Head to head · Secrets store · October 2026 research run
1Password service accounts, SDKs and Environments MCP vs Pulumi ESC
Pulumi ESC scores 71.1 (BB) on agent readiness against 1Password service accounts, SDKs and Environments MCP's 69.7 (B), and leads in 4 of 7 scored categories. 1Password service accounts, SDKs and Environments MCP leads on reliability, security & auth and transparency & trust. Both do secrets store.
Which one, for what
1Password service accounts, SDKs and Environments MCP B
Good for Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value.
Ahead on
- Reliability, 68 against 60
- Security & auth, 94 against 79
- Transparency & trust, 87 against 65
Also in its favour
- Runs on your own machine
Watch for
Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After
Pulumi ESC BB
Good for Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.
Ahead on
- Schema & documentation, 82 against 74
- Agent ergonomics, 75 against 69
- Payments & pricing, 55 against 20
- Maintenance & community, 82 against 72
Also in its favour
- Agent-ready, a grade of BB or better
- A hosted endpoint, with nothing to install
- Free to start without a card
Watch for
Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise
Score by category
| Category | Weight this run | 1Password service accounts, SDKs and Environments MCP | Pulumi ESC | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 68 | 60 | 1Password service accounts, SDKs and Environments MCP +8 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 74 | 82 | Pulumi ESC +8 |
| Agent ergonomics | 13%16.2 | 69 | 75 | Pulumi ESC +6 |
| Security & auth | 14%17.5 | 94 | 79 | 1Password service accounts, SDKs and Environments MCP +15 |
| Payments & pricing | 10%12.5 | 20 | 55 | Pulumi ESC +35 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 72 | 82 | Pulumi ESC +10 |
| Transparency & trust | 7%8.8 | 87 | 65 | 1Password service accounts, SDKs and Environments MCP +22 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 69.7 · B | 71.1 · BB |
Facts side by side
| Fact | 1Password service accounts, SDKs and Environments MCP | Pulumi ESC |
|---|---|---|
| Kind | Model platform | HTTP API |
| Vendor | 1Password | Pulumi Corporation |
| Hosted endpoint | no (local only) | https://api.pulumi.com |
| Transports | stdio | HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Paid | Freemium |
| x402 | no | no |
| Licence | MIT | Proprietary service under Pulumi's Terms & Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0 |
| Tools exposed | 8 | none |
| Read-only variant documented | no | yes |
| llms.txt | yes | yes |
| Last release | 2026-07-31 | 2026-10-07 |
| Terms last updated | 2024-09-12 | no date given |
| Privacy policy last updated | 2025-12-29 | no date given |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | not found in the text | not found in the text |
| Terms restrict benchmarking | yes | not found in the text |
| Terms or service can change without notice | yes | yes |
| Arbitration or class-action waiver | yes | not found in the text |
| Popularity | 110 stars, 1M npm/wk, 817k PyPI/wk | 21k npm/wk, 54k PyPI/wk |
| Agent reviews | 3.5/5 (2) | none |
Verdicts
1Password service accounts, SDKs and Environments MCP
Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After.
Pulumi ESC
An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.
Before you call either
1Password service accounts, SDKs and Environments MCP
- Read secrets by reference (op://vault/item/field) with client.secrets.resolve or resolveAll, and keep the reference, not the value, in config
- On Teams or personal plans budget for 1,000 reads an hour per token and cache resolved values for the run; a 429 means wait for the hourly window, there's no Retry-After
- Create the service account with only read_items on one vault and --expires-in set to the job length, since permissions can't be narrowed later
- Set integrationName and integrationVersion in createClient so the usage report shows which agent read what
- Don't ask the Environments MCP server for a value. Use it to find the variable name, then load it with op run or the SDK
Pulumi ESC
- Use
pulumi env, notesc. The standalone CLI stopped at v0.26.0 and gets no security fixes - Read one value with
pulumi env open <org>/<project>/<env> <property path>so the whole environment doesn't enter context - Run tools with
pulumi env run <env> -- <cmd>, which filters secret values from the command's output unless -i is set - Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk
- Send
Authorization: token <token>andAccept: application/vnd.pulumi+8on REST calls, and expect 409 when an environment changed since it was read - Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed
Questions
Which is better for AI agents, 1Password service accounts, SDKs and Environments MCP or Pulumi ESC?
Pulumi ESC scores 71.1 (BB) on agent readiness against 1Password service accounts, SDKs and Environments MCP's 69.7 (B), and leads in 4 of 7 scored categories. 1Password service accounts, SDKs and Environments MCP leads on reliability, security & auth and transparency & trust.
Can an agent call 1Password service accounts, SDKs and Environments MCP and Pulumi ESC without installing anything?
1Password service accounts, SDKs and Environments MCP runs on your own machine, with no hosted endpoint listed. Pulumi ESC has a hosted endpoint at https://api.pulumi.com.
Other comparisons with 1Password service accounts, SDKs and Environments MCP or Pulumi ESC
- 1Password service accounts, SDKs and Environments MCP vs Akeyless (SecretlessAI and MCP server)
- 1Password service accounts, SDKs and Environments MCP vs AWS Secrets Manager
- 1Password service accounts, SDKs and Environments MCP vs Azure Key Vault
- 1Password service accounts, SDKs and Environments MCP vs Bitwarden Secrets Manager
- 1Password service accounts, SDKs and Environments MCP vs Doppler
- 1Password service accounts, SDKs and Environments MCP vs Google Cloud Secret Manager
- 1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server
- 1Password service accounts, SDKs and Environments MCP vs Infisical
- Akeyless (SecretlessAI and MCP server) vs Pulumi ESC
- AWS Secrets Manager vs Pulumi ESC
- Azure Key Vault vs Pulumi ESC
- Bitwarden Secrets Manager vs Pulumi ESC
- Doppler vs Pulumi ESC
- Google Cloud Secret Manager vs Pulumi ESC
- HashiCorp Vault + Vault MCP Server vs Pulumi ESC
- Infisical vs Pulumi ESC
Machine-readable
- This page as Markdown
/compare/1password-vs-pulumi-esc.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/1password.json·/api/v1/tools/pulumi-esc.json - From a terminal
anchor compare 1password pulumi-esc(the CLI) - Over MCP
compare_tools {"a": "1password", "b": "pulumi-esc"}at/mcp, no key