1Password CLI Beta

1Password · The beta channel of 1Password’s op command-line tool for authorized vault access, secret references and scripted developer workflows.

CaskSecurity & PrivacyApple silicon · Intel
From homebrew/cask
30-day installs375#297 in App
1-year installs2.4KLast 365 days
Latest version2.42.0-beta.012 days ago · Oct 9
Download size14MBarm64 / x86_64 · zip
Release cadenceEvery 2 weeks3 releases in 30 days

About

1Password CLI Beta is the prerelease channel of the op command-line tool. It brings authorized 1Password access into a terminal and scripts, helping developers and administrators retrieve secrets, work with items and vaults, and avoid embedding reusable credentials directly in source code. This package installs the CLI, not the 1Password desktop app or a self-hosted password server.

Developer workflows

Use documented commands to list and inspect vaults, read or manage permitted items, and automate supported account workflows. Secret references can point to stored fields instead of duplicating plaintext secrets in configuration. op run resolves supported references into the environment of a child process, while other commands support structured output for scripts. The commands available to you remain limited by your account, vault access and authentication method.

1Password Environments and developer integrations have their own requirements. The CLI can integrate with the desktop app for system authentication such as Touch ID on a compatible Mac. Separately scoped service accounts are recommended by the publisher for shared or headless automation; account tokens must be protected just as carefully as the secrets they can retrieve.

Installation and macOS requirements

The official getting-started guide specifies macOS Big Sur 11 or later, a 1Password subscription, and 1Password for Mac for its desktop integration. Supported Mac shells include Bash, Zsh, sh and fish. Download the desired beta from the official CLI release history, choose the appropriate ZIP for your processor, and install op on your PATH; the publisher also offers a Universal PKG. The checked catalog download is the arm64 ZIP for Apple silicon, 14,041,079 bytes (version 2.42.0-beta.01). A separate amd64 ZIP is available for Intel Macs.

For this catalog channel use brew install --cask 1password-cli@beta, rather than the stable-channel command shown in general documentation. The cask conflicts with 1password-cli and 1password-cli@1, since they provide the same command. It declares no separate Homebrew formula dependency. Moving a binary into a protected system directory or running a PKG may require administrator authorization; ordinary vault commands do not imply a blanket Full Disk Access or Accessibility requirement.

Authentication, cost and network

The download is part of 1Password's commercial service ecosystem. A 1Password subscription and appropriate entitlement are required for the documented account workflows; downloading the CLI does not supply a free password-management account or unlimited developer-service access. Consult the current subscription and developer terms. The binary is not established as an unrestricted open-source program merely because related SDKs or shell plug-ins have public repositories.

For desktop integration, unlock the 1Password app and enable Integrate with 1Password CLI in Settings > Developer. Other authentication paths use the relevant account or service-account credentials. Network access is required for account communication, fetching secrets and updates, although supported caching may affect individual commands. Do not promise fully offline automation.

Beta and secret-handling cautions

This is a beta channel: changes and regressions can affect scripts before stable release. Test upgrades on noncritical workflows, pin a known version when reproducibility matters, and keep a recovery path to a supported build. Do not replace production credentials or rotate secrets merely to test a new CLI version.

Secrets injected into a process environment can be exposed by that process, its logs, debugging tools or downstream commands. The publisher explicitly says op run masking of stdout and stderr is best effort and does not guarantee concealment. Avoid printing credentials, saving secret-bearing output to public files, or committing tokens and generated plaintext configuration. Limit service-account scope and review scripts before allowing them to read vault data.

Sources: Official CLI overview, Getting started, Official release history, Secret references in scripts.

New What’s new in 2.42.0-beta.01 OpenNavo editorial

  • ImprovedReduce op environment read and op run --environment requests from 6 to 4.

An open-source interface for Homebrew. Installs run through the macOS app or the brew command.

© 2026 OpenNavo