credentials in Kernel—1Password items are discovered by domain matching.
How It Works
- Connect a service account — Add your 1Password service account token in the dashboard
- Domain matching — When Managed Auth needs credentials, it searches your connected vaults for items matching the target domain
- Automatic fill — Credentials (including TOTP secrets) are used to complete authentication
Credentials are retrieved securely at authentication time. Values are never stored in Kernel—they remain in 1Password.
Setup
Create a 1Password Service Account
Create a service account in 1Password with access to the vaults containing your login credentials.
Copy the service account token (starts with ops_).
Connect in Kernel Dashboard
Go to Integrations in the Kernel dashboard and click Connect 1Password.
Give your provider a name (e.g., my-1p) and paste your service account token. Kernel will validate the connection and show which vaults are accessible.
You can connect multiple 1Password accounts with different names.
Use with Managed Auth
Reference your 1Password provider in the credential object. You can either specify an explicit item path or use auto-lookup by domain.
// Option 1: Auto-lookup by domain
const auth = await kernel.auth.connections.create({
domain: 'github.com',
profile_name: 'my-github-profile',
credential: { provider: 'my-1p', auto: true },
});
// Option 2: Explicit item path (VaultName/ItemName)
const auth = await kernel.auth.connections.create({
domain: 'github.com',
profile_name: 'my-github-profile',
credential: { provider: 'my-1p', path: 'Engineering/github-login' },
});
const login = await kernel.auth.connections.login(auth.id);Path Format
When using explicit paths, specify VaultName/ItemName:
credential: { provider: 'my-1p', path: 'Engineering/github-login' }Vault and item names containing forward slashes (/) are not supported. Rename items in 1Password if needed.
Domain Matching
1Password items are matched by their website/URL field:
| 1Password Item URL | Matches Domain |
|---|---|
github.com | github.com |
https://github.com/login | github.com |
*.example.com | app.example.com, api.example.com |
If multiple items match a domain, the first match is used. Organize your vaults to ensure the correct credentials are selected.
TOTP Support
If your 1Password item has a one-time password (TOTP) field configured, it will be used automatically for 2FA—no additional setup needed.
Supported Login Types
Managed Auth fills direct logins from 1Password items: username/password credentials plus any TOTP field for 2FA. This includes signing directly into an identity provider itself—for example logging into a Google account with its stored username, password, and TOTP.
1Password's linked-item "sign in with" references are not supported. When an item delegates authentication to a separate item—for example a site item set to sign in with another login—that link is not exposed through the 1Password API, so Managed Auth can't follow it to the underlying credential. Store a direct login (username/password, plus a TOTP field if needed) for the target site instead.
Credential Options
The credential object supports multiple sources:
| Type | Example | Description |
|---|---|---|
| Kernel credential | { name: 'my-creds' } | Use a credential stored in Kernel |
| 1Password explicit | { provider: 'my-1p', path: 'Vault/Item' } | Use a specific 1Password item |
| 1Password auto | { provider: 'my-1p', auto: true } | Search 1Password by domain |
If no credential is specified, the flow will wait for manual input.
Security
| Feature | Description |
|---|---|
| Token encrypted | Service account token encrypted with per-org keys |
| No credential storage | Credentials stay in 1Password, retrieved at auth time |
| Vault access control | Limit access via 1Password service account permissions |
| Audit trail | 1Password logs all credential access |