1Password CLI Integration for Openclaw

A specialized skill for AI agents to securely install, authenticate, and manage credentials using the 1Password CLI.

steipete
v1.0.1
Jan 8, 2026
53
34.1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install 1password

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install 1password using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is 1Password CLI Integration?

The 1Password CLI skill empowers AI coding agents to interact directly with your 1Password vaults within a secure terminal environment. By utilizing Openclaw Skills, developers can automate the setup of the official 1Password command-line tool (op), handle complex multi-account authentication, and retrieve secrets without ever exposing sensitive data to plain text logs or chat interfaces.

This skill is designed to bridge the gap between AI automation and secure credential management. It ensures that sensitive API keys and environment variables are handled through 1Password's secure infrastructure, utilizing desktop app integration for biometric or master password verification while maintaining a persistent session for the agent's tasks.

1Password CLI Integration Use Cases

  • Automating the installation of the 1Password CLI on macOS and Linux systems.
  • Securely fetching environment variables for local development scripts without manual entry.
  • Injecting credentials into configuration files using op inject during automated deployments.
  • Managing multiple 1Password accounts and switching between them for different projects.
  • Verifying the current authentication status and vault accessibility within an AI-driven session.

How 1Password CLI Integration Works

  1. The agent identifies the operating system and shell to ensure the correct environment for the 1Password CLI.
  2. It verifies if the op binary is present and installs it via Homebrew if necessary.
  3. A dedicated tmux session with a unique socket name is created to manage the TTY requirements of the CLI.
  4. The agent initiates an authentication flow, prompting the user to unlock their 1Password desktop application.
  5. Commands are executed within the isolated tmux session to read, search, or inject secrets as requested.
  6. The agent captures the command output securely and terminates the tmux session once the task is complete.

1Password CLI Integration Setup

To use this integration with Openclaw Skills, first ensure you have the 1Password desktop app installed. Then, install the CLI via your package manager:

brew install 1password-cli

Enable the CLI integration in your 1Password settings (Settings > Developer > CLI Integration). Finally, ensure tmux is installed on your system, as this skill requires it for secure session handling. You can then trigger the sign-in flow through your agent to begin accessing your vaults.

1Password CLI Integration Data Schema & Taxonomy

The skill manages its operational state and security metadata using the following structure:

Component Details
Binary Name op (1Password CLI)
Session Handling Isolated tmux sockets via CLAWDBOT_TMUX_SOCKET_DIR
Session Naming Timestamped sessions (e.g., op-auth-YYYYMMDD-HHMMSS)
Authentication Persistent within the specific tmux socket until session termination
Output Guardrails Pane capture used to prevent secret leakage into standard output streams

1Password CLI Integration Advanced Features

  • Mandatory tmux session isolation to prevent authentication re-prompts and failures.
  • Support for op run and op inject to handle secrets as environment variables without disk persistence.
  • Multi-account management using the --account flag or OP_ACCOUNT environment variable.
  • Automated vault verification using op whoami to ensure the agent has the correct permissions.
  • Integration with the local 1Password desktop agent for secure, non-password-based unlocking.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*