> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect or rotate a password-manager integration

> Connect a password-manager integration (currently 1Password) by
providing a service account token, or rotate the token of an existing
integration. The token is validated (by listing the vaults it can
access) and then stored encrypted in the user's secret manager. During
browser automation logins the agent uses it to look up credentials and
2FA codes by domain; credential values are only exposed to the browser
as redacted secret references.




## OpenAPI

````yaml https://neo.api.projectdiscovery.io/api/openapi.json post /api/v1/browser/credential-provider
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
  - description: >-
      Application-internal endpoints used by the Neo UI. Not part of the public
      customer API surface.
    name: Internal
paths:
  /api/v1/browser/credential-provider:
    post:
      tags:
        - Browser
      summary: Connect or rotate a password-manager integration
      description: |
        Connect a password-manager integration (currently 1Password) by
        providing a service account token, or rotate the token of an existing
        integration. The token is validated (by listing the vaults it can
        access) and then stored encrypted in the user's secret manager. During
        browser automation logins the agent uses it to look up credentials and
        2FA codes by domain; credential values are only exposed to the browser
        as redacted secret references.
      operationId: post-v1-browser-credential-provider
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConnectBrowserCredentialProviderRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BrowserCredentialProviderStatus'
          description: The connected integration status
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Bad request - token missing/invalid, or integration unavailable on
            this plan
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized - valid authentication required
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Internal server error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    ConnectBrowserCredentialProviderRequest:
      properties:
        provider_type:
          description: The kind of password manager to connect. Defaults to onepassword.
          enum:
            - onepassword
          type: string
        token:
          description: |
            Password-manager service account token (e.g. a 1Password service
            account token, `ops_...`). Validated on connect and stored
            encrypted in the user's secret manager; never returned.
          type: string
      required:
        - token
      type: object
    BrowserCredentialProviderStatus:
      properties:
        connected:
          description: Whether a password-manager integration is connected.
          type: boolean
        provider_type:
          description: The kind of password manager connected.
          enum:
            - onepassword
          type: string
        vaults:
          description: |
            Names of the vaults accessible with the connected token (display
            only). Only populated on connect, when the token was just validated.
          items:
            type: string
          type: array
      required:
        - connected
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
      required:
        - error
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````