1Password Connect Server

<< Click to Display Table of Contents >>

Navigation:  Using SyncBackPro > Basic Operation > Secrets Manager >

1Password Connect Server

 

warning

The 1Password steps on this page are a summary, and 1Password may change them at any time. The definitive instructions are the ones on the 1Password web site: https://www.1password.dev/connect/get-started

 

SyncBackPro can retrieve usernames and passwords from 1Password. Unlike the other secrets managers it supports, it does not connect to 1Password directly. It connects to a 1Password Connect server that you run yourself, and that server is what talks to your 1Password account. You must therefore set up a Connect server before you can use 1Password with SyncBackPro.

 

The Connect server is part of 1Password Secrets Automation. It is a small REST service, supplied by 1Password as two Docker containers, that holds a copy of the items in the vaults you give it access to and hands them out to software that presents a valid access token. Because you host it, your secrets are not exposed to any other service, and you decide which machines can reach it.

 

 

What You Need

 

•A 1Password account with Secrets Automation. Connect servers are not limited to business accounts: they work with an Individual account too. On a Teams or Business account, your user account must also be in a group with permission to manage Secrets Automation.

•A machine to run the Connect server on, e.g. a Linux server, a NAS or a virtual machine, with Docker installed. It can be on your local network.

•Network access from the computer running SyncBackPro to that machine.

 

The Connect server does not need to be reachable from the Internet, and in most cases it should not be.

 

 

Step 1: Create a Shared Vault

 

A Connect server cannot access your Personal, Private or Employee vault, nor the default Shared vault. Create a new shared vault in 1Password, e.g. SyncBack, and put in it the logins and passwords you want SyncBackPro to use.

 

SyncBackPro can only use items in the Login and Password categories, and it only reads the username and password fields of those items. Items in other categories are ignored.

 

 

Step 2: Create the Connect Server

 

Sign in to your account on 1Password.com and:

 

1.Go to Developer and then Directory.

2.Under Infrastructure Secrets Management choose Other, then Create a Connect server.

3.Give the server a name and tick the shared vault you created in step 1. A Connect server can only see the vaults you tick here.

4.Save the 1password-credentials.json file that is offered to you. This file is how the Connect server itself signs in to 1Password, so keep it safe.

5.Create an access token for the server, and grant it access to the same vault. Copy the token, as it is not shown again. Note the expiry date you choose: when the token expires, profiles that use it will start to fail.

 

The same can be done from the command line with the 1Password CLI, using op connect server create and op connect token create.

 

 

Step 3: Deploy the Connect Server

 

Copy 1password-credentials.json to the machine that will run the server, and put the docker-compose.yaml file that 1Password provides in the same folder. It starts two containers:1password/connect-api (the REST API that SyncBackPro talks to) and 1password/connect-sync (which keeps its data in step with your 1Password account). Then start it:

 

 docker compose up -d

 

If you use Kubernetes, 1Password also provides a Helm chart for deploying the Connect server. See the 1Password Connect documentation for details.

 

By default the API listens on port 8080. To check that it is working, from the computer that will run SyncBackPro, open a browser or use curl in a Command Prompt (in Windows PowerShell type curl.exe instead, because curl there is a different command) to request:

 

 http://hostname:8080/v1/vaults

 

with the header Authorization: Bearer your-access-token. You should get back a list of the vaults that the token can see, each with an id and a name. If that works then SyncBackPro will work.

 

 

Step 4: Find the Vault ID

 

SyncBackPro needs the vault ID, not the vault name. It is the id value shown in the /v1/vaults response above. You can also get it with the 1Password CLI, using op vault list, or from the address bar when you open the vault on 1Password.com.

 

 

Step 5: Create the Connection

 

In SyncBackPro, go to the Secrets Manager (via the main burger menu), go to the Connections page, click Create and choose 1Password. You are then asked for:

 

 Name: The name you want to give to the connection. This is for your reference.

 URL: The address of your Connect server, e.g. http://hostname:8080. Do not include /v1, as SyncBackPro adds that itself.

 Vault Token: The access token you created in step 2.

 Vault: The vault ID from step 4.

 

SyncBackPro connects immediately and lists the items in the vault, so you will know straight away if any of the details are wrong. Once the connection exists, you create secrets that use it in the usual way, as described in Secrets Manager.

 

 

Security

 

•The access token is stored, encrypted, in the SyncBackPro settings. The value of a secret is never stored locally nor shown to the user.

•An access token can be used by anything that can reach the Connect server, so treat it as a password and limit which machines can reach the server, e.g. with a firewall rule.

•Connect uses plain HTTP by default. If the server is not on a trusted network then either configure the Connect server to serve HTTPS itself, using your own TLS certificate, or put it behind a reverse proxy that provides HTTPS. In both cases use thehttps:// address in the URL setting.

•Give the token access only to the vault that SyncBackPro needs. Revoking the token in 1Password immediately stops SyncBackPro from retrieving those secrets.

•Depending on your 1Password account type, you may be able to review in 1Password which items the Connect server accessed and when.

 

 

Limitations

 

•SyncBackPro only reads from 1Password. It never creates, changes or deletes items, and items cannot be added to 1Password from within SyncBackPro.

•Only Login and Password items are listed, and only their username and password fields are used. Private keys, e.g. for SFTP, cannot be retrieved from 1Password, so use another secrets manager for those.

•Items are identified by their title, so give each item a unique title. If two Login or Password items in the vault have the same title, both are refused with an error rather than guessed at: 1Password lists items in no fixed order, so the username and password could otherwise come from different items.

•A connection covers a single vault. If your secrets are in several vaults then create a connection for each one, and give the token access to each vault.

•1Password service accounts and the 1Password SDKs are not supported. A Connect server is required.

 

 

Troubleshooting

 

A 401 error: the token is wrong, has expired, has been revoked, or belongs to a different Connect server.

 

A 403 error: the token has not been given access to that vault, or the vault ID is wrong.

 

No secrets are listed: the vault contains no Login or Password items.

 

A 404 error: the URL is wrong. Check that /v1 has not been included.

 

Socket Error # 10061 Connection refused, Socket Error # 11001 Host not found or another socket error: SyncBackPro cannot reach the Connect server. Check the host name and the port number, that the server is running, and that a firewall is not blocking it. If SyncBackPro is run elevated, or as a scheduled task using another user account, make sure that account can reach the server as well.

 

400 Bad Request: Invalid Vault UUID: the Vault setting holds the vault's name, or something else that is not a vault ID. Use the vault ID.

 

More than one 1Password item is called ...: two Login or Password items have the same title. Rename one of them so that every title is unique, then, if needed, modify the secret in the Secrets Manager and select the item again.

 

Secret does not exist: the item has been renamed, deleted or moved out of the vault, or the token can no longer see it. Modify the secret in the Secrets Manager and select the item again.

 

Secrets work at first and then stop working: the access token has probably expired. Create a new token in 1Password and modify the connection to use it.

 

See also: Secrets Manager

 

 

 

All Content: 2BrightSparks Pte Ltd © 2003-2026