Skip to main content
February 26, 2026
Question

Feature Request: Remote approval for op CLI / desktop prompts to support Agentic Workflows

  • February 26, 2026
  • 11 replies
  • 398 views

Hey team,

Claude Code just release a new https://code.claude.com/docs/en/remote-control feature that lets you send prompts and commands to your desktop (or remote sandbox) directly from a mobile app. You might already be using it

I have a feeling a lot of devs are going to run into the same need for "remote 1Password auth" because of this.

I really love how smooth 1Password handles secret and env management. I keep all my dev keys in 1P, and a lot of my scripts are tightly coupled with the op CLI. For pure local development, this setup is flawless.

I tossed Claude Code into a local Docker sandbox for security reasons. Whenever it needed a 1Password key (like for git SSH), I just used SSH forwarding to my host machine for biometric auth. That worked fine since I was sitting right there.

But this new mobile remote control feature completely breaks that workflow. I'm not at my desk to scan my fingerprint. Sure, we could generate static tokens to let the agent grab what it needs, but that’s way too inflexible—agents need dynamic access to different resources.

If we could get a feature to approve desktop/CLI secret requests directly from the 1Password mobile app (maybe with some specific allow/deny rules and auth timeouts), it would be a massive help for agent-driven development. This applies to both local remote control and fully remote sandboxes.

Honestly, this would be a killer feature for me. Would love to know if this is something the team could consider.

 

11 replies

February 26, 2026

Hi @Gregory ,

thanks for writing in, this is a great idea and I'll pass it along to the team!  If more comes to mind, please do pass it along, we highly value feedback!

All the best,
Phil

ref: CFP-19201

June 4, 2026

Clearly this is a must have, 1password is currently really hard to use in the whole agentic world where things do not live locally anymore. We are investigate other tools to avoid putting secrets in cleartext in agentic environment.

July 30, 2026

I strongly strongly strongly support this request.  1Password prompting me to unlock it so Claude can sign my git commits using the SSH Agent is the only thing that stops me from starting a task with Claude Code and working from my phone.  Please prioritize this high!

Bach Nguyen
August 5, 2026

I completely agree and truly hope that 1Password will soon finish developing this feature.

August 13, 2026

I would love this feature. I was using Krypton (krypt.co) to unlock SSH Keys on my phone long time ago, which could be a similar idea. Looks like it was acquired by Akamai (https://techdocs.akamai.com/mfa/docs/akr-fido2-ssh-agent).

August 17, 2026

+1 for CFP-19201. I use Codex Remote from my phone to control development work running on my Mac. My SSH keys are managed by the local 1Password SSH Agent, but authorization prompts remain on the Mac and cannot be approved from the 1Password mobile app. This can block SSH reconnects and Git/SSH operations while I am away from the computer. A mobile push approval flow showing the requesting device or app, SSH key, destination, and short-lived Approve/Deny options would solve this without exporting personal keys or disabling approval. Please add my use case and vote to CFP-19201.

August 30, 2026

+1

So the request, concretely. Two things would each solve it on their own:

1. Per-request approval for the CLI that works off the requesting machine —
   the same shape as Agentic Autofill, but for `op read` / `op run` instead of a
   browser fill. The agent requests a specific item reference, I approve on a
   device I am actually holding, and the value reaches the requester over your
   encrypted channel without a third party in the middle.
2. Approval on a second device for prompts raised on the first, which is
   what this thread originally asked for. Even without remote CLI support, this
   fixes the case where I am simply not at my desk.

Two details that would decide whether it is usable for this:

- Context in the prompt. Agentic Autofill already shows which item is being
  requested. For a CLI request, the command and the working directory would make
  the difference between an informed approval and a reflex. Without it I am
  confirming that something wants a credential, which is not the same as knowing
  what I am agreeing to.
- No approval caching, or caching I can turn off per item. For credentials
  used a few times a month, an approval window is a small version of the
  standing access I am trying to avoid. Per-use is the point.

sastian
September 6, 2026

Adding our use case: AI agent infrastructure with blind CLI prompts

We run Hermes Agent — an open-source AI agent framework — on Linux desktops with 1Password managing all credentials. Multiple background services (Discord bots, web dashboards, inference gateways) resolve op:// secret references at startup via op read.

The blind prompt problem hits us on every service restart. Here's what our users see:

1Password Access Requested Allow /home/user/.hermes/hermes-agent/.hermes-runtime/python/generation-1785278974-417978-f7893c30/cpython-3.11.15-linux-x86_64-gnu/bin/python3.11 to get CLI access [Cancel] [Authorize]

That path is a bundled Python runtime. No human can tell what it is, what secret it's reading, or why. And authorizing grants full vault access — not just the one item being requested.

What we need in the prompt

  1. Which item is being requested — "Ollama API Key", not just "Binary Ranch vault"
  2. What the process is — "Hermes Agent (Discord gateway)" not a 120-character Python path
  3. Why it needs access — "starting up and needs the inference API key to respond to messages"
  4. What scope authorizing grants — "This will allow the process to read any item in the Binary Ranch vault" (currently undisclosed)

What we did as a workaround

We built a desktop notification layer in Hermes that fires before op read — so the user sees what's being accessed and why before the 1Password prompt appears. It's open source: PR #104531

But this is a band-aid. The real fix is 1Password showing item-level context in the CLI authorization dialog. We're asking for the same thing others on this thread have asked for: informed consent, not blind authorization.

+1 for CFP-19201. Please prioritize this — the agentic workflow space is growing fast and every developer running background services with op CLI hits this wall.

September 27, 2026

I have a Claude Code agent that I use basically like a GrokBot or Muse agent - it has its own dedicated machine, browser access, and connections to my email, etc. I often have it perform simple tasks for me like booking a haircut. Unfortunately, at present, I must first log into the target website (using the 1Password browser extension) manually before my agent can then use the authenticated session to complete the assigned task on my behalf. I would *love* for my Claude Code agent to be able to a) see a list of accounts in my 1Password vault and 2) allow for Claude Code to generate a request to use a password which I would approve or reject from the 1Password app on my phone. 

September 30, 2026

We strongly support this request and urgently need this feature as well.
We already make extensive use of the 1Password SSH Agent for secure LLM agent workflows. Keeping private keys protected while allowing agents to perform explicitly authorized operations is central to our setup.
Being able to approve requests remotely through the 1Password mobile app—including SSH Agent authorization prompts—would make a huge difference. We need to keep human approval in the loop even when we are away from the machine running the agent.
Please add our vote to CFP-19201 and prioritize this feature.