Can AI agents automate 1Password?

1Password · hybrid · identitydeveloper-tools

1Password is automatable today through the official op CLI. This record is 1Password (desktop apps, 1Password.com, Environments, CLI, Connect Server, and Events API), not Okta, Auth0, or HashiCorp Vault. op installs on macOS, Windows, and Linux, authenticates with the desktop app, a service-account token, or a Connect token, and supports --format json for item, vault, user, and group commands. That is the broadest documented agent path for vault items. The self-hosted Connect Server exposes a private REST API for vault and item CRUD with Authorization: Bearer access tokens and official Connect SDKs in Go, JavaScript, and Python. Connect cannot reach built-in Personal, Private, Employee, or default Shared vaults. The Events API is a separate Business-account REST surface for audit events, item usage, and sign-in attempts; it authenticates with a JWT-encoded bearer token and is read-only. Official 1Password SDKs for Go, JavaScript, and Python manage items and Environments using desktop-app prompts or OP_SERVICE_ACCOUNT_TOKEN. First-party MCP is the local 1password-mcp server inside the desktop app. It is scoped to Environments (create, list, rename, list variable names, append variables, mount local .env files). The opened vendor page states the server never returns stored secret values, even if an agent asks. Transport is stdio only. Cursor and Kiro integrations are documented as beta. Local .env mounts are Mac and Linux only. 1Password's developer homepage labels the Environments MCP as beta. The official MCP registry listing io.github.CakeRepository/1password is a third-party server and is not the desktop Environments MCP. A separate public docs-search MCP at https://www.1password.dev/mcp reads documentation only. The Users API for Partners is public preview and is outside this score. iPaaS connectors were not opened. Computer-use viability is unassessed. CLI scores 8 and is the best path. MCP stays at 5 because it is Environments-only, cannot return secrets, and is labeled beta.

Best path today: cli · Overall automatability: 8/10

Modalities

ModalityStatusDetail
APIyesrestconnect-bearer-tokenevents-jwt-bearer
coverage: partial · docs
SDKyesgojavascriptpython
official: yes
MCPyes
verdict: official
Integrationsunknown
CLIyes
Extensibilityunknown
webhooks: unknown
Data access
export: json · import: dotenv
RPA / UI automationunknownnative-desktopweb-dom
No repeatable UI probe was run. The official op CLI, Connect REST API, Events API, and Environments MCP cover practical secrets and Environments work without browser control.
Computer useunknown
measured verdicts only — "unknown" means not yet probed by us

Scores

apimcpintegrationsclirpacomputer useoverall
7588

Evidence

FactTierSourceDate
homepagedeclaredsource2026-09-03
licensedeclaredsource2026-09-03
platformsdeclaredsource2026-09-03
modalities.api.existsdeclaredsource2026-09-03
modalities.sdk.existsdeclaredsource2026-09-03
modalities.sdk.languages[0]declaredsource2026-09-03
modalities.sdk.languages[1]declaredsource2026-09-03
modalities.sdk.languages[2]declaredsource2026-09-03
modalities.api.kinds[0]declaredsource2026-09-03
modalities.api.auth[0]declaredsource2026-09-03
modalities.api.auth[1]declaredsource2026-09-03
modalities.api.coveragedeclaredsource2026-09-03
modalities.mcp.first_partydeclaredsource2026-09-03
modalities.cli.existsdeclaredsource2026-09-03
modalities.data_access.export[0]declaredsource2026-09-03
modalities.data_access.import[0]declaredsource2026-09-03
modalities.agent_docs.llms_txtdeclaredsource2026-09-03
verdict.scores.apideclaredsource2026-09-03
verdict.scores.mcpdeclaredsource2026-09-03
verdict.scores.clideclaredsource2026-09-03
freshness.watch[0].urldeclaredsource2026-09-03
freshness.watch[1].urldeclaredsource2026-09-03
freshness.watch[2].urldeclaredsource2026-09-03
freshness.watch[3].urldeclaredsource2026-09-03

Related tools

Other products in this database that share a category with 1Password.

Last verified 2026-09-03 · volatility high · JSON record