Password Manager
1Password MCP connector
Connect 1Password to Elaichi and Claude, ChatGPT, Cursor and the Elaichi Agent can list your 1Password users, look one up, suspend a departing person and reactivate a returning one, all under your own access and on the record.
-
How it connects. App credentials. The credential goes into a vault nobody reads back.
-
One address. https://api.elaichi.ai/mcp, the same for every user.
-
Their own access. An agent never gets more than the person it acts for.
How to connect
How to connect 1Password to Claude, ChatGPT or Cursor
Two steps, about a minute.
In Elaichi
Connect 1Password once
-
Open Connections, choose Add connection, and pick 1Password.
-
Optionally set Share with to give a team access, then press Connect.
-
Paste your 1Password app credentials. 1Password authenticates the app rather than a person. One person supplies the credentials once, and everyone else works through Share with.
The credential is vaulted. Nobody reads it back, not even the AI.
Add connection
Choose a connector.
In your AI client
Point it at one endpoint
Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.
Connect 1Password to Claude
-
1
Open Customize, then Connectors.
-
2
Press Add.
-
3
Name it, paste the MCP server URL, then Continue.
https://api.elaichi.ai/mcp -
4
Sign in and approve.
On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.
Connect 1Password to ChatGPT
-
1
Open Plugins, then press the + button.
-
2
Name it and paste the endpoint into Server URL.
https://api.elaichi.ai/mcp -
3
Leave Authentication on OAuth, then tick the risk acknowledgement.
-
4
Press Create, then sign in and approve.
Works on the web today. The plugin directory lives at chatgpt.com/plugins.
Connect 1Password to Cursor
-
1
Open
~/.cursor/mcp.json. -
2
Add the endpoint under
mcpServers.https://api.elaichi.ai/mcp -
3
Reload Cursor, then sign in and approve.
~/.cursor/mcp.json
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
Set up per machine, so repeat it on each computer you work from.
Connect 1Password to any MCP client
-
1
Add the endpoint as a remote MCP server.
https://api.elaichi.ai/mcp -
2
Sign in and approve.
{
"mcpServers": {
"elaichi": {
"url": "https://api.elaichi.ai/mcp"
}
}
}
The Elaichi Agent already has these tools, with nothing to set up.
Use cases
What teams do with 1Password through Elaichi
Every one of these runs inside the access the person already has, and lands in the same audit log.
-
IT
Suspend a leaver before the day ends
When someone leaves, ask the agent to find their 1Password user and suspend it straight away. The change is logged with your name on it.
-
Security
Check who still has a live 1Password user
Pull the full list of 1Password users and compare it with the current headcount. Anyone who should not be there gets flagged in one pass.
-
People Ops
Reactivate someone back from leave
When a person returns from parental or medical leave, ask for their 1Password user to be reactivated the morning they are back. No ticket, no waiting.
-
Compliance
Answer an access review in minutes
Get every 1Password user in a single list, with status, ready to paste into a quarterly access review. Repeat it next quarter with the same question.
-
Helpdesk
Look up one person's account status
A colleague says they cannot sign in to 1Password. Look up their user by name and see at once whether the account is suspended or active.
-
Finance
Count seats before the renewal
Before the 1Password renewal, list active and suspended users to see how many seats are really in use. Suspend the ones nobody needs to trim the bill.
Try asking
- “List every 1Password user and mark who is suspended”
- “Suspend Dana Whitfield's 1Password user, she left today”
- “Reactivate Priya Nair's 1Password user, she is back from leave”
AI tools
1Password tools for your AI agents
4 tools are ready to call through Elaichi's MCP endpoint the moment you connect 1Password, governed by the same roles, restrictions, and audit log as everything else in Elaichi.
No tools match your search.
See it in Elaichi
What connecting 1Password gets you
6 screens from the product, each doing one job for your 1Password account.
The agent
Ask who has 1Password access, in plain words.
Answers come from the live 1Password user list, not a stale export.
- users
- members
- seats
- suspensions
Ask Elaichi to work across your apps.
List every 1Password user and mark who is suspended
Suspend Dana Whitfield's 1Password user, she left today
Reactivate Priya Nair's 1Password user, she is back from leave
Also runs in Claude, ChatGPT or Cursor
MCP clients
1Password in Claude, ChatGPT and Cursor at once.
One governed endpoint, every client, no SDK and no shared API key.
Copy the endpoint
Tool catalog
All 4 1Password user tools, no code needed.
List, look up, suspend and reactivate 1Password users without writing a line.
- List all 1Password users
- Get single 1Password user by ID
- 1Password users suspend
- 1Password users reactivate
Toolboxes
Each team gets its own 1Password toolbox.
IT suspends and reactivates, Compliance only reads the 1Password user list.
- IT
- Security
- People Ops
- Compliance
Shared connections
Share 1Password access, never the credentials.
One admin connects 1Password, teammates work through it without seeing a secret.
- IT
- Security
- People Ops
- Compliance
Audit log
Every 1Password suspension has a name on it.
When, who, what happened and which 1Password user, in an append-only log.
- When
- Who
- What happened
- Type
Launching soon
From answering questions to doing the work
A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.
Automations
Offboarding in 1Password runs itself, with approval.
A schedule fetches 1Password users, drafts a digest, you approve, suspensions apply.
1Password digest
Run 418 · started 2 minutes ago · on behalf of Emma Laurent
-
✓
Schedule
Every weekday at 08:00
0.2s -
✓
Fetch users
1Password
1.4s -
✓
Group by owner
Transform
0.1s -
✓
Draft the digest
Agent step
Ran with 4 tools, returned a structured summary
6.2s -
Approve the digest
Needs approval
Assigned to Michael Brennan
Approve Deny -
Post the digest
1Password
Queued
Collections and dashboards
1Password seat health, refreshed on a schedule.
Active users, suspensions and 14 days of new 1Password users, by team.
1Password health
Refreshed 4 minutes ago · every 15 minutes · from the users collection
Users
1,284 ↓ 12%
Members
96 ↓ 8%
Needs attention
3 ↑ 2
Updated this week
412 ↑ 9%
Users created
Last 14 days
By team
Share of activity
IT 34%
Security 27%
People Ops 21%
Compliance 18%
Related connectors
More from the catalog
FAQ
Frequently asked questions
How do I connect 1Password to Claude?
Connect 1Password in Elaichi first, which asks for your 1Password app credentials and nothing else, so there is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Sign in to Elaichi as yourself and 1Password appears in Claude.
Does 1Password work with ChatGPT and Cursor as well as Claude?
Yes. Once 1Password is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect 1Password once and every client picks it up.
What can an AI agent actually do with my 1Password data?
With 1Password connected, an agent can list every user on your 1Password account, look up a single person to see whether they are active or suspended, suspend a user who has left, and reactivate a user who is back. It does not touch vaults, items or passwords, because this connector only deals in users.
Does connecting 1Password give the AI access to every vault and user?
No. Every call to 1Password runs as the person who signed in, so the agent can only see and change the 1Password users that person could manage themselves. Elaichi can narrow that further, for example to looking up users but never suspending them, and it can never widen it beyond what 1Password already allows that person.
Can I stop an agent from suspending or reactivating people in 1Password?
Yes. Restrictions in Elaichi apply per action, so you can allow listing and looking up 1Password users while blocking suspend and reactivate. A blocked action is never shown to Claude, ChatGPT or Cursor at all, so no prompt, however worded, can reach it.
What happens to a 1Password connection when someone leaves?
Offboarding that person in Elaichi ends their access to the 1Password connection at once, in every client they had it in. A shared 1Password connection keeps working for everyone else on the team. If you want 1Password gone entirely, disconnect it once in Elaichi and it disappears from Claude, ChatGPT, Cursor and every other client together.
Put 1Password in front of your team
Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.