NebulaNebula
Workspace

Password managers: Bitwarden and 1Password

Connect Bitwarden or 1Password so browser tasks sign in to sites as you, without you pasting a password into a chat.

When a task needs to sign in to a site, it can read the login from your own password manager instead of asking you for it. You connect Bitwarden or 1Password once, and from then on a browser task finds the right login for the page it's on.

Nothing is typed into a chat, and no agent sees your passwords in its conversation — the value goes straight into the sign-in form on the page.

This is for browser tasks — work where an agent opens a site and acts on it. Connecting a password manager doesn't change how your app connections work; those already act as you through each app's own API.

Connect one

Open Settings → Account → Connections → Password managers and choose Connect next to Bitwarden or 1Password.

You can connect both, and connecting one never disturbs the other. A browser task uses one vault, chosen the same way every time: Bitwarden if it's connected, otherwise 1Password. So if you connect both, 1Password sits unused until you disconnect Bitwarden. Connect only the one you want tasks to use.

Bitwarden needs three things from you: an API key, which is two values, and your master password. The API key lets Nebula sign in to your account; the master password is what actually decrypts the vault. Bitwarden's own words: your API key is not a substitute for your master password.

Sign in to your web vault — vault.bitwarden.com, or vault.bitwarden.eu if your account is on the EU region.

Go to Settings → Security → Keys and choose View API key. You'll be asked for your master password.

Copy client_id — it starts with user. — and client_secret. Ignore scope and grant_type; Nebula doesn't need them.

Back in Nebula, pick your region (US or EU), paste both values, and add your master password. Choose Connect.

Get the region right. It decides which Bitwarden server your details are sent to, and a US account won't open against the EU server.

Bitwarden's US and EU clouds only. A self-hosted Bitwarden server isn't supported — neither region points at it, so correct credentials still won't open the vault. Use 1Password if your Bitwarden is self-hosted.

Nebula holds all three values encrypted, because a Bitwarden vault cannot be decrypted without the master password. If you'd rather not store it anywhere, use 1Password instead — see the comparison below.

Which to choose

Bitwarden1Password
What you hand overAPI key (two values) and your master passwordOne service account token
What Nebula storesAll three, encryptedThe token, encrypted
Which logins it reachesEverything in your vaultOnly the vaults you grant
SetupCopy two values, enter master passwordMake a vault, move logins in, create a token
Revoke byRotating the client secret, or disconnectingDeleting the service account, or disconnecting
Works withBitwarden's US or EU cloud, not self-hostedAccounts whose permissions allow a service account

The honest trade: Bitwarden is quicker to set up but reaches your whole vault and needs your master password stored. 1Password takes longer to set up but is scoped to a vault you choose and never involves your master password.

After it's connected

The row shows how many logins were found and how many sites they cover. That count comes from reading your vault, and it counts only logins that have a website saved on them — the ones a task can actually reach. A login with no website, like a router password or a note, is never reachable, so it isn't counted.

That's why a vault can read 0 logins even though it's full: the logins in it have no website saved. Add the site to a login in your vault and it becomes usable.

A task only uses a login when the site it's on matches one in your vault. If nothing matches, the task carries on and tells you what it couldn't sign in to, rather than stopping.

If two logins in your vault cover the same site — a personal and a work account, say — the task signs in to neither. The page gives it nothing to choose between them, and signing you into the wrong account is worse than saying so. Keep one login per site in the vault Nebula reads.

If something goes wrong

"That token is valid but has not been given access to any vault." The 1Password service account exists but was granted nothing. Grant it access to the vault holding your logins, then connect again. You don't need a new token.

"Those details did not open the vault." For Bitwarden, check the region first — it's the most common cause — then the master password, then re-copy the client secret. For 1Password, the token may have been revoked; create a new one.

The row says to reconnect. A task tried to use the vault and was turned away, usually because the master password changed or the token was revoked. Connect again with current details.

A passing outage doesn't do this. If the vault simply couldn't be reached, the row stays as it was rather than sending you to re-enter details that were never wrong.

Disconnecting

Choose Disconnect. Nebula forgets the stored details immediately, and nothing reaches that vault again until you reconnect.

Disconnecting in Nebula doesn't revoke anything on the vendor's side. To be thorough, also rotate your Bitwarden client secret or delete the 1Password service account.

On this page