1Password

1Password logo
Stores passwords and secrets in encrypted vaults that your team can access and manage centrally.

1Password API

Sign in
both. API key or OAuth 2.0; API access on: 1Password Business or 1Password Enterprise Password Manager account (not included with 1Password Teams)Source

MCP server

What it is
Official 1Password Environments MCP server runs locally in the 1Password desktop app over stdio (command 1password-mcp); no fixed endpoint URL.

Checked on 2026-10-10 in the developer documentation.

How to use 1Password

This guide gets you from "I have passwords scattered across a browser, a notes file and my memory" to a clean, single vault that fills every login on demand and shares access to your team without anyone emailing a credential again. It is for anyone running more than a handful of accounts who wants password hygiene to be automatic, and for small teams who need to hand out access as a structure rather than a favour. By the end you will have 1Password set up the right way, the daily workflow running without friction, and the power features that turn it from a password box into the spine of how you manage secrets.

Getting set up

The first decision is the account type, and it matters more than people expect. A personal account protects your vault with a master password plus a separate account key, so even 1Password cannot read your data. A team or business account adds shared vaults, admin controls and provisioning, and it changes how you think: access becomes something you grant and revoke centrally, not something locked in one person's head. If you run anything resembling a company, start on the business tier even as a solo operator, because retrofitting team structure later is more painful than starting with it.

Read the full guide

Once the account exists, install everywhere you actually work: the desktop app, the browser extension, and the mobile app. The browser extension is the piece that earns its keep daily, so do not skip it and rely on copy-paste. Turn on biometric unlock (Touch ID, Face ID, Windows Hello) so unlocking is a fingerprint rather than a re-typed passphrase, and you stop being tempted to weaken the master password just to type it less.

Save your Emergency Kit, the document holding your account key, somewhere genuinely safe and offline. If you lose the account key on a personal plan, nobody recovers your vault, which is the point of the design and also the one way to lock yourself out permanently. Treat that piece of paper as seriously as a passport.

Before you import anything, plan your vaults. Vaults are the unit of sharing, so decide the structure up front: a Private vault for you alone, a shared household or team vault for things others need, and separate vaults for anything with a different access boundary (client work, finance, infrastructure). Then import your existing passwords (from a browser or another manager), and run the built-in audit to find the reused and weak ones.

How to actually use it

The order that delivers value fastest is import, then clean, then live in it.

Start by importing every credential you can find, including the ones rotting in your browser. Then open the security audit (1Password calls it Watchtower) and work the list: reused passwords first, because one breach there exposes several accounts, then weak passwords, then any flagged in a known breach. For each one, visit the site, change the password, and let 1Password generate a long unique replacement. You are not trying to fix everything in a day; you are trying to kill the reuse that turns one leak into many.

Once the vault is clean, change your habit: never type a password again. When you sign up for something new, let the extension suggest and save a generated password. When you log in, let it fill. When the browser offers to save a password, decline and let 1Password capture it instead, so you keep one source of truth rather than two half-full ones.

Then push past passwords. Store the things you currently keep in a notes app or a drawer: card details for faster checkout, secure notes for licences and recovery codes, identities for forms, and software keys. The more of your sensitive small data lives here, the more the single-vault habit actually holds.

Power moves

The feature that separates a pro is sharing through vaults, not through messages. When a teammate needs access to an account, you add the item to a shared vault and grant them the vault, and when they leave you revoke it in one place. Nobody ever pastes a password into a chat again, and offboarding stops being a frantic password-reset spree.

Turn on the one-time-password feature so 1Password stores your two-factor codes alongside the login and fills both together. This sounds like putting all your eggs in one basket, and it is a real trade-off, but for most accounts the convenience that makes you actually use unique passwords outweighs the theoretical loss, with your truly critical accounts kept on a separate hardware key.

For sharing outside your team, use the secure-link feature instead of email: it creates a link that expires and can be limited to specific recipients, so a one-off credential hand-off does not sit in someone's inbox forever.

If you build or operate software, 1Password reaches into developer territory: it stores SSH keys and can act as your SSH agent, it manages environment secrets, and it ships a command-line tool. That means a script can pull a secret at runtime from the vault rather than from a plaintext .env file, which is a genuine security upgrade for any real workflow.

Where it fits your stack

In a growth and ops stack, 1Password is the layer underneath everything that needs a login or a key. It plugs into the browser where most of your marketing and ops tools live, so every SaaS account fills automatically. On the team side, it integrates with identity providers for single sign-on and automated provisioning, so people get the right vaults when they join and lose them when they leave.

For the technical side of the stack it connects to the tools that hold secrets: the CLI feeds credentials into scripts and CI, the SSH agent handles server access, and secret references let an app read a key from the vault instead of from a committed file. The effect is that credentials stop being copied into a dozen places and start living in one place that the rest of your tooling reads from.

Pitfalls to avoid

The biggest mistake is a weak or memorable master password. Everything rests on it, so make it a long passphrase you can remember but nobody can guess, and never reuse it anywhere else.

The second is losing the account key. Save the Emergency Kit offline before you do anything else, because there is no reset button by design.

The third is half-adopting it: saving some passwords in 1Password and letting the browser keep the rest. Two sources of truth means you never trust either, and you fall back to old habits. Pick 1Password, turn off the browser's own password saving, and migrate fully.

The fourth, on teams, is dumping everything into one shared vault. That hands everyone access to everything and defeats the structure. Split vaults by access boundary from the start.

Finally, do not treat the audit as a one-time chore. New weak and breached passwords appear over time, so check Watchtower occasionally and keep the reuse count at zero.

How to automate 1Password

Native integrations

1Password lets people sign in with your single sign-on login, and the business plans include provisioning and deprovisioning. Set that up with the identity provider you already use, and check that removing someone from your directory also removes their access to shared vaults.

Automation idea: tie vault access to team membership. When someone joins the sales team, they get the sales vault, and when they leave, it goes.

API and webhooks

Developers get several routes. The command-line tool reads secrets into scripts. Service accounts give a machine its own limited access. The Connect server exposes a REST API, and there are SDKs for code.

Automation idea: stop keeping keys in env files. Let your deployment script ask 1Password for the key when it runs, so a leaked repository leaks nothing.

MCP server

1Password has official MCP servers, but not for the password vault itself. The vendor states it will not expose raw credentials through MCP. The servers cover SaaS Manager (formerly Trelica), Device Trust and Environments. The remote SaaS Manager connection is read-only.

Automation idea: connect an AI assistant to SaaS Manager and ask it which apps and users your company has, then review that list once a quarter.