1Password-Items

EventTitleChannelSampleRule
anyItems (catch-all)_catch_allNN
items-deleteDelete Trashed Vault Itemsitems-deleteNN
items-patchPatch Vault Itemsitems-patchYN
items-purgePurge Deleted Vault Itemsitems-purgeYN

any: Items (catch-all)

#

Description

Catch-all entry for 1Password rules that match items events without naming a specific action.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

items-delete: Delete Trashed Vault Items

#

Description

Vault items in the trash were deleted.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

items-patch: Patch Vault Items

#

Description

Vault items were added or updated.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "TQTWWX5CWBHYATC22GKCQPW57G",
  "timestamp": "12/20/2023, 10:25:59.348 PM",
  "location": {
    "country": "South Africa",
    "region": "Western Cape",
    "city": "Cape Town",
    "latitude": -33.91,
    "longitude": 18.4304
  },
  "actor_uuid": "QAGUTBKJBJFYZN6DTM5SUHWPYQ",
  "actor_details": {
    "uuid": "QAGUTBKJBJFYZN6DTM5SUHWPYQ",
    "name": "Austin Powers",
    "email": "austin.powers@securehats.nl"
  },
  "action": "patch",
  "object_type": "items",
  "object_uuid": "y3qz2o3lzdydm5yhyzaegrhs7m",
  "aux_id": "2",
  "aux_info": "1,0,0,0,0",
  "session": {
    "uuid": "AWIBK4BFIRCIBI4ZLCA2EZZYD4",
    "login_time": "2023-12-20T22:25:17.1095495Z",
    "device_uuid": "wrdbpwcdp26mn4wsj5ut2zeaai",
    "ip": "41.114.210.212"
  }
}

items-purge: Purge Deleted Vault Items

#

Description

Deleted vault items were marked to be purged.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "DUMMY-ID-0043",
  "action": "purge",
  "session": {
    "uuid": "DUMMY-ID-0044",
    "login_time": "2026-08-04T19:03:45.734728647Z",
    "device_uuid": "DUMMY-ID-0045",
    "ip": "192.0.2.11"
  },
  "aux_info": "1",
  "location": {
    "country": "Dummy Country 003",
    "region": "Dummy Region 003",
    "city": "Dummy City 005",
    "latitude": 0.0,
    "longitude": 0.0
  },
  "timestamp": "2026-08-04T20:13:47.648201667Z",
  "actor_type": "user",
  "actor_uuid": "DUMMY-USER-0016",
  "object_type": "items",
  "object_uuid": "DUMMY-ID-0046",
  "account_uuid": "DUMMY-ID-0004",
  "actor_details": {
    "uuid": "DUMMY-USER-0016",
    "name": "Dummy User 016",
    "email": "dummy.user016@example.invalid"
  }
}

References #