ScreenshotNeo

BlogHow-to

How to Automate 1Password Login in a Browser

Use 1Password’s browser extension to fill website logins, connect it to the desktop app for easier unlocking, or use the CLI for scripts.

By the ScreenshotNeo team4 October 20268 min read

To fill a saved website password, install and unlock the 1Password browser extension, then select 1Password’s sign-in prompt on the site or choose the saved Login item from the extension and select Open & Fill. To have the extension unlock when you unlock the desktop app, enable the connection in both apps. For scripts that need secrets, use 1Password CLI; automating a human browser sign-in is a different job.

These workflows do not disable 1Password’s security or keep the vault unlocked indefinitely. The browser extension locks when you quit the browser, and other auto-lock settings or organization policies can also require it to lock. 1Password’s auto-lock guidance explains those settings.

1. Choose what you want to automate

Goal Use What it does
Sign in to websites yourself Browser extension and a saved Login item Fills credentials when you select the sign-in prompt or use Open & Fill. Some sites may sign you in after you select the prompt.
Reduce repeated extension unlocks Desktop-app integration Connects the browser extension to the desktop app so unlocking the app can unlock the extension too.
Give a script credentials 1Password CLI Loads secrets into a process or configuration file at runtime. It does not control your interactive browser session.

The browser autofill workflow is usually the right answer to “How do I make 1Password fill my passwords automatically?” Desktop integration addresses “Can the extension unlock when I unlock the app?” Use CLI for “Can I use 1Password in a script?”

2. Set up website autofill

  1. Install the 1Password extension for your browser and open it.
  2. Unlock 1Password in the extension.
  3. Make sure the website Login item is saved in 1Password and has the correct website address and username.
  4. Visit the site’s sign-in page. Select the 1Password sign-in prompt to fill the saved Login item. Depending on the site, selecting the prompt may also submit the sign-in.
  5. If no prompt appears, open the extension from the browser toolbar, select the Login item, and choose Open & Fill.

For autofill, suggestions, and automatic saving preferences, open the extension settings and review Autofill & save. The precise prompt and sign-in behavior depends on the website. Follow 1Password’s browser extension instructions if the controls differ in your version.

When a login does not fill

  • Check that the saved item is a Login item and that its website address matches the site you are visiting.
  • On sites with separate username and password pages, fill the first step, continue to the next page, then fill again if needed.
  • For a site that uses single sign-on (SSO), the identity provider may control the sign-in flow. Use the organization’s sign-in option where provided.
  • Use the extension’s item picker if the inline sign-in prompt is absent or the site has multiple saved accounts.

3. Connect the extension to the desktop app

This optional connection makes the desktop app the unlock point for the extension. It does not disable auto-lock: the browser extension always locks when you quit the browser, and configured idle or sleep settings may lock it sooner.

  1. Update the 1Password desktop app, browser extension, and browser.
  2. Open and unlock the desktop app. Go to Settings → Browser and turn on Connect with 1Password in the browser.
  3. Open and unlock the browser extension. Go to its Settings → General and turn on Integrate this extension with the 1Password desktop app.
  4. Quit and reopen the desktop app, then restart the browser.

The connection guidance covers Chrome, Firefox, Edge, Brave, and Safari. On a Mac, Safari can also support unlocking with Touch ID even without the desktop app installed. See 1Password’s desktop-app connection troubleshooting for current platform steps.

4. Keep unlock behavior secure

Use integration to reduce repeated unlock prompts, not to remove the lock. The extension locks when the browser quits. You can review idle and device-sleep auto-lock behavior in 1Password, subject to the account type and any settings enforced by your organization.

If your organization uses Unlock with SSO, choose its identity-provider option in the extension. When adding a browser or device, you may need to approve it from an already linked app or browser and enter a verification code. Keep that code private; do not share it with anyone. See signing in with SSO and linking a new app or browser.

5. Use the CLI when a script needs secrets

Do not automate the extension’s unlock dialog to supply credentials to a program. The CLI is designed to load secrets into commands and scripts. First install and sign in to 1Password CLI, and store the required secrets in 1Password. The examples below use a secret reference such as op://prod/app/api-key; replace the vault, item, and field with your own. Avoid printing secret values or committing them to source control.

Load a secret for one command with op read

#!/usr/bin/env bash
set -euo pipefail

api_key="$(op read 'op://prod/app/api-key')"
API_KEY="$api_key" ./deploy.sh

The secret is passed to the command through its environment. Do not enable shell tracing with set -x around secret handling, since tracing can expose values in logs.

Resolve secret references with op run

Put references in a local environment file, for example:

# .env (keep this file out of version control)
API_KEY=op://prod/app/api-key

Run the application with the CLI:

op run --env-file=.env -- ./your-app

The CLI resolves references and passes the values to the process at runtime. Follow the current CLI documentation for exact flags and authentication requirements.

Render a configuration template with op inject

# config.template.json
{
  "apiKey": "op://prod/app/api-key"
}
op inject -i config.template.json -o config.json
./your-app --config config.json
rm -f config.json

Protect the rendered file: it contains resolved secrets. Prefer a temporary location with appropriate file permissions, and remove it when the process finishes. For interactive tools with supported shell plugins, op plugin run can provide credentials without putting them directly in the command configuration.

For automation, use a service account with access limited to the vaults it needs. 1Password recommends service accounts for least privilege. Its CLI documentation also describes an op run workflow for 1Password Environments as beta and requiring a specified beta CLI version; treat that capability as beta unless the current documentation says otherwise. See Load secrets into scripts.

Or skip the browser setup

If what you need is a screenshot of a sign-in page for documentation or debugging, ScreenshotNeo captures the page with one GET request. It is a website screenshot API and MCP server; it does not sign in to websites or manage 1Password credentials.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://support.1password.com/1password-extension/ -o shot.webp

See the ScreenshotNeo API documentation. Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Learn about ScreenshotNeo, then sign up for 1,000 free screenshots a month with no card.

Troubleshooting

Symptom Likely cause What to check
Saved login is not suggested The Login item’s website address does not match, the extension is locked, or suggestions/autofill preferences differ. Unlock the extension, check the saved item’s website, and review Autofill & save settings. Try selecting the item from the toolbar and Open & Fill.
Extension does not unlock with the desktop app One of the two integration switches is off, or one component is out of date. Update the app, extension, and browser; check both settings; restart both app and browser.
Connection stopped working after an OS update Background activity permission may be off on macOS Ventura or later. In System Settings, check General → Login Items & Extensions and allow 1Password background activity.
Managed Windows browser cannot connect Organization policy may block native messaging. Ask IT to check native messaging policies. Do not change a managed registry setting without authorization.
Linux app and extension cannot communicate A sandboxed Snap or Flatpak app/browser can prevent communication. Check how both components were installed and consult 1Password’s platform guidance for a supported installation path.
SSO asks to verify a browser A new browser/device needs approval through a linked app or browser. Follow the verification flow and keep the verification code private.
op command cannot resolve a secret reference The CLI is not signed in, the reference path is wrong, or the account/service account cannot access that vault or item. Check CLI authentication, exact vault/item/field names, and least-privilege access. Do not paste secret values into logs while debugging.

For desktop integration, use a supported browser and current versions; compatibility requirements change over time, so check the current 1Password system requirements. On organization-managed computers, native messaging may be disabled by policy. On Linux, sandboxed packaging is a frequent environment-specific obstacle; neither issue is necessarily fixed by reinstalling the extension alone.

Performance, reliability, and cost considerations

  • Autofill: It is interactive and depends on the site’s form and sign-in flow. Keep a manual Open & Fill path available for unusual forms or multi-step login pages.
  • Desktop integration: It removes an unlock step when the app and extension connect successfully, but browser quit and auto-lock behavior still apply. A supported browser, current components, and permitted native messaging are prerequisites.
  • CLI: Runtime secret loading avoids hard-coding values into scripts, but depends on CLI authentication, correct references, and the process having access. Limit service-account access to the required vaults and avoid exposing resolved values in logs or files.
  • Cost: This workflow uses your existing 1Password account and CLI access; consult 1Password for account or organization plan details. For unrelated website screenshot capture, ScreenshotNeo has a free allowance of 1,000 screenshots per month and paid plans starting at $5 for 3,000.

FAQ

Can 1Password submit a website login automatically?

Depending on the site, selecting the 1Password sign-in prompt may fill credentials and sign you in. The site determines whether an additional submit action is needed.

Can I keep 1Password unlocked all the time?

This guide does not recommend removing the vault’s security. Browser quit always locks the extension, and your auto-lock settings or organization policy may lock it sooner.

Can I automate a browser login with Selenium or Playwright and pull the password from 1Password?

For a human signing in, use the extension. For a script that needs a secret, use the CLI’s documented secret-loading methods and an appropriately restricted account. Browser automation and credential provisioning are separate workflows.

Does ScreenshotNeo automate 1Password sign-in?

No. ScreenshotNeo captures webpages as images or PDFs; it is not a password manager or browser login automation tool.