1Password CLI

Developer ToolsAI extracted

1Password CLI release notes.

Latest 2.38.1-beta.02 · by AgileBitsWebsite

Release activity

Release activity — 19 releases across 16 days in the last year. Each cell is one day; darker means more releases that day. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 19, 2026No releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026
MondayNo releases on Apr 20, 2026No releases on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026
TuesdayNo releases on Apr 21, 2026No releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 20261 release on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 20261 release on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Apr 22, 2026No releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 20261 release on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 20261 release on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 23, 2026No releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 20261 release on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on Apr 24, 2026No releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 20261 release on Jul 10, 2026No releases on Jul 17, 20261 release on Jul 24, 20262 releases on Jul 31, 2026
SaturdayNo releases on Apr 25, 2026No releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026

19 releases in the last year, busiest day 2

Changelog

2.38.1-beta.02

Changed 1
  • op environment read and op run --environment help text now includes note about start time on Apple silicon Macs
Fixed 1
  • op run help text for the --environment flag is now correct

op run help text for the --environment flag is now correct. op environment read and op run --environment help text now includes note about start time on Apple silicon Macs.

View originalPermalink
How 2.38.1-beta.02 went

2.38.2-beta.01

Changed 1
  • op environment read and op run --environment help text now includes note about start time on Apple silicon Macs
Fixed 1
  • op run help text for the --environment flag is now correct

op run help text for the --environment flag is now correct. op environment read and op run --environment help text now includes note about start time on Apple silicon Macs.

View originalPermalink
How 2.38.2-beta.01 went

2.38.1

Changed 2
  • Reading an item with op read or op item get now uses one fewer network round-trip per read
  • Reading an item or vault by name with op read, op item get, op item list, and op vault get now uses one fewer network round-trip when resolving a name

Reading an item with op read or op item get is now faster, using one fewer network round-trip per read. Reading an item or vault by name is now faster: op read, op item get, op item list, and op vault get use one fewer network round-trip when resolving a name.

View originalPermalink
How 2.38.1 went

2.38.1-beta.01

Changed 2
  • Reading an item with op read or op item get now uses one fewer network round-trip per read
  • Reading an item or vault by name with op read, op item get, op item list, and op vault get now uses one fewer network round-trip when resolving a name

Reading an item with op read or op item get is now faster, using one fewer network round-trip per read. Reading an item or vault by name is now faster: op read, op item get, op item list, and op vault get use one fewer network round-trip when resolving a name.

View originalPermalink
How 2.38.1-beta.01 went

2.38.0-beta.01

Added 1
  • Trigger a Google Workspace user provisioning sync with op provisioning google sync command

You can now trigger a Google Workspace user provisioning sync with op provisioning google sync.

View originalPermalink
How 2.38.0-beta.01 went

2.35.0

Added 15
  • Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Kiro CLI with API keys using 1Password Shell Plugins
  • Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins
Changed 6
  • The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured
  • The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning
  • Terraform workspace subcommands now trigger authentication via 1Password Shell Plugins
  • The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials
  • The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin
  • The awslogsCLI function has been renamed to capitalize CLI for consistency
Fixed 2
  • op no longer hangs when running a shell plugin from outside $HOME
  • Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled

Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the Kiro CLI with API keys using 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate twine, flit, and hatch to PyPI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @cpierce for their contribution! Authenticate the Descope CLI as a Descope account admin using 1Password Shell Plugins. Thanks to @scottisloud for their contribution! Authenticate the Expo and EAS CLIs using 1Password Shell Plugins. Thanks to @CodeByZach for their contribution! Authenticate the Google Gemini AI API CLI using 1Password Shell Plugins. Thanks to @fproulx-boostsecurity for their contribution! Authenticate the OpenTofu CLI with any supported provider using 1Password Shell Plugins. Thanks to @gargakshit for their contribution! Authenticate the UpCloud CLI using 1Password Shell Plugins. Thanks to @jksolbakken for their contribution! Authenticate the Exercism CLI using 1Password Shell Plugins. Thanks to @dethancosta for their contribution! Authenticate the CrateDB CLI using 1Password Shell Plugins. Thanks to @accraw for their contribution! The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured. Thanks to @scottisloud for their contribution! The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning. Thanks to @arunsathiya for their contribution! Tab completion is now supported when using shell plugins with bash and zsh shells. op no longer hangs when running a shell plugin from outside $HOME. Terraform 'workspace' subcommands now trigger authentication via 1Password Shell Plugins. Thanks to @moraisph for their contribution! The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials. Thanks to @owenvoke for their contribution! The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin. Thanks to @jbhannah for their contribution! The awslogsCLI function has been renamed to capitalize CLI for consistency. Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled.

View originalPermalink
How 2.35.0 went

2.37.0-beta.01

Added 15
  • Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Kiro CLI with API keys using 1Password Shell Plugins
  • Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins
Changed 6
  • The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured
  • The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning
  • Terraform workspace subcommands now trigger authentication via 1Password Shell Plugins
  • The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials
  • The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin
  • The awslogsCLI function has been renamed to capitalize CLI for consistency
Fixed 2
  • op no longer hangs when running a shell plugin from outside $HOME
  • Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled

Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the Kiro CLI with API keys using 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! Authenticate twine, flit, and hatch to PyPI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @cpierce for their contribution! Authenticate into the Descope CLI as a Descope account admin. Thanks to @scottisloud for their contribution! Authenticate the Expo and EAS CLIs using 1Password Shell Plugins. Thanks to @CodeByZach for their contribution! Authenticate the Google Gemini AI API CLI using 1Password Shell Plugins. Thanks to @fproulx-boostsecurity for their contribution! Authenticate the OpenTofu CLI with any supported provider using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @gargakshit for their contribution! Authenticate the UpCloud CLI using 1Password Shell Plugins. Thanks to @jksolbakken for their contribution! Authenticate the Exercism CLI using 1Password Shell Plugins. Thanks to @dethancosta for their contribution! Authenticate the CrateDB CLI using 1Password Shell Plugins. Thanks to @accraw for their contribution! The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured. Thanks to @scottisloud for their contribution! The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning. Thanks to @arunsathiya for their contribution! Tab completion is now supported when using shell plugins with bash and zsh shells. op no longer hangs when running a shell plugin from outside $HOME. Terraform 'workspace' subcommands now trigger authentication via 1Password Shell Plugins. Thanks to @moraisph for their contribution! The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials. Thanks to @owenvoke for their contribution! The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin. Thanks to @jbhannah for their contribution! The awslogsCLI function has been renamed to capitalize CLI for consistency. Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled.

View originalPermalink
How 2.37.0-beta.01 went

2.34.1

Changed 1
  • The 'op vault edit' help text now better describes how the Travel Mode flag works

The 'op vault edit' help text now better describes how the Travel Mode flag works.

View originalPermalink
How 2.34.1 went

2.36.0-beta.03

Added 4
  • Use `op user create` with Automated Provisioning configured
  • Use `op user suspend` with Automated Provisioning configured
  • Use `op user reactivate` with Automated Provisioning configured
  • Use `op provisioning configure` to set up Automated Provisioning

You can now use op user create with Automated Provisioning configured. You can now use op user suspend with Automated Provisioning configured. You can now use op user reactivate with Automated Provisioning configured. You can now use op provisioning configure to set up Automated Provisioning.

View originalPermalink
How 2.36.0-beta.03 went

2.34.0

Authenticate the Claude Code CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @malob for their contribution! { shell-plugins#519} Authenticate the Scaleway CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @jksolbakken for their contribution! { shell-plugins#515} The AWS shell plugin now supports the awslogs CLI. Thanks to @jonasws for their contribution! { shell-plugins#504} The AWS shell plugin now supports eksctl, the Amazon EKS CLI. Thanks to @skpaz for their contribution! { shell-plugins#500} The AWS shell plugin now supports the AWS SAM CLI. Thanks to @simonmcc for their contribution! { shell-plugins#473} The OpenAI shell plugin now supports the Codex CLI. Thanks to @shyim for their contribution! { shell-plugins#517} The ngrok shell plugin no longer performs a version check on every op plugin command when it is not initialized. Thanks to @MOmarMiraj for their contribution! { shell-plugins#474} The AWS CDK shell plugin now supports AWS Profiles that assume a role when specified by the --profile flag. Thanks to @waiteb3 for their contribution! { shell-plugins#463} op run now properly terminates the subprocess it was called with when cancelled (for example, with Ctrl+C). {284}

View originalPermalink
How 2.34.0 went

2.35.0-beta.01

Authenticate the Claude Code CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @malob for their contribution! { shell-plugins#519} Authenticate the Scaleway CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @jksolbakken for their contribution! { shell-plugins#515} The AWS plugin now supports the awslogs CLI. Thanks to @jonasws for their contribution! { shell-plugins#504} The AWS plugin now supports eksctl, the Amazon EKS CLI. Thanks to @skpaz for their contribution! { shell-plugins#500} The AWS plugin now supports the AWS SAM CLI. Thanks to @simonmcc for their contribution! { shell-plugins#473} The OpenAI Shell Plugin now supports the Codex CLI. Thanks to @shyim for their contribution! { shell-plugins#517} The Terraform plugin now triggers authentication for all terraform state subcommands, not just terraform state list. Thanks to @frans-otogone for their contribution! { shell-plugins#476} The ngrok plugin no longer performs a version check on every op plugin command when it is not initialized. Thanks to @MOmarMiraj for their contribution! { shell-plugins#474} The AWS CDK plugin now supports AWS Profiles that assume a role when specified by the --profile flag. Thanks to @waiteb3 for their contribution! { shell-plugins#463} op run now properly terminates the subprocess it was called with when cancelled (for example, with Ctrl+C). {284}

View originalPermalink
How 2.35.0-beta.01 went

2.33.1

op item edit help text now includes a warning that JSON item templates don't support passkeys. {INTF-1083} 1Password CLI commands now support the Account Trust Log when the user authenticates with the 1Password desktop app. {TRUST-628}

View originalPermalink
How 2.33.1 went

2.34.1-beta.01

1Password CLI commands now support the Account Trust Log when the user authenticates with the 1Password desktop app. {TRUST-628}

View originalPermalink
How 2.34.1-beta.01 went

2.34.0-beta.04

1Password CLI now correctly updates an account's Account Trust Log when the feature is enabled. {TRUST-628}

View originalPermalink
How 2.34.0-beta.04 went

2.34.0-beta.03

op environment help text now includes information about how to get the ID for a 1Password Environment. {TW-551}

View originalPermalink
How 2.34.0-beta.03 went

2.33.0

1Password CLI now supports updating an account's Account Trust Log when the feature is enabled. The --tags flag on op item edit now replaces existing tags instead of appending them. An empty --tags value now properly clears all tags. Empty tag strings in templates are now filtered out during op item create and op item edit. Default values for Date and MonthYear fields are now unset instead of zero. {INTF-189} Upgrade Go to 1.24.12 to resolve vulnerabilities. {0} Upgrade Go to 1.25.7 to resolve vulnerabilities. {0}

View originalPermalink
How 2.33.0 went

2.33.0-beta.02

op environment read allows reading environment variables from 1Password Environments. {DG-538} op run now supports loading variables from 1Password Environments by passing the --environment flag. {DG-31}

View originalPermalink
How 2.33.0-beta.02 went

2.32.1

The op item delete help text now notes that deleted items remain in Recently Deleted for 30 days. {4377} Tags are now deduplicated when using op item edit. {4088} 'op run' help text now notes shell expansion order of operations. {2971} op item create help text example now works without error. {4246} 1Password CLI now correctly exits with code 1 instead of 0 when encountering server error codes that are not recognized by the CLI. {DG-682}

View originalPermalink
How 2.32.1 went

2.32.0

You can now use 1Password CLI to recover accounts for family or team members. {4161}

View originalPermalink
How 2.32.0 went

2.31.1

The 1Password app integration with 1Password CLI now works again on Windows. {4325} A typo in the error message for 'op user confirm' has been fixed. {4329}

View originalPermalink
How 2.31.1 went

2.31.1-beta.01

This release fixes the 1Password CLI integration with the desktop application on Windows operating systems. To use the desktop app integration, you must be on 1Password for Windows nightly or beta (8.10.78+).

View originalPermalink
How 2.31.1-beta.01 went

2.31.0

1Password CLI no longer causes direnv to halt when the two are used together. {4250} Following the deprecation of CLI 1, the 1password/op:latest DockerHub tag will now always point to the latest version of CLI 2. {4267} The Go version has been bumped to 1.23.8. {4305} op vault list --filter now returns all vaults you have access to, regardless of permission level, making it easier to discover and manage vaults beyond just those with read access. {4189} 'op group user grant' now works correctly in MSP accounts. {4244}

View originalPermalink
How 2.31.0 went

2.31.0-beta.01

This release brings the beta build up to date with the changes on the stable release channel. It includes quality of life improvements and bug fixes for 1Password CLI. 1Password CLI no longer causes direnv to halt when the two are used together. {4250} Following the deprecation of CLI 1, the 1password/op:latest DockerHub tag will now always point to the latest version of CLI 2. {4267} op vault list --filter now returns all vaults you have access to, regardless of permission level, making it easier to discover and manage vaults beyond just those with read access. {4189} 'op group user grant' now works correctly in MSP accounts. {4244}

View originalPermalink
How 2.31.0-beta.01 went

2.30.3

This release includes security improvements, bug fixes for 1Password CLI commands, and introduces enhanced configuration options. The OP_RUN_NO_MASKING environment variable is now exposed to allow users to control the masking of the op run command output. {4089} For 1Password accounts that are managed by an MSP, 1Password CLI commands involving Service Accounts, Connect, or the Events API no longer occasionally return an error. {4033} The op read, op run and op inject commands no longer query archived items. {3893} On Windows, the CLI now checks each signature of the 1Password desktop app before connecting to it. {4136}

View originalPermalink
How 2.30.3 went

2.30.0

This release enables caching for service accounts and concealing sensitive information in the human readable output of items, as well as brings multiple other improvements and bug-fixes. Sensitive values from item management commands' human-readable output are now concealed and can be displayed using the --reveal flag. {4158} Caching is now being used for service account sessions on macOS and Linux. {4133} The error message when the CLI can't connect with the 1Password desktop app now includes a link to troubleshooting documentation for more help. {3933} op whoami will now signal if the CLI is authenticated as a human user. {4104} The output of op vault list now contains the created date and item count for each vault. {4092} The op item move and op item delete commands now also work for SSH Key items. {3951} The op vault revoke user command will no longer allow you to revoke permissions in a Personal, Private, or Employee vault. {3844} When the same environment variable name exists both in the OS environment and the dotenv file, op run now correctly sources the value from the dotenv file. {3667} Windows Authenticode signature now uses the SHA256 hashing algorithm. {4135}

View originalPermalink
How 2.30.0 went

2.30.0-beta.03

This release brings the ability to begin user recovery via the CLI, as well as multiple other improvements and bug-fixes. Beginning user recovery is now possible using the CLI. {4161} The error message when the CLI can't connect with the 1Password desktop app now includes a link to troubleshooting documentation for more help. {3933} The output of 'op vault list' now contains the created date and item count for each vault. {4092} The op item move and op item delete commands no longer error for SSH Key items. {3951} The op vault revoke user command will not allow you to revoke permissions in a Personal, Private, or Employee vault. {3844} When the same environment variable name exists both in the OS environment and the dotenv file, 'op run' now correctly sources the value from the dotenv file. {3667} Windows Authenticode signature now uses the SHA256 hashing algorithm. {4135}

View originalPermalink
How 2.30.0-beta.03 went

2.30.0-beta.02

This release brings the beta channel up to date with the stable channel, as well adds three new beta features. Additionally, the desktop app integration should now again work with the beta CLI. On first run of the CLI, there is now a prompt to automatically open the settings dialogue in 1Password 8 to check the "Integrate with CLI" checkbox. {3694} It's now possible to provision a temporary FIFO file using the --inject-file flag in op run. {3773} op whoami now also outputs the user type when authenticated as a human user. {4104} The desktop app integration now again works with beta builds of the CLI. {4075}

View originalPermalink
How 2.30.0-beta.02 went

2.29.0

This release adds support for administrators and owners to allow any user or group to create service accounts. It also includes other improvements to service accounts and Connect. Adjust service account creation functionality to support the new feature of enabling other users and groups to create service accounts. {3960} You can now use the op whoami command with a 1Password Connect server. {2636} Service account tokens now include device UUIDs for scalability purposes. {4009} The output when you create a service account can now be formatted as a json object by adding --format json to the command. {3996}

View originalPermalink
How 2.29.0 went

2.28.0

This release updates the name of the Private vault for 1Password Business accounts to "Employee vault", and also improves SSH key support and the macOS package installer. Private vaults have been renamed Employee vaults for 1Password Business accounts. {3810} 1Password can now retrieve PKCS1-formatted SSH keys using op read. {3993} The 1Password CLI package installer for macOS now correctly displays the CLI version in the package receipt. {4027}

View originalPermalink
How 2.28.0 went

2.27.0

This release includes error message improvements as well as fixes in SSH key formatting and permission management. op read will now output an error message consistent with the secret reference provided, when no matching field or section is found within the item. {3592} Output of SSH private keys on non-DOS OSes no longer includes the carriage return character in line-breaks. {3913} Users and groups can now grant and revoke permissions if they have the manage_vault permission. {3863}

View originalPermalink
How 2.27.0 went

2.26.1

This release builds the 1Password CLI for Darwin with an updated toolchain. The CLI build for Darwin now builds with Go 1.21.8. The previous version was built using an older version, which was causing alerts for certain customers.

View originalPermalink
How 2.26.1 went

2.26.0

This release gives you the ability to use 1Password CLI to manage 1Password Service Accounts, including commands to create service accounts and fetch service account rate limit usage. This release also brings other improvements and fixes for a better experience. op service-account create command allows you to create a new service account that you can use to automate secrets management. op service-account ratelimit command allows you to fetch information about service account rate limit usage. {3886} The op user provision command now clarifies that users will not be considered for billing until they accept their invitation. {3965} --expires-in flags now include support for days and weeks. {3298} The item share --expiry flag is now aliased to the standardized --expires-in flag. {3298} Corrected a typo in user suspend error message. {3298}

View originalPermalink
How 2.26.0 went

2.25.1

This release fixes a bug with the SSH key handling in the CLI. Retrieving an SSH Key using the CLI with Connect now works as expected. {3851}

View originalPermalink
How 2.25.1 went

2.25.0

This release improves how 1Password CLI lists vault permissions and fixes a bug related to updating password strength when editing items. op vault list --permission now allows you to retrieve a list of vaults for which a user or group has specific permissions. {3879} When setting a non-generated password, 1Password CLI now always correctly updates the password strength. {3787}

View originalPermalink
How 2.25.0 went

2.24.0

This release contains help-text improvements and two fixes, as well as an improved customizable installer for the CLI on MacOS.

View originalPermalink
How 2.24.0 went

2.23.0-beta.01

The 1Password CLI universal installer now allows for custom location selection. {3731} Terraform shell plugin now works as expected when using the ngrok provider. { shell-plugins#222} Terraform now requires authentication for init and state list. Thanks to @JustMaris for their contribution! { shell-plugins#380}

View originalPermalink
How 2.23.0-beta.01 went

2.23.0

op item edit now accepts JSON input via the --template flag. {1849} op item edit now supports piping items as JSON via stdin. {1849} The CLI now returns a helpful error when a user is not an owner and tries to add the Team Members group to a vault when the feature flag limitGroupVaultAccess is enabled. {3830} Error message now suggests rebooting the app when the CLI cannot connect. {3835} Error for op item edit when duplicate fields are found now formats better the field label that isn't in a section. {3849} Creating a vault with --icon=name now works again, using the updated icons. {3833} Error for op item edit when duplicated fields are found by label no longer prints the field's value. {3848}

View originalPermalink
How 2.23.0 went

2.22.0

Authenticate the Hugging Face CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @bala-ceg for their contribution! { shell-plugins#393} Authenticate the InfluxDB CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @bala-ceg for their contribution! { shell-plugins#392} Authenticate the Binance CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @bala-ceg for their contribution! { shell-plugins#391} Authenticate the LocalStack CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @simonrw for their contribution! { shell-plugins#371} Authenticate the Crowdin CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @JoeKarow for their contribution! { shell-plugins#359} Authenticate the Axiom CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#342} Authenticate the Kaggle CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#341} Authenticate the Todoist CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#340} Authenticate the Pipedream CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#338} Authenticate the Zapier CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#337} Authenticate the Vertica CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @parthiv11 for their contribution! { shell-plugins#327} Authenticate the Yugabyte CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @parthiv11 for their contribution! { shell-plugins#322} Authenticate the Upstash CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @siddhikhapare for their contribution! { shell-plugins#316} Authenticate the Civo CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @itsCheithanya for their contribution! { shell-plugins#296} Authenticate the MongoDB Atlas CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @joqim for their contribution! { shell-plugins#198} Authenticate the Flyctl CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @arunsathiya for their contribution! { shell-plugins#141} Help text for many commands is now simpler and uses active voice. {3676, 3768} op read help text now includes example for using ssh-format query parameter to get an SSH key's private key. {3795} Added a note to op run help text to explain access and option to use service accounts. {3804} Error messages in op item create and when provisioning actions fail are now more clear. {3263, 3766} op whoami for service accounts no longer asks to authenticate the service account token. Instead, it does it automatically. {3744} PostgreSQL plugin now also supports pgcli as an alternative to psql. Thanks to @szymon for their contribution! { shell-plugins#384} The Cachix plugin now checks for the ~/.config/cachix/cachix.dhall file and attempts to import an auth token using the specified file. Thanks to @dethancosta for their contribution! { shell-plugins#373} The Sentry CLI plugin now skips authentication when the --auth-token and --api-key are specified. Thanks to @roy9495 for their contribution! { shell-plugins#370} The Homebrew shell plugin now provides authentication for the upgrade, update, install and reinstall commands. Thanks to @cullenmcdermott for their contribution! { shell-plugins#369} The Sentry Plugin now has support for SENTRY_PROJECT & SENTRY_URL. Thanks to @JoeKarow for their contrib

View originalPermalink
How 2.22.0 went

2.21.0

SSH keys can now be generated with the op item create --category ssh command. {3736} The CLI can now be installed at any location and the desktop app integration will work as long as the latest version is being used. {3713} op, op signin and op account add help text is now simpler and less verbose. {3676}

View originalPermalink
How 2.21.0 went

2.20.0

Secret references now support retrieving attributes of an item field, such as MFA codes and SSH private key formats, using query parameters . {3691} op item move moves an item between vaults. {3698} When retrieving items of type SSH key, the private key is displayed in OpenSSH format. {2843} Items created using the shell plugins' importers now also contain the plugin's management URL. {3628} The CLI now shows shell plugin setup instructions when no installed plugins are detected. {3208} The CLI will not prompt to authorize if there are no secret references in the environment. {3695} op whoami output for service accounts (both human readable and JSON) is now on par with the output for regular users. {3482} op whoami now tells the user if the service account is authenticated or not. {3482} It's now possible to create a favorite item with op item create. {3704} It's now possible to update an item's favorite status with op item edit. {3704} There is no longer an error returned for shell plugins initialized before version 2.19.0. {3664} Addressed a rare case where a secret would not correctly be masked by the "op run" command. {3500} Using a 26-character long item title no longer results in an error when retrieving the item. {3523}

View originalPermalink
How 2.20.0 went
2.19.0

2.19.0 (build #2190004)

Secret references now support retrieving attributes of an item field, such as MFA codes and SSH private key formats, using query parameters. {3691} op item move moves an item between vaults. {3698} When retrieving items of type SSH key, the private key is displayed in OpenSSH format. {2843} Items created using the shell plugins' importers now also contain the plugin's management URL. {3628} The CLI now shows shell plugin setup instructions when no installed plugins are detected. {3208} The CLI will not prompt to authorize if there are no secret references in the environment. {3695} op whoami output for service accounts (both human readable and JSON) is now on par with the output for regular users. {3482} op whoami now tells the user if the service account is authenticated or not. {3482} It's now possible to create a favorite item with op item create. {3704} It's now possible to update an item's favorite status with op item edit. {3704} There is no longer an error returned for shell plugins initialized before version 2.19.0. {3664} Addressed a rare case where a secret would not correctly be masked by the "op run" command. {3500} Using a 26-character long item title no longer results in an error when retrieving the item. {3523} 1Password CLI no longer crashes when an invalid service account token is provided. {3591} op whoami JSON output for service account now has the keys in snake_case, matching the rest of the CLI JSON output. {3482} Authenticate the Oh Dear CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @owenvoke for their contribution! { shell-plugins#269} Executables "oaieval" and "oaievalset" are now supported within the OpenAI shell plugin. { shell-plugins#208} Authenticate the Vercel CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @j178 for their contribution! { shell-plugins#273} op plugin clear more clearly displays credentials which are about to be cleared. {3560} AWS shell plugin now supports sourcing credentials from another profile. { shell-plugins#299} GitHub shell plugin skips authentication if it runs with shell completion flag __complete. Thanks to @j178 for their contribution! { shell-plugins#271} Shell plugin help text now references plugin-executable instead of plugin-name for clarity. {3361} 1Password CLI will no longer return a "received unexpected response from 1Password app" for the first command that is executed when the 1Password app is locked. {3568} A typo in the op whoami help text has been fixed. {3646} AWS Shell Plugin no longer outputs aws-vault specific logs. { shell-plugins#297} AWS shell plugin no longer creates an .aws/config file when using the aws-vault importer. { shell-plugins#259}

View originalPermalink
How 2.19.0 went
2.19.0-beta.01

2.19.0-beta.01 (build #2190001)

Authenticate the Terraform CLI using Touch ID and other unlock options with 1Password Shell Plugins. {3495} Shell plugin help text now references plugin-executable instead of plugin-name for clarity. {3361} Deleting an SSH Key with the CLI now works as expected. {3508}

View originalPermalink
How 2.19.0-beta.01 went
2.18.0

2.18.0 (build #2180001)

Users can now authenticate with the CLI using 1Password Service Accounts. Users can now create items of custom categories by providing a template. {3483} Executing op plugin run with a plugin that has not yet been configured no longer exits after the configuration steps. {3537}

View originalPermalink
How 2.18.0 went
2.17.0

2.17.0 (build #2170001)

Authenticate the Akamai CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @wongle for their contribution! { shell-plugins#234} Authenticate the Laravel Vapor CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @andresayej for their contribution! { shell-plugins#245} Authenticate the Laravel Forge CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @andresayej for their contribution! { shell-plugins#244} Authenticate the Pulumi CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @ringods for their contribution! { shell-plugins#199} Authenticate the Zendesk CLI using Touch ID and other unlock options with 1Password Shell Plugins. { shell-plugins#207} AWS credentials stored in aws-vault can now be imported into 1Password. { shell-plugins#229} Authenticate the AWS CDK CLI using Touch ID and other unlock options with 1Password Shell Plugins. { shell-plugins#232} Assuming AWS roles and profiles is now supported with the AWS shell plugin. { shell-plugins#180} A deleted/restricted user that last updated an item will be displayed by name when running op item get. {3394} An error is thrown if a document is created/updated from the CLI through standard input but no content is provided. {2624} A description was added about configuring the CLI to use Connect / Service Account if no account is configured, in the help text of op signin. {3396} Users attempting to create new DOCUMENT items with Connect will now receive a friendlier error message. {3127} The --config and --session flags are now fully supported for op plugin and op whoami commands respectively. {3423} Typos in the help-text of document create and document edit concerning the misspelling of the --file-name flag have been corrected. {3432}

View originalPermalink
How 2.17.0 went
2.17.0-beta.01

2.17.0-beta.01 (build #2170001)

Generating SSH Keys with the CLI is now possible using the op ssh generate command. {2342} When no accounts are configured, the CLI also prints information about using it with Connect and Service Accounts. {3396}

View originalPermalink
How 2.17.0-beta.01 went
2.16.1

2.16.1 (build #2160101)

The help text for op events-api now specifies that Events Reporting is only available for business accounts. {3453} When initializing the SourceGraph shell plugin an appropriate management url will be displayed. { shell-plugins#228} Treasure Data shell plugin no longer returns an error during the init step, as its executable now correctly references its API Key credential. { shell-plugins#225} When initializing the Gitea plugin, it now also checks the default configuration directory on MacOS to find a credential to import. Thanks to @mcornick for their contribution! { shell-plugins#219}

View originalPermalink
How 2.16.1 went
2.16.0

2.16.0 (build #2160001)

The default features list when creating new Events API tokens will now include Audit Events, in addition to Sign-In Attempts and Item Usages. {3146} Authenticate Gitea CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @14zombies for their contribution! { shell-plugins#205} Authenticate Treasure Data CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @Lewuathe for their contribution! { shell-plugins#176} ngrok is now aware of the --config flag and of any existing config files in the default location on the user's filesystem. { shell-plugins#194} The HomeBrew shell plugin now skips authentication for the bump sub-command as well. Thanks to @MTCoster for their contribution! { shell-plugins#179} The --output flag of op document get is now doubled by --out-file, for consistency with other commands. {2960} To help with determining the 1Password item to use for a shell plugin, additional item metadata is now shown in the selection prompt. {3180} Shell plugins credential fields can now be identified by more than one name. {3386} document get now outputs the absolute file path on a successful file write and prompts to overwrite if the file already exists. {3383} Connect tokens with no vault access permissions can no longer be created using the 1Password CLI. {3167} Item count is now present in the JSON output of empty vaults' details. {2995} UpdatedAt and ItemCount attributes are now consistently up to date in the cached vaults. {3373} Item version is now up to date in the output of op item create and op item edit. {3387} Connect tokens can now be created when passing the --vault flag with the op connect token create. {3290} Items are now successfully returned by op item get even if they were last edited by a deleted or restricted user. {3394} The CLI will no longer silently succeed if the piped input is not handled properly. {3378} Item lookup by name will no longer fail when resource name is alphanumeric of length 26. {2614}

View originalPermalink
How 2.16.0 went

2.16.0-beta.01

This beta improves the performance and stability of 1Password Service Accounts. document get now outputs the absolute file path on a successful file write and prompts to overwrite if the file already exists. {3383} The stability of Service Accounts has been improved. {3401} Connect tokens with no vault access permissions can no longer be created using the 1Password CLI. {3167}

View originalPermalink
How 2.16.0-beta.01 went

2.15.0-beta.03

This release brings the beta build up to date with the changes on the stable release channel, as well as adds better support for handling autofill URLs. op item create and op item edit can now be used to perform CRUD operations on items' autofill URLs using the --autofill-urls flag. {3334} Items can now be consistently looked up by name. {2614}

View originalPermalink
How 2.15.0-beta.03 went

2.14.0

This release introduces five new shell plugins as well as improved error messages around shell plugin local builds and CLI command help text. Authenticate ngrok using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @arunsathiya for their contribution! { shell-plugins#165} Authenticate Vultr CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @arunsathiya for their contribution! { shell-plugins#159} Authenticate Snowflake CLI using Touch ID and other unlock options with 1Password Shell Plugins. { shell-plugins#161} Authenticate Fastly CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @arunsathiya for their contribution! { shell-plugins#169} Authenticate Sourcegraph CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @arunsathiya for their contribution! { shell-plugins#146} The AWS Shell Plugin now checks if the AWS_SHARED_CREDENTIALS_FILE environment variable is set and attempts to import credentials using the specified file. Thanks to @Volatus for their contribution! { shell-plugins#178} Error messages for shell plugin local builds now include link to troubleshooting documentation. {3286} Help text formatting is now more consistent across commands. {3343} op item help text now shows correct command for getting item category templates. {3358}

View originalPermalink
How 2.14.0 went

2.13.1

This release introduces four new shell plugins, as well as two importers. It also contains some improvements and fixes brought to the CLI commands and to the shell plugins' cache. In addition, this release fixes a bug introduced in 2.13.0, where the Windows binaries were not code-signed. Authenticate the Cargo CLI using Touch ID and other unlock options with 1Password Shell Plugins. { shell-plugins#139} Authenticate the Argo CD CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @ssttehrani for their contribution! { shell-plugins#145} Authenticate the Databricks CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @bsamseth for their contribution! { shell-plugins#143} Authenticate the OpenAI CLI using Touch ID and other unlock options with 1Password Shell Plugins. { shell-plugins#152} op update now allows you to look for updates from a specific channel via the --channel flag. {1648} Twilio CLI credentials can now be imported from the ~/.twilio-cli/config.json config file. { shell-plugins#112} Linode CLI credentials can now be imported from the ~/.config/linode-cli config file. Thanks to @alexclst for their contribution! { shell-plugins#113} Shell plugins now throw an error if a configured item is archived. {3232} When importing shell plugin credentials and prompting for a vault to store them in, 1Password CLI will only show vault names if all vaults have distinct names. {3244} The AWS, CircleCI, DigitalOcean, Fossa, GitHub, GitLab, Heroku and Okta plugins no longer unnecessarily prompt for authorization when no arguments are provided to the commands. { shell-plugins#126} The Homebrew and ReadMe plugins no longer unnecessarily prompt for authorization for 'help' or 'version' related commands. { shell-plugins#126} --vault flag for op item edit now has the appropriate description. {3273} Plugin cache no longer breaks when caching certain credentials. {3295} Code signing for 1Password CLI binaries for Windows has been fixed. {3347} Connecting 1Password CLI with the 1Password app for Windows is now again possible. {3347}

View originalPermalink
How 2.13.1 went

2.12.0

This release introduces three new Shell Plugins! Authenticate the ReadMe CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @kanadgupta for their contribution! { shell-plugins#106} Authenticate the Hcloud CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @shyim

View originalPermalink
How 2.12.0 went
View all

Discussion