wip-1passwordHeadless plugin for 1Password secrets using service accounts, resolving op:// references, reading/writing secrets, and listing vault items via JS SDK.
Install via ClawdBot CLI:
clawdbot install parkertoddbrooks/wip-1passwordGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
process.env.OPENAICalls external URL not in known-safe list
https://github.com/wipcomputer/wip-1passwordAudited Apr 18, 2026 · audit v1.0
Generated Mar 21, 2026
Automates the injection of API keys and credentials into CI/CD pipelines without hardcoding secrets. Resolves op:// references in configuration files at startup, ensuring secure, headless deployment workflows for DevOps teams.
Enables AI agents like Claude Code or OpenClaw to securely access and manage 1Password secrets during runtime. Supports reading API keys for external services and writing new secrets, ideal for autonomous AI applications requiring secure data handling.
Centralizes environment variable management across microservices by resolving secrets from 1Password at service startup. Prevents exposure of sensitive data in code repositories and simplifies updates to credentials in distributed systems.
Facilitates automated audits by listing and reading secrets from custom 1Password vaults to generate compliance reports. Helps security teams monitor access and usage of credentials without manual intervention, enhancing oversight.
Supports development of headless applications that require secure access to secrets without user interaction. Uses service accounts to read and write secrets programmatically, suitable for serverless functions or background services.
Offers a subscription-based service for integrating wip-1password into enterprise SaaS platforms. Provides managed support, updates, and compliance features, generating recurring revenue from businesses using 1Password for secret management.
Provides consulting services to help organizations implement and customize wip-1password for their specific workflows. Includes setup, training, and ongoing maintenance, with revenue from project-based fees and retainer agreements.
Monetizes the open-source wip-1password package by offering premium support, advanced features, or enterprise plugins. Generates revenue through support contracts and sales of enhanced capabilities beyond the basic MIT-licensed version.
💬 Integration Tip
Ensure the service account token is securely stored at ~/.openclaw/secrets/op-sa-token and configure openclaw.json to enable the plugin with a default vault for seamless startup resolution.
Scored Jun 19, 2026
Save durable memory without secrets
Direct REST API reader for Infisical secrets. Lightweight, no middleware. Use when the agent needs to fetch API keys or credentials from Infisical.
Mask sensitive company-project document content before analysis
1Password Connect API skill. Use when working with 1Password Connect for activity, vaults, heartbeat. Covers 15 endpoints.
On-screen agent alert: topmost message card + pulsating screen borders via Nameplate. Use before password-manager auth prompts or whenever blocked on the human.
Complete guide for using pass, the standard Unix password manager. Use this skill whenever the user asks about pass, password-store, managing passwords from...