↳ GitHub sourceConnector

1Password (Serverless)

Description

The 1Password CCP connector allows the user to ingest 1Password Audit, Signin & ItemUsage events into Microsoft Sentinel.
Declared author / publisher
[variables('_solutionPublisher')]

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
1Password API token
A 1Password API Token is required. See the [1Password documentation](https://support.1password.com/events-reporting/#appendix-issue-or-revoke-bearer-tokens) on how to create an API token.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

STEP 1 - Create a 1Password API token:
Follow the [1Password documentation](https://support.1password.com/events-reporting/#appendix-issue-or-revoke-bearer-tokens) for guidance on this step.
STEP 2 - Choose the correct base URL:
There are multiple 1Password servers which might host your events. The correct server depends on your license and region. Follow the [1Password documentation](https://developer.1password.com/docs/events-api/reference/#servers) to choose the correct server. Input the base URL as displayed by the documentation (including 'https://' and without a trailing '/').
STEP 3 - Enter your 1Password Details:
Enter the 1Password base URL & API Token below:
Base Url
API Token

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
[variables('_dataConnectorContentIdConnectorDefinition')]
Additional source files 1Solutions/1Password/Data Connectors/1Password_ccpv2/azuredeploy_1Password_poller_connector.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.