1Password Popover for Omarchy
A native Omarchy 4 bar panel for searching 1Password Login items and quickly using the selected credential. It talks directly to the 1Password desktop app through the official Python SDK; the 1Password CLI is not used. Initial search results contain only item titles, vault names, and login domains. A selected login's username is then added to the in-memory search index. Passwords and one-time passwords never enter QML.
Actions
- Click a login: show its fields in the details pane on the right
- Click a field: copy it immediately
Enteron a selected login: show its fieldsCtrl+L: open the login URLCtrl+R: refresh login metadataEscape: clear the search, then close the popover
The login list stays visible while its selected login's details are shown on the right, following the two-pane layout of the 1Password desktop app. Closing and reopening the popover keeps the most recently selected login visible.
Copied values use Wayland's sensitive, one-paste clipboard mode. Selecting a result never types into a window automatically.
Requirements
- Omarchy 4
uv- 1Password desktop app
- 1Password desktop app integration enabled for SDK authentication
wl-copyfromwl-clipboard
The helper pins onepassword-sdk==0.4.0 in inline dependency metadata. uv
installs it into its managed cache the first time the helper runs; nothing is
installed globally.
In 1Password, turn on Settings > Security > Unlock using system authentication, then Settings > Developer > Integrate with other apps.
Click the 1Password icon in the bar to open the anchored popover. Use the gear in its header to open the separate settings window, then enter the account name exactly as it appears at the top of the 1Password sidebar. This follows the same panel-and-settings interaction used by Omarchy's Home Assistant plugin.
One shell-wide service owns the persistent SDK helper (the same architecture as
the Home Assistant plugin), so approving 1Password once authorizes subsequent
popover opens and copy actions across every monitor. 1Password may ask again
after ten minutes without SDK activity or after the desktop app is locked.
The service keeps the fetched Login index in memory, so reopening the panel is
instant; press Ctrl+R when you want to fetch account changes from 1Password.
The same value can be configured from a terminal as a fallback:
1password-popover/bin/op-popover configure "Your 1Password account name"
This writes only the non-secret account name to
~/.config/omarchy/onepassword-popover.json. For an ephemeral override, set
OP_ACCOUNT_NAME in the environment that starts omarchy-shell.
Install
omarchy plugin add https://github.com/y4gg/1password-popover.git --enable
Open it from the bar, or bind a key to:
omarchy-shell y4gg.1password-popover toggle
Plugin files under ~/.config/omarchy/plugins/ hot-reload when changed. If a
change does not appear, run:
omarchy-shell shell rescanPlugins
Remove
To delete the saved account name as well, open the plugin settings and click Remove before removing the plugin. Then run:
omarchy plugin remove y4gg.1password-popover
Omarchy asks for confirmation, unloads the plugin, and safely removes or backs
up its plugin directory. Removing the plugin does not delete
~/.config/omarchy/onepassword-popover.json; use the settings action first if
you do not want to keep that configuration.
Security boundary
The SDK supplies Login overviews for the initial search without decrypting
usernames account-wide. Selecting a login retrieves that one item and returns
only its non-secret username and field descriptors; the username remains in
the shell service's memory so it becomes searchable. Copying a field retrieves
that item and hands the requested value directly to wl-copy; helper stdout
contains only JSON metadata or a success/error message. Passwords, OTP values,
and concealed custom-field values are never persisted, printed, placed in
shell arguments, or stored in QML. 1Password's approval prompt grants that
helper process a temporary session for the authorized account; locking
1Password ends it.