1Password CLI

Security & PrivacyAI extracted

1Password CLI release notes.

Latest 2.39.0 · by AgileBitsWebsiteRSS

Branches

2.39
2.39.0
2.38
2.38.2-beta.01
2.37
2.37.0-beta.01
2.36
2.36.0-beta.03
2.35
2.35.0
2.34
2.34.1
2.33
2.33.1
2.32
2.32.1

Release activity

Release activity — 21 releases across 18 days in the last year. Each cell is one day; darker means more releases that day. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026No releases on Sep 13, 2026
MondayNo releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 2026No releases on Aug 31, 2026No releases on Sep 7, 2026No releases on Sep 14, 2026
TuesdayNo releases on Jun 2, 20261 release on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 20261 release on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 20261 release on Aug 11, 2026No releases on Aug 18, 2026No releases on Aug 25, 2026No releases on Sep 1, 2026No releases on Sep 8, 2026No releases on Sep 15, 2026
WednesdayNo releases on Jun 3, 20261 release on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 20261 release on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026No releases on Aug 12, 2026No releases on Aug 19, 2026No releases on Aug 26, 2026No releases on Sep 2, 2026No releases on Sep 9, 2026
ThursdayNo releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 20261 release on Jul 30, 2026No releases on Aug 6, 20261 release on Aug 13, 2026No releases on Aug 20, 2026No releases on Aug 27, 2026No releases on Sep 3, 2026No releases on Sep 10, 2026
FridayNo releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 20261 release on Jul 10, 2026No releases on Jul 17, 20261 release on Jul 24, 20262 releases on Jul 31, 2026No releases on Aug 7, 20261 release on Aug 14, 2026No releases on Aug 21, 2026No releases on Aug 28, 2026No releases on Sep 4, 2026No releases on Sep 11, 2026
SaturdayNo releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 2026No releases on Aug 29, 2026No releases on Sep 5, 2026No releases on Sep 12, 2026

21 releases in the last year, busiest day 2

Changelog

Filter releases by branch
56 of 56 releases

2.39.0

Latest
Added 1
  • Debug output now includes per-request timing
Changed 2
  • Debug output now reports more information when a vault cannot be read
  • Reporting item usage for cached items no longer delays reading secrets, with usage data now sent in the background
Fixed 1
  • A vault lookup that fails on the server is now reported as an error instead of incorrectly saying the vault is not in the account
Security 1
  • Connection error messages no longer include the full request URL, which could contain the account's email address

From 1Password CLI

Debug output now includes per-request timing. {ECO-971} Debug output now reports more information when a vault cannot be read. {ECO-817} Reporting item usage for cached items no longer delays reading secrets: usage data is now sent in the background. {ECO-970} A vault lookup that fails on the server is now reported as an error instead of incorrectly saying the vault isn't in the account. {ECO-1017} Connection error messages no longer include the full request URL, which could contain the account's email address. {ECO-817}

View originalPermalink
How 2.39.0 went

2.39.1-beta.01

Added 1
  • Debug output now includes per-request timing
Changed 3
  • 1Password Environments commands are now significantly faster on Apple silicon Macs
  • Debug output now reports more information when a vault cannot be read
  • Reporting item usage for cached items no longer delays reading secrets as usage data is now sent in the background
Fixed 1
  • A vault lookup that fails on the server is now reported as an error instead of incorrectly saying the vault is not in the account
Security 1
  • Connection error messages no longer include the full request URL, which could contain the account's email address

From 1Password CLI

Debug output now includes per-request timing. {ECO-971} 1Password Environments commands are now significantly faster on Apple silicon Macs. {DG-1398} Debug output now reports more information when a vault cannot be read. {ECO-817} Reporting item usage for cached items no longer delays reading secrets: usage data is now sent in the background. {ECO-970} A vault lookup that fails on the server is now reported as an error instead of incorrectly saying the vault isn't in the account. {ECO-1017} Connection error messages no longer include the full request URL, which could contain the account's email address. {ECO-817}

View originalPermalink
How 2.39.1-beta.01 went

2.39.0-beta.02

Added 1
  • Debug output now includes per-request timing
Changed 3
  • 1Password Environments commands are now significantly faster on Apple silicon Macs
  • Debug output now reports more information when a vault cannot be read
  • Reporting item usage for cached items no longer delays reading secrets, with usage data now sent in the background
Fixed 1
  • A vault lookup that fails on the server is now reported as an error instead of incorrectly saying the vault is not in the account
Security 1
  • Connection error messages no longer include the full request URL, which could contain the account's email address

From 1Password CLI

Debug output now includes per-request timing. {ECO-971} 1Password Environments commands are now significantly faster on Apple silicon Macs. {DG-1398} Debug output now reports more information when a vault cannot be read. {ECO-817} Reporting item usage for cached items no longer delays reading secrets: usage data is now sent in the background. {ECO-970} A vault lookup that fails on the server is now reported as an error instead of incorrectly saying the vault isn't in the account. {ECO-1017} Connection error messages no longer include the full request URL, which could contain the account's email address. {ECO-817}

View originalPermalink
How 2.39.0-beta.02 went

2.38.1-beta.02

Changed 1
  • op environment read and op run --environment help text now includes note about start time on Apple silicon Macs
Fixed 1
  • op run help text for the --environment flag is now correct

From 1Password CLI

op run help text for the --environment flag is now correct. {0} op environment read and op run --environment help text now includes note about start time on Apple silicon Macs. {TW-1603}

View originalPermalink
How 2.38.1-beta.02 went

2.38.2-beta.01

Changed 1
  • op environment read and op run --environment help text now includes note about start time on Apple silicon Macs
Fixed 1
  • op run help text for the --environment flag is now correct

From 1Password CLI

op run help text for the --environment flag is now correct. {0} op environment read and op run --environment help text now includes note about start time on Apple silicon Macs. {TW-1603}

View originalPermalink
How 2.38.2-beta.01 went

2.38.1

Changed 2
  • Reading an item with op read or op item get now uses one fewer network round-trip per read
  • Reading an item or vault by name with op read, op item get, op item list, and op vault get now uses one fewer network round-trip when resolving a name

From 1Password CLI

Reading an item with op read or op item get is now faster, using one fewer network round-trip per read. {ECO-815} Reading an item or vault by name is now faster: op read, op item get, op item list, and op vault get use one fewer network round-trip when resolving a name. {ECO-816}

View originalPermalink
How 2.38.1 went

2.38.1-beta.01

Changed 2
  • Reading an item with op read or op item get now uses one fewer network round-trip per read
  • Reading an item or vault by name with op read, op item get, op item list, and op vault get now uses one fewer network round-trip when resolving a name

From 1Password CLI

Reading an item with op read or op item get is now faster, using one fewer network round-trip per read. {ECO-815} Reading an item or vault by name is now faster: op read, op item get, op item list, and op vault get use one fewer network round-trip when resolving a name. {ECO-816}

View originalPermalink
How 2.38.1-beta.01 went

2.38.0-beta.01

Added 1
  • Add `op provisioning google sync` command to trigger a Google Workspace user provisioning sync

From 1Password CLI

You can now trigger a Google Workspace user provisioning sync with op provisioning google sync. {PROV-1718}

View originalPermalink
How 2.38.0-beta.01 went

2.35.0

Added 15
  • Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Kiro CLI with API keys using 1Password Shell Plugins
  • Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins
Changed 6
  • The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured
  • The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning
  • Terraform workspace subcommands now trigger authentication via 1Password Shell Plugins
  • The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials
  • The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin
  • The awslogsCLI function has been renamed to capitalize CLI for consistency
Fixed 2
  • op no longer hangs when running a shell plugin from outside $HOME
  • Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled

From 1Password CLI

Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#613} Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#612} Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#611} Authenticate the Kiro CLI with API keys using 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#605} Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#604} Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#603} Authenticate twine, flit, and hatch to PyPI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @cpierce for their contribution! { shell-plugins#589} Authenticate the Descope CLI as a Descope account admin using 1Password Shell Plugins. Thanks to @scottisloud for their contribution! { shell-plugins#570} Authenticate the Expo and EAS CLIs using 1Password Shell Plugins. Thanks to @CodeByZach for their contribution! { shell-plugins#563} Authenticate the Google Gemini AI API CLI using 1Password Shell Plugins. Thanks to @fproulx-boostsecurity for their contribution! { shell-plugins#560} Authenticate the OpenTofu CLI with any supported provider using 1Password Shell Plugins. Thanks to @gargakshit for their contribution! { shell-plugins#553} Authenticate the UpCloud CLI using 1Password Shell Plugins. Thanks to @jksolbakken for their contribution! { shell-plugins#538} Authenticate the Exercism CLI using 1Password Shell Plugins. Thanks to @dethancosta for their contribution! { shell-plugins#404} Authenticate the CrateDB CLI using 1Password Shell Plugins. Thanks to @accraw for their contribution! { shell-plugins#394} The GitHub shell plugin now provisions GH_ENTERPRISE_TOKEN for GitHub Enterprise Server hosts and supports authenticating to both github.com and Enterprise when separate credentials are configured. Thanks to @scottisloud for their contribution! { shell-plugins#610} The Redis CLI shell plugin now supports authenticating Redis CLI with environment variable-based provisioning. Thanks to @arunsathiya for their contribution! { shell-plugins#276} Tab completion is now supported when using shell plugins with bash and zsh shells. { shell-plugins#433} op no longer hangs when running a shell plugin from outside $HOME. { shell-plugins#416} Terraform 'workspace' subcommands now trigger authentication via 1Password Shell Plugins. Thanks to @moraisph for their contribution! { shell-plugins#582} The Oh Dear shell plugin now checks for the ~/.ohdear/config.json file and attempts to import credentials. Thanks to @owenvoke for their contribution! { shell-plugins#577} The deprecated zsh.initExtra option has been replaced with zsh.initContent in the nix shell plugin. Thanks to @jbhannah for their contribution! { shell-plugins#550} The awslogsCLI function has been renamed to capitalize CLI for consistency. { shell-plugins#518} Deleting an invited or not-yet-activated user no longer fails on accounts with the Account Trust Log enabled. {TRUST-862}

View originalPermalink
How 2.35.0 went

2.37.0-beta.01

Added 9
  • Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Kiro CLI with API keys using 1Password Shell Plugins
  • Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins

From 1Password CLI

Authenticate the OpenCode CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#613} Authenticate the Cursor CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#612} Authenticate the Cline CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#611} Authenticate the Kiro CLI with API keys using 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#605} Authenticate JetBrains Junie CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#604} Authenticate the GitHub Copilot CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @eddumelendez for their contribution! { shell-plugins#603} Authenticate twine, flit, and hatch to PyPI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @cpierce for their contribution! { shell-plugins#589} Authenticate into the Descope CLI as a Descope account admin. Thanks to @scottisloud for their contribution! { shell-plugins#570} Authenticate the Expo and EAS CLIs using 1Password Shell Plugins. Thanks to @CodeByZach for their contribution! { shell-plugins#563}

View originalPermalink
How 2.37.0-beta.01 went

2.34.1

Changed 1
  • Improved help text for 'op vault edit' to better describe how the Travel Mode flag works

From 1Password CLI

The 'op vault edit' help text now better describes how the Travel Mode flag works.

View originalPermalink
How 2.34.1 went

2.36.0-beta.03

Added 4
  • Use `op user create` with Automated Provisioning configured
  • Use `op user suspend` with Automated Provisioning configured
  • Use `op user reactivate` with Automated Provisioning configured
  • Use `op provisioning configure` to set up Automated Provisioning
Changed 1
  • Improved 'op vault edit' help text to better describe how the Travel Mode flag works

From 1Password CLI

You can now use op user create with Automated Provisioning configured. You can now use op user suspend with Automated Provisioning configured. You can now use op user reactivate with Automated Provisioning configured. You can now use op provisioning configure to set up Automated Provisioning. The 'op vault edit' help text now better describes how the Travel Mode flag works.

View originalPermalink
How 2.36.0-beta.03 went

2.34.0

Added 7
  • Authenticate the Claude Code CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Scaleway CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • The AWS shell plugin now supports the awslogs CLI
  • The AWS shell plugin now supports eksctl, the Amazon EKS CLI
  • The AWS shell plugin now supports the AWS SAM CLI
  • The OpenAI shell plugin now supports the Codex CLI
  • The AWS CDK shell plugin now supports AWS Profiles that assume a role when specified by the --profile flag
Fixed 2
  • The ngrok shell plugin no longer performs a version check on every op plugin command when it is not initialized
  • op run now properly terminates the subprocess it was called with when cancelled

From 1Password CLI

Authenticate the Claude Code CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @malob for their contribution! Authenticate the Scaleway CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @jksolbakken for their contribution! The AWS shell plugin now supports the awslogs CLI. Thanks to @jonasws for their contribution! The AWS shell plugin now supports eksctl, the Amazon EKS CLI. Thanks to @skpaz for their contribution! The AWS shell plugin now supports the AWS SAM CLI. Thanks to @simonmcc for their contribution! The OpenAI shell plugin now supports the Codex CLI. Thanks to @shyim for their contribution! The ngrok shell plugin no longer performs a version check on every op plugin command when it is not initialized. Thanks to @MOmarMiraj for their contribution! The AWS CDK shell plugin now supports AWS Profiles that assume a role when specified by the --profile flag. Thanks to @waiteb3 for their contribution! op run now properly terminates the subprocess it was called with when cancelled (for example, with Ctrl+C).

View originalPermalink
How 2.34.0 went

2.35.0-beta.01

Added 7
  • Authenticate the Claude Code CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Scaleway CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • The AWS plugin now supports the awslogs CLI
  • The AWS plugin now supports eksctl, the Amazon EKS CLI
  • The AWS plugin now supports the AWS SAM CLI
  • The OpenAI Shell Plugin now supports the Codex CLI
  • The AWS CDK plugin now supports AWS Profiles that assume a role when specified by the --profile flag
Changed 1
  • The Terraform plugin now triggers authentication for all terraform state subcommands, not just terraform state list
Fixed 2
  • The ngrok plugin no longer performs a version check on every op plugin command when it is not initialized
  • op run now properly terminates the subprocess it was called with when cancelled

From 1Password CLI

Authenticate the Claude Code CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @malob for their contribution! Authenticate the Scaleway CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @jksolbakken for their contribution! The AWS plugin now supports the awslogs CLI. Thanks to @jonasws for their contribution! The AWS plugin now supports eksctl, the Amazon EKS CLI. Thanks to @skpaz for their contribution! The AWS plugin now supports the AWS SAM CLI. Thanks to @simonmcc for their contribution! The OpenAI Shell Plugin now supports the Codex CLI. Thanks to @shyim for their contribution! The Terraform plugin now triggers authentication for all terraform state subcommands, not just terraform state list. Thanks to @frans-otogone for their contribution! The ngrok plugin no longer performs a version check on every op plugin command when it is not initialized. Thanks to @MOmarMiraj for their contribution! The AWS CDK plugin now supports AWS Profiles that assume a role when specified by the --profile flag. Thanks to @waiteb3 for their contribution! op run now properly terminates the subprocess it was called with when cancelled (for example, with Ctrl+C).

View originalPermalink
How 2.35.0-beta.01 went

2.33.1

Added 1
  • 1Password CLI commands now support the Account Trust Log when the user authenticates with the 1Password desktop app
Changed 1
  • op item edit help text now includes a warning that JSON item templates don't support passkeys

From 1Password CLI

op item edit help text now includes a warning that JSON item templates don't support passkeys. 1Password CLI commands now support the Account Trust Log when the user authenticates with the 1Password desktop app.

View originalPermalink
How 2.33.1 went

2.34.1-beta.01

Added 1
  • 1Password CLI commands now support the Account Trust Log when the user authenticates with the 1Password desktop app

From 1Password CLI

1Password CLI commands now support the Account Trust Log when the user authenticates with the 1Password desktop app.

View originalPermalink
How 2.34.1-beta.01 went

2.34.0-beta.04

Fixed 1
  • Account Trust Log now correctly updates when the feature is enabled

From 1Password CLI

1Password CLI now correctly updates an account's Account Trust Log when the feature is enabled.

View originalPermalink
How 2.34.0-beta.04 went

2.34.0-beta.03

Changed 1
  • op environment help text now includes information about how to get the ID for a 1Password Environment

From 1Password CLI

op environment help text now includes information about how to get the ID for a 1Password Environment.

View originalPermalink
How 2.34.0-beta.03 went

2.33.0

Added 1
  • 1Password CLI now supports updating an account's Account Trust Log when the feature is enabled
Changed 3
  • The --tags flag on op item edit now replaces existing tags instead of appending them
  • An empty --tags value now properly clears all tags
  • Default values for Date and MonthYear fields are now unset instead of zero
Fixed 1
  • Empty tag strings in templates are now filtered out during op item create and op item edit
Security 2
  • Upgrade Go to 1.24.12 to resolve vulnerabilities
  • Upgrade Go to 1.25.7 to resolve vulnerabilities

From 1Password CLI

1Password CLI now supports updating an account's Account Trust Log when the feature is enabled. The --tags flag on op item edit now replaces existing tags instead of appending them. An empty --tags value now properly clears all tags. Empty tag strings in templates are now filtered out during op item create and op item edit. Default values for Date and MonthYear fields are now unset instead of zero. Upgrade Go to 1.24.12 to resolve vulnerabilities. Upgrade Go to 1.25.7 to resolve vulnerabilities.

View originalPermalink
How 2.33.0 went

2.33.0-beta.02

Added 1
  • op environment read command allows reading environment variables from 1Password Environments

From 1Password CLI

op environment read allows reading environment variables from 1Password Environments.

View originalPermalink
How 2.33.0-beta.02 went

2.32.1

Changed 2
  • op item delete help text now notes that deleted items remain in Recently Deleted for 30 days
  • op run help text now notes shell expansion order of operations
Fixed 3
  • Tags are now deduplicated when using op item edit
  • op item create help text example now works without error
  • 1Password CLI now correctly exits with code 1 instead of 0 when encountering server error codes that are not recognized by the CLI

From 1Password CLI

The op item delete help text now notes that deleted items remain in Recently Deleted for 30 days. {4377} Tags are now deduplicated when using op item edit. {4088} 'op run' help text now notes shell expansion order of operations. {2971} op item create help text example now works without error. {4246} 1Password CLI now correctly exits with code 1 instead of 0 when encountering server error codes that are not recognized by the CLI. {DG-682}

View originalPermalink
How 2.32.1 went

2.32.0

Added 1
  • Use 1Password CLI to recover accounts for family or team members

From 1Password CLI

You can now use 1Password CLI to recover accounts for family or team members. {4161}

View originalPermalink
How 2.32.0 went

2.31.1

Fixed 2
  • The 1Password app integration with 1Password CLI now works again on Windows
  • A typo in the error message for 'op user confirm' has been fixed

From 1Password CLI

The 1Password app integration with 1Password CLI now works again on Windows. {4325} A typo in the error message for 'op user confirm' has been fixed. {4329}

View originalPermalink
How 2.31.1 went

2.31.0

Changed 3
  • The 1password/op:latest DockerHub tag now always points to the latest version of CLI 2
  • The Go version has been bumped to 1.23.8
  • op vault list --filter now returns all vaults you have access to, regardless of permission level
Fixed 2
  • 1Password CLI no longer causes direnv to halt when the two are used together
  • op group user grant now works correctly in MSP accounts

From 1Password CLI

1Password CLI no longer causes direnv to halt when the two are used together. {4250} Following the deprecation of CLI 1, the 1password/op:latest DockerHub tag will now always point to the latest version of CLI 2. {4267} The Go version has been bumped to 1.23.8. {4305} op vault list --filter now returns all vaults you have access to, regardless of permission level, making it easier to discover and manage vaults beyond just those with read access. {4189} 'op group user grant' now works correctly in MSP accounts. {4244}

View originalPermalink
How 2.31.0 went

2.31.0-beta.01

Changed 2
  • The 1password/op:latest DockerHub tag now always points to the latest version of CLI 2
  • op vault list --filter now returns all vaults you have access to, regardless of permission level
Fixed 2
  • 1Password CLI no longer causes direnv to halt when the two are used together
  • op group user grant now works correctly in MSP accounts

From 1Password CLI

1Password CLI no longer causes direnv to halt when the two are used together. {4250} Following the deprecation of CLI 1, the 1password/op:latest DockerHub tag will now always point to the latest version of CLI 2. {4267} op vault list --filter now returns all vaults you have access to, regardless of permission level, making it easier to discover and manage vaults beyond just those with read access. {4189} 'op group user grant' now works correctly in MSP accounts. {4244}

View originalPermalink
How 2.31.0-beta.01 went

2.30.3

Added 1
  • Expose OP_RUN_NO_MASKING environment variable to allow users to control the masking of the op run command output
Changed 2
  • The op read, op run and op inject commands no longer query archived items
  • On Windows, the CLI now checks each signature of the 1Password desktop app before connecting to it
Fixed 1
  • For 1Password accounts managed by an MSP, 1Password CLI commands involving Service Accounts, Connect, or the Events API no longer occasionally return an error

From 1Password CLI

The OP_RUN_NO_MASKING environment variable is now exposed to allow users to control the masking of the op run command output. {4089} For 1Password accounts that are managed by an MSP, 1Password CLI commands involving Service Accounts, Connect, or the Events API no longer occasionally return an error. {4033} The op read, op run and op inject commands no longer query archived items. {3893} On Windows, the CLI now checks each signature of the 1Password desktop app before connecting to it. {4136}

View originalPermalink
How 2.30.3 went

2.30.0

Changed 7
  • Sensitive values from item management commands' human-readable output are now concealed and can be displayed using the --reveal flag
  • Caching is now being used for service account sessions on macOS and Linux
  • The error message when the CLI can't connect with the 1Password desktop app now includes a link to troubleshooting documentation
  • op whoami will now signal if the CLI is authenticated as a human user
  • The output of op vault list now contains the created date and item count for each vault
  • The op item move and op item delete commands now also work for SSH Key items
  • Windows Authenticode signature now uses the SHA256 hashing algorithm
Fixed 2
  • The op vault revoke user command will no longer allow you to revoke permissions in a Personal, Private, or Employee vault
  • When the same environment variable name exists both in the OS environment and the dotenv file, op run now correctly sources the value from the dotenv file

From 1Password CLI

Sensitive values from item management commands' human-readable output are now concealed and can be displayed using the --reveal flag. {4158} Caching is now being used for service account sessions on macOS and Linux. {4133} The error message when the CLI can't connect with the 1Password desktop app now includes a link to troubleshooting documentation for more help. {3933} op whoami will now signal if the CLI is authenticated as a human user. {4104} The output of op vault list now contains the created date and item count for each vault. {4092} The op item move and op item delete commands now also work for SSH Key items. {3951} The op vault revoke user command will no longer allow you to revoke permissions in a Personal, Private, or Employee vault. {3844} When the same environment variable name exists both in the OS environment and the dotenv file, op run now correctly sources the value from the dotenv file. {3667} Windows Authenticode signature now uses the SHA256 hashing algorithm. {4135}

View originalPermalink
How 2.30.0 went

2.30.0-beta.03

Added 1
  • Beginning user recovery is now possible using the CLI
Changed 4
  • The error message when the CLI can't connect with the 1Password desktop app now includes a link to troubleshooting documentation
  • The output of 'op vault list' now contains the created date and item count for each vault
  • The `op vault revoke user` command will not allow you to revoke permissions in a Personal, Private, or Employee vault
  • Windows Authenticode signature now uses the SHA256 hashing algorithm
Fixed 2
  • The `op item move` and `op item delete` commands no longer error for SSH Key items
  • When the same environment variable name exists both in the OS environment and the dotenv file, 'op run' now correctly sources the value from the dotenv file

From 1Password CLI

Beginning user recovery is now possible using the CLI. {4161} The error message when the CLI can't connect with the 1Password desktop app now includes a link to troubleshooting documentation for more help. {3933} The output of 'op vault list' now contains the created date and item count for each vault. {4092} The op item move and op item delete commands no longer error for SSH Key items. {3951} The op vault revoke user command will not allow you to revoke permissions in a Personal, Private, or Employee vault. {3844} When the same environment variable name exists both in the OS environment and the dotenv file, 'op run' now correctly sources the value from the dotenv file. {3667} Windows Authenticode signature now uses the SHA256 hashing algorithm. {4135}

View originalPermalink
How 2.30.0-beta.03 went

2.30.0-beta.02

Added 2
  • Prompt on first run of the CLI to automatically open the settings dialogue in 1Password 8 to check the "Integrate with CLI" checkbox
  • Provision a temporary FIFO file using the --inject-file flag in op run
Changed 1
  • op whoami now outputs the user type when authenticated as a human user
Fixed 1
  • Desktop app integration now works with beta builds of the CLI

From 1Password CLI

On first run of the CLI, there is now a prompt to automatically open the settings dialogue in 1Password 8 to check the "Integrate with CLI" checkbox. {3694} It's now possible to provision a temporary FIFO file using the --inject-file flag in op run. {3773} op whoami now also outputs the user type when authenticated as a human user. {4104} The desktop app integration now again works with beta builds of the CLI. {4075}

View originalPermalink
How 2.30.0-beta.02 went

2.29.0

Added 2
  • Use the op whoami command with a 1Password Connect server
  • Format the output when creating a service account as a JSON object by adding --format json to the command
Changed 2
  • Adjust service account creation functionality to support enabling other users and groups to create service accounts
  • Service account tokens now include device UUIDs for scalability purposes

From 1Password CLI

Adjust service account creation functionality to support the new feature of enabling other users and groups to create service accounts. {3960} You can now use the op whoami command with a 1Password Connect server. {2636} Service account tokens now include device UUIDs for scalability purposes. {4009} The output when you create a service account can now be formatted as a json object by adding --format json to the command. {3996}

View originalPermalink
How 2.29.0 went

2.28.0

Added 1
  • 1Password can now retrieve PKCS1-formatted SSH keys using op read
Changed 1
  • Private vaults have been renamed Employee vaults for 1Password Business accounts
Fixed 1
  • The 1Password CLI package installer for macOS now correctly displays the CLI version in the package receipt

From 1Password CLI

Private vaults have been renamed Employee vaults for 1Password Business accounts. {3810} 1Password can now retrieve PKCS1-formatted SSH keys using op read. {3993} The 1Password CLI package installer for macOS now correctly displays the CLI version in the package receipt. {4027}

View originalPermalink
How 2.28.0 went
2.27.0

2.27.0 (build #2270003)

Changed 1
  • Users and groups can now grant and revoke permissions if they have the manage_vault permission
Fixed 2
  • op read will now output an error message consistent with the secret reference provided when no matching field or section is found within the item
  • Output of SSH private keys on non-DOS OSes no longer includes the carriage return character in line-breaks

From 1Password CLI

op read will now output an error message consistent with the secret reference provided, when no matching field or section is found within the item. {3592} Output of SSH private keys on non-DOS OSes no longer includes the carriage return character in line-breaks. {3913} Users and groups can now grant and revoke permissions if they have the manage_vault permission. {3863}

View originalPermalink
How 2.27.0 went
2.26.1

2.26.1 (build #2260101)

Changed 1
  • The CLI build for Darwin now builds with Go 1.21.8

From 1Password CLI

The CLI build for Darwin now builds with Go 1.21.8. The previous version was built using an older version, which was causing alerts for certain customers.

View originalPermalink
How 2.26.1 went
2.26.0

2.26.0 (build #2260001)

Added 2
  • op service-account create command allows you to create a new service account that you can use to automate secrets management
  • op service-account ratelimit command allows you to fetch information about service account rate limit usage
Changed 3
  • op user provision command now clarifies that users will not be considered for billing until they accept their invitation
  • --expires-in flags now include support for days and weeks
  • item share --expiry flag is now aliased to the standardized --expires-in flag
Fixed 1
  • Corrected a typo in user suspend error message

From 1Password CLI

op service-account create command allows you to create a new service account that you can use to automate secrets management. op service-account ratelimit command allows you to fetch information about service account rate limit usage. {3886} The op user provision command now clarifies that users will not be considered for billing until they accept their invitation. {3965} --expires-in flags now include support for days and weeks. {3298} The item share --expiry flag is now aliased to the standardized --expires-in flag. {3298} Corrected a typo in user suspend error message. {3298}

View originalPermalink
How 2.26.0 went
2.25.1

2.25.1 (build #2250101)

Retrieving an SSH Key using the CLI with Connect now works as expected. {3851}

View originalPermalink
How 2.25.1 went
2.25.0

2.25.0 (build #2250001)

Added 1
  • Add --permission flag to op vault list to retrieve vaults for which a user or group has specific permissions
Fixed 1
  • Correctly update password strength when setting a non-generated password

From 1Password CLI

op vault list --permission now allows you to retrieve a list of vaults for which a user or group has specific permissions. {3879} When setting a non-generated password, 1Password CLI now always correctly updates the password strength. {3787}

View originalPermalink
How 2.25.0 went
2.24.0

2.24.0 (build #2240001)

Added 1
  • The 1Password CLI macOS installer now allows for custom location selection
Changed 3
  • Help text now uses present tense more consistently where actions in the present are described
  • Help text now refers to the 1Password app consistently
  • Help text now refers to Connect server instances and tokens consistently
Fixed 2
  • op group user grant and op group user revoke no longer panic when the group does not exist
  • Duo MFA is no longer prompted for more often than required

From 1Password CLI

The 1Password CLI MacOS installer now allows for custom location selection. {3731} Help text now uses present tense more consistently where actions in the present are described. {3768} Help text now refers to the 1Password app consistently. {3626} Help text now refers to Connect server instances and tokens consistently. {3476} op group user grant and op group user revoke no longer panic when the group doesn't exist. {3859} Duo MFA is no longer more often prompted for than required. {3907}

View originalPermalink
How 2.24.0 went
2.23.0-beta.01

2.23.0-beta.01 (build #2230001)

Added 1
  • 1Password CLI universal installer now allows for custom location selection
Changed 1
  • Terraform now requires authentication for init and state list
Fixed 1
  • Terraform shell plugin now works as expected when using the ngrok provider

From 1Password CLI

The 1Password CLI universal installer now allows for custom location selection. {3731} Terraform shell plugin now works as expected when using the ngrok provider. { shell-plugins#222} Terraform now requires authentication for init and state list. Thanks to @JustMaris for their contribution! { shell-plugins#380}

View originalPermalink
How 2.23.0-beta.01 went
2.23.0

2.23.0 (build #2230001)

Added 2
  • op item edit now accepts JSON input via the --template flag
  • op item edit now supports piping items as JSON via stdin
Changed 2
  • The CLI now returns a helpful error when a user is not an owner and tries to add the Team Members group to a vault when the feature flag limitGroupVaultAccess is enabled
  • Error message now suggests rebooting the app when the CLI cannot connect
Fixed 3
  • Error for op item edit when duplicate fields are found now formats better the field label that is not in a section
  • Creating a vault with --icon=name now works again, using the updated icons
  • Error for op item edit when duplicated fields are found by label no longer prints the field's value

From 1Password CLI

op item edit now accepts JSON input via the --template flag. {1849} op item edit now supports piping items as JSON via stdin. {1849} The CLI now returns a helpful error when a user is not an owner and tries to add the Team Members group to a vault when the feature flag limitGroupVaultAccess is enabled. {3830} Error message now suggests rebooting the app when the CLI cannot connect. {3835} Error for op item edit when duplicate fields are found now formats better the field label that isn't in a section. {3849} Creating a vault with --icon=name now works again, using the updated icons. {3833} Error for op item edit when duplicated fields are found by label no longer prints the field's value. {3848}

View originalPermalink
How 2.23.0 went
2.22.0

2.22.0 (build #2220002)

Added 17
  • Authenticate the Hugging Face CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the InfluxDB CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Binance CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the LocalStack CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Crowdin CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Axiom CLI using Touch ID and other unlock options with 1Password Shell Plugins
Changed 9
  • Help text for many commands is now simpler and uses active voice
  • op read help text now includes example for using ssh-format query parameter to get an SSH key's private key
  • Added a note to op run help text to explain access and option to use service accounts
  • Error messages in op item create and when provisioning actions fail are now more clear
  • op whoami for service accounts no longer asks to authenticate the service account token, instead it does it automatically
  • PostgreSQL plugin now also supports pgcli as an alternative to psql

From 1Password CLI

Authenticate the Hugging Face CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @bala-ceg for their contribution! { shell-plugins#393} Authenticate the InfluxDB CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @bala-ceg for their contribution! { shell-plugins#392} Authenticate the Binance CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @bala-ceg for their contribution! { shell-plugins#391} Authenticate the LocalStack CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @simonrw for their contribution! { shell-plugins#371} Authenticate the Crowdin CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @JoeKarow for their contribution! { shell-plugins#359} Authenticate the Axiom CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#342} Authenticate the Kaggle CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#341} Authenticate the Todoist CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#340} Authenticate the Pipedream CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#338} Authenticate the Zapier CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @rajapri28613 for their contribution! { shell-plugins#337} Authenticate the Vertica CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @parthiv11 for their contribution! { shell-plugins#327} Authenticate the Yugabyte CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @parthiv11 for their contribution! { shell-plugins#322} Authenticate the Upstash CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @siddhikhapare for their contribution! { shell-plugins#316} Authenticate the Civo CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @itsCheithanya for their contribution! { shell-plugins#296} Authenticate the MongoDB Atlas CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @joqim for their contribution! { shell-plugins#198} Authenticate the Flyctl CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @arunsathiya for their contribution! { shell-plugins#141} Help text for many commands is now simpler and uses active voice. {3676, 3768} op read help text now includes example for using ssh-format query parameter to get an SSH key's private key. {3795} Added a note to op run help text to explain access and option to use service accounts. {3804} Error messages in op item create and when provisioning actions fail are now more clear. {3263, 3766} op whoami for service accounts no longer asks to authenticate the service account token. Instead, it does it automatically. {3744} PostgreSQL plugin now also supports pgcli as an alternative to psql. Thanks to @szymon for their contribution! { shell-plugins#384} The Cachix plugin now checks for the ~/.config/cachix/cachix.dhall file and attempts to import an auth token using the specified file. Thanks to @dethancosta for their contribution! { shell-plugins#373} The Sentry CLI plugin now skips authentication when the --auth-token and --api-key are specified. Thanks to @roy9495 for their contribution! { shell-plugins#370} The Homebrew shell plugin now provides authentication for the upgrade, update, install and reinstall commands. Thanks to @cullenmcdermott for their contribution! { shell-plugins#369} The Sentry Plugin now has support for SENTRY_PROJECT & SENTRY_URL. Thanks to @JoeKarow for their contrib

View originalPermalink
How 2.22.0 went
2.21.0

2.21.0 (build #2210002)

Added 6
  • Add a note to `op run` help text to explain access and option to use service accounts
  • PostgreSQL plugin now supports `pgcli` as an alternative to psql
  • Cachix plugin checks for the `~/.config/cachix/cachix.dhall` file and attempts to import an auth token using the specified file
  • Sentry Plugin now has support for `SENTRY_PROJECT` & `SENTRY_URL`
  • PostgreSQL plugin now supports the `pg_dump` and `pg_restore` CLI utilities
  • Homebrew shell plugin now provides authentication for the `upgrade`, `update`, `install` and `reinstall` commands
Changed 7
  • Error messages in `op item create` and when provisioning actions fail are now more clear
  • `op whoami` for service accounts no longer asks to authenticate the service account token and instead does it automatically
  • Sentry CLI plugin now skips authentication when the `--auth-token` and `--api-key` are specified
  • OpenAI now has updated docs and management URLs
  • When generating the plugin template, set only the last word of the credential name as the default 1Password field name if it's longer than seven characters
  • The ngrok plugin now uses envvars in ngrok version 3.2.1 and higher
  • `op vault list` now only returns vaults the account has read access to
Fixed 4
  • The ngrok plugin now specifies the correct credential length
  • Bring back deprecated JSON keys for `op whoami` output for service account for backwards-compatibility
  • `op whoami` throws the appropriate error if an invalid service account token is set
  • When searching for an item by title and vault where the title is 26 characters long, the item will now be returned

From 1Password CLI

Added a note to op run help text to explain access and option to use service accounts. Error messages in op item create and when provisioning actions fail are now more clear. op whoami for service accounts no longer asks to authenticate the service account token. Instead, it does it automatically. PostgreSQL plugin now also supports pgcli as an alternative to psql. The Cachix plugin now checks for the ~/.config/cachix/cachix.dhall file and attempts to import an auth token using the specified file. The Sentry CLI plugin now skips authentication when the --auth-token and --api-key are specified. The Homebrew shell plugin now provides authentication for the upgrade, update, install and reinstall commands. The Sentry Plugin now has support for SENTRY_PROJECT & SENTRY_URL. The PostgreSQL plugin now also supports the pg_dump and pg_restore CLI utilities. OpenAI now has updated docs and management URLs. When generating the plugin template, set only the last word of the credential name as the default 1Password field name, if it's longer than seven characters. The ngrok plugin now specifies the correct credential length. The ngrok plugin now uses envvars in ngrok version 3.2.1 and higher. Bring back deprecated JSON keys for op whoami output for service account for backwards-compatibility. op whoami throws the appropriate error if an invalid service account token is set. When searching for an item by title and vault where the title is 26 characters long, the item will now be returned. op vault list now only returns vaults the account has read access to.

View originalPermalink
How 2.21.0 went
2.20.0

2.20.0 (build #2200001)

Added 7
  • SSH keys can now be generated with the op item create --category ssh command
  • Secret references now support retrieving attributes of an item field, such as MFA codes and SSH private key formats, using query parameters
  • op item move moves an item between vaults
  • It's now possible to create a favorite item with op item create
  • It's now possible to update an item's favorite status with op item edit
  • op whoami now tells the user if the service account is authenticated or not
  • The CLI now shows shell plugin setup instructions when no installed plugins are detected
Changed 6
  • The CLI can now be installed at any location and the desktop app integration will work as long as the latest version is being used
  • op, op signin and op account add help text is now simpler and less verbose
  • When retrieving items of type SSH key, the private key is displayed in OpenSSH format
  • Items created using the shell plugins' importers now also contain the plugin's management URL
  • op whoami output for service accounts (both human readable and JSON) is now on par with the output for regular users
  • op whoami JSON output for service account now has the keys in snake_case, matching the rest of the CLI JSON output
Fixed 5
  • There is no longer an error returned for shell plugins initialized before version 2.19.0
  • Addressed a rare case where a secret would not correctly be masked by the op run command
  • Using a 26-character long item title no longer results in an error when retrieving the item
  • 1Password CLI no longer crashes when an invalid service account token is provided
  • The CLI will not prompt to authorize if there are no secret references in the environment

From 1Password CLI

SSH keys can now be generated with the op item create --category ssh command. The CLI can now be installed at any location and the desktop app integration will work as long as the latest version is being used. op, op signin and op account add help text is now simpler and less verbose. Secret references now support retrieving attributes of an item field, such as MFA codes and SSH private key formats, using query parameters. op item move moves an item between vaults. When retrieving items of type SSH key, the private key is displayed in OpenSSH format. Items created using the shell plugins' importers now also contain the plugin's management URL. The CLI now shows shell plugin setup instructions when no installed plugins are detected. The CLI will not prompt to authorize if there are no secret references in the environment. op whoami output for service accounts (both human readable and JSON) is now on par with the output for regular users. op whoami now tells the user if the service account is authenticated or not. It's now possible to create a favorite item with op item create. It's now possible to update an item's favorite status with op item edit. There is no longer an error returned for shell plugins initialized before version 2.19.0. Addressed a rare case where a secret would not correctly be masked by the "op run" command. Using a 26-character long item title no longer results in an error when retrieving the item. 1Password CLI no longer crashes when an invalid service account token is provided. op whoami JSON output for service account now has the keys in snake_case, matching the rest of the CLI JSON output.

View originalPermalink
How 2.20.0 went
2.19.0

2.19.0 (build #2190004)

Added 4
  • Authenticate the Oh Dear CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Executables oaieval and oaievalset are now supported within the OpenAI shell plugin
  • Authenticate the Vercel CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • AWS shell plugin now supports sourcing credentials from another profile
Changed 3
  • op plugin clear more clearly displays credentials which are about to be cleared
  • GitHub shell plugin skips authentication if it runs with shell completion flag __complete
  • Shell plugin help text now references plugin-executable instead of plugin-name for clarity
Fixed 4
  • 1Password CLI will no longer return a received unexpected response from 1Password app error for the first command executed when the 1Password app is locked
  • A typo in the op whoami help text has been fixed
  • AWS Shell Plugin no longer outputs aws-vault specific logs
  • AWS shell plugin no longer creates an .aws/config file when using the aws-vault importer

From 1Password CLI

Authenticate the Oh Dear CLI using Touch ID and other unlock options with 1Password Shell Plugins. Executables "oaieval" and "oaievalset" are now supported within the OpenAI shell plugin. Authenticate the Vercel CLI using Touch ID and other unlock options with 1Password Shell Plugins. op plugin clear more clearly displays credentials which are about to be cleared. AWS shell plugin now supports sourcing credentials from another profile. GitHub shell plugin skips authentication if it runs with shell completion flag __complete. Shell plugin help text now references plugin-executable instead of plugin-name for clarity. 1Password CLI will no longer return a "received unexpected response from 1Password app" for the first command that is executed when the 1Password app is locked. A typo in the op whoami help text has been fixed. AWS Shell Plugin no longer outputs aws-vault specific logs. AWS shell plugin no longer creates an .aws/config file when using the aws-vault importer.

View originalPermalink
How 2.19.0 went
2.19.0-beta.01

2.19.0-beta.01 (build #2190001)

Added 1
  • Authenticate the Terraform CLI using Touch ID and other unlock options with 1Password Shell Plugins
Changed 1
  • Shell plugin help text now references plugin-executable instead of plugin-name for clarity
Fixed 1
  • Deleting an SSH Key with the CLI now works as expected

From 1Password CLI

Authenticate the Terraform CLI using Touch ID and other unlock options with 1Password Shell Plugins. Shell plugin help text now references plugin-executable instead of plugin-name for clarity. Deleting an SSH Key with the CLI now works as expected.

View originalPermalink
How 2.19.0-beta.01 went
2.18.0

2.18.0 (build #2180001)

Added 2
  • Users can now authenticate with the CLI using 1Password Service Accounts
  • Users can now create items of custom categories by providing a template
Fixed 1
  • Executing op plugin run with a plugin that has not yet been configured no longer exits after the configuration steps

From 1Password CLI

Users can now authenticate with the CLI using 1Password Service Accounts. Users can now create items of custom categories by providing a template. Executing op plugin run with a plugin that has not yet been configured no longer exits after the configuration steps.

View originalPermalink
How 2.18.0 went

2.18.0-beta.01

This beta release brings the beta channel up-to-date with the latest stable.

View originalPermalink
How 2.18.0-beta.01 went
2.17.0

2.17.0 (build #2170001)

Added 8
  • Authenticate the Akamai CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Laravel Vapor CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Laravel Forge CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Pulumi CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Zendesk CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Import AWS credentials stored in aws-vault into 1Password
  • Authenticate the AWS CDK CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Support assuming AWS roles and profiles with the AWS shell plugin
Changed 3
  • Display deleted or restricted users by name when running op item get
  • Add description about configuring the CLI to use Connect or Service Account if no account is configured in the help text of op signin
  • Fully support the --config and --session flags for op plugin and op whoami commands respectively
Fixed 3
  • Throw an error if a document is created or updated from the CLI through standard input but no content is provided
  • Display a friendlier error message when users attempt to create new DOCUMENT items with Connect
  • Correct typos in the help text of document create and document edit concerning the misspelling of the --file-name flag

From 1Password CLI

Authenticate the Akamai CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate the Laravel Vapor CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate the Laravel Forge CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate the Pulumi CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate the Zendesk CLI using Touch ID and other unlock options with 1Password Shell Plugins. AWS credentials stored in aws-vault can now be imported into 1Password. Authenticate the AWS CDK CLI using Touch ID and other unlock options with 1Password Shell Plugins. Assuming AWS roles and profiles is now supported with the AWS shell plugin. A deleted/restricted user that last updated an item will be displayed by name when running op item get. An error is thrown if a document is created/updated from the CLI through standard input but no content is provided. A description was added about configuring the CLI to use Connect / Service Account if no account is configured, in the help text of op signin. Users attempting to create new DOCUMENT items with Connect will now receive a friendlier error message. The --config and --session flags are now fully supported for op plugin and op whoami commands respectively. Typos in the help-text of document create and document edit concerning the misspelling of the --file-name flag have been corrected.

View originalPermalink
How 2.17.0 went

2.17.0-beta.01

Added 1
  • Add `op ssh generate` command to generate SSH keys with the CLI
Changed 1
  • When no accounts are configured, the CLI now prints information about using it with Connect and Service Accounts

From 1Password CLI

Generating SSH Keys with the CLI is now possible using the op ssh generate command. When no accounts are configured, the CLI also prints information about using it with Connect and Service Accounts.

View originalPermalink
How 2.17.0-beta.01 went

2.16.1

Changed 2
  • Help text for op events-api now specifies that Events Reporting is only available for business accounts
  • Gitea plugin now checks the default configuration directory on MacOS to find a credential to import when initializing
Fixed 2
  • SourceGraph shell plugin now displays an appropriate management url when initializing
  • Treasure Data shell plugin no longer returns an error during the init step as its executable now correctly references its API Key credential

From 1Password CLI

The help text for op events-api now specifies that Events Reporting is only available for business accounts. When initializing the SourceGraph shell plugin an appropriate management url will be displayed. Treasure Data shell plugin no longer returns an error during the init step, as its executable now correctly references its API Key credential. When initializing the Gitea plugin, it now also checks the default configuration directory on MacOS to find a credential to import.

View originalPermalink
How 2.16.1 went

2.16.0

Added 5
  • Authenticate Gitea CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate Treasure Data CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Add --out-file flag to op document get as an alias for --output for consistency with other commands
  • Shell plugins credential fields can now be identified by more than one name
  • Item count is now present in the JSON output of empty vaults' details
Changed 5
  • Default features list when creating new Events API tokens now includes Audit Events in addition to Sign-In Attempts and Item Usages
  • ngrok shell plugin is now aware of the --config flag and existing config files in the default location
  • HomeBrew shell plugin now skips authentication for the bump sub-command
  • Shell plugin selection prompt now shows additional item metadata to help determine the correct 1Password item
  • document get now outputs the absolute file path on successful file write and prompts to overwrite if the file already exists
Fixed 7
  • Connect tokens with no vault access permissions can no longer be created using the 1Password CLI
  • UpdatedAt and ItemCount attributes are now consistently up to date in the cached vaults
  • Item version is now up to date in the output of op item create and op item edit
  • Connect tokens can now be created when passing the --vault flag with op connect token create
  • Items are now successfully returned by op item get even if they were last edited by a deleted or restricted user
  • CLI will no longer silently succeed if the piped input is not handled properly
  • Item lookup by name will no longer fail when resource name is alphanumeric of length 26

From 1Password CLI

The default features list when creating new Events API tokens will now include Audit Events, in addition to Sign-In Attempts and Item Usages. Authenticate Gitea CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate Treasure Data CLI using Touch ID and other unlock options with 1Password Shell Plugins. ngrok is now aware of the --config flag and of any existing config files in the default location on the user's filesystem. The HomeBrew shell plugin now skips authentication for the bump sub-command as well. The --output flag of op document get is now doubled by --out-file, for consistency with other commands. To help with determining the 1Password item to use for a shell plugin, additional item metadata is now shown in the selection prompt. Shell plugins credential fields can now be identified by more than one name. document get now outputs the absolute file path on a successful file write and prompts to overwrite if the file already exists. Connect tokens with no vault access permissions can no longer be created using the 1Password CLI. Item count is now present in the JSON output of empty vaults' details. UpdatedAt and ItemCount attributes are now consistently up to date in the cached vaults. Item version is now up to date in the output of op item create and op item edit. Connect tokens can now be created when passing the --vault flag with the op connect token create. Items are now successfully returned by op item get even if they were last edited by a deleted or restricted user. The CLI will no longer silently succeed if the piped input is not handled properly. Item lookup by name will no longer fail when resource name is alphanumeric of length 26.

View originalPermalink
How 2.16.0 went

2.16.0-beta.01

Changed 2
  • document get now outputs the absolute file path on a successful file write and prompts to overwrite if the file already exists
  • The stability of Service Accounts has been improved
Fixed 1
  • Connect tokens with no vault access permissions can no longer be created using the 1Password CLI

From 1Password CLI

document get now outputs the absolute file path on a successful file write and prompts to overwrite if the file already exists. The stability of Service Accounts has been improved. Connect tokens with no vault access permissions can no longer be created using the 1Password CLI.

View originalPermalink
How 2.16.0-beta.01 went

2.15.0-beta.03

Added 1
  • Add --autofill-urls flag to op item create and op item edit commands to perform CRUD operations on items' autofill URLs
Changed 1
  • Items can now be consistently looked up by name

From 1Password CLI

op item create and op item edit can now be used to perform CRUD operations on items' autofill URLs using the --autofill-urls flag. Items can now be consistently looked up by name.

View originalPermalink
How 2.15.0-beta.03 went

2.14.0

Added 5
  • Authenticate ngrok using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate Vultr CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate Snowflake CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate Fastly CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate Sourcegraph CLI using Touch ID and other unlock options with 1Password Shell Plugins
Changed 3
  • The AWS Shell Plugin now checks if the AWS_SHARED_CREDENTIALS_FILE environment variable is set and attempts to import credentials using the specified file
  • Error messages for shell plugin local builds now include link to troubleshooting documentation
  • Help text formatting is now more consistent across commands

From 1Password CLI

Authenticate ngrok using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate Vultr CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate Snowflake CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate Fastly CLI using Touch ID and other unlock options with 1Password Shell Plugins. Authenticate Sourcegraph CLI using Touch ID and other unlock options with 1Password Shell Plugins. The AWS Shell Plugin now checks if the AWS_SHARED_CREDENTIALS_FILE environment variable is set and attempts to import credentials using the specified file. Error messages for shell plugin local builds now include link to troubleshooting documentation. Help text formatting is now more consistent across commands.

View originalPermalink
How 2.14.0 went
2.13.1

2.13.1 (build #2130101)

Added 2
  • Authenticate the Cargo CLI using Touch ID and other unlock options with 1Password Shell Plugins
  • Authenticate the Argo CD CLI using Touch ID and other unlock options with 1Password Shell Plugins

From 1Password CLI

Authenticate the Cargo CLI using Touch ID and other unlock options with 1Password Shell Plugins. { shell-plugins#139} Authenticate the Argo CD CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @ssttehrani for their contribution! { shell-plugins

View originalPermalink
How 2.13.1 went

2.12.0

Added 2
  • ReadMe CLI shell plugin for authenticating using Touch ID and other unlock options
  • Hcloud CLI shell plugin for authenticating using Touch ID and other unlock options

From 1Password CLI

This release introduces three new Shell Plugins! Authenticate the ReadMe CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @kanadgupta for their contribution! { shell-plugins#106} Authenticate the Hcloud CLI using Touch ID and other unlock options with 1Password Shell Plugins. Thanks to @shyim

View originalPermalink
How 2.12.0 went
View all

Discussion