# https://github.com/CakeRepository/1Password-MCP Project Manual

Generated on: 2026-05-22 15:55:01 UTC

## Table of Contents

- [Repository Overview](#overview)
- [Entrypoints and Runtime Surface](#entrypoints)
- [Architecture Evidence Map](#architecture)
- [Operations and Verification Boundaries](#operations)

<a id='overview'></a>

## Repository Overview

### Related Pages

Related topics: [Entrypoints and Runtime Surface](#entrypoints), [Architecture Evidence Map](#architecture), [Operations and Verification Boundaries](#operations)

<details>
<summary>Relevant source files</summary>

The following source files were used to generate this page:

- [README.md](https://github.com/CakeRepository/1Password-MCP/blob/main/README.md)
- [package.json](https://github.com/CakeRepository/1Password-MCP/blob/main/package.json)
- [src/client.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/client.ts)
- [src/config.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/config.ts)
- [src/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/index.ts)
- [src/logger.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/logger.ts)
- [src/types.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/types.ts)
- [src/utils.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/utils.ts)
- [src/prompts/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/prompts/index.ts)
- [src/resources/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/resources/index.ts)
- [src/tools/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/index.ts)
- [src/tools/item-delete.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/item-delete.ts)
</details>

# Repository Overview

This page is generated from repository evidence because the Human Wiki provider was unavailable. It intentionally limits itself to README and file-tree facts.

## README Evidence

# 1Password MCP Server

[![CI](https://github.com/CakeRepository/1Password-MCP/actions/workflows/ci.yml/badge.svg)](https://github.com/CakeRepository/1Password-MCP/actions/workflows/ci.yml)
[![npm](https://img.shields.io/npm/v/@takescake/1password-mcp)](https://www.npmjs.com/package/@takescake/1password-mcp)
[![License](https://img.shields.io/badge/license-Apache--2.0-blue)](LICENSE)

A community-built [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that connects MCP-compatible AI clients (Claude Desktop, VS Code Copilot, OpenAI Codex, Gemini, etc.) to **1Password** vaults via a [Service Account](https://developer.1password.com/docs/service-accounts/).

> **Not an official 1Password product.** This is a community project.

---

## Features

### Tools (8)

| Tool | Description |
|------|-------------|
| `vault_list` | List all accessible vaults |
| `item_lookup` | Search items by title in a vault |
| `item_delete` | Delete an item from a vault |
| `password_create` | Create a new password/login item |
| `password_read` | Retrieve a password via secret reference (`op://vault/item/field`) or vault/item ID |
| `password_update` | Rotate/update an existing password |
| `password_generate` | Generate a cryptographically secure random password |
| `password_generate_memorable` | Generate a memorable passphrase from ~500 dictionary words |

### Prompts (4)

| Prompt | Description |
|--------|-------------|
| `generate-secure-password` | Guided workflow to generate and store a secure password |
| `credential-rotation` | Step-by-step credential rotation: read, generate, update, verify |
| `vault-audit` | Audit vault contents: list items, categorize, flag concerns |
| `secret-reference-helper` | Construct `op://vault/item/field` references interactively |

### Resources (3)

| Resource URI | Description |
|-------------|-------------|
| `1password://config` | Current server configuration (non-secret) |
| `1password://vaults` | Browsable list of all accessible vaults |
| `1password://vaults/{vaultId}/items` | Browsable list of items in a vault |

---

## Quick Start

### Prerequisites

- **Node.js** >= 18
- A [1Password Service Account token](https://developer.1password.com/docs/service-accounts/)

### Claude Desktop / VS Code / IDEs (JSON)

```json
{
  "mcpServers": {
    "1password": {
      "command": "npx",
      "args": ["-y", "@takescake/1p

[excerpt truncated]

## Selected Source Inventory

- `README.md`
- `package.json`
- `src/client.ts`
- `src/config.ts`
- `src/index.ts`
- `src/logger.ts`
- `src/types.ts`
- `src/utils.ts`
- `src/prompts/index.ts`
- `src/resources/index.ts`
- `src/tools/index.ts`
- `src/tools/item-delete.ts`

| File | Evidence role | Size |
|---|---|---|
| `README.md` | README/product and usage evidence | 6558 bytes |
| `package.json` | package/runtime metadata | 1590 bytes |
| `src/client.ts` | implementation surface | 1359 bytes |
| `src/config.ts` | implementation surface | 4081 bytes |
| `src/index.ts` | implementation surface | 2257 bytes |
| `src/logger.ts` | implementation surface | 1194 bytes |
| `src/types.ts` | implementation surface | 1012 bytes |
| `src/utils.ts` | implementation surface | 7361 bytes |
| `src/prompts/index.ts` | implementation surface | 8034 bytes |
| `src/resources/index.ts` | implementation surface | 5235 bytes |
| `src/tools/index.ts` | implementation surface | 1025 bytes |
| `src/tools/item-delete.ts` | implementation surface | 1273 bytes |

Source: `[README.md:1-120]()`

---

<a id='entrypoints'></a>

## Entrypoints and Runtime Surface

### Related Pages

Related topics: [Repository Overview](#overview), [Architecture Evidence Map](#architecture), [Operations and Verification Boundaries](#operations)

<details>
<summary>Relevant source files</summary>

The following source files were used to generate this page:

- [README.md](https://github.com/CakeRepository/1Password-MCP/blob/main/README.md)
- [package.json](https://github.com/CakeRepository/1Password-MCP/blob/main/package.json)
- [src/client.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/client.ts)
- [src/config.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/config.ts)
- [src/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/index.ts)
- [src/logger.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/logger.ts)
- [src/types.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/types.ts)
- [src/utils.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/utils.ts)
- [src/prompts/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/prompts/index.ts)
- [src/resources/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/resources/index.ts)
- [src/tools/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/index.ts)
- [src/tools/item-delete.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/item-delete.ts)
</details>

# Entrypoints and Runtime Surface

The files below are the highest-signal candidates for how the project is installed, started, configured, or embedded. Treat this as an evidence map, not an inferred API contract.

| File | Evidence role | Size |
|---|---|---|
| `README.md` | README/product and usage evidence | 6558 bytes |
| `package.json` | package/runtime metadata | 1590 bytes |
| `src/client.ts` | implementation surface | 1359 bytes |
| `src/config.ts` | implementation surface | 4081 bytes |
| `src/index.ts` | implementation surface | 2257 bytes |
| `src/logger.ts` | implementation surface | 1194 bytes |
| `src/types.ts` | implementation surface | 1012 bytes |
| `src/utils.ts` | implementation surface | 7361 bytes |
| `src/prompts/index.ts` | implementation surface | 8034 bytes |
| `src/resources/index.ts` | implementation surface | 5235 bytes |
| `src/tools/index.ts` | implementation surface | 1025 bytes |
| `src/tools/item-delete.ts` | implementation surface | 1273 bytes |

Source: `[README.md:1-120](https://github.com/CakeRepository/1Password-MCP/blob/main/README.md)`

---

<a id='architecture'></a>

## Architecture Evidence Map

### Related Pages

Related topics: [Repository Overview](#overview), [Entrypoints and Runtime Surface](#entrypoints), [Operations and Verification Boundaries](#operations)

<details>
<summary>Relevant source files</summary>

The following source files were used to generate this page:

- [README.md](https://github.com/CakeRepository/1Password-MCP/blob/main/README.md)
- [package.json](https://github.com/CakeRepository/1Password-MCP/blob/main/package.json)
- [src/client.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/client.ts)
- [src/config.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/config.ts)
- [src/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/index.ts)
- [src/logger.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/logger.ts)
- [src/types.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/types.ts)
- [src/utils.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/utils.ts)
- [src/prompts/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/prompts/index.ts)
- [src/resources/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/resources/index.ts)
- [src/tools/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/index.ts)
- [src/tools/item-delete.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/item-delete.ts)
</details>

# Architecture Evidence Map

This section maps source paths into likely architectural areas based on repository layout only. Claims that require execution are intentionally not made here.

- `.`: `README.md`, `package.json`
- `src`: `src/client.ts`, `src/config.ts`, `src/index.ts`, `src/logger.ts`, `src/types.ts`, `src/utils.ts`

Source: `[package.json:1-120](https://github.com/CakeRepository/1Password-MCP/blob/main/package.json)`

---

<a id='operations'></a>

## Operations and Verification Boundaries

### Related Pages

Related topics: [Repository Overview](#overview), [Entrypoints and Runtime Surface](#entrypoints), [Architecture Evidence Map](#architecture)

<details>
<summary>Relevant source files</summary>

The following source files were used to generate this page:

- [README.md](https://github.com/CakeRepository/1Password-MCP/blob/main/README.md)
- [package.json](https://github.com/CakeRepository/1Password-MCP/blob/main/package.json)
- [src/client.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/client.ts)
- [src/config.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/config.ts)
- [src/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/index.ts)
- [src/logger.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/logger.ts)
- [src/types.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/types.ts)
- [src/utils.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/utils.ts)
- [src/prompts/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/prompts/index.ts)
- [src/resources/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/resources/index.ts)
- [src/tools/index.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/index.ts)
- [src/tools/item-delete.ts](https://github.com/CakeRepository/1Password-MCP/blob/main/src/tools/item-delete.ts)
</details>

# Operations and Verification Boundaries

Operational guidance is limited to files that are present in the repository. Before using this project in an agent workflow, verify install, quickstart, and runtime behavior in a sandbox.

- Documentation signal: `README.md`
- Runtime/package signal: `package.json`
- Source inspection signal: `src/client.ts`
- Source inspection signal: `src/config.ts`
- Source inspection signal: `src/index.ts`
- Source inspection signal: `src/logger.ts`
- Source inspection signal: `src/types.ts`
- Source inspection signal: `src/utils.ts`
- Source inspection signal: `src/prompts/index.ts`
- Source inspection signal: `src/resources/index.ts`

Source: `[src/client.ts:1-120](https://github.com/CakeRepository/1Password-MCP/blob/main/src/client.ts)`

---

---

## Doramagic Pitfall Log

Project: cakerepository/1password-mcp

Summary: Found 10 potential pitfall items; 0 are high/blocking. Highest priority: installation - 来源证据：Bug: serverInfo version reports 2.0.0 while package is 2.0.3.

## 1. installation · 来源证据：Bug: serverInfo version reports 2.0.0 while package is 2.0.3

- Severity: medium
- Evidence strength: source_linked
- Finding: GitHub 社区证据显示该项目存在一个安装相关的待验证问题：Bug: serverInfo version reports 2.0.0 while package is 2.0.3
- User impact: 可能增加新用户试用和生产接入成本。
- Suggested check: 来源显示可能已有修复、规避或版本变化，说明书中必须标注适用版本。
- Guardrail action: 不得脱离来源链接放大为确定性结论；需要标注适用版本和复核状态。
- Evidence: community_evidence:github | cevd_c441f769d48f47f1afd84343d4edca96 | https://github.com/CakeRepository/1Password-MCP/issues/2 | 来源讨论提到 npm 相关条件，需在安装/试用前复核。

## 2. configuration · 可能依赖账号登录

- Severity: medium
- Evidence strength: source_linked
- Finding: 项目说明出现 login/OAuth/account/sign in 等关键词。
- User impact: 用户无法离线体验，账号权限和授权范围需要提前说明。
- Suggested check: 确认登录是否必须、授权范围是什么、失败时如何降级。
- Guardrail action: 账号授权范围未知时，不能承诺本地离线可用。
- Evidence: packet_text.keyword_scan | mcp_registry:io.github.CakeRepository/1password:2.0.3 | https://registry.modelcontextprotocol.io/v0.1/servers/io.github.CakeRepository%2F1password/versions/2.0.3 | matched login / oauth / account keyword

## 3. capability · 能力判断依赖假设

- Severity: medium
- Evidence strength: source_linked
- Finding: README/documentation is current enough for a first validation pass.
- User impact: 假设不成立时，用户拿不到承诺的能力。
- Suggested check: 将假设转成下游验证清单。
- Guardrail action: 假设必须转成验证项；没有验证结果前不能写成事实。
- Evidence: capability.assumptions | mcp_registry:io.github.CakeRepository/1password:2.0.3 | https://registry.modelcontextprotocol.io/v0.1/servers/io.github.CakeRepository%2F1password/versions/2.0.3 | README/documentation is current enough for a first validation pass.

## 4. maintenance · 维护活跃度未知

- Severity: medium
- Evidence strength: source_linked
- Finding: 未记录 last_activity_observed。
- User impact: 新项目、停更项目和活跃项目会被混在一起，推荐信任度下降。
- Suggested check: 补 GitHub 最近 commit、release、issue/PR 响应信号。
- Guardrail action: 维护活跃度未知时，推荐强度不能标为高信任。
- Evidence: evidence.maintainer_signals | mcp_registry:io.github.CakeRepository/1password:2.0.3 | https://registry.modelcontextprotocol.io/v0.1/servers/io.github.CakeRepository%2F1password/versions/2.0.3 | last_activity_observed missing

## 5. security_permissions · 下游验证发现风险项

- Severity: medium
- Evidence strength: source_linked
- Finding: no_demo
- User impact: 下游已经要求复核，不能在页面中弱化。
- Suggested check: 进入安全/权限治理复核队列。
- Guardrail action: 下游风险存在时必须保持 review/recommendation 降级。
- Evidence: downstream_validation.risk_items | mcp_registry:io.github.CakeRepository/1password:2.0.3 | https://registry.modelcontextprotocol.io/v0.1/servers/io.github.CakeRepository%2F1password/versions/2.0.3 | no_demo; severity=medium

## 6. security_permissions · 存在评分风险

- Severity: medium
- Evidence strength: source_linked
- Finding: no_demo
- User impact: 风险会影响是否适合普通用户安装。
- Suggested check: 把风险写入边界卡，并确认是否需要人工复核。
- Guardrail action: 评分风险必须进入边界卡，不能只作为内部分数。
- Evidence: risks.scoring_risks | mcp_registry:io.github.CakeRepository/1password:2.0.3 | https://registry.modelcontextprotocol.io/v0.1/servers/io.github.CakeRepository%2F1password/versions/2.0.3 | no_demo; severity=medium

## 7. security_permissions · 来源证据：Feature Request: Support macOS Keychain as alternative to plaintext token in config

- Severity: medium
- Evidence strength: source_linked
- Finding: GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：Feature Request: Support macOS Keychain as alternative to plaintext token in config
- User impact: 可能影响授权、密钥配置或安全边界。
- Suggested check: 来源显示可能已有修复、规避或版本变化，说明书中必须标注适用版本。
- Guardrail action: 不得脱离来源链接放大为确定性结论；需要标注适用版本和复核状态。
- Evidence: community_evidence:github | cevd_fb3c79d607e04beb8c638c2b33173c07 | https://github.com/CakeRepository/1Password-MCP/issues/5 | 来源讨论提到 windows 相关条件，需在安装/试用前复核。

## 8. security_permissions · 来源证据：Security: upgrade @modelcontextprotocol/sdk to >=1.26.0 (GHSA-345p-7cg4-v4c7)

- Severity: medium
- Evidence strength: source_linked
- Finding: GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：Security: upgrade @modelcontextprotocol/sdk to >=1.26.0 (GHSA-345p-7cg4-v4c7)
- User impact: 可能增加新用户试用和生产接入成本。
- Suggested check: 来源显示可能已有修复、规避或版本变化，说明书中必须标注适用版本。
- Guardrail action: 不得脱离来源链接放大为确定性结论；需要标注适用版本和复核状态。
- Evidence: community_evidence:github | cevd_02e306c61d114d4ab6a734b1bb2f23ef | https://github.com/CakeRepository/1Password-MCP/issues/1 | 来源类型 github_issue 暴露的待验证使用条件。

## 9. maintenance · issue/PR 响应质量未知

- Severity: low
- Evidence strength: source_linked
- Finding: issue_or_pr_quality=unknown。
- User impact: 用户无法判断遇到问题后是否有人维护。
- Suggested check: 抽样最近 issue/PR，判断是否长期无人处理。
- Guardrail action: issue/PR 响应未知时，必须提示维护风险。
- Evidence: evidence.maintainer_signals | mcp_registry:io.github.CakeRepository/1password:2.0.3 | https://registry.modelcontextprotocol.io/v0.1/servers/io.github.CakeRepository%2F1password/versions/2.0.3 | issue_or_pr_quality=unknown

## 10. maintenance · 发布节奏不明确

- Severity: low
- Evidence strength: source_linked
- Finding: release_recency=unknown。
- User impact: 安装命令和文档可能落后于代码，用户踩坑概率升高。
- Suggested check: 确认最近 release/tag 和 README 安装命令是否一致。
- Guardrail action: 发布节奏未知或过期时，安装说明必须标注可能漂移。
- Evidence: evidence.maintainer_signals | mcp_registry:io.github.CakeRepository/1password:2.0.3 | https://registry.modelcontextprotocol.io/v0.1/servers/io.github.CakeRepository%2F1password/versions/2.0.3 | release_recency=unknown

<!-- canonical_name: cakerepository/1password-mcp; human_manual_source: deepwiki_human_wiki -->
