Overview

The 1Password integration brings your password manager roster into LowerPlane’s access reviews. A password manager is the keys to every other system, so auditors treat lingering access to it as one of the highest-severity offboarding failures there is. LowerPlane collects the account roster only — who has a 1Password account, whether it is active, and when it was created. It never reads vaults, items, passwords, secrets, or shared credentials of any kind. The integration only ever reads from 1Password; it cannot suspend, reactivate, or modify users.

Prerequisites

You need 1Password Enterprise Password Manager (Business tier) and owner, administrator, or Security group permissions. Individual, Families, and Teams Starter accounts cannot create the OAuth application this integration requires.
This integration uses the 1Password Users API for Partners, which is in public preview. If OAuth Application does not appear in your Integrations Directory on a Business account, contact 1Password support — availability can vary while the API is in preview.

How to Connect

1

Create an OAuth Application in 1Password

Sign in to your 1Password account in a browser, then select Integrations in the left sidebar.Open the Directory tab — the OAuth Application tile is not on Your Integrations, which only lists integrations you have already created. Select OAuth Application.
Do not use Events Reporting. It issues a single bearer token for activity streams and has no user-list endpoint, so it cannot produce the roster this integration needs.
2

Configure the application

FieldValue
Application NameLowerPlane
DescriptionOptional — e.g. “Read-only user roster sync for compliance access reviews”
Redirect URLAny HTTPS URL, e.g. https://app.lowerplane.com/integrations
Scopeslist users and get user only
The redirect URL is never used. LowerPlane authenticates with the OAuth 2.0 client credentials grant, which is a direct server-to-server token exchange with no browser redirect — 1Password simply requires the field to be a valid HTTPS URL.
Leave suspend users and reactivate users unchecked. LowerPlane is read-only and granting write scopes to a compliance integration widens its blast radius for no benefit.
3

Generate and save the credentials

Select Generate credentials. 1Password shows your Client ID and Client Secret.
The client secret is displayed once. There is no way to reveal it later — if you lose it you must delete the OAuth application and create a new one.
4

Find your Account ID

The Account ID is the 26-character UUID of the 1Password account the OAuth application was created in. It is not shown in the OAuth application flow, but it is in the URL of the vault app.In the 1Password web app, select View vault items at the bottom of the admin sidebar. The address bar becomes:
https://company.1password.com/app#/MRQJNZFHFFHY3MAI7ORCIL4GSM/AllItems/...
                                   └──────── Account ID ────────┘
The segment immediately after /app#/ is your Account ID. It appears again as the prefix of the item path — same value, item IDs are namespaced under it.
Only the /app#/ URL carries the account UUID. An Integrations page URL such as .../integrations/events_reporting/DLJO2XRM5BHEJFUXFFQA624YTU contains the integration’s UUID instead. Both are 26 characters, so the mistake is easy to make and produces a connection that authenticates and then fails to list users.
5

Connect in LowerPlane

Go to Integrations in LowerPlane, find 1Password under Security, and enter:
  • Region — match your sign-in domain: US (.com), Canada (.ca), or Europe (.eu). Custom sign-in domains like company.1password.com are still the US region.
  • Client ID and Client Secret from step 3
  • Account ID from step 4
Click Connect. Credentials are checked against 1Password on the first sync, not at connect time — so watch the first sync result to confirm the scopes and Account ID are right. Syncs run daily by default, and you can trigger one manually from the integration page.

What LowerPlane Collects

Account Roster

Every member of the 1Password account: user ID, email, display name, account state (active, suspended, deleted), and creation date.

Access Status

Each account’s state matched against your Personnel > People records to determine whether the access is still justified.
Evidence is stored as onepassword-user-access-list and tagged for access-control and credential-management controls.

Automated Checks

1Password users are matched to your Personnel > People records by email address. That match drives the checks below, so keeping People current is what makes the results meaningful.
CheckPasses when
1Password user should be identifiedThe account has both an email address and a display name
User access to critical 1Password system should be validThe account belongs to a known person who has not been offboarded, and is active
1Password access should be removed for offboarded userNo terminated employee still has an active 1Password account

What each failure means

A 1Password account is missing an email address or a display name, so it cannot be traced back to a named individual. This check looks only at the 1Password account itself — it does not consult your People records.To resolve: set the person’s name on the account in 1Password under People, or remove the account if it is no longer needed.
The account either belongs to nobody in your People records, or belongs to someone marked as terminated. Both mean the access cannot be justified.To resolve: remove or suspend the user in 1Password, or correct the person’s record in People if their status is wrong.
A person marked terminated in People still has an ACTIVE 1Password account.This is the highest-priority finding of the three. A live password manager account is standing access to every credential that person was ever given, which usually means the offboarding was incomplete across several other systems too.To resolve: suspend or delete the user in 1Password under People. A suspended account reports as disabled and passes on the next sync.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Access to the credential store is restricted to authorized personnel and revoked on termination
ISO 27001Provisioning and deprovisioning controls are enforced for secret and credential management

Access Reviews

1Password users also appear in Personnel > Access Reviews alongside your other connected tools, registered as a critical system. Reviewers can confirm or flag access there as part of a periodic review campaign.
The Users API roster carries no group or role field, so every user is recorded at the member access level. Owners and administrators are not distinguishable through this API — if your review needs privilege levels, capture them from the 1Password admin console manually.

Limitations

The Users API returns the roster and nothing else. That means LowerPlane cannot report:
  • Group membership or privilege level — no way to separate owners and administrators from regular members
  • MFA enrollment — two-factor status is not exposed
  • Provisioning history — no event trail of who was added or removed, or when
These are constraints of the 1Password API, not of LowerPlane, and they apply equally to other compliance platforms built on the same endpoint.

Troubleshooting

Three causes, in order of likelihood:
  1. Wrong tab — the tile is under Directory, not Your Integrations.
  2. Account tier — the Users API requires 1Password Enterprise Password Manager (Business tier). Individual, Families, and Teams Starter accounts do not have it.
  3. Preview availability — the Users API for Partners is in public preview, so availability can vary. Contact 1Password support if the tile is missing on a Business account where you hold the right permissions.
There is no workaround: without an OAuth application the integration cannot be configured.
The client ID and secret are valid — the token exchange succeeded — but the roster call did not. Either the OAuth application is missing the list users scope, or the Account ID is wrong.Re-check the Account ID against the /app#/ URL in the 1Password vault app, and confirm the scopes on the OAuth application in 1Password.
The client ID or secret is wrong. Secrets are shown once and cannot be re-read, so if you are unsure whether you copied it completely, delete the OAuth application and create a new one rather than guessing.
Almost always the wrong Account ID — typically another account the same admin belongs to, or the integration UUID copied from an Integrations page URL. Re-read it from the /app#/ URL as described in step 4.A region mismatch produces the same symptom: a .eu or .ca account queried against api.1password.com will not find the roster.
The email addresses in 1Password do not match your People records. Emails are matched exactly, in lowercase — confirm the addresses in Personnel > People are the same ones used to sign in to 1Password, not a work alias.The identification check does not use People records, so it will keep passing.