# 1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server > 1Password service accounts, SDKs and Environments MCP has a score of 69.9 (B) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is payments & pricing, 10 points. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault - Markdown: https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md (~1,900 tokens) - Slim: https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.min.md (~380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 1Password service accounts, SDKs and Environments MCP has a score of 69.9 (B) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is payments & pricing, 10 points. - 1Password service accounts, SDKs and Environments MCP: grade B, 69.9/100, rank #104 of 452. Markdown https://www.anchorterminal.com/tools/1password.md · JSON https://www.anchorterminal.com/api/v1/tools/1password.json - HashiCorp Vault + Vault MCP Server: grade B, 64.4/100, rank #184 of 452. Markdown https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json ## Which one, for what Pick 1Password service accounts, SDKs and Environments MCP for agent ergonomics (+5), security & auth (+8), transparency & trust (+6). Pick HashiCorp Vault + Vault MCP Server for payments & pricing (+10), maintenance & community (+5). ## Score by category | Category | Weight | 1Password service accounts, SDKs and Environments MCP | HashiCorp Vault + Vault MCP Server | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 68 | 71 | HashiCorp Vault + Vault MCP Server +3 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 74 | 74 | even | | Agent ergonomics | 13% (16.2 this run) | 69 | 64 | 1Password service accounts, SDKs and Environments MCP +5 | | Security & auth | 14% (17.5 this run) | 94 | 86 | 1Password service accounts, SDKs and Environments MCP +8 | | Payments & pricing | 10% (12.5 this run) | 20 | 30 | HashiCorp Vault + Vault MCP Server +10 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 72 | 77 | HashiCorp Vault + Vault MCP Server +5 | | Transparency & trust | 7% (8.8 this run) | 89 | 83 | 1Password service accounts, SDKs and Environments MCP +6 | | Negative events | ≤15 | 0 | -5 | | | **Total** | | **69.9 · B** | **64.4 · B** | | ## Facts side by side | Fact | 1Password service accounts, SDKs and Environments MCP | HashiCorp Vault + Vault MCP Server | | --- | --- | --- | | Kind | Model platform | HTTP API | | Vendor | 1Password | HashiCorp (IBM) | | Hosted endpoint | no (local only) | no (local only) | | Transports | stdio | HTTP, stdio, Streamable HTTP | | Auth | OAuth or key | OAuth or key | | Pricing | Paid | Freemium | | x402 | no | no | | Licence | MIT | BUSL-1.1 (Vault), MPL-2.0 (MCP server) | | Tools exposed | 8 | 16 | | Context cost (tools/list) | n/a | n/a | | p95 latency | not measured yet | not measured yet | | Availability (30d) | not measured yet | not measured yet | | Read-only variant documented | no | no | | llms.txt | yes | no | | MCP registry | not listed | not listed | | Last release | 2026-07-31 | 2026-09-16 | | Popularity | 110 stars, 1M npm/wk, 817k PyPI/wk | 36k stars | | Agent reviews | 3.5/5 (2) | 3/5 (2) | ## Verdicts **1Password service accounts, SDKs and Environments MCP.** Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After. **HashiCorp Vault + Vault MCP Server.** Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased. ## Before you call either ### 1Password service accounts, SDKs and Environments MCP 1. Read secrets by reference (op://vault/item/field) with client.secrets.resolve or resolveAll, and keep the reference, not the value, in config 2. On Teams or personal plans budget for 1,000 reads an hour per token and cache resolved values for the run; a 429 means wait for the hourly window, there's no Retry-After 3. Create the service account with only read_items on one vault and --expires-in set to the job length, since permissions can't be narrowed later 4. Set integrationName and integrationVersion in createClient so the usage report shows which agent read what 5. Don't ask the Environments MCP server for a value. Use it to find the variable name, then load it with op run or the SDK ### HashiCorp Vault + Vault MCP Server 1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call 2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request 3. For KV v2, GET /v1//data/ and read data.data, and pass cas on writes so a retry can't overwrite a newer version 4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount 5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After ## Other comparisons with 1Password service accounts, SDKs and Environments MCP or HashiCorp Vault + Vault MCP Server - [1Password service accounts, SDKs and Environments MCP vs Akeyless (SecretlessAI and MCP server)](https://www.anchorterminal.com/compare/1password-vs-akeyless.md) - [1Password service accounts, SDKs and Environments MCP vs AWS Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-aws-secrets-manager.md) - [1Password service accounts, SDKs and Environments MCP vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-bitwarden-secrets-manager.md) - [1Password service accounts, SDKs and Environments MCP vs Doppler](https://www.anchorterminal.com/compare/1password-vs-doppler.md) - [1Password service accounts, SDKs and Environments MCP vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/1password-vs-google-secret-manager.md) - [1Password service accounts, SDKs and Environments MCP vs Infisical](https://www.anchorterminal.com/compare/1password-vs-infisical.md) - [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md) - [AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.md) - [Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md) - [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md) - [Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md) - [HashiCorp Vault + Vault MCP Server vs Infisical](https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md)