1Password — can an agent use it?
1Password is positioning itself as the credential layer for agentic AI — Credential Broker, agent hooks for Claude Code and Cursor, and SDKs that let agents read secrets at runtime. The developer surface (1password.dev) is strong, but the main site lacks structured data and llms.txt, and enterprise pricing is quote-only.
FIND & RETRIEVE · 5.8
ACT & TRANSACT · 5.6
TRUST & DURABILITY · 8.0
FIND & RETRIEVE5.8/10Can an agent get correct information?
Machine-readable surface5.5/10
No llms.txt on 1password.com (the developer portal at 1password.dev has one). Sitemap valid and referenced in robots.txt. No JSON-LD structured data on the main site. Semantic HTML is good (H1, main, nav). 471 words of SSR HTML — content renders without JS. No .well-known/mcp.json, no .well-known/ai-catalog. No Content-Signal directives. The split between 1password.com (marketing) and 1password.dev (developers) means agents need to discover the dev portal to find machine-readable content. source
Information retrieval quality4/10
All business/enterprise product pricing is behind 'Request a quote' — Unified Access, Enterprise Password Manager, SaaS Manager, Privileged Access, Device Trust all show no prices. The pricing page renders without JS but contains no dollar figures for business tiers. An agent cannot answer 'how much does 1Password cost for my 50-person company?' without a sales call. Personal/family pricing may exist but was not in the fetched evidence. source
Documentation for machines8/10
1password.dev has comprehensive developer docs with its own llms.txt index. SDKs for Python, JavaScript, and Go with quickstarts. CLI with full command reference and biometric auth. Service accounts documented. Environments docs for .env files. Agent hooks for Claude Code and Cursor documented. MCP server configuration page exists. Events API and Users API (Public Preview) documented. 750,000+ developers claimed. source
ACT & TRANSACT5.6/10Can an agent do the job?
Action coverage7.5/10
SDKs (Python/JS/Go) enable vault CRUD — create, read, update, delete items programmatically. CLI covers all vault operations. Service Accounts for machine-to-machine access. Connect server for CI/CD pipeline integration. Events API for SIEM. Users API (Public Preview) for provisioning. Credential Broker verifies AI agents at runtime and delivers scoped credentials. Core actions (manage secrets, read/write vault items) are well-covered. Not 10 because provisioning APIs are preview and some admin actions remain UI-only. source
Agent protocol support6/10
Developer docs mention MCP server configuration for agents, and agent hooks for Claude Code and Cursor. The home page markets Credential Broker as a runtime credential delivery system for AI agents. However, 1Password is not in the official MCP registry, no .well-known/mcp.json exists, and mentions_mcp=false in the automated signal sweep. The agent surface exists but is emergent — the Credential Broker is the real story, not a traditional MCP tool-calling surface. Community MCP wrappers may exist but no official comprehensive MCP server was confirmed. source
Access & auth friction7/10
Service accounts are self-serve for Teams/Business/Enterprise tiers. SDKs handle auth with service account tokens. CLI supports biometric auth. Individual accounts are self-serve signup with 14-day free trial. However, enterprise features (Credential Broker, Privileged Access, SaaS Manager) require a sales conversation. Rate limits exist per tier but are documented on the developer portal, not publicly visible from the evidence fetched. source
Agent payment capability2.5/10
1Password is a subscription service where a human admin manages billing. No ACP, AP2, MPP, or x402 support. Enterprise pricing is quote-based via sales. An agent cannot subscribe, upgrade, or pay on behalf of a user. The service is about managing credentials, not processing payments, but the subscription itself has no programmatic billing path. source
Cost & rate fairness5/10
Service accounts have hourly and daily rate limits that vary by tier (Individual/Family, Teams, Business) per the developer FAQ, but actual numbers are not published in the publicly-accessible evidence. Enterprise pricing is fully opaque (quote-only). No evidence of agent-vs-human price discrimination. The cost structure for API access via service accounts is bundled into the subscription, which is reasonable, but the lack of public rate-limit documentation makes it hard for an agent builder to plan. source
TRUST & DURABILITY8.0/10Will it still work next quarter?
Permission & ToS stance7/10
robots.txt is minimal with no AI-specific rules — neither blocking nor explicitly welcoming AI crawlers. The policy is accidental rather than deliberate. No Content-Signal directives. The main ToS (fetched) has no explicit anti-bot or anti-automation clauses, and the company actively markets to AI agent builders ('Secure access for every human and AI agent' is the homepage headline). Developer terms likely exist separately at 1password.dev but were not fetchable. The Credential Broker product is built for agents, so the commercial posture is pro-automation even if the legal surface doesn't say so explicitly. source
Reliability & continuity9/10
Excellent status page at status.1password.com with 17 individually tracked components including CLI, Service Accounts, Connect, Partnership API, Events API. 99.96% overall uptime over 90 days. Most components at 100%. Founded 2005, 20+ year track record. SOC 2 audited. Individual components like 'Syncing items between devices' and 'Access to passwords' are separately monitored — mature operational transparency. source
Sources
Point-in-time assessment — services change terms, prices and APIs often. That volatility is itself scored under Reliability & continuity. Re-verified at least quarterly.
- 1password.com — home — Unified Access platform, Credential Broker for AI agents, headline 'every human and AI agent' (accessed 2026-09-07)
- 1password.com/pricing — pricing — all business tiers quote-only, no public prices (accessed 2026-09-07)
- 1password.com/robots.txt — robots — minimal, no AI-specific rules (accessed 2026-09-07)
- 1password.dev/llms.txt — developer llms.txt — SDK, CLI, service accounts, AI agent hooks, MCP server docs (accessed 2026-09-07)
- 1password.com/developer-security — developer page — SDKs (Python/JS/Go), CLI, service accounts, Credential Broker, 750K+ developers (accessed 2026-09-07)
- status.1password.com — status — 17 components, 99.96% uptime, CLI/Service Accounts/Connect individually tracked (accessed 2026-09-07)
- 1password.com/legal/terms-of-service — ToS — no anti-automation clauses found, separate developer terms likely exist (accessed 2026-09-07)
- 1password.com/sitemap.xml — sitemap — valid XML, multi-language, referenced in robots.txt (accessed 2026-09-07)
- docs.1password.com — docs subdomain — requires 1Password account login, not publicly browseable (accessed 2026-09-07)
- 1password.dev — developer portal — SDK quickstarts, AI-readable docs, GitHub links, community (accessed 2026-09-07)