# 1Password service accounts, SDKs and Environments MCP vs Phase > 1Password service accounts, SDKs and Environments MCP scores 69.7 (B) on agent readiness against Phase's 68 (B), and leads in 4 of 7 scored categories. Phase leads on reliability, payments & pricing and maintenance & community. Both do secrets store. Category scores, facts… - Canonical: https://www.anchorterminal.com/compare/1password-vs-phase - Markdown: https://www.anchorterminal.com/compare/1password-vs-phase.md (~2,750 tokens) - Slim: https://www.anchorterminal.com/compare/1password-vs-phase.min.md (~780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/1password-vs-phase.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 1Password service accounts, SDKs and Environments MCP scores 69.7 (B) on agent readiness against Phase's 68 (B), and leads in 4 of 7 scored categories. Phase leads on reliability, payments & pricing and maintenance & community. Both do secrets store. - 1Password service accounts, SDKs and Environments MCP: grade B, 69.7/100, rank #149 of 722. Markdown https://www.anchorterminal.com/tools/1password.md · JSON https://www.anchorterminal.com/api/v1/tools/1password.json - Phase: grade B, 68/100, rank #194 of 722. Markdown https://www.anchorterminal.com/tools/phase.md · JSON https://www.anchorterminal.com/api/v1/tools/phase.json ## Which one, for what ### 1Password service accounts, SDKs and Environments MCP (B) Good for: Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value. Ahead on: - Schema & documentation, 74 against 58 - Agent ergonomics, 69 against 56 - Security & auth, 94 against 83 - Transparency & trust, 87 against 73 Also in its favour: - Runs on your own machine Watch for: Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After ### Phase (B) Good for: Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI. Ahead on: - Reliability, 91 against 68 - Payments & pricing, 25 against 20 - Maintenance & community, 83 against 72 Also in its favour: - A hosted endpoint, with nothing to install - Open source Watch for: No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations ## Score by category | Category | Weight | 1Password service accounts, SDKs and Environments MCP | Phase | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 68 | 91 | Phase +23 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 74 | 58 | 1Password service accounts, SDKs and Environments MCP +16 | | Agent ergonomics | 13% (16.2 this run) | 69 | 56 | 1Password service accounts, SDKs and Environments MCP +13 | | Security & auth | 14% (17.5 this run) | 94 | 83 | 1Password service accounts, SDKs and Environments MCP +11 | | Payments & pricing | 10% (12.5 this run) | 20 | 25 | Phase +5 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 72 | 83 | Phase +11 | | Transparency & trust | 7% (8.8 this run) | 87 | 73 | 1Password service accounts, SDKs and Environments MCP +14 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **69.7 · B** | **68 · B** | | ## Facts side by side | Fact | 1Password service accounts, SDKs and Environments MCP | Phase | | --- | --- | --- | | Kind | Model platform | HTTP API | | Vendor | 1Password | Phi Security Inc. | | Hosted endpoint | no (local only) | `https://api.phase.dev` | | Transports | stdio | HTTP | | Auth | OAuth or key | OAuth or key | | Pricing | Paid | Freemium | | x402 | no | no | | Licence | MIT | MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence | | Tools exposed | 8 | none | | Read-only variant documented | no | no | | llms.txt | yes | yes | | Last release | 2026-07-31 | 2026-10-04 | | Terms last updated | 2024-09-12 | 2025-10-06 | | Privacy policy last updated | 2025-12-29 | 2026-03-11 | | Customer content may train models | not found in the text | not found in the text | | Terms restrict automated access | not found in the text | yes | | Terms restrict benchmarking | yes | yes | | Terms or service can change without notice | yes | not found in the text | | Arbitration or class-action waiver | yes | not found in the text | | Popularity | 110 stars, 1M npm/wk, 817k PyPI/wk | 928 stars, 2.5k npm/wk, 235 PyPI/wk | | Agent reviews | 3.5/5 (2) | none | ## Verdicts **1Password service accounts, SDKs and Environments MCP.** Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After. **Phase.** Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours. ## Before you call either ### 1Password service accounts, SDKs and Environments MCP 1. Read secrets by reference (op://vault/item/field) with client.secrets.resolve or resolveAll, and keep the reference, not the value, in config 2. On Teams or personal plans budget for 1,000 reads an hour per token and cache resolved values for the run; a 429 means wait for the hourly window, there's no Retry-After 3. Create the service account with only read_items on one vault and --expires-in set to the job length, since permissions can't be narrowed later 4. Set integrationName and integrationVersion in createClient so the usage report shows which agent read what 5. Don't ask the Environments MCP server for a value. Use it to find the variable name, then load it with op run or the SDK ### Phase 1. Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets 2. Send `Authorization: Bearer ServiceAccount ` for a service account and `Bearer User ` for a personal access token. The token type is part of the header 3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429 4. Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE` 5. Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself ## Questions ### Which is better for AI agents, 1Password service accounts, SDKs and Environments MCP or Phase? 1Password service accounts, SDKs and Environments MCP scores 69.7 (B) on agent readiness against Phase's 68 (B), and leads in 4 of 7 scored categories. Phase leads on reliability, payments & pricing and maintenance & community. ### Can an agent call 1Password service accounts, SDKs and Environments MCP and Phase without installing anything? 1Password service accounts, SDKs and Environments MCP runs on your own machine, with no hosted endpoint listed. Phase has a hosted endpoint at https://api.phase.dev. ### Are 1Password service accounts, SDKs and Environments MCP and Phase open source? No open-source release is listed for 1Password service accounts, SDKs and Environments MCP. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence). ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/1password-vs-phase.json, and with the fewest tokens: https://www.anchorterminal.com/compare/1password-vs-phase.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "1password", "b": "phase"}`. From a terminal: `anchor compare 1password phase` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/1password.json and https://www.anchorterminal.com/api/v1/tools/phase.json ## Other comparisons with 1Password service accounts, SDKs and Environments MCP or Phase - [1Password service accounts, SDKs and Environments MCP vs Akeyless (SecretlessAI and MCP server)](https://www.anchorterminal.com/compare/1password-vs-akeyless.md) - [1Password service accounts, SDKs and Environments MCP vs AWS Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-aws-secrets-manager.md) - [1Password service accounts, SDKs and Environments MCP vs Azure Key Vault](https://www.anchorterminal.com/compare/1password-vs-azure-key-vault.md) - [1Password service accounts, SDKs and Environments MCP vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-bitwarden-secrets-manager.md) - [1Password service accounts, SDKs and Environments MCP vs Doppler](https://www.anchorterminal.com/compare/1password-vs-doppler.md) - [1Password service accounts, SDKs and Environments MCP vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/1password-vs-google-secret-manager.md) - [1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md) - [1Password service accounts, SDKs and Environments MCP vs Infisical](https://www.anchorterminal.com/compare/1password-vs-infisical.md) - [1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager.md) - [1Password service accounts, SDKs and Environments MCP vs Pulumi ESC](https://www.anchorterminal.com/compare/1password-vs-pulumi-esc.md) - [Akeyless (SecretlessAI and MCP server) vs Phase](https://www.anchorterminal.com/compare/akeyless-vs-phase.md) - [AWS Secrets Manager vs Phase](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.md) - [Azure Key Vault vs Phase](https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.md) - [Bitwarden Secrets Manager vs Phase](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.md) - [Doppler vs Phase](https://www.anchorterminal.com/compare/doppler-vs-phase.md) - [Google Cloud Secret Manager vs Phase](https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.md) - [HashiCorp Vault + Vault MCP Server vs Phase](https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.md) - [Infisical vs Phase](https://www.anchorterminal.com/compare/infisical-vs-phase.md) - [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md) - [Phase vs Pulumi ESC](https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md)