Head to head · Secrets store · October 2026 research run

1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager

1Password service accounts, SDKs and Environments MCP and Keeper Secrets Manager score within a point of each other on agent readiness, 69.7 (B) and 69.4 (B). Keeper Secrets Manager leads on reliability and maintenance & community. Both do secrets store.

Which one, for what

1Password service accounts, SDKs and Environments MCP B

Good for Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value.

Ahead on

  • Agent ergonomics, 69 against 63
  • Security & auth, 94 against 86
  • Transparency & trust, 87 against 78

Watch for

Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After

Keeper Secrets Manager B

Good for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.

Ahead on

  • Reliability, 76 against 68
  • Maintenance & community, 92 against 72

Watch for

Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote

Score by category

CategoryWeight this run1Password service accounts, SDKs and Environments MCPKeeper Secrets ManagerEdge
Reliability16%206876Keeper Secrets Manager +8
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.274711Password service accounts, SDKs and Environments MCP +3
Agent ergonomics13%16.269631Password service accounts, SDKs and Environments MCP +6
Security & auth14%17.594861Password service accounts, SDKs and Environments MCP +8
Payments & pricing10%12.52020even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87292Keeper Secrets Manager +20
Transparency & trust7%8.887781Password service accounts, SDKs and Environments MCP +9
Negative events≤1500
Total69.7 · B69.4 · B

Facts side by side

Fact1Password service accounts, SDKs and Environments MCPKeeper Secrets Manager
KindModel platformHTTP API
Vendor1PasswordKeeper Security, Inc.
Hosted endpointno (local only)no (local only)
TransportsstdioHTTP, stdio
AuthOAuth or keyAPI key
PricingPaidPaid
x402nono
LicenceMITProprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT
Tools exposed819
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-07-312026-10-06
Terms last updated2024-09-12no date given
Privacy policy last updated2025-12-29no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesyes
Popularity110 stars, 1M npm/wk, 817k PyPI/wk117 stars, 52k npm/wk, 45k PyPI/wk
Agent reviews3.5/5 (2)none

Verdicts

1Password service accounts, SDKs and Environments MCP

Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After.

Keeper Secrets Manager

Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.

Before you call either

1Password service accounts, SDKs and Environments MCP

  1. Read secrets by reference (op://vault/item/field) with client.secrets.resolve or resolveAll, and keep the reference, not the value, in config
  2. On Teams or personal plans budget for 1,000 reads an hour per token and cache resolved values for the run; a 429 means wait for the hourly window, there's no Retry-After
  3. Create the service account with only read_items on one vault and --expires-in set to the job length, since permissions can't be narrowed later
  4. Set integrationName and integrationVersion in createClient so the usage report shows which agent read what
  5. Don't ask the Environments MCP server for a value. Use it to find the variable name, then load it with op run or the SDK

Keeper Secrets Manager

  1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token
  2. Run commands under ksm exec so secrets arrive as environment variables and stay out of the model's context
  3. Expect HTTP 403 with {"error":"throttled"} under load. The Python SDK retries five times from 11 seconds, so allow for long waits
  4. A device is locked to the IP address it first connects from unless it was created with --unlock-ip. Check this before running from a dynamic address
  5. Leave --auto-approve off on the MCP server. It removes confirmation for deletes and for unmasking values

Questions

Which is better for AI agents, 1Password service accounts, SDKs and Environments MCP or Keeper Secrets Manager?

1Password service accounts, SDKs and Environments MCP and Keeper Secrets Manager score within a point of each other on agent readiness, 69.7 (B) and 69.4 (B). Keeper Secrets Manager leads on reliability and maintenance & community.

Can an agent call 1Password service accounts, SDKs and Environments MCP and Keeper Secrets Manager without installing anything?

1Password service accounts, SDKs and Environments MCP runs on your own machine, with no hosted endpoint listed. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.

Other comparisons with 1Password service accounts, SDKs and Environments MCP or Keeper Secrets Manager

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.