Can AI agents automate 1Password?
1Password · hybrid · identitydeveloper-tools
1Password is automatable today through the official op CLI. This record is 1Password (desktop apps, 1Password.com, Environments, CLI, Connect Server, and Events API), not Okta, Auth0, or HashiCorp Vault. op installs on macOS, Windows, and Linux, authenticates with the desktop app, a service-account token, or a Connect token, and supports --format json for item, vault, user, and group commands. That is the broadest documented agent path for vault items. The self-hosted Connect Server exposes a private REST API for vault and item CRUD with Authorization: Bearer access tokens and official Connect SDKs in Go, JavaScript, and Python. Connect cannot reach built-in Personal, Private, Employee, or default Shared vaults. The Events API is a separate Business-account REST surface for audit events, item usage, and sign-in attempts; it authenticates with a JWT-encoded bearer token and is read-only. Official 1Password SDKs for Go, JavaScript, and Python manage items and Environments using desktop-app prompts or OP_SERVICE_ACCOUNT_TOKEN. First-party MCP is the local 1password-mcp server inside the desktop app. It is scoped to Environments (create, list, rename, list variable names, append variables, mount local .env files). The opened vendor page states the server never returns stored secret values, even if an agent asks. Transport is stdio only. Cursor and Kiro integrations are documented as beta. Local .env mounts are Mac and Linux only. 1Password's developer homepage labels the Environments MCP as beta. The official MCP registry listing io.github.CakeRepository/1password is a third-party server and is not the desktop Environments MCP. A separate public docs-search MCP at https://www.1password.dev/mcp reads documentation only. The Users API for Partners is public preview and is outside this score. iPaaS connectors were not opened. Computer-use viability is unassessed. CLI scores 8 and is the best path. MCP stays at 5 because it is Environments-only, cannot return secrets, and is labeled beta.
Best path today: cli · Overall automatability: 8/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | restconnect-bearer-tokenevents-jwt-bearer coverage: partial · docs |
| SDK | yes | gojavascriptpython official: yes |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | yes | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: json · import: dotenv | |
| RPA / UI automation | unknown | native-desktopweb-dom No repeatable UI probe was run. The official op CLI, Connect REST API, Events API, and Environments MCP cover practical secrets and Environments work without browser control.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 7 | 5 | — | 8 | — | — | 8 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-09-03 |
license | declared | source | 2026-09-03 |
platforms | declared | source | 2026-09-03 |
modalities.api.exists | declared | source | 2026-09-03 |
modalities.sdk.exists | declared | source | 2026-09-03 |
modalities.sdk.languages[0] | declared | source | 2026-09-03 |
modalities.sdk.languages[1] | declared | source | 2026-09-03 |
modalities.sdk.languages[2] | declared | source | 2026-09-03 |
modalities.api.kinds[0] | declared | source | 2026-09-03 |
modalities.api.auth[0] | declared | source | 2026-09-03 |
modalities.api.auth[1] | declared | source | 2026-09-03 |
modalities.api.coverage | declared | source | 2026-09-03 |
modalities.mcp.first_party | declared | source | 2026-09-03 |
modalities.cli.exists | declared | source | 2026-09-03 |
modalities.data_access.export[0] | declared | source | 2026-09-03 |
modalities.data_access.import[0] | declared | source | 2026-09-03 |
modalities.agent_docs.llms_txt | declared | source | 2026-09-03 |
verdict.scores.api | declared | source | 2026-09-03 |
verdict.scores.mcp | declared | source | 2026-09-03 |
verdict.scores.cli | declared | source | 2026-09-03 |
freshness.watch[0].url | declared | source | 2026-09-03 |
freshness.watch[1].url | declared | source | 2026-09-03 |
freshness.watch[2].url | declared | source | 2026-09-03 |
freshness.watch[3].url | declared | source | 2026-09-03 |
Related tools
Other products in this database that share a category with 1Password.
Last verified 2026-09-03 · volatility high · JSON record