For everyday browsing, 1Password can fill a saved Login item when you choose its prompt or use Open & Fill; it can submit the form automatically unless you turn that option off. For repeatable, authorized browser tests, Playwright can sign in during setup, save browser storage state, and load that state in later tests. These are separate workflows: the available documentation does not establish a supported direct connection that lets Playwright retrieve credentials from 1Password.
Choose the right approach for the job
| Approach | Best for | How sign-in works | Tradeoff |
|---|---|---|---|
| 1Password browser extension | A person signing in while browsing | You select a matching Login item; form submission can be disabled. | The site may need additional steps, and you should verify the domain before filling or submitting. |
| Playwright saved storage state | Repeated authorized browser tests | A setup test signs in once; later browser contexts load the saved state. | The state is sensitive and sessions can expire, so protect and refresh it. |
Neither approach guarantees an unattended login on every site. Multi-factor authentication, passkeys, CAPTCHA, and site-specific access controls may require human action or make automation unsuitable.
Use the 1Password extension for interactive sign-in
- Install the 1Password extension in a supported browser and sign in to the extension.
- In 1Password, check that the relevant Login item has the correct website address. 1Password uses the saved URL to match a login to a site. See 1Password Autofill.
- Open the website’s sign-in page and check that its domain is the one you intended to visit.
- Select the 1Password sign-in prompt and choose the Login item. Alternatively, open the extension and choose the saved login. With Open & Fill, 1Password opens the saved site and fills the matching login. See 1Password’s browser extension instructions.
- Confirm the page and sign-in result. 1Password says the extension signs in after the chosen Login is filled, but unusual or multi-step forms may behave differently.
Control automatic form submission
1Password submits filled forms by default. If you would rather inspect the form and submit it yourself, open the extension’s Autofill & save settings and disable automatic form submission. The precise interface may vary by browser or extension version; consult the current extension instructions if the label or location differs.
Autofill is user-triggered, not a silent sign-in process. 1Password states, “1Password will never Autofill without your input, even when there’s only one suggested item available.” Its security guidance also warns that deceptive pages can try to trick people into interacting with Autofill. Check the address bar and be deliberate about what you select; see 1Password’s browser Autofill security guidance.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Reuse a signed-in session in Playwright
For a site you are authorized to test, Playwright’s documented pattern is to authenticate in a setup project, write browser storage state to a file, and configure subsequent tests to load it. This avoids repeating the login steps for each test. The example below follows Playwright’s TypeScript test-runner pattern; adapt the sign-in URL, selectors, and success check to your application. Keep credentials outside the source file.
1. Store credentials outside the test code
For a local example, set environment variables in the shell before running tests. Playwright documents environment variables as one way to pass values from outside test source code; they are not a complete secret-management solution. Use your team’s approved secret-management approach in shared or production environments. See Playwright’s parameterization documentation.
export TEST_USERNAME='your-test-account'
export TEST_PASSWORD='your-test-password'
PowerShell equivalent:
$env:TEST_USERNAME = 'your-test-account'
$env:TEST_PASSWORD = 'your-test-password'
2. Create a setup test that signs in and saves state
In the following example, the login form uses labels “Email” and “Password,” and a successful sign-in leads to /dashboard. Change these assumptions to match the test site.
Rank #2
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
// tests/auth.setup.ts
import { test as setup, expect } from '@playwright/test';
import path from 'node:path';
const authFile = path.join(__dirname, '../playwright/.auth/user.json');
setup('authenticate', async ({ page }) => {
const username = process.env.TEST_USERNAME;
const password = process.env.TEST_PASSWORD;
if (!username || !password) {
throw new Error('Set TEST_USERNAME and TEST_PASSWORD before running tests');
}
await page.goto('https://example.com/login');
await page.getByLabel('Email').fill(username);
await page.getByLabel('Password').fill(password);
await page.getByRole('button', { name: 'Sign in' }).click();
await expect(page).toHaveURL(/dashboard/);
await page.context().storageState({ path: authFile });
});
Replace https://example.com/login and the selectors with the target site’s actual sign-in details. The URL assertion is an example success check, not a universal indicator; assert something meaningful for your app.
3. Configure the setup and authenticated test projects
In playwright.config.ts, run authentication setup first, then tell the test project to load its saved state:
import { defineConfig, devices } from '@playwright/test';
export default defineConfig({
testDir: './tests',
projects: [
{
name: 'setup',
testMatch: /.*.setup.ts/,
},
{
name: 'chromium',
use: {
...devices['Desktop Chrome'],
storageState: 'playwright/.auth/user.json',
},
dependencies: ['setup'],
},
],
});
A later test can use the signed-in page normally:
import { test, expect } from '@playwright/test';
test('opens the account dashboard', async ({ page }) => {
await page.goto('https://example.com/dashboard');
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible();
});
Playwright’s authentication guide documents this setup-and-reuse workflow and additional configurations: Playwright Authentication.
Rank #3
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
4. Keep saved state out of Git
Storage state can contain cookies and headers that let someone impersonate the account. Add its directory to .gitignore:
playwright/.auth
Playwright says, “We strongly discourage checking them into private or public repositories.” Restrict file access, avoid sharing state files, and use a temporary output location or clean up the file when persistence is unnecessary.
Free tools Windows power users keep installed
One-click scans. No signup required.
When tests run in parallel
If tests modify shared server-side data, a single account can make parallel tests interfere with one another. Playwright documents using separate accounts and state per worker for this case. If tests are read-only or otherwise isolated, a shared authenticated state may be appropriate; choose based on how the application handles concurrent sessions and data.
Rank #4
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
What 1Password does—and does not—do for Playwright
The documented 1Password browser flow is interactive filling by a person. Playwright’s documented flow accepts credentials in test setup and reuses browser state. The cited documentation does not establish a supported method for Playwright to control an unlocked 1Password extension or programmatically retrieve a Login item’s secret. Do not treat the extension prompt as an unattended automation API.
If an automated test needs to enter a password, supply it through your approved secret-management process rather than embedding it in the test file. Once authenticated, storage state can keep later tests from repeating that login, but it remains a credential-bearing artifact.
Security and reliability boundaries
For people using Autofill
- Verify the site domain before selecting a Login item; a saved URL match is useful but does not make a deceptive page trustworthy.
- Keep the browser and extension current, and disable automatic submission if you want to review filled forms before they are sent.
- 1Password warns that malicious pages may use deceptive overlays or clickjacking to induce interaction with Autofill. Consider stronger confirmation or a locked extension when the situation calls for more control.
For AI-assisted or autonomous browsing
In a security advisory dated January 30, 2026, 1Password described how an assistant with browser-level user permissions might trigger extension behavior. It also says users can disable automatic sign-in for the 1Password web app. Treat webpage content as untrusted input, and do not let an agent handle account credentials without deliberate authorization. Read 1Password’s advisory on AI-assisted browsing.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
For test sessions
- Expect saved authentication to stop working when cookies or sessions expire, are revoked, or are invalidated by the site; rerun setup to refresh the state.
- Do not assume MFA, passkeys, CAPTCHA, or other access controls can be bypassed. Use the site’s permitted test process and keep human verification where required.
- For tests that share state or alter common data, isolate accounts or workers to avoid cross-test interference.
Troubleshoot common problems
- The 1Password prompt does not appear: Confirm the extension is installed, unlocked, and signed in; check that the Login item has the correct site URL; then try the extension toolbar and select the item manually.
- The wrong login is suggested: Verify the domain in the browser and edit the Login item’s saved website address to match the legitimate sign-in page. Do not fill credentials on a lookalike domain.
- The form fills but does not sign in: The website may use a multi-step form, a different field structure, or a separate submission control. Review the fields and complete the site’s next step; turn off automatic submission if it causes an unwanted action.
- Playwright reports missing credentials: Set
TEST_USERNAMEandTEST_PASSWORDin the process that launches the tests, and check for typos in the variable names. - Playwright cannot find a label or button: Replace the example selectors with accessible labels and roles used by the actual form; wait for the expected form state if the page renders it asynchronously.
- The saved state is missing: Ensure the setup project runs before the authenticated project and that the configured state path matches the path written by
storageState. - The test is signed out despite loading state: The site’s session may have expired or require a new verification step. Rerun authentication setup and inspect whether the site stores required session data in a way the configured state captures.
- Parallel tests affect each other: Use separate test accounts and per-worker state when tests mutate shared application data, following Playwright’s guidance.
What about 1Password Universal Sign-In?
1Password’s January 2026 announcement describes Universal Sign-In as a single prompt that can select among a site’s authentication methods and fill credentials across multiple steps. That is a vendor announcement, not evidence that the capability is available for every account, platform, or website. Check 1Password’s announcement and verify availability in your own extension before relying on it.
Or skip the browser setup
If the goal is capturing a website rather than testing an authenticated account flow, ScreenshotNeo offers a screenshot API and MCP server. One GET request returns an image or PDF, without requiring you to configure Playwright for a capture. It is not a replacement for signing into a protected site or testing an authentication flow.
Example request (see the ScreenshotNeo API documentation for options):
Quick Recap
curl -G "https://api.screenshotneo.com/v1/shot"
-d access_key=YOUR_API_KEY
--data-urlencode url=https://example.com
-o shot.webp
- Cookie banners, popups, and chat widgets are removed before the shot.
- Bot checks, blank pages, and failed loads are never billed.
- An MCP server lets AI agents take screenshots.
- 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000.
Sign up free for ScreenshotNeo.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

