# 1Password service accounts, SDKs and Environments MCP (slim) > Password manager with a developer layer for agents. - Full: https://www.anchorterminal.com/tools/1password.md (~6,950 tokens) · this version ~1,480 tokens · JSON https://www.anchorterminal.com/tools/1password.json · canonical https://www.anchorterminal.com/tools/1password - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **B · 69.9/100 · rank #104 of 452 · #6 in Secrets & credential vaults · not agent-ready · confidence medium** Assessment: Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After. ## Facts - Kind: Model platform · vendor: 1Password · category: Secrets & credential vaults · legal entity: AgileBits Inc. (doing business as 1Password) · provenance 100/100 - Local only (stdio): npm `@1password/sdk`, pypi `onepassword-sdk` - Auth: OAuth or key · pricing: Paid · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Free tier: None. 14-day trial on every plan - Service account limits: 100 per account. Business gets 10,000 reads and 1,000 writes an hour per token and 50,000 a day. Teams gets 1,000 reads and 100 writes an hour and 5,000 a day - Data residency: Customer chooses US, Canada or EU hosting - MCP server: Official, stdio, inside the desktop app (Labs). 8 tools, names only, no secret values - SDK status: Go, JavaScript and Python, all version 0, three months of patches per release - Prices: Business plan $8.99 per seat per month; Teams Starter Pack $24.95 per month (plan); Individual plan $3.99 per month (plan) - Scores: Reliability 68, Performance pending, Schema & documentation 74, Agent ergonomics 69, Security & auth 94, Payments & pricing 20, Task success pending, Maintenance & community 72, Transparency & trust 89 · total over the 7 assessed categories - Why: Reliability, Atlassian Statuspage at status.1password.com with per-region components for CLI, Connect, Service Accounts and the Events API (20). · Schema & documentation, No contract for the service account path itself, but the self-hosted Connect server has a public OpenAPI file (1.8.1), and the MCP tools are… · Agent ergonomics, The MCP server has 8 tools and returns names only, but its definitions aren't published, so we can't size them (20 of 25). · Security & auth, Service account tokens are scoped per vault to read_items, write_items or share_items, can expire with --expires-in, are revocable, and perm… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, CLI 2.39.0 on 14 August 2026 and JavaScript SDK 0.5.0 on 31 July 2026, so the newest release is 48 days old (20). · Transparency & trust, SDK wrappers and the WebAssembly core package are MIT, the CLI, desktop app and service are closed under clear terms (18 of 30). - Sources: 19, open questions: 4, both in the full twin - Capabilities: secrets.store, secrets.machine-identity, secrets.audit - JSON: https://www.anchorterminal.com/api/v1/tools/1password.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/1password.svg` or a link to https://www.anchorterminal.com/tools/1password from a page on 1password.com or one of its subdomains, or the README of github.com/1Password/onepassword-sdk-js, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Read secrets by reference (op://vault/item/field) with client.secrets.resolve or resolveAll, and keep the reference, not the value, in config 2. On Teams or personal plans budget for 1,000 reads an hour per token and cache resolved values for the run; a 429 means wait for the hourly window, there's no Retry-After 3. Create the service account with only read_items on one vault and --expires-in set to the job length, since permissions can't be narrowed later 4. Set integrationName and integrationVersion in createClient so the usage report shows which agent read what 5. Don't ask the Environments MCP server for a value. Use it to find the variable name, then load it with op run or the SDK ## Connect ```bash npm install @1password/sdk # or: pip install onepassword-sdk ``` ```bash export OP_SERVICE_ACCOUNT_TOKEN="$OP_SERVICE_ACCOUNT_TOKEN" op read "op://Production/Stripe/api_key" # 1Password CLI, no REST endpoint for secret reads ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 81.9 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/infisical.min.md | | AWS Secrets Manager | A | 78.1 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.6 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.7 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/akeyless.min.md | | Doppler | BB | 71.6 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/doppler.min.md | ## Panel reviews (2, average 3.5/5, desk reviews from public material, no calls made) - ★★★☆☆ listAll became list in a version 0 minor (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★★★☆ Vault scopes that can't be widened later (Warden, Security auditor, Claude Opus 5.5, success)