PandaOSPandaOSby Pandata
Apps & Integrations

1Password

Browse project vaults, copy and create credentials, and control what Panda can read.

Connect 1Password

Open Settings > Apps > 1Password, enable the app, and click Connect or Load vaults. Enable Integrate with 1Password CLI in the 1Password desktop app under Settings > Developer. PandaOS uses that desktop connection and does not store a service-account token.

Starting PandaOS, restoring a panel, changing projects, and returning focus to the app do not request authentication. Connect, Refresh, and explicit vault actions may ask you to authorize through 1Password. If you decline, PandaOS waits for another action.

Choose project vaults

In the app's Vaults settings, choose which vaults a project may use. An unconfigured project starts with its Private or Employee vaults. AI can read secrets and AI can edit are off by default for every vault; making a vault visible enables neither. AI can read lets agents return values and download attached files; AI can edit lets them create items, replace field values and attach files, each behind an approval card. Worktrees follow their parent project's choices.

Without AI-readable access, Panda receives item metadata rather than passwords, notes or custom field values. Enable AI-readable access only for vaults whose values you want available in the chat.

While the 1Password app is enabled, browser autofill in a project offers and fills only logins from that project's vaults. With the app disabled, autofill works across your whole account as before. After the browser page changes under an open picker, click Show saved logins to search again. Page changes and background polling do not request authentication.

Browse, copy and create

Open the 1Password workspace tab, then choose a vault and item. Secrets stay masked. A field's Copy button puts its value on your clipboard; PandaOS clears it after 90 seconds if the clipboard still contains that value. One-time-code copying copies the current code, never its seed.

Use the plus button beside search to create a Login, Password, API Credential or Secure Note. Password generation happens when you save, and the generated value is not shown in PandaOS. After saving, the new row is marked Just added. If confirmation of a save is lost, check the vault before saving again to avoid creating a duplicate.

Ask Panda to use 1Password

The app provides three actions:

  • onepassword_open opens the panel without reading a vault.
  • onepassword_read lists the project's cached vaults, searches items, or reads one item. Item values are returned only when the vault permits AI access.
  • onepassword_item creates an item or transfers a field into a project .env file through the Credentials Manager.

Actions that contact 1Password ask for confirmation before running, even if the tool is otherwise set to automatic. A recently loaded vault list does not prove the desktop app is still unlocked. With no cached vault list, load it in the panel first. Cached vault listing and opening the panel do not contact 1Password.

Transfer without showing the secret

Ask Panda to transfer a field to a variable such as API_KEY in .env.local. The confirmation identifies the requested operation. The secret moves into the Credentials Manager without appearing in the tool result. Values from a vault without AI-readable access receive no-access protection. Existing variables keep the more restrictive access level, and replacing one requires an explicit overwrite request.

Protected transfer requires Credentials Manager access control to be enabled. It refuses one-time-code fields, paths outside the project, and values the current .env parser cannot preserve, including multiline values. If permissions cannot be saved, the secret is not written.