MCP server for 1Password service accounts
Most developer tooling work still happens through a UI a human drives. 1password MCP server moves it into the conversation instead. MCP server for 1Password service accounts.
Built on the MCP TypeScript SDK v2 with protocol negotiation for 2026-07-28 (and legacy clients). Secrets stay in 1Password; agents prefer op:// references and op_run so plaintext never has to land in the model transcript.
The server publishes 1 tool. What each one is for:
Discover — The Discover tool exposed by this serverSetup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client. The configuration blocks on this page cover the common clients.
Configuration is passed through the environment: OP_SERVICE_ACCOUNT_TOKEN, OP_KEYCHAIN_SERVICE, OP_KEYCHAIN_ACCOUNT, OP_MCP_ALLOWED_VAULTS, API_TOKEN, YOUR_SERVICE_ACCOUNT_TOKEN. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
You need two things: 1. Node.js 20 or newer 2. A 1Password Service Account with access to the vault(s) you want the AI to use
Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. 1password's toolset — Discover — is a fair guide to whether it matches your workflow. It is maintained by CakeRepository; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against 1password's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| Discover | The Discover tool exposed by this server. |
{
"mcpServers": {
"1password": {
"command": "npx",
"args": ["-y", "@takescake/1password-mcp"],
"env": {
"OP_SERVICE_ACCOUNT_TOKEN": "YOUR_SERVICE_ACCOUNT_TOKEN"
}
}
}
}Configuration as documented by the project. Restart the client after saving.
You need two things: 1. Node.js 20 or newer 2. A 1Password Service Account with access to the vault(s) you want the AI to use
| Variable | Description | Required |
|---|---|---|
| OP_SERVICE_ACCOUNT_TOKEN | Credential the server authenticates with. | Yes |
| OP_KEYCHAIN_SERVICE | Credential the server authenticates with. | Yes |
| OP_KEYCHAIN_ACCOUNT | Credential the server authenticates with. | Yes |
| OP_MCP_ALLOWED_VAULTS | Configuration value read at startup. | Optional |
| API_TOKEN | Credential the server authenticates with. | Yes |
| YOUR_SERVICE_ACCOUNT_TOKEN | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.