Skip to content

Future of this project, project maintenance & scaling to a broader plugin ecosystem #537

Description

@fearoffish

There haven't been any commits of significance in at least 3 months. Is this just a project that now exists so you can put it in marketing?

I'm seriously disappointed in myself, maybe that's my frustration. I've convinced companies and individuals to use 1Password and shell-plugins was one of the selling points. Now I have egg on my face, because I've had to tell many of them they have to fork the repository themselves and do any changes they need.

Activity

  1. SimonBarendse commented on Aug 14, 2025

    @SimonBarendse
    Member

    Apologies @fearoffish. You're right, we haven't been able to give this project the attention it deserves recently. We're starting some internal discussions on best path forward.

  2. sterlinm commented on Aug 23, 2025

    @sterlinm
    Contributor

    Thanks @SimonBarendse, that's good to hear! I've had a PR that's been limping along for a while (it hasn't been a huge priority for me either) and I'd love to know whether I should just throw in the towel. Thanks!

    #511

  3. NeckBeardPrince commented on Oct 17, 2025

    @NeckBeardPrince

    Two months later and still nothing.

  4. SimonBarendse commented on Oct 17, 2025

    @SimonBarendse
    Member

    Hi folks, want to let you know that this is still on our radar. We're currently exploring to support plugins without them needing to be merged into this repo so that we're no longer blocking new plugins as a gatekeeper and the plugin ecosystem can further scale.

    Curious for your feedback on a workflow that would look something like this for a first version:

    1. Clone the repo (e.g. https://github.com/sterlinm/1password-plugin-duckdb)
    2. Thoroughly review the code - since 1Password team isn't reviewing each plugin
    3. Build the code and move to plugin directory (~/.op/plugins/local)
    4. Plugin is now detected by and can be used with 1Password CLI
  5. SimonBarendse commented on Oct 17, 2025

    @SimonBarendse
    Member

    Thoroughly review the code - since 1Password team isn't reviewing each plugin

    Just like with GitHub Actions, Terraform providers and libraries you use other signals will develop that will help determine what plugins you trust, and everyone can make their own evaluation depending on your risk profile (e.g. if a plugin received lots of endorsements and reviews from the community or if that same plugin lives under https://github.com/duckdb).

  6. NeckBeardPrince commented on Oct 17, 2025

    @NeckBeardPrince

    Can I suggest pinning this issue so it's more visible to the community? Maybe changing the title to something that invites more of a community discussion.

  7. changed the title [-]Is this project abandoned?[/-] [+]Future of this project, project maintenance & scaling to a broader plugin ecosystem[/+] on Oct 17, 2025
  8. SimonBarendse commented on Oct 17, 2025

    @SimonBarendse
    Member

    Thanks for the suggestion @NeckBeardPrince ! Done ✅

  9. SimonBarendse commented on Oct 17, 2025

    @SimonBarendse
    Member

    Main two questions I'd love input from the community on:

    1. For folks creating new plugins: Would you be open to hosting this under a namespace you own?
    2. For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?
  10. NeckBeardPrince commented on Oct 17, 2025

    @NeckBeardPrince

    Hi folks, want to let you know that this is still on our radar. We're currently exploring to support plugins without them needing to be merged into this repo so that we're no longer blocking new plugins as a gatekeeper and the plugin ecosystem can further scale.

    Curious for your feedback on a workflow that would look something like this for a first version:

    1. Clone the repo (e.g. https://github.com/sterlinm/1password-plugin-duckdb)
    2. Thoroughly review the code - since 1Password team isn't reviewing each plugin
    3. Build the code and move to plugin directory (~/.op/plugins/local)
    4. Plugin is now detected by and can be used with 1Password CLI
    

    For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?

    I would be really, really hesitant to use a 1P plugin from a random user's GitHub; I think others would feel the same way. The backbone of 1Password is trust in the platform to secure our data. I have concerns about using plugins that aren't reviewed or approved by 1Password.

    Just like with GitHub Actions, Terraform providers etc. other signals will develop that will help determine what plugins you trust.

    Those ecosystems have been around for much longer than 1P shell plugins and aren't as niche as a CLI for a password manager.

  11. fearoffish commented on Oct 20, 2025

    @fearoffish
    Author

    Main two questions I'd love input from the community on:

    1. For folks creating new plugins: Would you be open to hosting this under a namespace you own?

    I'd be happy to host a plugin under my own GitHub account...but

    1. For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?

    ...as @NeckBeardPrince said, I'd be very hesitant as a user of that repository. My trust is with 1Password, not random users. I say "hesitant" not "against" because personally I would read it anyway.

    If what you're implying is that the 1Password team don't want to manage this anymore and the feature could potentially go away, then I'd be happy with the "clone, review code, put in my local directory and use it" method. As long as we can get rid of the annoying warning.

  12. arayaryoma commented on Nov 11, 2025

    @arayaryoma

    @SimonBarendse Thank you for asking for feedback from the community.

    I'm using 1Password for both family and business accounts.

    As others have mentioned, it's quite difficult to fully trust community plugins even those with several stars or contributions on GitHub.
    We must exercise caution in deciding which plugins are safe to use.

    The existing 1Password plugins are reliable because they have gone through 1Password's official review process.

    I strongly agree with @fearoffish:

    My trust is with 1Password, not random users.

  13. Tensho commented on Nov 20, 2025

    @Tensho

    I think 1Password Shell Plugins are useful, it's a nice and clear concept. However I ditched them completely due to the lack of terraform CLI support, which has been asked in a record number of issues in this repo but systematically neglected. I use 1Password Environments → .env → mise to provision provider credentials in bulk nowadays.

    Regarding the ownership model, I think it should follow a HashiCorp-style approach. Core plugins — the ones used by millions — should be maintained by 1Password, while third-party plugins should remain in the hands of the community. As we’ve seen in open-source ecosystems (Terraform providers, Kubernetes CSI drivers, etc.), in-tree development doesn’t scale well. That’s why a proper plugin system (with an SDK) should be introduced as early as possible. Ideally, plugin distribution would also be handled through some kind of registry.

  14. NeckBeardPrince commented on Feb 14, 2026

    @NeckBeardPrince

    It's been almost four months, and still no updates. Not really inspiring confidence.

  15. NeckBeardPrince commented on Mar 26, 2026

    @NeckBeardPrince

    @SimonBarendse any updates, please?

  16. cconrad commented on Apr 7, 2026

    @cconrad

    @SimonBarendse

    1. For folks creating new plugins: Would you be open to hosting this under a namespace you own?

    Sure, but...

    1. For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?

    No - I feel reviews are part of what our organisation (and my family, being a personal user too) pays AgileBits for. Otherwise just remove the marketing of this whole repo from your docs. Or even better, if you implemented plugins for popular services yourself. I can't believe AWS is the only one of the three major clouds supported by op.

  17. marcleblanc2 commented on Apr 22, 2026

    @marcleblanc2
    Contributor

    For folks creating new plugins: Would you be open to hosting this under a namespace you own?

    For folks using plugins: Would you feel comfortable using plugins outside of the 1Password namespace and being responsible for the security review of plugins you use?

    No, having a plugin in a repo under the 1Password org comes with some legitimacy / trust

  18. NeckBeardPrince commented on Apr 22, 2026

    @NeckBeardPrince

    So frustrating that they can't even respond to us.

  19. scottisloud commented on May 1, 2026

    @scottisloud
    Contributor

    Hi folks,
    Thank you for your patience and for sharing your thoughts about the future of this repository. Your frustration is understandable, especially for those of you who have recommended shell plugins to others. We appreciate that and take your concerns seriously.

    We are working on additional capacity to better sustain our open source repos and the community. In fact, the latest batch of changes from shell-plugins has been shipped in the most recent CLI release (link). But that's just a start and we know we need to do more. We plan to begin working through the backlog of issues and PRs, and are developing long-term solutions to improve the review time for submissions and overall health of this repo.

    We are grateful for your interest, and appreciate your understanding. Thank you for being part of our community!

  20. Glennmen commented on May 26, 2026

    @Glennmen
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions