# Scrapfly Documentation

## Table of Contents

### Dashboard

- [Intro](https://scrapfly.io/docs)
- [Project](https://scrapfly.io/docs/project)
- [Account](https://scrapfly.io/docs/account)
- [Workspace & Team](https://scrapfly.io/docs/workspace-and-team)
- [Billing](https://scrapfly.io/docs/billing)

### Products

#### MCP Server

- [Getting Started](https://scrapfly.io/docs/mcp/getting-started)
- [Tools & API Spec](https://scrapfly.io/docs/mcp/tools)
- [Authentication](https://scrapfly.io/docs/mcp/authentication)
- [Examples & Use Cases](https://scrapfly.io/docs/mcp/examples)
- [FAQ](https://scrapfly.io/docs/mcp/faq)
##### Integrations

- [Overview](https://scrapfly.io/docs/mcp/integrations)
- [Claude Desktop](https://scrapfly.io/docs/mcp/integrations/claude-desktop)
- [Claude Code](https://scrapfly.io/docs/mcp/integrations/claude-code)
- [ChatGPT](https://scrapfly.io/docs/mcp/integrations/chatgpt)
- [Cursor](https://scrapfly.io/docs/mcp/integrations/cursor)
- [Cline](https://scrapfly.io/docs/mcp/integrations/cline)
- [Windsurf](https://scrapfly.io/docs/mcp/integrations/windsurf)
- [Zed](https://scrapfly.io/docs/mcp/integrations/zed)
- [Roo Code](https://scrapfly.io/docs/mcp/integrations/roo-code)
- [VS Code](https://scrapfly.io/docs/mcp/integrations/vscode)
- [LangChain](https://scrapfly.io/docs/mcp/integrations/langchain)
- [LlamaIndex](https://scrapfly.io/docs/mcp/integrations/llamaindex)
- [CrewAI](https://scrapfly.io/docs/mcp/integrations/crewai)
- [OpenAI](https://scrapfly.io/docs/mcp/integrations/openai)
- [n8n](https://scrapfly.io/docs/mcp/integrations/n8n)
- [Make](https://scrapfly.io/docs/mcp/integrations/make)
- [Zapier](https://scrapfly.io/docs/mcp/integrations/zapier)
- [Vapi AI](https://scrapfly.io/docs/mcp/integrations/vapi)
- [Agent Builder](https://scrapfly.io/docs/mcp/integrations/agent-builder)
- [Custom Client](https://scrapfly.io/docs/mcp/integrations/custom-client)


#### Web Scraping API

- [Getting Started](https://scrapfly.io/docs/scrape-api/getting-started)
- [API Specification]()
- [Monitoring](https://scrapfly.io/docs/monitoring)
- [Customize Request](https://scrapfly.io/docs/scrape-api/custom)
- [Debug](https://scrapfly.io/docs/scrape-api/debug)
- [Unblocker (formerly ASP)](https://scrapfly.io/docs/scrape-api/unblocker)
- [Proxy](https://scrapfly.io/docs/scrape-api/proxy)
- [Proxy Mode](https://scrapfly.io/docs/scrape-api/proxy-mode)
- [Proxy Mode - Screaming Frog](https://scrapfly.io/docs/scrape-api/proxy-mode/screaming-frog)
- [Proxy Mode - Apify](https://scrapfly.io/docs/scrape-api/proxy-mode/apify)
- [(Auto) Data Extraction](https://scrapfly.io/docs/scrape-api/extraction)
- [Javascript Rendering](https://scrapfly.io/docs/scrape-api/javascript-rendering)
- [Javascript Scenario](https://scrapfly.io/docs/scrape-api/javascript-scenario)
- [SSL](https://scrapfly.io/docs/scrape-api/ssl)
- [DNS](https://scrapfly.io/docs/scrape-api/dns)
- [Cache](https://scrapfly.io/docs/scrape-api/cache)
- [Batch (Multi-URL Scraping)](https://scrapfly.io/docs/scrape-api/batch)
- [Session](https://scrapfly.io/docs/scrape-api/session)
- [Webhook](https://scrapfly.io/docs/scrape-api/webhook)
- [Schedule](https://scrapfly.io/docs/scrape-api/schedule)
- [Screenshot](https://scrapfly.io/docs/scrape-api/screenshot)
- [Errors](https://scrapfly.io/docs/scrape-api/errors)
- [Timeout](https://scrapfly.io/docs/scrape-api/understand-timeout)
- [Throttling](https://scrapfly.io/docs/throttling)
- [Troubleshoot](https://scrapfly.io/docs/scrape-api/troubleshoot)
- [Billing](https://scrapfly.io/docs/scrape-api/billing)
- [FAQ](https://scrapfly.io/docs/scrape-api/faq)

#### Crawler API

- [Getting Started](https://scrapfly.io/docs/crawler-api/getting-started)
- [API Specification]()
- [Retrieving Results](https://scrapfly.io/docs/crawler-api/results)
- [WARC Format](https://scrapfly.io/docs/crawler-api/warc-format)
- [Data Extraction](https://scrapfly.io/docs/crawler-api/extraction-rules)
- [Search](https://scrapfly.io/docs/crawler-api/search)
- [Prompt & Extract](https://scrapfly.io/docs/crawler-api/prompt)
- [Auto Refresh](https://scrapfly.io/docs/crawler-api/refresh)
- [Webhook](https://scrapfly.io/docs/crawler-api/webhook)
- [Schedule](https://scrapfly.io/docs/crawler-api/schedule)
- [Billing](https://scrapfly.io/docs/crawler-api/billing)
- [Errors](https://scrapfly.io/docs/crawler-api/errors)
- [Troubleshoot](https://scrapfly.io/docs/crawler-api/troubleshoot)
- [FAQ](https://scrapfly.io/docs/crawler-api/faq)

#### Screenshot API

- [Getting Started](https://scrapfly.io/docs/screenshot-api/getting-started)
- [API Specification]()
- [Accessibility Testing](https://scrapfly.io/docs/screenshot-api/accessibility)
- [Webhook](https://scrapfly.io/docs/screenshot-api/webhook)
- [Schedule](https://scrapfly.io/docs/screenshot-api/schedule)
- [Billing](https://scrapfly.io/docs/screenshot-api/billing)
- [Errors](https://scrapfly.io/docs/screenshot-api/errors)

#### Extraction API

- [Getting Started](https://scrapfly.io/docs/extraction-api/getting-started)
- [API Specification]()
- [Rules Template](https://scrapfly.io/docs/extraction-api/rules-and-template)
- [LLM Extraction](https://scrapfly.io/docs/extraction-api/llm-prompt)
- [AI Auto Extraction](https://scrapfly.io/docs/extraction-api/automatic-ai)
- [Webhook](https://scrapfly.io/docs/extraction-api/webhook)
- [Billing](https://scrapfly.io/docs/extraction-api/billing)
- [Errors](https://scrapfly.io/docs/extraction-api/errors)
- [FAQ](https://scrapfly.io/docs/extraction-api/faq)

#### Data API


#### Proxy Saver

- [Getting Started](https://scrapfly.io/docs/proxy-saver/getting-started)
- [Fingerprints](https://scrapfly.io/docs/proxy-saver/fingerprints)
- [Optimizations](https://scrapfly.io/docs/proxy-saver/optimizations)
- [SSL Certificates](https://scrapfly.io/docs/proxy-saver/certificates)
- [Protocols](https://scrapfly.io/docs/proxy-saver/protocols)
- [Pacfile](https://scrapfly.io/docs/proxy-saver/pacfile)
- [Secure Credentials](https://scrapfly.io/docs/proxy-saver/security)
- [Billing](https://scrapfly.io/docs/proxy-saver/billing)

#### Cloud Browser API

- [Getting Started](https://scrapfly.io/docs/cloud-browser-api/getting-started)
- [Proxy & Geo-Targeting](https://scrapfly.io/docs/cloud-browser-api/proxy)
- [Unblock API](https://scrapfly.io/docs/cloud-browser-api/unblock)
- [Captcha Solver](https://scrapfly.io/docs/cloud-browser-api/captcha-solver)
- [File Downloads](https://scrapfly.io/docs/cloud-browser-api/file-downloads)
- [Session Resume](https://scrapfly.io/docs/cloud-browser-api/session-resume)
- [Human-in-the-Loop](https://scrapfly.io/docs/cloud-browser-api/human-in-the-loop)
- [Debug Mode](https://scrapfly.io/docs/cloud-browser-api/debug-mode)
- [Browser Extensions](https://scrapfly.io/docs/cloud-browser-api/extensions)
- [Native Browser MCP](https://scrapfly.io/docs/cloud-browser-api/mcp)
- [DevTools Protocol](https://scrapfly.io/docs/cloud-browser-api/cdp-reference)
##### Integrations

- [Puppeteer](https://scrapfly.io/docs/cloud-browser-api/puppeteer)
- [Playwright](https://scrapfly.io/docs/cloud-browser-api/playwright)
- [Selenium](https://scrapfly.io/docs/cloud-browser-api/selenium)
- [Vercel Agent Browser](https://scrapfly.io/docs/cloud-browser-api/agent-browser)
- [Browser Use](https://scrapfly.io/docs/cloud-browser-api/browser-use)
- [Stagehand](https://scrapfly.io/docs/cloud-browser-api/stagehand)

- [Billing](https://scrapfly.io/docs/cloud-browser-api/billing)
- [Errors](https://scrapfly.io/docs/cloud-browser-api/errors)


### Tools

- [Antibot Detector](https://scrapfly.io/docs/tools/antibot-detector)

### SDK

- [Golang](https://scrapfly.io/docs/sdk/golang)
- [Python](https://scrapfly.io/docs/sdk/python)
- [Rust](https://scrapfly.io/docs/sdk/rust)
- [TypeScript](https://scrapfly.io/docs/sdk/typescript)
- [Scrapy](https://scrapfly.io/docs/sdk/scrapy)

### Integrations

- [Getting Started](https://scrapfly.io/docs/integration/getting-started)
- [LangChain](https://scrapfly.io/docs/integration/langchain)
- [LlamaIndex](https://scrapfly.io/docs/integration/llamaindex)
- [CrewAI](https://scrapfly.io/docs/integration/crewai)
- [Zapier](https://scrapfly.io/docs/integration/zapier)
- [Make](https://scrapfly.io/docs/integration/make)
- [n8n](https://scrapfly.io/docs/integration/n8n)

### Academy

- [Overview](https://scrapfly.io/academy)
- [Web Scraping Overview](https://scrapfly.io/academy/scraping-overview)
- [Tools](https://scrapfly.io/academy/tools-overview)
- [Reverse Engineering](https://scrapfly.io/academy/reverse-engineering)
- [Static Scraping](https://scrapfly.io/academy/static-scraping)
- [HTML Parsing](https://scrapfly.io/academy/html-parsing)
- [Dynamic Scraping](https://scrapfly.io/academy/dynamic-scraping)
- [Hidden API Scraping](https://scrapfly.io/academy/hidden-api-scraping)
- [Headless Browsers](https://scrapfly.io/academy/headless-browsers)
- [Hidden Web Data](https://scrapfly.io/academy/hidden-web-data)
- [JSON Parsing](https://scrapfly.io/academy/json-parsing)
- [Data Processing](https://scrapfly.io/academy/data-processing)
- [Scaling](https://scrapfly.io/academy/scaling)
- [Walkthrough Summary](https://scrapfly.io/academy/walkthrough-summary)
- [Scraper Blocking](https://scrapfly.io/academy/scraper-blocking)
- [Proxies](https://scrapfly.io/academy/proxies)

---

# 1Password Integration

 Browser automation that logs in somewhere needs a password at runtime, and pasting that password into a script or an environment variable puts it wherever the script runs, wherever its logs go, and in the hands of anyone who can read the repo. Scrapfly's 1Password integration removes that step. A Cloud Browser [credential vault](https://scrapfly.io/docs/cloud-browser-api/credential-vault) mirrors items from a 1Password service account, seals them under a key only you hold, and fills them into headless Chrome server-side the moment your session opens a page. Your code passes a vault name and a key on the connection URL. It never sees the password itself.

 **Rolling out gradually.** The credential vault, and this 1Password link, are enabling progressively across accounts. If [Vault](https://scrapfly.io/dashboard/cloud-browser/vault) is not in your dashboard sidebar yet, reach out to your account manager or [contact us](https://scrapfly.io/contact) to request access. The rest of this page describes what the integration does and how it works so you can evaluate it ahead of time.

## Prerequisites

- A Scrapfly account with an API key.
- A [1Password service account](https://developer.1password.com/docs/service-accounts/) token, scoped to **read access on one vault**. Create a vault in 1Password dedicated to what Scrapfly automation needs to log into, rather than pointing the token at a vault that also holds unrelated personal or team items: everything the token can read in that vault is a candidate to mirror.
- An understanding of the vault key model: a Cloud Browser vault is end-to-end encrypted under a 32-byte key that only you hold. Scrapfly generates it once, hands it to you, and never stores it. See [Security model](#security-model) below.

 A 1Password service account can never see a **Personal**, **Private**, or **Employee** vault, whatever access it is granted in 1Password's own permission screen. Those vault types are excluded from service-account visibility by 1Password itself. Point the token at a shared vault you created for this purpose.

## How It Works End to End

 Four things happen, in order, and each one changes who can read the secret.

1. **Link.** You paste the 1Password service-account token into a Cloud Browser vault. Scrapfly seals it as a reserved item inside that vault, under the same 32-byte customer-held key that protects every other item you add by hand. The token is never written anywhere in plaintext once this step completes.
2. **Mirror.** On a sync pass, Scrapfly opens the sealed token (which requires your vault key), calls 1Password's API for the vault you selected, and maps each supported item (Login, Password, API Credentials, Secure Note) onto a vault item shape. The mapped plaintext exists only in the Go process's memory for the length of that one pass.
3. **Seal.** Each mapped item is sealed under your vault's key and written to storage, the same encrypted-at-rest path every manually entered vault item goes through. Nothing from the mapping step is logged or persisted unsealed.
4. **Inject.** When a Cloud Browser session opens with `vault` and `vault_key` on the connection URL, Scrapfly decrypts every item transiently and pushes it into the browser over Scrapium's internal `PasswordManager` CDP domain, on your script's first page attach. Passwords land in Chromium's real password store; a form fills the way it would in your own browser. The plaintext travels from the vault to the browser process and nowhere else. See [Leak prevention](https://scrapfly.io/docs/cloud-browser-api/credential-vault#leak-prevention) for what is scrubbed out of screenshots, DOM dumps, and CDP responses afterward.

 | Where the secret is | Who can read it |
|---|---|
| 1Password service-account token, at rest | Nobody. It is ciphertext in Scrapfly's database, sealed under your vault key. |
| Mirrored item (password, TOTP seed, blob), at rest | Nobody. Same sealed storage as a manually entered item. |
| Plaintext during a sync pass | Held only in server memory for the duration of one 1Password fetch and reseal. Not written to disk or to any log line. |
| Plaintext during a session | The Scrapium browser process, and the login form on the page you navigated to. Your script's CDP connection does not see it; see [Leak prevention](https://scrapfly.io/docs/cloud-browser-api/credential-vault#leak-prevention). |

## Set Up 1Password in the Dashboard

 Open a vault's [detail page](https://scrapfly.io/dashboard/cloud-browser/vault) and click **Connect 1Password**. If you have not created a vault yet, the same page creates one; see [Create a vault and fill it](https://scrapfly.io/docs/cloud-browser-api/credential-vault#create-and-fill) for that first step.

1. **Paste the service-account token.** Scrapfly tests it against 1Password immediately and lists the vaults it can see, so a bad or over-scoped token is caught before anything is saved.
2. **Pick the upstream vault.** Choose which 1Password vault to mirror from. Only vaults the token has read access to appear here.
3. **Set an optional title filter and tag filter.** A title filter (glob) and a tag filter narrow which items are mirrored, so a token scoped to a broader vault than you would like can still be limited to the items your automation actually needs.
4. **Choose a sync mode.** `on_session` (the default) refreshes the mirror right before a Cloud Browser session opens against it; `manual` only refreshes when you click **Sync now**. See [Keeping it in sync](#keeping-in-sync).
5. **Connect.** The first sync runs immediately, using whichever mode you picked. The vault's card then shows the linked provider, the mirrored item count, and buttons for **Sync now**, **Test connection**, **Rotate token**, and **Unlink**.

## What Gets Mirrored, and What Does Not

 Four 1Password item categories map onto vault items. Everything else is skipped and counted in the sync report, never dropped without a reason.

 | 1Password category | Becomes |
|---|---|
| Login, Password | One `password` vault item per website on the entry (up to 10), plus one `totp` item per one-time-password field on it (up to 5). |
| API Credentials | One `blob` item holding the credential field. |
| Secure Note | One `blob` item holding the note body. |
| Everything else (SSH keys, documents, credit cards, identities, and any category 1Password adds in the future) | Skipped, reported as `category_unsupported`. |

 **Passkeys never mirror.** A 1Password service account is not given passkey material by 1Password itself, whatever access the token is granted, so a passkey field on a Login item is always skipped. If your login flow depends on a passkey, enroll it directly in a Cloud Browser vault with a virtual authenticator instead; see the [passkey item type](https://scrapfly.io/docs/cloud-browser-api/credential-vault#create-and-fill).

 One 1Password Login item fans out into several vault items: a `password` row for every distinct website on it, and a `totp` row for every one-time-password field. A login with three saved URLs and a TOTP field becomes four mirrored items from one 1Password entry, each counted separately against the per-vault item cap in [Limits](#limits).

## Use 1Password Credentials in a Cloud Browser Session

 A linked vault is used exactly the way a manually filled vault is: pass `vault` (the vault's name) and `vault_key` (the base64-encoded key you saved at vault creation) on the Cloud Browser WebSocket URL. Scrapfly resolves the name, refreshes the 1Password mirror if the sync window has elapsed, decrypts every item, and pushes it into the browser on your script's first page attach. A run that never attaches to a page, one that only talks to the CDP `Target` domain, gets nothing injected.

 | Parameter | Value |
|---|---|
| `vault` | The vault's name (not its id). |
| `vault_key` | Base64-encoded 32-byte key, the same value the SDKs' `vault_key` field and the CLI's `--vault-key` flag take. |

Build the connection in your preferred language, or with the raw WebSocket URL:

   Raw WebSocket URL   Python SDK   TypeScript SDK   Go SDK   Rust SDK

  ```
wss://browser.scrapfly.io/?key=$SCRAPFLY_API_KEY&vault=$VAULT_NAME&vault_key=$VAULT_KEY&proxy_pool=public_residential_pool
```

 ```
from scrapfly import ScrapflyClient, BrowserConfig

client = ScrapflyClient(key="{{ YOUR_API_KEY }}")
config = BrowserConfig(vault="$VAULT_NAME", vault_key="$VAULT_KEY")
ws_url = client.cloud_browser(config)
```

 ```
import { ScrapflyClient, BrowserConfig } from "scrapfly-sdk";

const client = new ScrapflyClient({ key: "{{ YOUR_API_KEY }}" });
const config = new BrowserConfig({ vault: "$VAULT_NAME", vault_key: "$VAULT_KEY" });
const wsUrl = client.cloudBrowser(config);
```

 ```
cfg := &scrapfly.CloudBrowserConfig{
    Vault:    "$VAULT_NAME",
    VaultKey: "$VAULT_KEY",
}
wsURL := client.CloudBrowser(cfg)
```

 ```
let config = BrowserConfig {
    vault: Some("$VAULT_NAME".into()),
    vault_key: Some("$VAULT_KEY".into()),
    ..Default::default()
};
let ws_url = client.cloud_browser_url(&config);
```

 Playwright and Puppeteer connect the same way, over CDP, with Scrapium autofilling the credential the moment your script attaches to a page:

   Playwright (Python)   Puppeteer (Node)

  ```
import asyncio, os
from playwright.async_api import async_playwright

async def main():
    ws = (
        "wss://browser.scrapfly.io/"
        f"?key={os.environ['SCRAPFLY_API_KEY']}"
        f"&vault={os.environ['VAULT_NAME']}"
        f"&vault_key={os.environ['VAULT_KEY']}"
    )
    async with async_playwright() as p:
        browser = await p.chromium.connect_over_cdp(ws)
        page = browser.contexts[0].pages[0] if browser.contexts[0].pages else await browser.contexts[0].new_page()
        await page.goto("https://web-scraping.dev/password-manager-test")
        await page.click("#pm-username-input")
        await page.click("#pm-password-input")
        await page.click("button[type=\"submit\"]")
        await browser.close()

asyncio.run(main())
```

 ```
const puppeteer = require("puppeteer-core");

const BROWSER_WS = `wss://browser.scrapfly.io?key=${process.env.SCRAPFLY_API_KEY}&vault=${process.env.VAULT_NAME}&vault_key=${process.env.VAULT_KEY}`;

(async () => {
    const browser = await puppeteer.connect({ browserWSEndpoint: BROWSER_WS });
    const [page] = await browser.pages();
    await page.goto("https://web-scraping.dev/password-manager-test");
    await browser.close();
})();
```

 **Selenium CDP** and **Scrapy** take the same two parameters the same way: Selenium has no native CDP WebSocket connect, so the [Selenium integration doc](https://scrapfly.io/docs/cloud-browser-api/selenium) uses Playwright as the CDP transport underneath it; Scrapy reuses the Python SDK's `BrowserConfig`. Every other CDP client (a raw `websockets` connection, a language without a Scrapfly SDK) works the same way: it is a query-string parameter, not an API call.

Scrapfly CLI:

 ```
scrapfly browser --vault "$VAULT_NAME" --vault-key "$VAULT_KEY" --proxy-pool public_residential_pool
```

## Keeping It in Sync

 | Mode | When it syncs |
|---|---|
| `on_session` (default) | Refreshes right before a Cloud Browser session opens against the vault, if the sync TTL has elapsed since the last sync. The TTL defaults to 15 minutes and can be set between 1 minute and 24 hours. The refresh is best-effort and non-blocking: if the fetch slot is busy with another vault's sync, the session opens on the existing mirror rather than waiting. |
| `manual` | Never syncs on its own. Only **Sync now** in the dashboard, or the sync REST endpoint, refreshes it. |

 A sync that fails with an auth, rate-limit, or scope error backs off for one hour before Scrapfly retries on its own, so a dead token is not retried on every session. **Sync now** skips that back-off, since clicking it is the retry. **Test connection** checks the stored token against 1Password without touching any item. **Rotate token** replaces the stored service-account token and requires your vault key, since the new token is sealed under it.

 **Unlink** removes the connection. The **keep mirrored items as manual credentials** checkbox is on by default: leave it checked and the mirrored items stay in the vault as ordinary manual items you can edit again. Uncheck it and every mirrored item is deleted with the link. Either way, the sealed service-account token itself is always deleted; it never lingers after an unlink.

 A mirrored item cannot be edited or deleted directly through the vault API or dashboard. A `PATCH` or `DELETE` against one is refused with `409 Conflict`; edit the item at the source in 1Password and let the next sync pick it up, or unlink first.

## Limits

 | Limit | Value |
|---|---|
| Items considered per sync pass | 1000 |
| Mirrored items per vault | 200 |
| Websites per Login/Password item | 10 |
| TOTP fields per Login/Password item | 5 |
| Size per blob (API Credential or Secure Note mirror) | 64 KiB |
| Total blob bytes per sync pass | 4 MiB |
| Mirrored item label length | 64 characters |
| Mirrored item origin length | 255 characters |
| Sync TTL range (`on_session`) | 1 minute to 24 hours |

 An item that would push a vault past the mirrored-item cap or a pass past the blob-byte budget is skipped for that pass and reported, the same as an unsupported category; it is picked up on a later sync once room frees up.

 Scrapfly also serializes every call into the 1Password SDK to one at a time, fleet-wide per pod, because the SDK itself is single-threaded. A busy slot never delays your session: the session-path refresh is non-blocking and falls back to the existing mirror. It does mean sync intervals are worth setting with your own 1Password service-account request budget in mind. 1Password enforces its own per-service-account daily request ceiling, shared across every integration using that token; a short TTL on many vaults sharing one token is what triggers `ERR::BROWSER::VAULT_PROVIDER_RATE_LIMITED`.

## Troubleshooting: Errors and Skipped Items

 Two error codes come from a Cloud Browser session that references a vault. Four more come only from the linked-service REST endpoints (link, update, sync, test), never from a session: a 1Password outage or a dead token degrades the mirror to its last successful sync, it does not fail your browser allocation.

 | Error code | HTTP | Where it happens | What it means |
|---|---|---|---|
| [`VAULT_NOT_FOUND`](https://scrapfly.io/docs/cloud-browser-api/error/ERR::BROWSER::VAULT_NOT_FOUND) | 404 | Session open | The vault does not exist for this user, project, or environment. Most common cause: a `LIVE` vault used in a `TEST` session, or the reverse. |
| [`VAULT_KEY_INVALID`](https://scrapfly.io/docs/cloud-browser-api/error/ERR::BROWSER::VAULT_KEY_INVALID) | 400 | Session open | The `vault_key` is missing, malformed, or does not match the key the vault was sealed with. Checked before the browser is allocated, so a wrong key never costs you a session. |
| [`VAULT_PROVIDER_AUTH_FAILED`](https://scrapfly.io/docs/cloud-browser-api/error/ERR::BROWSER::VAULT_PROVIDER_AUTH_FAILED) | 401 | Link, sync, or test endpoint | 1Password rejected the stored service-account token. Rotate the token on the vault. |
| [`VAULT_PROVIDER_RATE_LIMITED`](https://scrapfly.io/docs/cloud-browser-api/error/ERR::BROWSER::VAULT_PROVIDER_RATE_LIMITED) | 429 | Link, sync, or test endpoint | 1Password rate-limited the service account. Its daily request budget is shared by every integration using that token. |
| [`VAULT_PROVIDER_UNAVAILABLE`](https://scrapfly.io/docs/cloud-browser-api/error/ERR::BROWSER::VAULT_PROVIDER_UNAVAILABLE) | 503 | Link, sync, or test endpoint | 1Password could not be reached. The vault keeps serving its last successful mirror. |
| [`VAULT_PROVIDER_SCOPE`](https://scrapfly.io/docs/cloud-browser-api/error/ERR::BROWSER::VAULT_PROVIDER_SCOPE) | 403 | Link, sync, or test endpoint | The service-account token cannot see the requested 1Password vault. Personal, Private, and Employee vaults are never reachable by a service account, whatever permissions it has. |

### Why one item did not mirror

 A sync pass never drops an upstream item silently. Every item it does not mirror is counted and reported with one of these reasons:

 | Reason | Cause |
|---|---|
| `category_unsupported` | Not a Login, Password, API Credentials, or Secure Note item. |
| `no_password` / `no_website` | A Login or Password item has no password value, or none of its websites are usable. |
| `website_autofill_never` | You marked that website "never autofill" in 1Password. |
| `website_invalid` / `website_scheme_unsupported` | The stored URL does not parse, or is not `http`/`https` (for example a mobile-app `android://` entry). |
| `website_fanout_capped` | More than 10 websites on one item; the rest are dropped for that item. |
| `totp_fanout_capped` | More than 5 one-time-password fields on one item. |
| `totp_unparseable` / `totp_algorithm_unsupported` / `totp_digits_out_of_range` / `totp_period_out_of_range` | The stored TOTP seed or its parameters do not fit RFC 6238. |
| `no_secret_field` / `field_type_unsupported` | An API Credentials item has no usable concealed field. |
| `note_empty` | A Secure Note item has no body. |
| `blob_too_large` | An API Credential or Secure Note body is over 64 KiB. |
| `item_cap_exceeded` | The vault already holds 200 mirrored items. |
| `blob_budget_exceeded` | This pass already sealed 4 MiB of blob data. |
| `label_collision` | The generated label matches a label already used by a manually entered item in the same vault. The manual item wins; the mirrored candidate is skipped, not renamed. |
| `username_too_long` / `source_ref_too_long` | An upstream value is longer than the vault's column limits. |

 Passkeys are not in this table because they are never fetched at all: 1Password does not hand passkey material to a service account, so there is nothing for the sync pass to see or skip.

## Security Model

- **Scrapfly cannot read a vault without your key.** Every item, including the 1Password token itself, is sealed under the 32-byte key you were given when the vault was created. Scrapfly's database holds ciphertext.
- **The vault key is yours alone, and it cannot be recovered.** Scrapfly never stores it. If it is lost, every item in that vault, including the linked 1Password token, becomes permanently unreadable. There is no support-ticket recovery path.
- **Mirrored items are read-only.** A `PATCH` or `DELETE` against a mirrored item is refused with `409 Conflict`. The source of truth stays in 1Password.
- **Credential material is kept out of your CDP stream.** Once a vault-filled field is submitted, its value is redacted from `Page.captureScreenshot`, video, the live VNC view, `DOM.getOuterHTML`, `Accessibility.getFullAXTree`, and `Runtime.evaluate` results, for the rest of the session. Full detail is on the [Credential Vault leak-prevention page](https://scrapfly.io/docs/cloud-browser-api/credential-vault#leak-prevention).
- **The 1Password token can be revoked without touching your vault.** Revoke or expire it in 1Password at any time; the next sync surfaces `VAULT_PROVIDER_AUTH_FAILED` and the mirror simply stops refreshing until you rotate it.

## FAQ

#####   Can I use my existing 1Password service account, or do I need a new one?

 Either works, as long as the token has read access to a vault scoped to what your automation needs. Because everything readable in that vault is a mirror candidate, a token already used for other automation against a broad vault will mirror more than you may want; a title or tag filter narrows that, or a dedicated vault avoids the question entirely.

#####   Does this work with headless Chrome, or only a visible browser?

 Cloud Browser sessions run headless by default. Injection happens over the CDP `PasswordManager` domain regardless of whether a human is watching over VNC; the worked example above drives a fully headless Playwright session.

#####   Can my script read the plaintext password back out?

 No, for a mirrored `password` or `totp` item. It fills the form and is redacted from every CDP response your script can request afterward. A mirrored `blob` item (an API Credentials or Secure Note mirror) is the exception: it is never injected into the browser and is meant to be read back through the vault item REST endpoint, since there is no form field for it to fill.

#####   Can I mix manually entered items and 1Password-mirrored items in one vault?

 Yes. A single vault can hold manual items alongside items mirrored from a linked 1Password vault; both inject into the same session the same way. What a vault cannot do is link to a second 1Password vault at once, or link at all while it still holds items owned by a different provider from an earlier link.

#####   What happens to running sessions if I rotate or revoke the 1Password token?

 Nothing, immediately. A session already open has already had its credentials injected; revoking the upstream token only affects the next sync pass. Rotating the token in the dashboard requires your vault key, since the new token is sealed under it, and clears any auth back-off so the next sync tries again right away.

#####   Does Scrapfly support other secret managers besides 1Password?

 1Password is the only linked secret manager today. A vault also accepts items entered directly through the dashboard or the REST API, independent of any provider link; see [Create a vault and fill it](https://scrapfly.io/docs/cloud-browser-api/credential-vault#create-and-fill).

## Next Steps

 [  **Credential Vault** - item types, the PasswordManager CDP domain, and the full leak-prevention model  ](https://scrapfly.io/docs/cloud-browser-api/credential-vault) [  **RPA Vault** - reference a vault item by label from a Workflow or an AI Agent, including mirrored 1Password items  ](https://scrapfly.io/docs/rpa/vault) [  **Cloud Browser Getting Started** - connect Playwright, Puppeteer, or Selenium to a remote browser session  ](https://scrapfly.io/docs/cloud-browser-api/getting-started)
