Overview
The 1Password integration brings your password manager roster into LowerPlane’s access reviews. A password manager is the keys to every other system, so auditors treat lingering access to it as one of the highest-severity offboarding failures there is. LowerPlane collects the account roster only — who has a 1Password account, whether it is active, and when it was created. It never reads vaults, items, passwords, secrets, or shared credentials of any kind. The integration only ever reads from 1Password; it cannot suspend, reactivate, or modify users.Prerequisites
This integration uses the 1Password Users API for Partners, which is in public preview. If OAuth Application does not appear in your Integrations Directory on a Business account, contact 1Password support — availability can vary while the API is in preview.
How to Connect
Create an OAuth Application in 1Password
Sign in to your 1Password account in a browser, then select Integrations in the left sidebar.Open the Directory tab — the OAuth Application tile is not on Your Integrations, which only lists integrations you have already created. Select OAuth Application.
Configure the application
| Field | Value |
|---|---|
| Application Name | LowerPlane |
| Description | Optional — e.g. “Read-only user roster sync for compliance access reviews” |
| Redirect URL | Any HTTPS URL, e.g. https://app.lowerplane.com/integrations |
| Scopes | list users and get user only |
Leave suspend users and reactivate users unchecked. LowerPlane is read-only and granting write scopes to a compliance integration widens its blast radius for no benefit.
Generate and save the credentials
Select Generate credentials. 1Password shows your Client ID and Client Secret.
Find your Account ID
The Account ID is the 26-character UUID of the 1Password account the OAuth application was created in. It is not shown in the OAuth application flow, but it is in the URL of the vault app.In the 1Password web app, select View vault items at the bottom of the admin sidebar. The address bar becomes:The segment immediately after
/app#/ is your Account ID. It appears again as the prefix of the item path — same value, item IDs are namespaced under it.Connect in LowerPlane
Go to Integrations in LowerPlane, find 1Password under Security, and enter:
- Region — match your sign-in domain: US (.com), Canada (.ca), or Europe (.eu). Custom sign-in domains like
company.1password.comare still the US region. - Client ID and Client Secret from step 3
- Account ID from step 4
What LowerPlane Collects
Account Roster
Every member of the 1Password account: user ID, email, display name, account state (active, suspended, deleted), and creation date.
Access Status
Each account’s state matched against your Personnel > People records to determine whether the access is still justified.
onepassword-user-access-list and tagged for access-control and credential-management controls.
Automated Checks
1Password users are matched to your Personnel > People records by email address. That match drives the checks below, so keeping People current is what makes the results meaningful.| Check | Passes when |
|---|---|
| 1Password user should be identified | The account has both an email address and a display name |
| User access to critical 1Password system should be valid | The account belongs to a known person who has not been offboarded, and is active |
| 1Password access should be removed for offboarded user | No terminated employee still has an active 1Password account |
What each failure means
1Password user should be identified
1Password user should be identified
A 1Password account is missing an email address or a display name, so it cannot be traced back to a named individual. This check looks only at the 1Password account itself — it does not consult your People records.To resolve: set the person’s name on the account in 1Password under People, or remove the account if it is no longer needed.
User access to critical 1Password system should be valid
User access to critical 1Password system should be valid
The account either belongs to nobody in your People records, or belongs to someone marked as terminated. Both mean the access cannot be justified.To resolve: remove or suspend the user in 1Password, or correct the person’s record in People if their status is wrong.
1Password access should be removed for offboarded user
1Password access should be removed for offboarded user
A person marked terminated in People still has an
ACTIVE 1Password account.This is the highest-priority finding of the three. A live password manager account is standing access to every credential that person was ever given, which usually means the offboarding was incomplete across several other systems too.To resolve: suspend or delete the user in 1Password under People. A suspended account reports as disabled and passes on the next sync.Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Access to the credential store is restricted to authorized personnel and revoked on termination |
| ISO 27001 | Provisioning and deprovisioning controls are enforced for secret and credential management |
Access Reviews
1Password users also appear in Personnel > Access Reviews alongside your other connected tools, registered as a critical system. Reviewers can confirm or flag access there as part of a periodic review campaign.The Users API roster carries no group or role field, so every user is recorded at the
member access level. Owners and administrators are not distinguishable through this API — if your review needs privilege levels, capture them from the 1Password admin console manually.Limitations
The Users API returns the roster and nothing else. That means LowerPlane cannot report:- Group membership or privilege level — no way to separate owners and administrators from regular members
- MFA enrollment — two-factor status is not exposed
- Provisioning history — no event trail of who was added or removed, or when
Troubleshooting
OAuth Application is not in the Integrations Directory
OAuth Application is not in the Integrations Directory
Three causes, in order of likelihood:
- Wrong tab — the tile is under Directory, not Your Integrations.
- Account tier — the Users API requires 1Password Enterprise Password Manager (Business tier). Individual, Families, and Teams Starter accounts do not have it.
- Preview availability — the Users API for Partners is in public preview, so availability can vary. Contact 1Password support if the tile is missing on a Business account where you hold the right permissions.
Authenticated but listing users failed
Authenticated but listing users failed
The client ID and secret are valid — the token exchange succeeded — but the roster call did not. Either the OAuth application is missing the list users scope, or the Account ID is wrong.Re-check the Account ID against the
/app#/ URL in the 1Password vault app, and confirm the scopes on the OAuth application in 1Password.The token endpoint returns 401
The token endpoint returns 401
The client ID or secret is wrong. Secrets are shown once and cannot be re-read, so if you are unsure whether you copied it completely, delete the OAuth application and create a new one rather than guessing.
Connected, but no users are returned
Connected, but no users are returned
Almost always the wrong Account ID — typically another account the same admin belongs to, or the integration UUID copied from an Integrations page URL. Re-read it from the
/app#/ URL as described in step 4.A region mismatch produces the same symptom: a .eu or .ca account queried against api.1password.com will not find the roster.All users fail the critical access check
All users fail the critical access check
The email addresses in 1Password do not match your People records. Emails are matched exactly, in lowercase — confirm the addresses in Personnel > People are the same ones used to sign in to 1Password, not a work alias.The identification check does not use People records, so it will keep passing.