Omahub
← All plugins
L

1Password Popover

by Local

Search 1Password logins with the official SDK and securely copy a selected field.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
02dd36c
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
02dd36c
Reviewed
1 month ago

The plugin is a 1Password popover that uses the official SDK to list and copy login fields. It does not persist secrets, uses a sensitive clipboard, and the code is transparent and non-obfuscated.

  • The plugin relies on the 1Password SDK and uv to fetch dependencies, which could be a supply chain risk if compromised.
  • The helper script passes secrets to wl-copy via command line arguments, which may be visible in process listings, though it uses sensitive clipboard mode.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/y4gg/1password-popover --enable
Productivity #bar #quickshell #security

1Password Popover for Omarchy

A native Omarchy 4 bar panel for searching 1Password Login items and quickly using the selected credential. It talks directly to the 1Password desktop app through the official Python SDK; the 1Password CLI is not used. Initial search results contain only item titles, vault names, and login domains. A selected login's username is then added to the in-memory search index. Passwords and one-time passwords never enter QML.

Actions

  • Click a login: show its fields in the details pane on the right
  • Click a field: copy it immediately
  • Enter on a selected login: show its fields
  • Ctrl+L: open the login URL
  • Ctrl+R: refresh login metadata
  • Escape: clear the search, then close the popover

The login list stays visible while its selected login's details are shown on the right, following the two-pane layout of the 1Password desktop app. Closing and reopening the popover keeps the most recently selected login visible.

Copied values use Wayland's sensitive, one-paste clipboard mode. Selecting a result never types into a window automatically.

Requirements

  • Omarchy 4
  • uv
  • 1Password desktop app
  • 1Password desktop app integration enabled for SDK authentication
  • wl-copy from wl-clipboard

The helper pins onepassword-sdk==0.4.0 in inline dependency metadata. uv installs it into its managed cache the first time the helper runs; nothing is installed globally.

In 1Password, turn on Settings > Security > Unlock using system authentication, then Settings > Developer > Integrate with other apps.

Click the 1Password icon in the bar to open the anchored popover. Use the gear in its header to open the separate settings window, then enter the account name exactly as it appears at the top of the 1Password sidebar. This follows the same panel-and-settings interaction used by Omarchy's Home Assistant plugin.

One shell-wide service owns the persistent SDK helper (the same architecture as the Home Assistant plugin), so approving 1Password once authorizes subsequent popover opens and copy actions across every monitor. 1Password may ask again after ten minutes without SDK activity or after the desktop app is locked. The service keeps the fetched Login index in memory, so reopening the panel is instant; press Ctrl+R when you want to fetch account changes from 1Password.

The same value can be configured from a terminal as a fallback:

1password-popover/bin/op-popover configure "Your 1Password account name"

This writes only the non-secret account name to ~/.config/omarchy/onepassword-popover.json. For an ephemeral override, set OP_ACCOUNT_NAME in the environment that starts omarchy-shell.

Install

omarchy plugin add https://github.com/y4gg/1password-popover.git --enable

Open it from the bar, or bind a key to:

omarchy-shell y4gg.1password-popover toggle

Plugin files under ~/.config/omarchy/plugins/ hot-reload when changed. If a change does not appear, run:

omarchy-shell shell rescanPlugins

Remove

To delete the saved account name as well, open the plugin settings and click Remove before removing the plugin. Then run:

omarchy plugin remove y4gg.1password-popover

Omarchy asks for confirmation, unloads the plugin, and safely removes or backs up its plugin directory. Removing the plugin does not delete ~/.config/omarchy/onepassword-popover.json; use the settings action first if you do not want to keep that configuration.

Security boundary

The SDK supplies Login overviews for the initial search without decrypting usernames account-wide. Selecting a login retrieves that one item and returns only its non-secret username and field descriptors; the username remains in the shell service's memory so it becomes searchable. Copying a field retrieves that item and hands the requested value directly to wl-copy; helper stdout contains only JSON metadata or a success/error message. Passwords, OTP values, and concealed custom-field values are never persisted, printed, placed in shell arguments, or stored in QML. 1Password's approval prompt grants that helper process a temporary session for the authorized account; locking 1Password ends it.