Local MCP access to approved 1Password fields without exposing plaintext secrets to AI agents.
Local MCP access to approved 1Password items and profile data for AI agents.
npm package · setup guide · security model · uninstall guide
Agents receive encrypted local handles, not plaintext 1Password secrets. At the moment of copy or paste, the MCP resolves the selected field locally through the 1Password CLI and sends it to the OS clipboard or active app.
The repo contains no personal 1Password data. Every install connects to that user's own 1Password CLI and local approval policy.
Not affiliated with or endorsed by 1Password.
MCPVAULT.MCPVAULT.MCPVAULT fields for specific websites.The MCP tools only expose approved fields from the configured agent vault. The local profile-data section can also expose user-entered values such as email, phone, address, name, and company.
Install from npm:
npm install -g onepassword-agent-mcp
Run the friendly installer. It detects supported MCP clients, shows what it found, and asks before changing their user configuration. On macOS it separately offers the optional visible menu-bar shortcut:
onepassword-agent-mcp install
Or install from GitHub:
npm install -g github:gambadio/onepassword-agent-mcp
Prefer explicit commands? Check your setup and connect clients manually:
onepassword-agent-mcp doctor
Connect every detected MCP client with one command:
onepassword-agent-mcp setup all --apply
Start the local console:
onepassword-agent-mcp admin
Open:
http://127.0.0.1:7319
Full walkthrough: docs/USER_GUIDE.md
Uninstall guide: docs/UNINSTALL.md
No. Installing the npm package itself adds commands only. It does not install a launch agent, daemon, background service, startup item, browser extension, or hidden resident process.
onepassword-agent-mcp admin runs the local approval console only while that terminal process is alive.onepassword-agent-mcp mcp is a stdio MCP server. MCP clients such as Claude Code, Codex, or VS Code launch it as a child process when they need it.onepassword-agent-mcp setup ... --apply only writes MCP client configuration. Existing JSON files are backed up before a merge.~/.onepassword-mcp.You can see this explanation any time:
onepassword-agent-mcp runtime
On macOS, the guided installer can add a clearly labeled 1P item to the menu bar. You can also enable it later under Mac Menu Bar Shortcut in the local admin page.
The companion is built locally from the readable Swift source in native/MenuBarApp.swift. No opaque app binary is shipped in the npm package. The generated app uses the project's teal shield logo, is placed at ~/Applications/1Password Agent MCP.app, and never asks for administrator access.
Manual controls:
onepassword-agent-mcp menubar status
onepassword-agent-mcp menubar install
onepassword-agent-mcp menubar launch
onepassword-agent-mcp menubar remove
onepassword-agent-mcp menubar install --launch-at-login
onepassword-agent-mcp menubar login on
onepassword-agent-mcp menubar login off
onepassword-agent-mcp menubar uninstall --apply
Use menubar remove to close the visible shortcut without uninstalling it, and menubar launch to show it again. Use menubar install after uninstalling it. The local admin page offers the same installation controls under Mac Menu Bar Shortcut while the admin console is running.
The menu contains Open Admin Console, Stop Admin Console, Launch Menu Bar at Login, Remove From Menu Bar, and Uninstall Menu Bar Shortcut. Open Admin Console starts the console when needed and then opens it, so there is no separate Start action. Remove From Menu Bar only closes the visible helper; it stays installed and can be reopened. Uninstall Menu Bar Shortcut removes the helper and its login item after confirmation. Neither action changes MCP client configuration, local approvals, MCPVAULT, or 1Password items.
The admin console itself has explicit process controls:
onepassword-agent-mcp admin status
onepassword-agent-mcp admin stop
op)OP_SERVICE_ACCOUNT_TOKENmacOS:
brew install node 1password-cli
Enable the 1Password desktop integration:
On macOS, leave 1Password CLI path as op for automatic discovery. The admin console, MCP server, and doctor check PATH, then /opt/homebrew/bin/op and /usr/local/bin/op. This also works when the menu-bar app starts with macOS's limited GUI environment. Existing settings that use op work without a reset or reinstall. A custom path or wrapper command is used exactly as configured.
The console is a simple left-to-right vault flow:
MCPVAULT exists and can create it.MCPVAULT area. Drag an item from the left list onto it, then choose Copy or Move.MCPVAULT.Copy is the safe default. Copy now uses 1Password's revealed JSON clone pipe so the destination item keeps the original fields. Move is available, but 1Password creates a new item in the destination vault and deletes the original item from the source vault.
After copying, nothing is shared with agents yet. In All Fields, copied items stay compact so the page remains easy to scan. Click Review Details on an item, tick only the details the agent may use, then click Approve Selected. Credit cards show normal checkout details separately from sensitive details like CVV or PIN. Blank allowed-sites fields mean the approved item may be used on all URLs. Items in MCPVAULT can also be deleted from the approval console after a confirmation prompt.
When agents are allowed to create new credentials, those items are saved into MCPVAULT first. In Approve Agent Items, open the saved item and use Save this item to another vault to copy or move it into a normal 1Password vault. Copy keeps the agent-vault version. Move removes it from MCPVAULT and removes local approvals for that copied item.
Under Advanced local settings, enable Automatically approve items agents create, then click Save Settings. This option defaults to off. Agent item creation must also be enabled.
When enabled, a verified save_secret_item automatically approves every supported field of the new item in the configured agent vault, including credit-card CVV and PIN. The agent can use the resulting encrypted handles immediately. Existing items and items copied or moved in through the admin console still need manual approval.
The CLI controls the same saved option:
onepassword-agent-mcp settings auto-approve on
onepassword-agent-mcp settings auto-approve off
onepassword-agent-mcp settings --json
Changes apply to subsequent new saves without restarting the MCP server. Add --dry-run to preview a change. Turning the option off keeps existing approvals; disable or delete individual approvals in Allowed For Agents to revoke them. The automatic approval choice is recorded when each save starts. Retrying an older save or a save that opted out does not opt it into automatic approval, and retries do not reinstate revoked approvals.
Automatic approvals use allowedSites when provided, otherwise the saved item's website. An empty list or an item without a website allows all sites. approveForAgents: false skips approval for that save. With automatic approval off, approveForAgents: true retains the existing single-field approval behavior, using approveField when supplied and allowing all sites unless allowedSites is provided. With automatic approval on, approveField does not narrow the set of approved fields.
The setup CLI prints a dry run by default. It detects Claude Code, Claude Desktop, Codex, VS Code, Xcode coding agents, and Raycast AI when they are installed:
onepassword-agent-mcp setup all
Apply setup to every detected client:
onepassword-agent-mcp setup all --apply
The command uses absolute executable paths so GUI apps do not depend on Terminal's PATH. Claude Desktop and VS Code JSON are merged with timestamped backups. Xcode's private Codex and Claude configuration folders are handled separately because Xcode does not use the normal CLI configuration.
Raycast stores MCP configuration in app-managed storage and does not expose a supported external config writer. The CLI opens Raycast's official Import Servers screen; review the prepared entry and confirm it once in Raycast. This is the only interactive client-specific step.
onepassword-agent-mcp setup claude-code --apply
Equivalent command:
claude mcp add --scope user onepassword-agent-mcp -- onepassword-agent-mcp mcp
onepassword-agent-mcp setup codex --apply
Equivalent command:
codex mcp add onepassword-agent-mcp -- onepassword-agent-mcp mcp
onepassword-agent-mcp setup copilot --apply
Equivalent VS Code command:
code --add-mcp '{"name":"onepassword-agent-mcp","command":"onepassword-agent-mcp","args":["mcp"]}'
Workspace fallback at .vscode/mcp.json:
{
"servers": {
"onepassword-agent-mcp": {
"type": "stdio",
"command": "onepassword-agent-mcp",
"args": ["mcp"]
}
}
}
onepassword-agent-mcp setup claude-desktop --apply
The CLI safely merges the server into Claude Desktop's user JSON and preserves all other settings.
onepassword-agent-mcp setup xcode --apply
This configures the isolated Codex and Claude Agent environments used only inside Xcode.
onepassword-agent-mcp setup raycast --apply
Raycast opens its native import screen for the final confirmation. Raycast asks before MCP tool calls by default.
ChatGPT Desktop is intentionally not included in local setup. ChatGPT currently connects to remote MCP servers rather than arbitrary local stdio commands. Do not expose this password bridge through a public tunnel merely to connect it.
Print generic MCP JSON:
onepassword-agent-mcp setup generic --json
Generic config:
{
"mcpServers": {
"onepassword-agent-mcp": {
"command": "onepassword-agent-mcp",
"args": ["mcp"]
}
}
}
Stop the local approval console by pressing Ctrl-C in the terminal running:
onepassword-agent-mcp admin
Disconnect MCP clients:
onepassword-agent-mcp uninstall all
onepassword-agent-mcp uninstall all --apply
The uninstall command removes its entries from Claude Code, Claude Desktop, Codex, VS Code, and Xcode where present, then removes the optional menu-bar app/login item. Raycast opens Manage Servers for an explicit removal because its settings are app-managed. Other client settings and all 1Password data remain untouched.
Remove the global npm package:
npm uninstall -g onepassword-agent-mcp
Optional: delete this app's local approvals and encryption key:
onepassword-agent-mcp uninstall state
onepassword-agent-mcp uninstall state --apply
This deletes ~/.onepassword-mcp. It does not delete 1Password vaults or items. Delete MCPVAULT inside 1Password only if you intentionally want to remove that vault.
onepassword_status: check CLI, MCPVAULT, local approvals, profile data, and settings.find_secrets_for_site: return approved encrypted handles for a website.list_approved_secrets: list approved handles and allowed sites.copy_secret: resolve a handle and copy the selected field to the clipboard.paste_secret: resolve a handle, copy it, paste into the active app, and return no plaintext.clear_secret_clipboard: clear the clipboard.save_secret_item: save a new login, password, API credential, secure note, or credit card into MCPVAULT when the local save setting is enabled. Returns verification and approval status, plus approvedFields (and the first field as approvedField for compatibility). Automatic approval follows the local autoApproveAgentItems setting.get_profile_data: return user-defined profile data allowed for the current site.find_passwords_for_site, list_approved_passwords, copy_password, paste_password, and clear_password_clipboard: compatibility aliases.admin_ui_info: return the approval console URL.Protected:
Still sensitive:
get_profile_data returns plaintext profile values you explicitly added in the admin UI.For the strictest boundary, use a 1Password service account scoped only to MCPVAULT.
Read docs/SECURITY.md before using this with powerful browser-control agents.
Default state location:
~/.onepassword-mcp/policy.json
~/.onepassword-mcp/key.bin
Use a different state directory:
ONEPASSWORD_MCP_HOME=/path/to/state onepassword-agent-mcp admin
Use a different agent vault name:
MCP_VAULT_NAME=AgentVault onepassword-agent-mcp admin
Headless service-account example:
{
"mcpServers": {
"onepassword-agent-mcp": {
"command": "onepassword-agent-mcp",
"args": ["mcp"],
"env": {
"OP_SERVICE_ACCOUNT_TOKEN": "ops_...",
"MCP_VAULT_NAME": "MCPVAULT"
}
}
}
}
Do not commit service account tokens.
Run:
onepassword-agent-mcp doctor
Common fixes:
op missing: install the 1Password CLI. On macOS, automatic discovery also checks the standard Homebrew locations even if they are absent from PATH.op in Advanced local settings for automatic discovery, or correct an explicitly configured CLI path. doctor and the status APIs report the selected executable. Older releases that only searched PATH need the full path, such as /opt/homebrew/bin/op on Apple Silicon Macs.OP_SERVICE_ACCOUNT_TOKEN.MCPVAULT missing: start the admin console and click Create MCPVAULT.code: install the VS Code shell command or use .vscode/mcp.json.onepassword-agent-mcp admin.Clone the repo:
git clone https://github.com/gambadio/onepassword-agent-mcp.git
cd onepassword-agent-mcp
npm install
Run checks:
npm run build
npm run typecheck
npm test
Run locally:
npm run dev:admin
npm run dev:mcp
Maintainer releases are automated through GitHub Actions with short-lived OIDC credentials. See docs/RELEASING.md; local npm publish and repeated device authorization are not part of the release process.
MIT
save_secret_item reports created, verified, itemId, vaultId, and
operationId. Success requires a readback that matches the intended title,
category, destination, websites, and field values. Secret values are compared
locally and are never included in the result. The optional approvalStatus
is separate: an item can be saved and verified while its approval still needs
review in the admin UI.
Reuse the same requestId and input after an interrupted save. If omitted,
identical item contents in the same destination are deduplicated. Supply a new
requestId only to intentionally create another item. Recovery uses a unique
opmcp-… item tag and a local operation record, never a title match. If a previous
operation cannot be reconciled, the tool reports an unresolved result instead
of silently creating another item. An approval revoked by the user is never
reinstated by a save retry.
On macOS and Linux, JSON crosses an OS pipe with no plaintext temporary files or secret values in command arguments. The runner preserves the terminal session for 1Password authorization and cleans up its child process group on timeout or cancellation. Copy reads and verifies supported JSON fields, including concealed values. Items containing attachments, documents, or passkeys must be copied using the 1Password app.
Restart existing MCP clients and the admin console after updating so every writer uses the current policy locking and save verification code. Existing settings, approvals, and the encryption key are retained.
npm ci
npm run typecheck
npm test
npx playwright install chromium
npm run test:ui
npm run build
node scripts/test-live.mjs
The final command tests all five categories using real CLI dry runs. Unlock 1Password and authorize CLI access when prompted. To additionally test actual MCP saves, exact readback, retry deduplication, and copy, run:
node scripts/test-live.mjs --create
This requires the saved agent-creation setting. It creates uniquely tagged
synthetic fixtures in the configured agent vault, verifies them, then moves
those exact fixtures to Recently Deleted. It uses isolated local policy state.
If verification or cleanup fails, it prints the recovery state directory and
retains it for inspection. doctor checks CLI authorization, destination
visibility, local creation permission, and console liveness; it does not
perform save/copy validation.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y onepassword-agent-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-gambadio-onepassword-agent-mcp": {
"command": "npx",
"args": [
"-y",
"onepassword-agent-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceonepassword-agent-mcpnpmio.github.gambadio/onepassword-agent-mcp works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.