Local MCP access to approved 1Password fields without exposing plaintext secrets to AI agents.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Local MCP access to approved 1Password items and profile data for AI agents.
npm package Β· setup guide Β· security model Β· uninstall guide
Agents receive encrypted local handles, not plaintext 1Password secrets. At the moment of copy or paste, the MCP resolves the selected field locally through the 1Password CLI and sends it to the OS clipboard or active app.
The repo contains no personal 1Password data. Every install connects to that user's own 1Password CLI and local approval policy.
Not affiliated with or endorsed by 1Password.
MCPVAULT.MCPVAULT.MCPVAULT fields for specific websites.The MCP tools only expose approved fields from the configured agent vault. The local profile-data section can also expose user-entered values such as email, phone, address, name, and company.
Install from npm:
Run the friendly installer. It detects supported MCP clients, shows what it found, and asks before changing their user configuration. On macOS it separately offers the optional visible menu-bar shortcut:
Or install from GitHub:
Prefer explicit commands? Check your setup and connect clients manually:
Connect every detected MCP client with one command:
Start the local console:
Open:
Full walkthrough: docs/USER_GUIDE.md
Uninstall guide: docs/UNINSTALL.md
No. Installing the npm package itself adds commands only. It does not install a launch agent, daemon, background service, startup item, browser extension, or hidden resident process.
onepassword-agent-mcp admin runs the local approval console only while that terminal process is alive.onepassword-agent-mcp mcp is a stdio MCP server. MCP clients such as Claude Code, Codex, or VS Code launch it as a child process when they need it.onepassword-agent-mcp setup ... --apply only writes MCP client configuration. Existing JSON files are backed up before a merge.~/.onepassword-mcp.You can see this explanation any time:
On macOS, the guided installer can add a clearly labeled 1P item to the menu bar. You can also enable it later under Mac Menu Bar Shortcut in the local admin page.
The companion is built locally from the readable Swift source in native/MenuBarApp.swift. No opaque app binary is shipped in the npm package. The generated app uses the project's teal shield logo, is placed at ~/Applications/1Password Agent MCP.app, and never asks for administrator access.
Manual controls:
Use menubar remove to close the visible shortcut without uninstalling it, and menubar launch to show it again. Use menubar install after uninstalling it. The local admin page offers the same installation controls under Mac Menu Bar Shortcut while the admin console is running.
The menu contains Open Admin Console, Stop Admin Console, Launch Menu Bar at Login, Remove From Menu Bar, and Uninstall Menu Bar Shortcut. Open Admin Console starts the console when needed and then opens it, so there is no separate Start action. Remove From Menu Bar only closes the visible helper; it stays installed and can be reopened. Uninstall Menu Bar Shortcut removes the helper and its login item after confirmation. Neither action changes MCP client configuration, local approvals, MCPVAULT, or 1Password items.
The admin console itself has explicit process controls:
op)OP_SERVICE_ACCOUNT_TOKENmacOS:
Enable the 1Password desktop integration:
The console is a simple left-to-right vault flow:
MCPVAULT exists and can create it.MCPVAULT area. Drag an item from the left list onto it, then choose Copy or Move.MCPVAULT.Copy is the safe default. Copy now uses 1Password's revealed JSON clone pipe so the destination item keeps the original fields. Move is available, but 1Password creates a new item in the destination vault and deletes the original item from the source vault.
After copying, nothing is shared with agents yet. In All Fields, copied items stay compact so the page remains easy to scan. Click Review Details on an item, tick only the details the agent may use, then click Approve Selected. Credit cards show normal checkout details separately from sensitive details like CVV or PIN. Blank allowed-sites fields mean the approved item may be used on all URLs. Items in MCPVAULT can also be deleted from the approval console after a confirmation prompt.
When agents are allowed to create new credentials, those items are saved into MCPVAULT first. In Approve Agent Items, open the saved item and use Save this item to another vault to copy or move it into a normal 1Password vault. Copy keeps the agent-vault version. Move removes it from MCPVAULT and removes local approvals for that copied item.
The setup CLI prints a dry run by default. It detects Claude Code, Claude Desktop, Codex, VS Code, Xcode coding agents, and Raycast AI when they are installed:
Apply setup to every detected client:
The command uses absolute executable paths so GUI apps do not depend on Terminal's PATH. Claude Desktop and VS Code JSON are merged with timestamped backups. Xcode's private Codex and Claude configuration folders are handled separately because Xcode does not use the normal CLI configuration.
Raycast stores MCP configuration in app-managed storage and does not expose a supported external config writer. The CLI opens Raycast's official Import Servers screen; review the prepared entry and confirm it once in Raycast. This is the only interactive client-specific step.
Equivalent command:
Equivalent command:
Equivalent VS Code command:
Workspace fallback at .vscode/mcp.json:
The CLI safely merges the server into Claude Desktop's user JSON and preserves all other settings.
This configures the isolated Codex and Claude Agent environments used only inside Xcode.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/onepassword-agent-mcp)<a href="https://allmcps.com/mcp/onepassword-agent-mcp"><img src="https://allmcps.com/api/badge/onepassword-agent-mcp?style=directory" alt="Onepassword Agent MCP on AllMCPs" /></a>