> ## Documentation Index
> Fetch the complete documentation index at: https://browseruse-0aece648-agency-browser-quickstart-v4-sdk.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# 1Password & 2FA

> Auto-fill passwords and TOTP codes from 1Password in API tasks: v4 runs with secret bindings, v2 and v3 tasks with a vault id.

## Setup

### 1. Create a dedicated vault

Create a new vault in 1Password for Browser Use. Add the credentials you want the agent to access (usernames, passwords, and 2FA/TOTP codes).

### 2. Create a service account token

1. Go to [1Password Developer Tools - Service Accounts](https://my.1password.eu/developer-tools/active/service-accounts)
2. Click **New Service Account**, name it "Browser Use Cloud"
3. Grant **read access** to the dedicated vault
4. Copy the generated token

### 3. Connect to Browser Use Cloud

1. Go to [Browser Use Cloud Settings - Secrets](https://cloud.browser-use.com/settings?tab=secrets)
2. Click **Create Integration**
3. Paste your service account token

## Use a vault in a v4 run

A v4 run does not take a vault id. It takes **secret bindings**: each binding names one field of one 1Password item, gives it an alias the agent can ask for, and lists the hosts it may be typed into. The value never reaches the model; the server types it into the focused field when the agent asks for the alias on an allowed domain. Bindings are run-scoped, so a follow-up run that needs the same login must send them again.

<CodeGroup>
  ```python Python theme={null}
  from browser_use_sdk.v4 import BrowserUse

  with BrowserUse() as client:
      run = client.runs.create(
          "Log into Jira and create a ticket for the Q4 release",
          secret_bindings=[
              {
                  "alias": "jira_password",
                  "source": {
                      "type": "onepassword",
                      "integrationId": "<integration id from Settings → Secrets>",
                      "vaultId": "<vault id>",
                      "itemId": "<item id>",
                      "fieldId": "password",
                  },
                  "allowedDomains": ["atlassian.net"],
              }
          ],
      )
      print(client.runs.wait_for_completion(run.id).result)
  ```

  ```typescript TypeScript theme={null}
  import { BrowserUse } from "browser-use-sdk/v4";

  const client = new BrowserUse();
  const run = await client.runs.create({
    task: "Log into Jira and create a ticket for the Q4 release",
    secretBindings: [
      {
        alias: "jira_password",
        source: {
          type: "onepassword",
          integrationId: "<integration id from Settings → Secrets>",
          vaultId: "<vault id>",
          itemId: "<item id>",
          fieldId: "password",
        },
        allowedDomains: ["atlassian.net"],
      },
    ],
  });
  ```
</CodeGroup>

* `integrationId` is the 1Password integration you connected under **Settings → Secrets**.
* `vaultId` and `itemId` are the 1Password UUIDs of the vault and item (copy them from 1Password).
* `fieldId` is the field's id, not its label: `username`, `password`, or `one-time-password` for a TOTP field, which resolves to the current code.
* `allowedDomains` are bare hostnames; a host covers its subdomains.

In the chat UI at cloud.browser-use.com the same picker lives under **Run settings → Credentials**: choose the vault, the item, and the field, give it an alias, and list the domains.

## Use a vault in a v2 or v3 task

<CodeGroup>
  ```python Python theme={null}
  from browser_use_sdk import AsyncBrowserUse

  client = AsyncBrowserUse()
  result = await client.run(
      "Log into my Jira account and create a new ticket",
      op_vault_id="your-vault-id",
      allowed_domains=["*.atlassian.net"],
  )
  print(result.output)
  ```

  ```typescript TypeScript theme={null}
  import { BrowserUse } from "browser-use-sdk";

  const client = new BrowserUse();
  const result = await client.run(
    "Log into my Jira account and create a new ticket",
    {
      opVaultId: "your-vault-id",
      allowedDomains: ["*.atlassian.net"],
    },
  );
  console.log(result.output);
  ```
</CodeGroup>

For SSO/OAuth redirects, include all required domains:

<CodeGroup>
  ```python Python theme={null}
  result = await client.run(
      "Log into Jira and create a ticket for the Q4 release",
      op_vault_id="your-vault-id",
      allowed_domains=["*.atlassian.net", "*.okta.com"],
  )
  ```

  ```typescript TypeScript theme={null}
  const result = await client.run(
    "Log into Jira and create a ticket for the Q4 release",
    {
      opVaultId: "your-vault-id",
      allowedDomains: ["*.atlassian.net", "*.okta.com"],
    },
  );
  ```
</CodeGroup>

## How it works

When the agent encounters a login form:

1. It identifies the service (e.g., Twitter, GitHub, LinkedIn)
2. Retrieves matching credentials from your 1Password vault
3. Fills in the username and password
4. If 2FA is required and a TOTP code is stored, it generates and enters the code automatically

<Note>
  The agent never sees your actual credentials. The actual username, password, and 2FA codes are filled in programmatically — keeping your secrets hidden from the AI model.
</Note>
