Linking 1Password as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The 1Password connector syncs sign in attempts, item usages, audit events, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Pull your 1Password security event streams - sign-in attempts, item usages, and audit events - .
This uses the 1Password Events API, which requires a 1Password Business or Enterprise plan. Create an Events Reporting integration in your 1Password admin console and issue a bearer token with the event types you want to sync:
- Sign-in attempts
- Item usages
- Audit events
Select the region where your 1Password account is hosted - the Events API is served from a region-specific address.
You'll be asked for:
- Account region: choose between 1Password.com (events.1password.com), 1Password.ca (events.1password.ca), 1Password.eu (events.1password.eu) and 1Password Enterprise (events.ent.1password.com).
- Events Reporting token: for example
eyJhbGciOiJFUzI1NiIsIm....
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All 1Password tables are full refresh. Each sync replaces the contents of the table.
Configuration
| Option | Type | Required |
|---|---|---|
Account region | select | Yes |
Events Reporting token | password | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
sign_in_attempts | Attempts to sign in to a 1Password account: who attempted to sign in, from which client and IP address, when the attempt was made, and — for failed attempts — the cause of the failure. | Incremental, Full refresh | timestamp | — |
item_usages | Usage of items in shared vaults: which item was modified, accessed, or used, by whom, from which client and IP address, and the vault where the item is stored. | Incremental, Full refresh | timestamp | — |
audit_events | Administrative actions performed by team members within a 1Password account: when an action was performed and by whom, along with the type and object of the action. | Incremental, Full refresh | timestamp | — |
Troubleshooting
- If the connection fails with an authorization error, the events Reporting token is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.