Automic VaultAutomic Vault

cask

Install 1password-cli with Homebrew Cask

Command-line interface for 1Password. Version 2.35.0 via Homebrew Cask; verified 2026-07-13. Also installable with nix: nix profile install nixpkgs#_1password-cli.

agent safety

Agent safety answer

1password-cli brokers access to secrets and vault items from local workflows.

Credential access

Can read secrets, documents, and account metadata after authentication.

Remote mutation

Can edit vault items and service-account-backed secret state.

Publish/artifact risk

Can export or inject secrets into downstream release tools.

Recommended control

Gate item reads, exports, edits, and service-account token use.

Agent-use guidance

Allow metadata inspection only; require approval for secret reads or item mutations.

install

Additional install commands

macOS

Homebrew Caskverified · 100%
brew install --cask 1password-cli

local Homebrew cask metadata

overview

Package summary

Command-line interface for 1Password

Commands and aliases

  • op

history

Project history and usage

1Password CLI is the official op command for using 1Password from a terminal, scripts, and developer workflows.

Project history

The official get-started documentation describes 1Password CLI as bringing 1Password to the terminal, with installation paths for macOS, Windows, and Linux and integration with the desktop app for local authentication.

1Password's official CLI 2 release notes show an actively maintained product-history stream for the modern CLI, including package installer changes, desktop app integration fixes, shell plugin work, and Docker tag behavior after CLI 1 deprecation.

Adoption history

CLI adoption is tied to developer and operations workflows: Homebrew, winget, manual installs, Docker images, shell plugins, scripts, and desktop-app-backed authentication are all documented official distribution or usage paths.

How it is used

Users run op to sign in, manage vault items, retrieve secrets, automate scripts, and integrate 1Password with shell and development workflows. The configuration directory can be controlled with --config or OP_CONFIG_DIR, otherwise it follows documented XDG and legacy directory precedence.

Why package nerds care

For package maintainers, 1Password CLI is notable because the Homebrew cask wraps a proprietary vendor-distributed binary, while the install docs state the cask is maintained by both Homebrew and 1Password developers and downloads from AgileBits/1Password CDN domains.

Timeline

  • 2020s: 1Password CLI 2 becomes the actively maintained CLI line documented by the official CLI2 release notes.
  • 2020s: Official install docs document Homebrew, winget, Linux package managers, manual downloads, and desktop app integration.
  • 2025: CLI 2 release notes mention Docker tag behavior following CLI 1 deprecation.

Related projects

  • Related official surfaces include the 1Password desktop apps, 1Password Connect, shell plugins, Docker images, and the Homebrew Cask packaging repository.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for 1password-cli. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
${XDG_CONFIG_HOME}/op~/.config/op~/.op${XDG_CONFIG_HOME}/.op

executables

Installed executables

CommandKindExposureNote
opbinaryHomebrew cask binaryop

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version2.35.0
manager updated2026-07-13
local dataok
upstreamnot checked
latest detectednot detected

https://developer.1password.com/docs/cli

install metadata

Package metadata

Package keycask:1password-cli
Version2.35.0
Package managerHomebrew Cask
Package manager pagehttps://formulae.brew.sh/cask/1password-cli
Homepagehttps://developer.1password.com/docs/cli
Upstream docshttps://developer.1password.com/docs/cli
Source archivehttps://cache.agilebits.com/dist/1P/op2/pkg/v2.35.0/op_darwin_arm64_v2.35.0.zip
Last updated2026-07-13T16:16:01Z
Pulseupdated
SHA-2566dcb9528c1ace2f18f7808418afe5dd58ed1376038aa4f907af7e0462582712b
Download URLhttps://cache.agilebits.com/dist/1P/op2/pkg/v2.35.0/op_darwin_arm64_v2.35.0.zip
Bottlenot recorded
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew cask API
Taphomebrew/cask
Full Token1password-cli
Names
  • 1Password CLI
Conflicts With
Artifacts
Deprecatedno
Disabledno

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

_1password-cli

nix profile install nixpkgs#_1password-cli
  • normalized package name match
  • Matched by: 1password Cli
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/_1/_1password-cli/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
MacPorts95%

1password-cli

sudo port install 1password-cli
  • normalized package name match
  • Matched by: 1password Cli
MacPorts ports tree · api.github.com · MacPorts ports tree: security/1password-cli/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/1password-cli

scoop install main/1password-cli
  • normalized package name match
  • Matched by: 1password Cli
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/1password-cli.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

AgileBits.1Password.CLI

winget install --id AgileBits.1Password.CLI -e
  • normalized package name match
  • Matched by: 1password Cli
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: AgileBits.1Password.CLI from https://cdn.winget.microsoft.com/cache/source.msix
Chocolatey92%

op

choco install op
  • installed executable or alias match
  • Matched by: Op
Chocolatey community package catalog · community.chocolatey.org · Chocolatey community package catalog: op from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='11','office365homepremium'

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment