
1password
- 16 installs
- 869 repo stars
- Updated June 8, 2026
- beita6969/scienceclaw
1password is a Claude skill that installs, signs into, and uses the 1Password CLI (op) to read, inject, and run secrets from vaults.
About
This skill covers setting up and using the 1Password CLI (op) to manage secrets. It walks through installing the CLI, enabling desktop app integration, signing in for single or multiple accounts, and reading, injecting, or running secrets. It requires running op inside a dedicated tmux session and prefers op run and op inject over writing secrets to disk.
- Sets up and signs into the 1Password CLI (op)
- Reads, injects, and runs secrets from 1Password vaults
- Requires op to run inside a dedicated tmux session
1password by the numbers
- 16 all-time installs (skills.sh)
- Ranked #1,609 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 2, 2026 (Skillselion catalog sync)
1password capabilities & compatibility
- Capabilities
- secrets management · credential injection · cli auth
- Use cases
- security audit · devops
- Platforms
- macOS · Linux
- Pricing
- Free
What 1password says it does
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
Prefer `op run` / `op inject` over writing secrets to disk.
npx skills add https://github.com/beita6969/scienceclaw --skill 1passwordAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 16 |
|---|---|
| repo stars | ★ 869 |
| Last updated | June 8, 2026 |
| Repository | beita6969/scienceclaw ↗ |
What it does
Install, sign into, and use the 1Password CLI to read, inject, and run secrets from vaults.
Who is it for?
Fetching and injecting secrets from 1Password into commands
Skip if: Storing or managing non-secret data or general password-manager UI tasks
When should I use this skill?
You need to install, sign into, or read secrets from the 1Password CLI
What you get
A working op CLI session that reads, injects, and runs secrets without writing them to disk.
- authenticated op CLI session
- injected secrets in commands
By the numbers
- 7-step sign-in workflow
Files
1Password CLI
Follow the official CLI get-started steps. Don't guess install commands.
References
references/get-started.md(install + app integration + sign-in flow)references/cli-examples.md(realopexamples)
Workflow
1. Check OS + shell. 2. Verify CLI present: op --version. 3. Confirm desktop app integration is enabled (per get-started) and the app is unlocked. 4. REQUIRED: create a fresh tmux session for all op commands (no direct op calls outside tmux). 5. Sign in / authorize inside tmux: op signin (expect app prompt). 6. Verify access inside tmux: op whoami (must succeed before any secret read). 7. If multiple accounts: use --account or OP_ACCOUNT.
REQUIRED tmux session (T-Max)
The shell tool uses a fresh TTY per command. To avoid re-prompts and failures, always run op inside a dedicated tmux session with a fresh socket/session name.
Example (see tmux skill for socket conventions, do not reuse old session names):
SOCKET_DIR="${OPENCLAW_TMUX_SOCKET_DIR:-${CLAWDBOT_TMUX_SOCKET_DIR:-${TMPDIR:-/tmp}/openclaw-tmux-sockets}}"
mkdir -p "$SOCKET_DIR"
SOCKET="$SOCKET_DIR/openclaw-op.sock"
SESSION="op-auth-$(date +%Y%m%d-%H%M%S)"
tmux -S "$SOCKET" new -d -s "$SESSION" -n shell
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op signin --account my.1password.com" Enter
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op whoami" Enter
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op vault list" Enter
tmux -S "$SOCKET" capture-pane -p -J -t "$SESSION":0.0 -S -200
tmux -S "$SOCKET" kill-session -t "$SESSION"Guardrails
- Never paste secrets into logs, chat, or code.
- Prefer
op run/op injectover writing secrets to disk. - If sign-in without app integration is needed, use
op account add. - If a command returns "account is not signed in", re-run
op signininside tmux and authorize in the app. - Do not run
opoutside tmux; stop and ask if tmux is unavailable.
op CLI examples (from op help)
Sign in
op signinop signin --account <shorthand|signin-address|account-id|user-id>
Read
op read op://app-prod/db/passwordop read "op://app-prod/db/one-time password?attribute=otp"op read "op://app-prod/ssh key/private key?ssh-format=openssh"op read --out-file ./key.pem op://app-prod/server/ssh/key.pem
Run
export DB_PASSWORD="op://app-prod/db/password"op run --no-masking -- printenv DB_PASSWORDop run --env-file="./.env" -- printenv DB_PASSWORD
Inject
echo "db_password: {{ op://app-prod/db/password }}" | op injectop inject -i config.yml.tpl -o config.yml
Whoami / accounts
op whoamiop account list
1Password CLI get-started (summary)
- Works on macOS, Windows, and Linux.
- macOS/Linux shells: bash, zsh, sh, fish.
- Windows shell: PowerShell.
- Requires a 1Password subscription and the desktop app to use app integration.
- macOS requirement: Big Sur 11.0.0 or later.
- Linux app integration requires PolKit + an auth agent.
- Install the CLI per the official doc for your OS.
- Enable desktop app integration in the 1Password app:
- Open and unlock the app, then select your account/collection.
- macOS: Settings > Developer > Integrate with 1Password CLI (Touch ID optional).
- Windows: turn on Windows Hello, then Settings > Developer > Integrate.
- Linux: Settings > Security > Unlock using system authentication, then Settings > Developer > Integrate.
- After integration, run any command to sign in (example in docs:
op vault list). - If multiple accounts: use
op signinto pick one, or--account/OP_ACCOUNT. - For non-integration auth, use
op account add.
Related skills
Forks & variants (1)
1password has 1 known copy in the catalog totaling 5 installs. They canonicalize to this original listing.
- firecrawl - 5 installs
FAQ
Why must op run inside tmux?
The shell tool uses a fresh TTY per command, so a dedicated tmux session avoids re-prompts and sign-in failures.
How should secrets be used?
Prefer op run and op inject over writing secrets to disk, and never paste secrets into logs, chat, or code.