Repository navigation
Future of this project, project maintenance & scaling to a broader plugin ecosystem #537
Description
Activity
Apologies @fearoffish. You're right, we haven't been able to give this project the attention it deserves recently. We're starting some internal discussions on best path forward.
Reacted by sterlinm and Jamie van DykeThanks @SimonBarendse, that's good to hear! I've had a PR that's been limping along for a while (it hasn't been a huge priority for me either) and I'd love to know whether I should just throw in the towel. Thanks!
Two months later and still nothing.
Hi folks, want to let you know that this is still on our radar. We're currently exploring to support plugins without them needing to be merged into this repo so that we're no longer blocking new plugins as a gatekeeper and the plugin ecosystem can further scale.
Curious for your feedback on a workflow that would look something like this for a first version:
- Clone the repo (e.g. https://github.com/sterlinm/1password-plugin-duckdb)
- Thoroughly review the code - since 1Password team isn't reviewing each plugin
- Build the code and move to plugin directory (~/.op/plugins/local)
- Plugin is now detected by and can be used with 1Password CLI
Thoroughly review the code - since 1Password team isn't reviewing each plugin
Just like with GitHub Actions, Terraform providers and libraries you use other signals will develop that will help determine what plugins you trust, and everyone can make their own evaluation depending on your risk profile (e.g. if a plugin received lots of endorsements and reviews from the community or if that same plugin lives under https://github.com/duckdb).
Can I suggest pinning this issue so it's more visible to the community? Maybe changing the title to something that invites more of a community discussion.
Reacted by Simon Barendse- pinned this issue
on Oct 17, 2025 - changed the title
[-]Is this project abandoned?[/-][+]Future of this project, project maintenance & scaling to a broader plugin ecosystem[/+]on Oct 17, 2025 Thanks for the suggestion @NeckBeardPrince ! Done ✅
Main two questions I'd love input from the community on:
- For folks creating new plugins: Would you be open to hosting this under a namespace you own?
- For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?
Reacted by MarcHi folks, want to let you know that this is still on our radar. We're currently exploring to support plugins without them needing to be merged into this repo so that we're no longer blocking new plugins as a gatekeeper and the plugin ecosystem can further scale.
Curious for your feedback on a workflow that would look something like this for a first version:
1. Clone the repo (e.g. https://github.com/sterlinm/1password-plugin-duckdb) 2. Thoroughly review the code - since 1Password team isn't reviewing each plugin 3. Build the code and move to plugin directory (~/.op/plugins/local) 4. Plugin is now detected by and can be used with 1Password CLIFor folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?
I would be really, really hesitant to use a 1P plugin from a random user's GitHub; I think others would feel the same way. The backbone of 1Password is trust in the platform to secure our data. I have concerns about using plugins that aren't reviewed or approved by 1Password.
Just like with GitHub Actions, Terraform providers etc. other signals will develop that will help determine what plugins you trust.
Those ecosystems have been around for much longer than 1P shell plugins and aren't as niche as a CLI for a password manager.
Reacted by araya, Marc and KaiMain two questions I'd love input from the community on:
- For folks creating new plugins: Would you be open to hosting this under a namespace you own?
I'd be happy to host a plugin under my own GitHub account...but
- For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?
...as @NeckBeardPrince said, I'd be very hesitant as a user of that repository. My trust is with 1Password, not random users. I say "hesitant" not "against" because personally I would read it anyway.
If what you're implying is that the 1Password team don't want to manage this anymore and the feature could potentially go away, then I'd be happy with the "clone, review code, put in my local directory and use it" method. As long as we can get rid of the annoying warning.
Reacted by araya@SimonBarendse Thank you for asking for feedback from the community.
I'm using 1Password for both family and business accounts.
As others have mentioned, it's quite difficult to fully trust community plugins even those with several stars or contributions on GitHub.
We must exercise caution in deciding which plugins are safe to use.The existing 1Password plugins are reliable because they have gone through 1Password's official review process.
I strongly agree with @fearoffish:
My trust is with 1Password, not random users.
Reacted by Andrew Babichev and MarcI think 1Password Shell Plugins are useful, it's a nice and clear concept. However I ditched them completely due to the lack of
terraformCLI support, which has been asked in a record number of issues in this repo but systematically neglected. I use 1Password Environments →.env→ mise to provision provider credentials in bulk nowadays.Regarding the ownership model, I think it should follow a HashiCorp-style approach. Core plugins — the ones used by millions — should be maintained by 1Password, while third-party plugins should remain in the hands of the community. As we’ve seen in open-source ecosystems (Terraform providers, Kubernetes CSI drivers, etc.), in-tree development doesn’t scale well. That’s why a proper plugin system (with an SDK) should be introduced as early as possible. Ideally, plugin distribution would also be handled through some kind of registry.
Reacted by Josh AsplundIt's been almost four months, and still no updates. Not really inspiring confidence.
@SimonBarendse any updates, please?
- For folks creating new plugins: Would you be open to hosting this under a namespace you own?
Sure, but...
- For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?
No - I feel reviews are part of what our organisation (and my family, being a personal user too) pays AgileBits for. Otherwise just remove the marketing of this whole repo from your docs. Or even better, if you implemented plugins for popular services yourself. I can't believe AWS is the only one of the three major clouds supported by
op.Reacted by Andrew Babichev and MarcFor folks creating new plugins: Would you be open to hosting this under a namespace you own?
For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?
No, having a plugin in a repo under the 1Password org comes with some legitimacy / trust
Reacted by Claus Conrad, Adam Stracener and Ilari OrasSo frustrating that they can't even respond to us.
Hi folks,
Thank you for your patience and for sharing your thoughts about the future of this repository. Your frustration is understandable, especially for those of you who have recommended shell plugins to others. We appreciate that and take your concerns seriously.We are working on additional capacity to better sustain our open source repos and the community. In fact, the latest batch of changes from shell-plugins has been shipped in the most recent CLI release (link). But that's just a start and we know we need to do more. We plan to begin working through the backlog of issues and PRs, and are developing long-term solutions to improve the review time for submissions and overall health of this repo.
We are grateful for your interest, and appreciate your understanding. Thank you for being part of our community!
Reacted by Claus ConradReacted by Marc and Andrew BabichevReacted by Marc and Andrew BabichevReacted by Marc and Andrew BabichevWhy this project is very important:
https://x.com/jiahan_c/status/2059117171553550710?s=46&t=o2YtZD2dH5IkcpFTInQhowReacted by Claus Conrad, Scott Lougheed and MarcReacted by MarcReacted by Marc
There haven't been any commits of significance in at least 3 months. Is this just a project that now exists so you can put it in marketing?
I'm seriously disappointed in myself, maybe that's my frustration. I've convinced companies and individuals to use 1Password and shell-plugins was one of the selling points. Now I have egg on my face, because I've had to tell many of them they have to fork the repository themselves and do any changes they need.