Onepassword Agent MCP server
Local MCP access to approved 1Password fields without exposing plaintext secrets to AI agents.
0 stars87 downloads/wk
Reviews
Write oneNobody has reviewed Onepassword Agent yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Onepassword Agent tools (14, 1 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
admin_ui_infoReturn the local admin UI URL and state path. Does not return secrets.
clear_password_clipboardClear the OS clipboard after a copy/paste password operation.
clear_secret_clipboardClear the OS clipboard after a copy/paste operation.
copy_passwordCompatibility alias for copy_secret. Resolves an encrypted handle, copies it to the clipboard, and returns no plaintext.
copy_secretResolve an encrypted secret handle at the last moment, copy the value to the OS clipboard, and return no plaintext.
find_passwords_for_siteCompatibility alias for find_secrets_for_site. Returns approved encrypted handles and never returns plaintext.
find_secrets_for_siteReturn approved encrypted handles for a website. Handles can represent passwords, API credentials, credit-card fields, secure notes, or other approved 1Password fields. Plaintext is never returned.
get_profile_dataReturn user-defined profile data from the local admin page, such as email, phone, address, name, company, or username. This tool returns plaintext profile values that the user explicitly added for agent use.
list_approved_passwordsCompatibility alias for list_approved_secrets. Does not return plaintext secret values.
list_approved_secretsList approved encrypted handles and allowed sites. Does not return plaintext secret values.
onepassword_statusCheck local policy and 1Password CLI status. Never returns secrets.
paste_passwordCompatibility alias for paste_secret. Resolves an encrypted handle, pastes it into the active app, and returns no plaintext.
paste_secretResolve an encrypted secret handle, copy it to the clipboard, paste into the active app, and return no plaintext.
save_secret_itemwrite actionCreate a new item in the configured MCPVAULT. Use this when the user asks the agent to save a new password, API credential, secure note, or credit-card entry. Secret values are sent to the local 1Password CLI through stdin, not command arguments.
Public scan report
scanner v0.1.7 · 2026-09-19 · same rubric, same numbers if you re-run it
- Code scan41 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 3 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Install directly
Runs npx -y onepassword-agent-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add onepassword-agent-mcp -- npx -y onepassword-agent-mcp
Onepassword Agent: common questions
- Is Onepassword Agent MCP server safe?
- Yes, by our scan: it is graded A (92/100). Read the Onepassword Agent safety report
- How do I install Onepassword Agent?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Onepassword Agent need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Onepassword Agent maintained?
- The last commit was 4 days ago (2026-09-16). The latest release is v0.3.8.
- What can I use instead of Onepassword Agent?
- Servers from other publishers that do the same job: Actual Budget MCP Server, PatchX Freenote Agent MCP server and Husk MCP server. Compare all Onepassword Agent alternatives.
Alternatives to Onepassword Agent
Same job from other publishers: the closest match first, then the best rated.
- Actual Budget MCP ServerMCP server exposing Actual Budget accounts, transactions, budgets and reporting to LLM assistants.not reviewedEstablishedB
- PatchX Freenote AgentPatchX Freenote MCP: summaries, memories, model results and user-approved webhook workflows.not reviewedGrowingA
- HuskLocal-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configsnot reviewedGrowingA