Skip to content

1Password

When you connect a 1Password account to Oblique, Oblique will automatically sync the account and its users.

As you add people to 1Password, suspend them, or remove them, these changes are automatically synced to Oblique.

You can add multiple 1Password accounts to Oblique. These function as separate integrations and are distinguished by their account ID.

Oblique syncs the following from your 1Password account.

1Password objectOblique objectCapability
UsersAccountsRead-only
AccountResourcesRead-only
Account membershipEntitlementsRead-only

Oblique doesn’t sync 1Password groups, vaults, or who has access to each vault.

Oblique syncs each active 1Password user as an Oblique account. Suspended users aren’t synced.

1Password accounts are matched to Oblique users by email.

Oblique’s 1Password integration is read-only. Oblique can’t make changes to your 1Password account or its users.

Oblique syncs the following from 1Password as resources:

  • The 1Password account you connected

Every account has an entitlement for the 1Password account.

The 1Password integration doesn’t read information about roles in 1Password.

The 1Password integration connects using an OAuth application you create in 1Password, and requires the following scope:

1Password scopeWhat Oblique uses it for
List usersRead the account’s users
You must be an admin to add an integration.

You connect a 1Password account to Oblique by creating an OAuth application in 1Password, then adding its credentials, your sign-in domain, and your account ID to Oblique. You need to be an owner or administrator in 1Password to create an OAuth application. OAuth applications may only be available on certain 1Password plans.

To create an OAuth application, in 1Password:

  1. Navigate to Integrations > Directory, then select OAuth Application.
  2. Name the application, for example Oblique.
  3. Enter a redirect URL. This is required by 1Password but not used by Oblique. Enter any valid URL, such as https://example.com.
  4. Under Select scopes, select List users.
  5. Select Generate credentials, then copy the client ID and the client secret. 1Password only shows the client secret once.

Then, to add a 1Password integration, navigate to the Integrations page:

  1. Select Add integration.
  2. Select 1Password.
  3. Under Connect, in Sign-in domain, enter the domain of your 1Password sign-in address, such as acme.1password.com or acme.1password.eu.
  4. In Account ID, paste your account ID. To find it, select Open your vault items. Your account ID is the 26-character string between /app#/ and /AllItems in your browser’s address bar, such as ABYALEX3KZF3ZD4DJVBKARRNPY.
  5. In Client ID and Client secret, paste the credentials you created.
  6. Select Add integration.

Oblique will immediately start syncing the account’s users.

Change 1Password integration’s authorizations

Section titled “Change 1Password integration’s authorizations”
You must be an admin to replace an integration's credentials.

If the OAuth application’s credentials are revoked or need rotating, you can replace them without removing the integration. From the integration’s detail page:

  1. Navigate to the Settings tab.
  2. Under Connection, select Replace OAuth client credentials….
  3. Paste the new Client ID and Client secret, then select Replace OAuth client credentials.

You can only replace the credentials with ones for the same 1Password account. To change the account, instead delete the integration and add another one.

Oblique’s 1Password integration is read-only, so it can’t be used to manage your 1Password account or its users. Make these changes in 1Password directly, and Oblique will sync them automatically.

You must be an admin to remove an integration.

To remove a 1Password integration, from the integration’s detail page:

  1. Navigate to the Settings tab.
  2. At the bottom of the page, under Delete integration, select Delete integration….
  3. In the confirmation dialog, type the text to confirm, then select Delete integration.

This will immediately stop all syncing and remove all resources from the integration.