Is there a standard 1Password can use/define to interoperate with websites?
Maybe this has been asked already, but is there a guide that 1Password publishes for how to be fully interoperable with 1Password? It would seem that simply using a field called username/password would suffice, but it would be nice to have a guide on best practices, perhaps by enumerating a list of common names that would be detected by 1Password.
While this may not be super helpful by itself, I think there could be some value in extending this "standard" of sorts to more password-related functionality. For example, the ability to reset passwords. 1Password could standardize a /.well-known/passwords.txt
-like file that contains metadata about the site. It could list a specific page that can be used to reset your password. 1Password can access this well-known endpoint to retrieve the page, and then display this page to the user if they would like to reset their password. The URL of the login page could similarly be retrieved.
This standard could also include password-restriction filters. For example, the password must have a special character. 1Password could use this to generate a password that would already be compatible with the site.
For password resets, this could lead into some functionality such that you could hit a button and 1Password could automatically go through and reset all of your passwords for you. This would enable healthy key rotation.
And as sites adopt it, it could enable transition to more secure methods of authentication. Such as automatically detecting your login in 1Password, rather than needing to go through a login form at all!
1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Comments
-
Hi @chris13524:
This is some very great feedback, and I'm happy to share that 1Password in the browser already does a lot of what you're asking for!
We have a guide on best practices on how to design your website to work well with 1Password: Design your website to work best with 1Password
1Password in the browser is also aware of
.well-known/change-password
, and uses that to determine what page to change a Login's password on: A Well-Known URL for Changing PasswordsThe Smart Password Generator in 1Password in the browser is also able to detect password rules on websites. It has two sources for that: a password rules repository created by our friends at Apple, apple/password-manager-resources, as well as checking the
passwordrules
attribute directly on a password field.As for what the future might hold, this might be interesting. 😁 A vision of the future with 1Password
Jack
0 -
Wow! I'm blown away. Looking forward to the future with 1Password!
0 -
I'm looking forward to it just as much as you are @chris13524! Stay tuned! 😁
Jack
0