Requirements
- A 1Password account.
- The latest nightly release of 1Password for Mac or Linux.
- NVIDIA OpenShell installed, with a running gateway.
- A coding agent that OpenShell supports, like Claude Code.
How it works
When you connect a 1Password Environment to an OpenShell gateway, 1Password transfers custody of the Environment’s secrets to OpenShell for a defined time-to-live (TTL). OpenShell controls which services the agent can reach during that window. The agent sends requests from inside the sandbox using placeholder values, so it never sees your actual secrets. OpenShell replaces the placeholders with secret values only when a request matches the active network policy and the provider’s approved host. Secret values never enter the agent process or context. When the time window expires or if the request doesn’t match, OpenShell stops replacing the placeholders, so requests that need the secret fail while the sandbox keeps running. OpenShell governs how the agent runs, which services it can reach, and where its inference requests go. OpenShell enforces these controls outside the agent’s process, so the agent can’t change or get around them.Step 1: Set up an Environment
Set up an Environment in 1Password to store your project secrets for a specific project or development context. If you already have an Environment you want to use, skip to step 2.- In the 1Password desktop app, go to Developer > View Environments.
- Select New environment.
- Enter a name for the new Environment, then select Save.
- Add the variables for your project or import an existing
.envfile.
Step 2: Turn on the integration
- Open the 1Password desktop app.
- Select your account or collection at the top of the sidebar, then navigate to Settings > Developer.
- Under Developer Integrations, select Provision OpenShell providers.
Step 3: Connect the Environment to OpenShell
To connect an Environment to OpenShell:- In the 1Password desktop app, select Developer in the sidebar, then select View Environments.
- Find the name of the Environment you want to use and select View environment.
- Under “Connect to”, select the Connect button next to “OpenShell provider”.
- Provider name: The name you’ll pass to
openshell sandbox create --provider <provider-name>. - Whether you want to use an existing provider profile or create your own:
- Existing profile: Use a profile that’s already been imported on your gateway, such as one for AWS or GitHub. A new gateway has no profiles until someone imports them.
- New profile: 1Password creates a profile on your gateway for you. You set the host, port, and read/write permissions.
- Host: The host a sandbox can make requests to. OpenShell only attaches this provider’s credentials to requests for the approved host and port.
- Port: The port a sandbox can reach on that host. Requests to any other port don’t receive the credential.
- Allow writes: Select this to allow write operations at the approved destination. If you leave it unselected, the provider allows read-only access.
- Secrets expire: The duration of time that OpenShell will resolve placeholders in requests from the sandbox with your secrets. After expiration, the sandbox keeps running, but OpenShell stops resolving the placeholders. To restore access, approve a new connection.
After you configure your provider, select Connect.
You’ll be prompted to authorize OpenShell’s access to your Environment with a detailed authorization prompt that includes the provider name, variables, destinations, expiry, and your account name.
Step 4: Run the setup command
With the provider set up, you can now attach the provider to an OpenShell sandbox. OpenShell owns the sandbox and has custody of the credentials in your Environment for the time window you set.- In the 1Password desktop app, open the Environment.
- In the “Connected to” section, select the ellipsis to the right of “OpenShell provider” then select Copy setup commands.
-
Paste and run the command in your terminal. The copied command creates a sandbox with your provider attached and starts a Bash shell. For example:
To start an agent, edit the command before you run it. Use
--fromto specify an image that contains the agent, and replacebashafter--with the agent’s command. For example:If your agent needs another credential, such as an API key, you can set up another OpenShell provider from a 1Password Environment. Add a--providerflag for each provider you want to attach.
Step 5: Test the connection
Give your agent a task that needs secrets from your Environment. For example, if you set up a GitHub provider, ask the agent to write a script and push it to your repository. Replace<org> and <repo> with your GitHub username or organization and repository name.
openshell term in a terminal outside the sandbox and look for allowed requests to github.com or api.github.com.
The push only works if the provider allows writes and the sandbox’s network policy permits pushes to your repository. If the push is denied, check the deny reason in openshell term.
Manage your workflows
Reconnect an Environment to OpenShell
To reconnect an expired Environment to OpenShell:- In the 1Password desktop app, select Developer in the sidebar, then select View Environments.
- Find the name of the Environment you want to reconnect and select the ellipsis > Send again.
Remove an Environment from OpenShell
To remove an Environment from OpenShell:- In the 1Password desktop app, select Developer in the sidebar, then select View Environments.
- Find the name of the Environment you want to remove and select the ellipsis > Delete workflow.
Troubleshooting
If you don’t see the option to connect to OpenShell
Make sure you’re using the latest nightly version of the 1Password desktop app. To check your current version:- Open the 1Password desktop app.
- Select your account or collection at the top of the sidebar, then navigate to Settings > About.