wip-1passwordHeadless plugin for 1Password secrets using service accounts, resolving op:// references, reading/writing secrets, and listing vault items via JS SDK.
Install via ClawdBot CLI:
clawdbot install parkertoddbrooks/wip-1passwordGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
process.env.OPENAICalls external URL not in known-safe list
https://github.com/wipcomputer/wip-1passwordAudited Apr 18, 2026 · audit v1.0
Generated Mar 21, 2026
Automates the injection of API keys and credentials into CI/CD pipelines without hardcoding secrets. Resolves op:// references in configuration files at startup, ensuring secure, headless deployment workflows for DevOps teams.
Enables AI agents like Claude Code or OpenClaw to securely access and manage 1Password secrets during runtime. Supports reading API keys for external services and writing new secrets, ideal for autonomous AI applications requiring secure data handling.
Centralizes environment variable management across microservices by resolving secrets from 1Password at service startup. Prevents exposure of sensitive data in code repositories and simplifies updates to credentials in distributed systems.
Facilitates automated audits by listing and reading secrets from custom 1Password vaults to generate compliance reports. Helps security teams monitor access and usage of credentials without manual intervention, enhancing oversight.
Supports development of headless applications that require secure access to secrets without user interaction. Uses service accounts to read and write secrets programmatically, suitable for serverless functions or background services.
Offers a subscription-based service for integrating wip-1password into enterprise SaaS platforms. Provides managed support, updates, and compliance features, generating recurring revenue from businesses using 1Password for secret management.
Provides consulting services to help organizations implement and customize wip-1password for their specific workflows. Includes setup, training, and ongoing maintenance, with revenue from project-based fees and retainer agreements.
Monetizes the open-source wip-1password package by offering premium support, advanced features, or enterprise plugins. Generates revenue through support contracts and sales of enhanced capabilities beyond the basic MIT-licensed version.
💬 Integration Tip
Ensure the service account token is securely stored at ~/.openclaw/secrets/op-sa-token and configure openclaw.json to enable the plugin with a default vault for seamless startup resolution.
Scored Jun 19, 2026
1Password Connect API skill. Use when working with 1Password Connect for activity, vaults, heartbeat. Covers 15 endpoints.
Complete guide for using pass, the standard Unix password manager. Use this skill whenever the user asks about pass, password-store, managing passwords from...
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/...
Rotate and update secrets in environment files, generate Vault commands, and manage secret rotation workflows.
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/...
Secure credential exchange with auto-expiry for Pilot Protocol agents. Use this skill when: 1. You need to share API keys, tokens, or credentials securely be...