1Password
Connect 1Password as your access review source using the SCIM Bridge carrier token so the platform can list the members of your Business account.
The platform reads your 1Password account members through the 1Password SCIM bridge so you can check who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- The owner or administrator role in a 1Password Business account (automatic user provisioning requires both plan and role)
- Automatic provision of users already in force, either hosted by 1Password or on a SCIM bridge you have deployed yourself
- The SCIM Bridge URL, which the Connect dialog asks alongside the token. Enter the pathless bridge address, for example
https://scim.example.com, the 1Password form asks its identity provider guides. the platform attachs/scim/v2/Usersto it. SCIM URL If necessary, enter the following content:https://provisioning.1password.com/scim/v2, then enterhttps://provisioning.1password.com
Collected Fields
Section entitled “Collected Fields”| the platform field | 1Password field | Notes |
|---|---|---|
| Name | displayName |
Returns to name.formatted, then to name.givenName and name.familyName associated with a space |
userName |
Returns to the main address in emails. |
|
| Role | Not supported | |
| Admin | Not supported | |
| Status | active |
Listed as inactive when active is false, including when the answer omits the field |
| MFA | Not supported | |
| Last login | Not supported | |
| External ID | id |
Stable ID used to track your account through reviews |
| Created at | meta.created |
Empty left when the value is not a timestamp RFC 3339 |
A SCIM user record has a timestamp meta.lastModified, but that timestamp records the last profile change rather than an authentication, so the platform does not report it as a last authentication. the platform does not read any role from the SCIM record, so it does not register any account as an administrator.
Step 1: Create a Bearer Token
“Step 1: Create a Bearer Token”- In 1Password.comSigned as owner or administrator, select Integrations in the side bar, then your identity provider in User Provisioning section.
- For provisioning hosted by 1Password, select Set up hosted provisioningFor a self-hosted bridge, choose the deployment platform and follow the 1Password deployment guide for it.
- Copy the bearer token that 1Password fails at the end of the setup and stores it securely. 1Password recommends saving credentials in 1Password. You can deploy a self-hosting bridge with the ___ZBT_I18N_RUNTIME_BLOCK_187__ file that 1Password generates along with the token, so keep both.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find 1Password, click API KeyPut a book sign, enter the SCIM Bridge URL (the address of the bridge for which the token was issued, without path), and click Connect.
Name of Source 1Password and attract account members to your campaigns.
Troubleshooting
Section “Troubleshooting”- Token rejected. The bridge only supports the carrier token associated with the
scimsessionfile it runs with, so a token from a previous setting or another 1Password integration fails. Regenerate Credentials Specifications of 1Password Integrations The page issues a new pair, so reconnect with the new token. - No members appear. The platform lists the users that the bridge returns to its endpoint
/scim/v2/Usersand passes over any record without an email address. - SCIM Bridge URL rejected. The URL must use
httporhttpsand include a host, for examplehttps://scim.example.com. the platform calls the bridge from its own servers, so you cannot connect a bridge that is accessible only on a private network. - No account is marked as an administrator. The platform does not read any role from the SCIM user records, so the role and administrator remain empty for each member.
- Provisional is not available. Automated user provisioning is a 1Password Business This function, and only a owner or administrator can set it.