1Password Integration
Business password vault event log ingested for insider threat and credential risk detection.
What this integration does
1Password meets agentic SOC
1Password Business emits an Events API stream covering vault item access, team member activity, sign-in events, and administrative changes. ManySignal ingests this stream to detect suspicious credential access patterns, unusual vault item exports, and compromised team member sessions — enriching detections with the broader identity context from Okta, Entra ID, and endpoint telemetry.
1Password Events API integration for real-time event streaming
Vault item access and copy event detection
Team member sign-in anomaly detection
Data collected
- Sign-in events with device, IP, and MFA status
- Item access and copy events (credential viewed or copied)
- Vault and item creation, modification, and deletion events
- Team member provisioning and role change events
- Integration and service account activity
Actions supported
- Alert security team on sensitive vault item access
- Correlate 1Password session with concurrent anomalous activity
- Trigger ITSM ticket on mass vault item export
- Suspend team member via Okta/Entra ID integration
Getting started
Set up in minutes
- 1
Enable 1Password Events Reporting
- 2
Add the connector in ManySignal
- 3
Configure alert thresholds
1Password Integration: frequently asked questions
Does ManySignal ingest actual password values?
No. 1Password's Events API does not expose credential values. ManySignal receives metadata: which vault item was accessed, by whom, from where, and when.
Can ManySignal detect a compromised 1Password master password?
ManySignal detects anomalous sign-in patterns: new device, unusual country, concurrent sessions from different IPs. These are strong indicators of account compromise even without direct access to the master password.
Does this work with 1Password Teams (not Business)?
The Events API is available on 1Password Business and Enterprise plans. Teams plan does not include the Events API.
How does this integrate with identity provider events?
ManySignal correlates 1Password sign-in events with Okta or Entra ID authentication events for the same user. A 1Password sign-in that doesn't match any IDP session can indicate session hijacking.
Can I monitor specific vaults?
Yes. ManySignal supports vault-level filtering in the connector configuration, allowing you to focus on sensitive vaults (production credentials, executive credentials) with elevated alert thresholds.
Is there a rate limit on the Events API?
1Password Events API has rate limits per token. ManySignal respects these limits with automatic backoff and does not drop events during rate-limited periods.
Can ManySignal detect offboarded employees accessing 1Password?
Yes. By correlating with HR system or identity provider deprovisioning events, ManySignal can alert when a suspended user's credentials are used to access 1Password — a common offboarding gap risk.
What 1Password event types are supported?
sign_in, item_usage (view, copy, reveal), audit (team member changes, integration changes), and client_activity (app opens, lock/unlock) events are all supported.
How quickly do events appear in ManySignal?
Events are ingested within 30–60 seconds of occurrence through the Events API polling mechanism.
Does ManySignal support 1Password Secrets Automation?
1Password Secrets Automation (service accounts) events appear in the Events API and are ingested by ManySignal. This enables monitoring of non-human identity access to the vault alongside human user activity.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.