Credential access
Can read secrets, documents, and account metadata after authentication.
cask / rank 12
Command-line interface for 1Password. Version 2.38.1 via Homebrew Cask; verified 2026-07-30.
agent safety
1password-cli brokers access to secrets and vault items from local workflows.
Can read secrets, documents, and account metadata after authentication.
Can edit vault items and service-account-backed secret state.
Can export or inject secrets into downstream release tools.
Gate item reads, exports, edits, and service-account token use.
Allow metadata inspection only; require approval for secret reads or item mutations.
install
brew install --cask 1password-cliprovider-native install command
overview
Command-line interface for 1Password
history
1Password CLI is the official op command for using 1Password from a terminal, scripts, and developer workflows.
The official get-started documentation describes 1Password CLI as bringing 1Password to the terminal, with installation paths for macOS, Windows, and Linux and integration with the desktop app for local authentication.
1Password's official CLI 2 release notes show an actively maintained product-history stream for the modern CLI, including package installer changes, desktop app integration fixes, shell plugin work, and Docker tag behavior after CLI 1 deprecation.
CLI adoption is tied to developer and operations workflows: Homebrew, winget, manual installs, Docker images, shell plugins, scripts, and desktop-app-backed authentication are all documented official distribution or usage paths.
Users run op to sign in, manage vault items, retrieve secrets, automate scripts, and integrate 1Password with shell and development workflows. The configuration directory can be controlled with --config or OP_CONFIG_DIR, otherwise it follows documented XDG and legacy directory precedence.
For package maintainers, 1Password CLI is notable because the Homebrew cask wraps a proprietary vendor-distributed binary, while the install docs state the cask is maintained by both Homebrew and 1Password developers and downloads from AgileBits/1Password CDN domains.
security posture
No matching local secret-handling manifest was found for 1password-cli. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
${XDG_CONFIG_HOME}/op~/.config/op~/.op${XDG_CONFIG_HOME}/.opexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
op | binary | Homebrew cask binary | op |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | cask:1password-cli |
|---|---|
| Version | 2.38.1 |
| Package manager | Homebrew Cask |
| Homepage | https://developer.1password.com/docs/cli |
| Last updated | 2026-07-30T21:48:56Z |
| Pulse | updated |
| SHA-256 | 027996374724375f7aa199cfff0443c722e0b42d0787ba96714c6499462c70c8 |
| Download URL | https://cache.agilebits.com/dist/1P/op2/pkg/v2.38.1/op_darwin_arm64_v2.38.1.zip |
| Bottle | not recorded |
| Service | none declared |
source trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.