> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# 1Password

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/one-password.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=d0c1870b75b330511299678bcca738e5" alt="" noZoom width="24" height="24" data-path="images/connectors/one-password.svg" />

  <h1>1Password</h1>
</div>

## Connection

### Setup

Follow 1Password's [automated provisioning setup](https://support.1password.com/scim/), either hosted
by 1Password or on your own SCIM bridge, and copy the bearer token it gives you.

### Settings

| Setting      | Required | Description                                                                                                         |
| ------------ | -------- | ------------------------------------------------------------------------------------------------------------------- |
| SCIM URL     |          | SCIM root of a self-hosted 1Password SCIM bridge. Leave empty for provisioning hosted by 1Password.                 |
| Bearer token | Yes      | Bearer token from the 1Password provisioning setup page, or the one minted with your SCIM bridge. Stored encrypted. |

### Permissions

Minimum permissions the connection requires.

| Capability        | Required | Granted by (any one)        |
| ----------------- | -------- | --------------------------- |
| Provision members | Yes      | `Provisioning bearer token` |
| Read groups       | Yes      | `Provisioning bearer token` |

## one\_password.user

### Fields

| Field        | Type   | Required | Description                                                                                    |
| ------------ | ------ | -------- | ---------------------------------------------------------------------------------------------- |
| `userName`   | string | Yes      | Email address the invitation goes to and the member signs in with.                             |
| `givenName`  | string | Yes      | First name.                                                                                    |
| `familyName` | string | Yes      | Last name.                                                                                     |
| `active`     | bool   |          | Whether the member is active. An inactive member is suspended, and keeps the vaults they held. |
| `groups`     | grant  |          | Groups the member belongs to, which is what carries vault access. One row grants one group.    |
| `groups[]`   | string |          | Group ID.                                                                                      |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in 1Password, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `userName`    | `worker.business_email` |

## Examples

### 1Password members

A 1Password seat for every engineer, in the groups that carry vault access, suspended and cleared when they leave.

```hcl theme={null}
stage active {
  target one_password.user {
    userName   = worker.business_email
    givenName  = worker.legal_name.given
    familyName = worker.legal_name.family
    active     = true
    groups     = ["Engineering"]
  }
}
```
