Save an API key from the macOS clipboard to 1Password without putting the secret in model context, chat transcripts, command arguments, or shell history. Optionally install the same value into a project env file without retrieving it from 1Password.
The prompt hook recognises a line beginning opadd , snapshots the clipboard, and gives the model a one-time snapshot ID. The model can then derive a useful title and hostname—and add known key scopes to the notes—before invoking opadd.
- macOS
- 1Password CLI authenticated interactively or with
OP_SERVICE_ACCOUNT_TOKEN