Skip to content

1Password

Bring your own 1Password tenant into OpsMerge. Connect a read-only service account once, then technicians browse every vault the token can read under Credentials, including live two-factor (TOTP) codes. Optionally map a vault to a client so its items also surface on that client's tickets.

OpsMerge never stores your 1Password data. Item titles are listed live; secret values (and TOTP codes) are fetched only when a technician clicks Reveal, held in memory just long enough to display, and every reveal is written to the audit log.

Why organise vaults by type, not per client. A 1Password service account's vault access is fixed when you create it, you cannot add vaults to it later. So structure 1Password around a handful of shared vaults by type (AD, Websites, 365, Clients) and grant the service account those. Because the Credentials area browses everything the token can read, onboarding a new client needs no token changes.

Connecting

  1. In your 1Password admin console, go to Developer → Service Accounts and create a service account named OpsMerge.
  2. Grant it read access to the vaults you want technicians to see — and nothing else. Write access is not needed and not used.
  3. Copy the token (1Password shows it once).
  4. In OpsMerge, go to Settings → 1Password, paste the token and click Connect. The token is verified with a live vault list before it is saved, and stored encrypted.

Browsing credentials

Open Credentials (under CRM in the sidebar) to browse every vault the service account can read. Expand a vault to list its items, search across titles, and click Reveal on any item to fetch its fields live. Concealed fields stay masked until toggled and can be copied without unmasking. Two-factor (TOTP) fields show the current code with a rotation countdown and refresh themselves when the code rolls over.

Browsing and revealing require the Reveal credentials (1Password) permission (see below). No vault mapping is needed for this, connect the token and you can browse.

Mapping vaults to clients (optional)

Mapping is optional. On the settings page you can map a vault to the client it belongs to; a vault can be mapped to more than one client, and a client can have several vaults. Once mapped, tickets for that client also show a Credentials (1Password) card listing the vault's item titles, so the creds are one click away in context. Everything remains browseable under Credentials whether or not it is mapped.

Permissions

  • Viewing item titles on a ticket requires the clients-list permission.
  • Reveal requires the dedicated Reveal credentials (1Password) permission (credentials.reveal, under Integrations in the roles editor) — kept separate from document management so you can grant it to a smaller set of people. Admins have it by default; every reveal is audit-logged with who, when, and which item (never the value).
  • Connecting/disconnecting and vault mapping require settings management.

Disconnecting

Settings → 1Password → Disconnect removes the token and all mappings from OpsMerge. Nothing changes in 1Password; revoke the service account there if you want the token dead everywhere.

OpsMerge is a product of Brindleford Technologies Ltd, company number 16871436, registered in England and Wales.