Skip to main content
  • An Enkryptify workspace with admin access
  • A 1Password account with permission to create service accounts
  • A 1Password vault that the service account can access
  • A 1Password service account token with item read and write permissions
Enkryptify connects to 1Password with the service account token you provide during setup. The token is encrypted and reused when you create additional 1Password syncs.
  • The service account must be able to:
    • List the vaults it can access
    • List items in the selected vault
    • Create and update items in the selected vault
    • Delete items in the selected vault when using individual item mode and deleting Enkryptify secrets
1Password service accounts cannot access built-in Personal, Private, Employee, or default Shared vaults. Create or select a vault that can be granted to the service account.
The 1Password sync supports two storage modes:
  • Individual items — each Enkryptify secret is written as its own 1Password Password item. You can optionally add a title prefix.
  • Secure Note — all Enkryptify secrets are written to one Secure Note as .env content. You can select an existing Secure Note or let Enkryptify create one.

Steps to complete

1

Create a new sync

  • Go to the Syncs tab of your project and click on 1Password.
2

Create a 1Password service account

  • Sign in to your 1Password account in the browser.
  • Open the Developer area.
  • Create a new service account.
  • Grant it access to the vaults you want Enkryptify to sync to.
  • Give it item read and write permissions for those vaults.
3

Copy the service account token

  • Copy the token shown by 1Password.
  • Store the token securely. 1Password only shows it once.
4

Authenticate in Enkryptify

  • Paste the service account token into Enkryptify.
  • Enkryptify validates the token by listing the vaults available to the service account.
5

Select a 1Password vault

  • Choose the vault that should receive your synced secrets.
  • Only vaults available to the service account are shown.
6

Choose a storage mode

  • Choose One 1Password item per secret to keep every secret as a separate 1Password item.
  • Choose All secrets in one Secure Note to write all secrets to one .env-style Secure Note.
7

Configure the destination

  • For individual item mode, optionally enter an item name prefix.
  • For Secure Note mode, choose an existing Secure Note or choose to create a new one.
8

Link an Enkryptify environment

  • Choose the Enkryptify environment to sync from.
  • Secret names and shared values from this environment will be written to the selected 1Password destination.