> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cantina.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# 1Password

> Connect 1Password to Clarion to monitor audit events, sign-in attempts, and item usage events from your 1Password Business account.

This guide walks you through connecting your 1Password Business account to Clarion via the 1Password Events Reporting API. Once connected, Clarion polls 1Password every minute for audit events, sign-in attempts, and item usage events, and uses them to detect suspicious activity and create alerts.

> **Estimated time:** 5 minutes. You will need **1Password Business** with permission to set up Events Reporting integrations.

## Prerequisites

* A **1Password Business** account with access to **Integrations → Directory**
* A **Clarion workspace** with the 1Password integration page open
* A secure place to store the bearer token generated in 1Password

***

## Step 1 - Create a bearer token in 1Password

1. Sign in to your [1Password account](https://start.1password.com/).
2. Go to **Integrations** → **Directory**.
3. Under **Events Reporting**, click **Other** and set up a new integration.
4. Select the event types to report:
   * Audit events
   * Sign-in attempts
   * Item usage events
5. Copy the generated **bearer token**.

> Copy the bearer token immediately - it will only be shown once. Store it securely.

***

## Step 2 - Enter the bearer token in Clarion

1. In Clarion, open **Integrations** → **1Password**.
2. Paste the **Bearer Token** from 1Password.
3. Click **Connect**.

Clarion validates the token and begins polling the Events Reporting API for new events every minute.

***

## What happens next

Once connected, Clarion will:

* Poll 1Password every minute for audit events, sign-in attempts, and item usage events
* Create alerts from suspicious activity based on your configured alert filters
* Use 1Password event data to enrich investigations and triage

You can manage which events create alerts from the **Alert Filters** section on the 1Password integration page.

***

## Update or rotate the bearer token

To replace the bearer token (for example, after rotating it in 1Password):

1. Generate a new bearer token in 1Password under **Integrations → Directory → Events Reporting**.
2. In Clarion, open **Integrations** → **1Password**.
3. Paste the new token into **Update Bearer Token** and click **Update Token**.

***

## Troubleshooting

### The connection fails or events stop arriving

* Confirm the bearer token was generated for the correct 1Password account and has not been revoked
* Verify the integration in 1Password still includes audit events, sign-in attempts, and item usage events
* Use **Sync now** on the 1Password integration page in Clarion to trigger an immediate poll
