1Password CLI Python Wrapper
Python wrapper for 1Password CLI with Pydantic Settings integration. Automatically injects secrets from op:// references while preserving types.
Features
- Automatic secret injection with
op://reference detection - Pydantic Settings integration with pre-validation injection
- Type preservation (int, float, bool, None, lists)
- Full type hints with
py.typedmarker - Performance optimized (skips CLI calls when no secrets detected)
- Timeout protection and clear error messages
Installation
pip install 1password-cli
Prerequisites: 1Password CLI installed and authenticated (op signin)
Usage
String injection:
from scottzach1.onepassword_cli import inject_string_1password
password = inject_string_1password("op://vault/database/password")
Dictionary injection:
from scottzach1.onepassword_cli import inject_dictionary_1password
config = {
"database_url": "op://vault/database/url",
"api_key": "op://vault/api/key",
"port": 5432, # Non-secret values preserved
}
injected = inject_dictionary_1password(config)
Pydantic Settings:
from scottzach1.onepassword_cli import OnePasswordSettings
class AppSettings(OnePasswordSettings):
database_url: str = "op://vault/database/url"
api_key: str = "op://vault/api/key"
port: int = 8080
settings = AppSettings() # Secrets injected automatically
API
inject_string_1password(value, check_cli=True)- Inject secrets into a stringinject_dictionary_1password(data, check_cli=True, in_place=False)- Inject secrets into a dictionaryOnePasswordSettings- Pydantic Settings base class with automatic injection
See docstrings for parameters and exceptions.
Development
# Setup
uv sync --dev && uv run pre-commit install
# Test
uv run pytest tests/ -v -m "not integration"
uv run coverage run -m pytest tests/ -m "not integration"
# Lint/Format
uv run ruff check src/ tests/ --fix
uv run ruff format src/ tests/
License
MIT License - see LICENSE file.
Metadata
Release files for 1password-cli 0.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| 1password_cli-0.0.1.tar.gz | 68.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| 1password_cli-0.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 76.8 kB
Release files / 1password_cli-0.0.1.tar.gz
| Download URL | 1password_cli-0.0.1.tar.gz |
|---|---|
| Size | 68.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a277c66acc10e46f92f71df2af751eceee6e52354a6dee9d108b0ef339f52bb9
|
|
BLAKE2b-256 checksum How to use checksums |
197afc4c69b583d479fee5645080e4f1bd70c6df4b016447217f473ef9a54368
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 23, 2026.
Transparency logRelease files / 1password_cli-0.0.1-py3-none-any.whl
| Download URL | 1password_cli-0.0.1-py3-none-any.whl |
|---|---|
| Size | 8.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
22cc63c8973a8e70900e9e4c38c1e5495aaefcca8d6135e80af596f02abc89e6
|
|
BLAKE2b-256 checksum How to use checksums |
09ff6fd72ca55d5bff66ba87c5867ce96533d28e3c6b9d9ea8811a35b0d0e205
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 23, 2026.
Transparency log