Skip to main content
Connect 1Password to Oleria to inventory the credential-bearing items your team stores in vaults — API keys, passwords, SSH keys, and database credentials — and the activity they generate. Oleria reads this data through 1Password’s Service Accounts and Events Reporting APIs, mapping non-human identities (NHIs) to the vaults they reside in and to sign-in and item-usage activity. This page walks through generating both credentials in 1Password and connecting them to your Oleria workspace.

What Oleria discovers

Once connected, Oleria continuously discovers and maps the following from your 1Password account:
  • Non-human identities (NHIs) - credential-bearing items in your vaults — API keys, passwords, SSH keys, and database credentials stored in 1Password.
  • Resource instances - the vaults in your 1Password account, the items they contain, and the access grants tied to each vault.
  • Activities - audit events, sign-in attempts, and item usage reported through 1Password’s Events Reporting API.
Oleria authenticates to 1Password using a Service Account (created in the steps below), but the NHIs it discovers are credential-bearing vault items — not the Service Account itself. 1Password’s Events Reporting API is scoped to account-wide activity, not individual user profiles.

Prerequisites

  • 1Password administrator access, to create a Service Account and an Events Reporting API token.
  • Your 1Password Events Reporting region (United States, Europe, or Canada) - you’ll need this when connecting in Oleria.

Create a Service Account in 1Password

1

Open the Service Account wizard

Sign in to 1Password as an administrator, select Developer in the sidebar, then open the Directory tab. Under Access Tokens, select Service Account.1Password Developer Directory tab with the Access Tokens section and the Service Account card
2

Name the service account

Enter a descriptive name, for example OleriaAccount, then select Next.Create a Service Account wizard with the service account name field filled in
3

Grant vault access

Select all the vaults you want Oleria to inventory and set Read access for each, then select Next.
Leave Allow creation of new vaults unchecked - Oleria only needs read access to inventory existing vaults.
Create a Service Account wizard Vault access step with the Choose vaults section
4

Grant environment access

If the wizard shows an Environment access step, you can leave it unselected and select Next — Oleria doesn’t use Environments.
5

Save the token

Select Create Account, then copy the generated authorization token immediately, or select Save in 1Password to store it in a vault.
1Password shows the Service Account token only once. Store it securely - if you lose it, you must create a new Service Account and update the integration in Oleria.

Create an Events Reporting API token in 1Password

1

Open Events Reporting

Select Integrations in the sidebar. In the Events Reporting section, select Other, since Oleria isn’t a listed SIEM platform.
If your account already has integrations configured, selecting Integrations may open directly to a Directory view instead.
1Password Integrations page with the Events Reporting section and the Other option
2

Name the integration

Enter a descriptive name, for example OleriaEventReporter, then select Add Integration.Events Reporting wizard with the System Name field filled in
3

Configure the token

Enter a Token Name, set Expires After (30, 90, 180 days, or Never), then turn on all three Events to Report toggles - Sign-in attempts, Item usage events, and Audit events. Select Issue Token.Events Reporting Set up token step with Sign-in attempts, Item usage events, and Audit events toggled on
4

Save the token

Copy the generated token immediately, or select Save in 1Password to store it securely.
1Password shows the Events API token only once. Store it securely - if you lose it, you must create a new token and update the integration in Oleria.
5

Note your Events Reporting region

Confirm which region your 1Password account reports events from - United States, Europe, or Canada. You’ll select this region when connecting in Oleria.

Connect 1Password to Oleria

1

Open the integration

Go to your Oleria workspace, select Integrations -> select 1Password.
2

Complete the connection form

Select Continue and fill in the connection form:Oleria Connect with 1Password panel with the Service Account Token and Events API Token entered and Europe (eu) selected as the Events Region
3

Save the integration

Select Authenticate to validate and save the integration. Oleria checks both tokens against 1Password before saving.

Verify the integration

Confirm the 1Password instance appears in your Oleria workspace’s connected integrations. After the first sync completes, you can review the discovered credential items, vault access, and activity in your Oleria workspace. Oleria workspace Connected integrations tab showing the 1Password integration
If you rotate either credential, edit the integration in Oleria, paste the new token, and select Update. The next sync runs with the new credentials.

Contact us

For questions about this integration, contact us at support@oleria.com.