pkg.sopackage field notes

cask / rank 12

Install 1password-cli with Homebrew Cask

Command-line interface for 1Password. Version 2.38.1 via Homebrew Cask; verified 2026-07-30.

agent safety

Agent safety answer

1password-cli brokers access to secrets and vault items from local workflows.

Credential access

Can read secrets, documents, and account metadata after authentication.

Remote mutation

Can edit vault items and service-account-backed secret state.

Publish/artifact risk

Can export or inject secrets into downstream release tools.

Recommended control

Gate item reads, exports, edits, and service-account token use.

Agent-use guidance

Allow metadata inspection only; require approval for secret reads or item mutations.

install

Additional install commands

macOS

Homebrew Caskverified ยท 100%
brew install --cask 1password-cli

provider-native install command

overview

Package summary

Command-line interface for 1Password

Commands and aliases

  • op

history

Project history and usage

1Password CLI is the official op command for using 1Password from a terminal, scripts, and developer workflows.

Project history

The official get-started documentation describes 1Password CLI as bringing 1Password to the terminal, with installation paths for macOS, Windows, and Linux and integration with the desktop app for local authentication.

1Password's official CLI 2 release notes show an actively maintained product-history stream for the modern CLI, including package installer changes, desktop app integration fixes, shell plugin work, and Docker tag behavior after CLI 1 deprecation.

Adoption history

CLI adoption is tied to developer and operations workflows: Homebrew, winget, manual installs, Docker images, shell plugins, scripts, and desktop-app-backed authentication are all documented official distribution or usage paths.

How it is used

Users run op to sign in, manage vault items, retrieve secrets, automate scripts, and integrate 1Password with shell and development workflows. The configuration directory can be controlled with --config or OP_CONFIG_DIR, otherwise it follows documented XDG and legacy directory precedence.

Why package nerds care

For package maintainers, 1Password CLI is notable because the Homebrew cask wraps a proprietary vendor-distributed binary, while the install docs state the cask is maintained by both Homebrew and 1Password developers and downloads from AgileBits/1Password CDN domains.

Timeline

  • 2020s: 1Password CLI 2 becomes the actively maintained CLI line documented by the official CLI2 release notes.
  • 2020s: Official install docs document Homebrew, winget, Linux package managers, manual downloads, and desktop app integration.
  • 2025: CLI 2 release notes mention Docker tag behavior following CLI 1 deprecation.

Related projects

  • Related official surfaces include the 1Password desktop apps, 1Password Connect, shell plugins, Docker images, and the Homebrew Cask packaging repository.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for 1password-cli. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
${XDG_CONFIG_HOME}/op~/.config/op~/.op${XDG_CONFIG_HOME}/.op

executables

Installed executables

CommandKindExposureNote
opbinaryHomebrew cask binaryop

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version2.38.1
manager updated2026-07-30
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keycask:1password-cli
Version2.38.1
Package managerHomebrew Cask
Homepagehttps://developer.1password.com/docs/cli
Last updated2026-07-30T21:48:56Z
Pulseupdated
SHA-256027996374724375f7aa199cfff0443c722e0b42d0787ba96714c6499462c70c8
Download URLhttps://cache.agilebits.com/dist/1P/op2/pkg/v2.38.1/op_darwin_arm64_v2.38.1.zip
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation