Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Use 1Password as the credential authority and inject values only when the automation process starts. Keep usernames and passwords out of Playwright or Selenium source files, resolve 1Password references with the op CLI, and let the browser script read ordinary environment variables. Use the browser extension for a person supervising a browser; use CLI injection with a least-privilege service account for unattended tests and CI.

The two workable ways to use 1Password

There are two different jobs people call “using 1Password with browser automation.” An attended run can use the 1Password browser extension to save and fill a login while a person watches the browser. An unattended test should not depend on extension pop-ups or a human unlock action. Instead, the 1Password CLI supplies secrets to the test process at runtime.

Extension autofill for attended browsers

The extension can save a login, fill the username and password, and fill additional fields that were captured when the login was saved. It is useful while creating a test, diagnosing a selector, or running a headed browser under supervision. Chrome, Brave and Edge require permission for the extension to read and change data on websites and to communicate with cooperating native applications. Review those permissions before enabling the extension in a profile that contains unrelated work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CLI injection for unattended tests

The CLI has three relevant commands:

  • op run resolves secret references and exposes the resulting values to a child process.
  • op read reads one referenced field, which is useful for setup scripts or a narrowly scoped operation.
  • op inject renders a template containing 1Password references, such as a configuration file.

For automated jobs, create a service account or another controlled CLI identity with access only to the vault and items required by that job. The test source should contain selectors, URLs and assertions; it should not contain the credential values.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Set up a reference-based environment

  1. Create a dedicated vault or collection. Store the login or API credential used by the test there. Separate test accounts from production accounts.
  2. Record secret references, not secret values. A reference has the form op://Vault/Item/field. The field is commonly username or password, but use the field names that exist in your item.
  3. Give the automation identity least privilege. A CI service account should be able to read only the required vault and items. Do not use a personal account with broad access for a shared runner.
  4. Keep a reference-only environment file. For example, .env.1password can contain:
E2E_USER=op://QA-Vault/Shop-Test/username
E2E_PASS=op://QA-Vault/Shop-Test/password
BASE_URL=https://staging.example.test

This file identifies where values come from; it does not contain the values themselves. Protect any local files that might contain resolved output, and never print the environment to diagnose a failure.

Playwright: inject at process start

Playwright recommends passing secrets from outside the test source. Your test reads process.env, while op run resolves the references before Playwright starts.

Minimal Playwright test

import { test, expect } from '@playwright/test';

test('signs in with the test account', async ({ page }) => {
  await page.goto(process.env.BASE_URL + '/login');
  await page.getByLabel('Email').fill(process.env.E2E_USER);
  await page.getByLabel('Password').fill(process.env.E2E_PASS);
  await page.getByRole('button', { name: 'Sign in' }).click();
  await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible();
});

In a shell, run the test through op run:

op run --env-file=.env.1password -- npx playwright test

The exact command can be wrapped by your package script or CI step. The important boundary is that the child process receives the values only for its lifetime. Do not replace references with literal passwords in a checked-in .env file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reading one value with op read

Use a direct read when a setup operation needs one value and does not need the full test environment:

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
export TEST_TOKEN="$(op read 'op://QA-Vault/Shop-Test/password')"
node create-fixture.js

Do not use shell tracing, debug output or an exception message that includes the resulting variable. A direct read is still a secret in the receiving process.

Generating a file with op inject

For tools that require a configuration file, keep references in a template and render it immediately before use. A template might contain:

base_url={{ op://QA-Vault/Shop-Test/base_url }}
username={{ op://QA-Vault/Shop-Test/username }}
password={{ op://QA-Vault/Shop-Test/password }}

Render it with op inject, use the output, and remove the resolved file in cleanup. Prefer environment injection when the tool supports it because fewer processes and files handle the secret.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Selenium: the same boundary, a different test API

Selenium does not need to know that 1Password supplied the values. Read environment variables in the test and let the CLI provide them.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
import os
from selenium import webdriver
from selenium.webdriver.common.by import By
from selenium.webdriver.support.ui import WebDriverWait
from selenium.webdriver.support import expected_conditions as EC

user = os.environ['E2E_USER']
password = os.environ['E2E_PASS']
base_url = os.environ['BASE_URL']

driver = webdriver.Chrome()
try:
    driver.get(base_url + '/login')
    driver.find_element(By.ID, 'email').send_keys(user)
    driver.find_element(By.ID, 'password').send_keys(password)
    driver.find_element(By.CSS_SELECTOR, 'button[type="submit"]').click()
    WebDriverWait(driver, 15).until(
        EC.visibility_of_element_located((By.CSS_SELECTOR, '[data-test="dashboard"]'))
    )
finally:
    driver.quit()

Start it in the same way:

op run --env-file=.env.1password -- python test_login.py

Selectors in this example are illustrative. Use stable IDs or test attributes from your application rather than changing selectors to accommodate a password manager.

Should an automated browser use the extension?

Usually, no for CI. Extension autofill introduces an interactive dependency: the extension must be installed in that browser profile, have the right site permissions, be unlocked, and successfully identify the login form. Headless runs generally have no person available to approve a fill or unlock the vault.

Use the extension when a human is supervising a headed browser and wants visible save-and-fill behavior. Use CLI injection when the process must run unattended, when you need deterministic inputs, or when a service account is the appropriate authentication boundary. This is an execution-model choice, not a claim that one mode is universally better.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CI configuration and reproducibility

  1. Install the CLI and authorize it noninteractively. Store the service-account credential in the CI provider’s protected secret store. Make it available only to the job that needs it.
  2. Install the browser framework and matching browsers. For Playwright, install the framework’s browser binaries and operating-system dependencies in the image or job. Re-run the install command after a Playwright upgrade because releases can change supported browser versions.
  3. Resolve references in the job command. Invoke the test runner as a child of op run, rather than writing resolved credentials to the repository workspace.
  4. Start with one worker. Playwright’s CI guidance prioritizes one worker for stability and reproducibility. Add sharding or more parallel capacity only after the environment is reliable and the test account can safely support concurrent sessions.
  5. Pin versions. Pin the automation framework and review browser upgrades as compatibility changes. A changed browser can alter selectors, consent dialogs or timing.
  6. Control artifacts. Screenshots, traces, videos and failure logs can contain usernames, account data or pages reached after login. Restrict uploads, redact where possible, and set retention appropriate to the sensitivity of the test.

Official Playwright container images and CI-provider examples can simplify browser dependencies, but the same secret boundary applies: the runner receives values at process start, and test code never becomes a credential store.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Security boundaries you should not ignore

What the extension protects

1Password describes its extension as running in a WebExtensions sandbox with isolated extension pages, iframes, messaging APIs, input sanitization and a restrictive content-security policy. A page script should not be able to directly inspect the extension’s protected user interface.

What an unlocked browser still exposes

Isolation is not a guarantee against a compromised automation host. 1Password warns that malware controlling the browser, debugging tools or a malicious extension may access information while 1Password is unlocked. Use a trusted operating system and browser, remove unnecessary extensions, and consider a separate browser profile for untrusted extensions.

AI-driven browsing

In a January 30, 2026 security advisory, 1Password described a setting that disables automatic sign-in for the 1Password web app, preventing automated browser activity when the extension is unlocked. For an AI agent driving a browser, use a shorter lock timeout and require confirmation before sensitive fills. A locked extension cannot be manipulated in the same way as an unlocked one, but the agent should still run in a controlled profile with limited access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prevent accidental disclosure

  • Do not put passwords in source code, command history, screenshots, traces, CI annotations or test titles.
  • Do not log process.env, the output of op read, or rendered templates.
  • Use a dedicated test account with minimal permissions and nonproduction data.
  • Keep the browser profile used by CI separate from personal profiles.
  • Rotate the item value in 1Password; the next op run invocation resolves the current value without changing the test source.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is to capture a page after an automated workflow, ScreenshotNeo can return a screenshot or PDF with one GET request. It is separate from the login step: run Playwright or Selenium to authenticate and reach the page, then give ScreenshotNeo a URL that is publicly reachable or otherwise configured for the access method you choose.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

ScreenshotNeo removes cookie-consent banners, newsletter popups and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and each response identifies the page verdict and billing status in headers. It also provides an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

One-call cURL example

See the ScreenshotNeo documentation for request options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan. Create a free ScreenshotNeo account to try it without a card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshooting common failures

Symptom Likely cause Fix
op: command not found The CLI is missing or not on the runner’s PATH. Install the 1Password CLI in the image or job and verify op --version before starting the test.
“unauthorized” or vault access denied The service account is not authorized for the referenced vault, or the CI credential is unavailable. Grant only the required vault access, check the reference spelling and confirm the protected CI variable is present without printing its value.
The variable is empty The environment file was not passed to op run, the reference points to the wrong field, or the child command was placed outside the op run invocation. Run op run --env-file=... -- env only in a safe local diagnostic context, checking variable names rather than values; then correct the file or command boundary.
Login form is not filled The extension is locked, lacks site permission, or the page’s fields changed. For an attended run, unlock the extension and review browser permissions. For CI, remove the extension dependency and fill from environment variables using stable selectors.
Playwright cannot launch in CI Browser binaries or operating-system dependencies are absent or do not match the pinned framework. Install the matching Playwright browsers and dependencies, or use an official container image; rerun installation after framework upgrades.
Tests pass alone but fail in parallel Shared accounts, state or rate limits are not safe for concurrent sessions. Return to one worker, isolate test data, then introduce intentional sharding only after concurrency is proven safe.
A trace or screenshot contains a secret The artifact captured a filled form or authenticated page. Restrict artifact upload, redact or disable sensitive captures, and use a dedicated low-privilege account.

Operational checklist

  • References use op:// paths and no plaintext credential is committed.
  • The automation identity can read only the required vault and items.
  • The browser extension is reserved for supervised runs unless its lifecycle and permissions are deliberately managed.
  • CI installs pinned, matching browser binaries and begins with one worker.
  • Logs, traces, screenshots and videos are treated as potentially sensitive.
  • Lock timeouts and confirmation controls are enabled for AI-assisted or otherwise untrusted browser control.

Frequently Asked Questions

Does op run permanently change my shell environment?

No. It supplies resolved values to the child process you start after --. A later shell command does not automatically retain those values.

Can I use ScreenshotNeo to perform the 1Password login?

No. ScreenshotNeo captures a target URL; it does not replace your browser automation, vault authorization or login flow. Use Playwright or Selenium for authentication, then capture an appropriate page.

What happens after I rotate a password in 1Password?

A subsequent CLI invocation resolves the updated item value, so the test source and its secret references can remain unchanged.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.