Repository navigation
Document 1Password Agentic Autofill for vault credentials - #631
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
There was a problem hiding this comment.
Risk assessment: Very Low
I reviewed the diff (4 files, +552/−1). Every change is documentation for the Mintlify site:
docs.jsonaddsvaults/1passwordto the vaults sidebar.integrations/1password.mdxadds a note that links to the new page.vaults/overview.mdxadds a short availability note and a related link.vaults/1password.mdxis a new page: prose, tables, and TypeScript/Python SDK samples.
Nothing here changes runtime code, auth, permissions, infrastructure, CI, schemas, or model-instruction files. The main branch ruleset does not require code owner review, and this PR had no existing approval.
Approving as Very Low risk.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 01f93d9. Configure here.
There was a problem hiding this comment.
Risk assessment: Very Low
Re-evaluated after 1f2e679 ("Shorten 1Password page description"). The existing approval from this automation still applies, so I am not approving again.
The new commit changes one frontmatter line in vaults/1password.mdx: the page description is shortened to a single sentence. The rest of the PR is unchanged from the previously approved commit.
Full diff vs main (4 files, +552/−1) is still Mintlify documentation only:
docs.jsonaddsvaults/1passwordto the vaults sidebar.integrations/1password.mdxadds a note linking to the new page.vaults/overview.mdxadds a short availability note and a related link.vaults/1password.mdxis a new page of prose, tables, and TypeScript/Python SDK samples.
No runtime code, auth, permissions, infrastructure, CI, schemas, or model-instruction files changed. The main ruleset does not require code owner review. Risk did not increase, so the existing approval stands.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Risk assessment: Very Low
Re-evaluated after 10eff0f (“Send provider kernel in credential create samples”). The existing approval from this automation still applies, so I am not approving again.
The new commit stays inside Mintlify docs:
snippets/collect-browser-credentials.mdxandvaults/credentials.mdxaddprovider: "kernel"to the TypeScript and Python credential-create samples, plus a sentence that points at the 1Password page.vaults/1password.mdxmoves the unreleased-SDK note from a rendered<Note>into a hidden comment.
Full diff vs main (6 files, +555/−2) is still sidebar config, prose, tables, and SDK samples. No runtime code, auth, permissions, infrastructure, CI, schemas, or model-instruction files changed. The main ruleset does not require code owner review. Risk did not increase, so the existing approval stands.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Risk assessment: Very Low
Re-evaluated after 046ae70 (“Update 1Password docs for renamed access request operations”). This automation already approved the PR, and the new commit does not raise the risk, so I am not approving again and I am not dismissing the existing approval.
The new commit stays inside Mintlify docs (vaults/1password.mdx, vaults/credentials.mdx, snippets/collect-browser-credentials.mdx):
- Operation names in prose and samples change from
1pw_request_access/1pw_poll_accessto1pw_create_access_request/1pw_access_request_status. - Fill, recovery, and isolation wording is tightened (fill might submit; the extension is not removed after use).
- Credential-create copy notes that a missing
providerstill defaults tokernel.
Full diff vs main is still 6 documentation files: sidebar config in docs.json, a cross-link note, prose, tables, and TypeScript/Python samples. No runtime code, auth, permissions, infrastructure, CI, schemas, or model-instruction files changed. The main ruleset does not require code owner review (require_code_owner_review is false) and does not dismiss stale reviews on push. Risk did not increase, so the existing approval stands.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Risk assessment: Very Low
Re-evaluated after b8d0c24 (“Update 1Password docs for account keys, stored tokens, and multi-entry fill”). This automation already approved the PR, and the new commit does not raise the risk, so I am not approving again and I am not dismissing the existing approval.
The new commit changes only Mintlify docs:
vaults/1password.mdxrewrites the brokered-approval page: connected-account vs storedaccess_token/integration_key, multi-entry requests,entry_idon1pw_fill, and updated limitation wording. Samples stay TypeScript and Python inside the docs page.vaults/credentials.mdxupdates a hidden maintainer comment that records which SDK preview the samples were checked against.
Full diff vs main is still 6 documentation files (docs.json sidebar entry, cross-links, prose, tables, and SDK samples). No runtime code, auth or permissions implementation, infrastructure, CI, schemas, or model-instruction files changed. The main ruleset does not require code owner review (require_code_owner_review is false) and does not dismiss stale reviews on push. Risk did not increase, so the existing approval stands.
Sent by Cursor Automation: Assign PR reviewers
There was a problem hiding this comment.
Risk assessment: Very Low
Re-evaluated after ce08ff9 (“Trim autofill lock note and remove preview pins from 1Password docs”). This automation already approved the PR, and the new commit does not raise the risk, so I am not approving again and I am not dismissing the existing approval.
The new commit changes only Mintlify docs:
vaults/1password.mdxremoves a hidden maintainer comment and shortens two sentences about what1pw_fillblocks (CDP and browser API calls). The surrounding limitation still tells readers to use a dedicated browser and not to give untrusted automation access to it.vaults/credentials.mdxshortens a hidden maintainer comment about theproviderfield. The published sentence and theprovider: "kernel"samples are unchanged.
Full diff vs main is still 6 documentation files (docs.json sidebar entry, cross-links, prose, tables, and SDK samples). No runtime code, auth or permissions implementation, infrastructure, CI, schemas, or model-instruction files changed. The main ruleset does not require code owner review (require_code_owner_review is false) and does not dismiss stale reviews on push. Risk did not increase, so the existing approval stands.
Sent by Cursor Automation: Assign PR reviewers
AnnaXWang
left a comment
There was a problem hiding this comment.
current wording understates the browser lock’s importance and should explain our security boundary
Can we describe it as “exclusive browser control during autofill” and explain the observable behavior:
- new customer CDP, WebDriver, and browser api requests receive 423 Locked
existing proxied control connections are interrupted, not paused; clients may need to reconnect - only KERNEL’s authenticated autofill connection can control the browser until 1pw_fill returns
- The current note at vaults/1password.mdx:620–624 is too vague. It also omits an important boundary: the lock covers KERNEL’s proxied control paths, not page scripts, other extensions, or live-view/out-of-band input.
Does live-view input remain possible during fill? If yes, we should disable it or call this exclusion out in our docs.
Suggested copy:
while 1pw_fill runs, KERNEL gives the autofill operation exclusive control of the browser. new CDP, WebDriver, and browser api requests are rejected, and existing control connections are interrupted. reconnect after the call returns.
this prevents concurrent automation from reading the page while credential values are present. it does not isolate credentials from the destination page, its scripts, or other extensions in the browser.
Also, add a short “how credentials are protected” section near the top, before the OAuth-client choices. Explain the lifecycle:
- the user chooses the exact login to grant in 1Password
- KERNEL stores encrypted connection material and credential references, not the login values
- the 1Password extension fetches the credential and fills it; KERNEL’s api returns status, never values
- KERNEL verifies that the destination shares the approved login’s origin
- KERNEL locks the browser while values are temporarily in the page
on fillFailed or autosubmitFailed, the extension clears filled values before returning - the destination website necessarily receives the credential, and its scripts can observe it
- use one user per dedicated browser and do not load untrusted extensions
|
@AnnaXWang addressed your review summary in 4368c6e:
|



Summary
Adds
vaults/1password.mdx("1Password Agentic Autofill"), a page that covers using 1Password Agentic Autofill in a Kernel browser, with KERNEL-hosted collection as the fallback:KERNEL-hosted collection: a short summary that links to the existing credential item and fill docs instead of repeating them.
1Password brokered approval: a
credentialitem withprovider: "1password", built on 1Password Agentic Autofill and linked to 1Password's partner docs. The page is organized around two OAuth client choices:credential_accountto link the user's account, create acredentialreferencing it by item key (account), then request access and run1pw_fillonce the user approves. KERNEL runs the OAuth flow, stores the connection, and refreshes its tokens. 1Password's consent screen and approval prompt show KERNEL.credentialholding theaccess_tokenandintegration_key(encrypted, never returned) with optionalaccess_token_expires_at. Before each task, refresh the token on your backend and send it with1pw_update_access_token, which keeps the integration key, requests, and pending or approved state.Choosing between them: the page tells integrators to ask the end user whether they want to use 1Password. If they do, link the account and request the login through 1Password; if they don't, or that path fails (declined consent, declined or failed access request, repeated fill failures, unsupported account), fall back to a KERNEL-hosted
credentialitem. It also calls out 1Password's API limits: the login must be in a private, non-shared vault, and passkeys aren't supported. The vaults overview and credential item pages repeat the fallback.The brokered section also covers:
loginentries, withentry_idon1pw_fillwhen several approved entries share the page origin.1pw_create_access_request(the 1Password extension loads into the browser on demand), the native approval link, and1pw_access_request_status.1pw_fillagain on each page of a multi-page sign-in, including a later one-time password page. A note says the browser is locked while1pw_fillruns: inbound control surfaces such as CDP and browser API calls are blocked.readyafter a grant ends, so asking again means a newcredentialitem. Links to 1Password's grant and connection lifetime sections.1pw_recover, deletion order, and limitations.It also links the page from the vaults overview and nav, and adds a note to the Managed Auth 1Password page that separates the two integrations.
Also adds
provider: "kernel"to the existing credential create samples invaults/credentials.mdxandsnippets/collect-browser-credentials.mdx. The generated SDK types require the field. The API still treats a create withoutprovideraskernel, so existing integrations and the CLI example keep working. Update samples are unchanged because updates don't acceptprovider.Written against an unmerged API change
1pw_update_access_token. Re-typecheck against the first published SDK release that includes 1Password vault items.Testing
vaults/1password.mdx,vaults/credentials.mdx, and the collect and fill snippets.tsc --strictandpyrightreport 0 errors against the newest available preview, except for the two stored-token blocks.entry_idbodies. The same schemas rejectaccount_id, six entries, andcustomer_managedclients.providerfails typechecking.mint broken-linksfinds none.mint dev,/vaults/1password,/vaults/credentials,/vaults/overview, and/auth/fill-from-vaultreturn 200 and contain no preview-build or TODO text. No visual screenshot was taken.