# 1Password SaaS Manager MCP. AI Agent Connect

> 1Password SaaS Manager MCP connects your 1Password organization to any MCP-compatible client. Your agent can now inspect your SaaS catalog, audit logs, and team structures. It can also interact with automation workflows by firing signals to advance or gate specific steps in a run.

## Overview
- **Category:** security-compliance
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_koedeH4TF1TmeS5PQerjYBdnleULTxy2fMPzASG1/ai-agent-connect
- **Tags:** 1password, saas-manager, saas-catalog, audit-log, workflows

## Description

You can now give your AI agent a seat at the table for 1Password administration. This MCP connects directly to the 1Password SaaS Manager API, allowing your agent to reason about your organization's software footprint and user structure. Instead of clicking through dashboards, you can ask your agent to pull a list of active SaaS apps or check who belongs to a specific team. It can even dig into the audit log to find specific permission changes or sign-in anomalies. For teams using 1Password automations, your agent can inspect the status of a workflow run and fire signals to move a process forward or hold it for review. It turns your AI client into a functional extension of your security and identity operations.

## Tools

### fire_workflow_signal
Sends a signal to a specific activity within a 1Password workflow run. Use this to advance or unblock a process when you explicitly tell your agent to do so.

### list_teams
Retrieves the list of teams within your 1Password organization. This helps your agent understand team hierarchy and group-level access.

### list_workflows
Shows all automation workflows configured in the 1Password SaaS Manager. Your agent uses this to find specific workflows before inspecting their runs.

### get_application
Fetches detailed information about a specific SaaS application from your catalog. Use this to inspect an app after finding it in the list.

### get_workflow_run
Provides the status and details of a specific automation workflow run. This is how your agent checks why a process might be stuck.

### list_applications
Returns the full list of SaaS applications tracked in your 1Password organization. It supports pagination via cursors for large catalogs.

### list_audit_events
Reads the 1Password audit log. Your agent uses this to track user actions, permission changes, or security events within a specific timeframe.

### list_people
Lists the users present in your 1Password organization. This allows your agent to verify headcount or check individual membership status.

## Prompt Examples

**Prompt:** 
```
Which SaaS applications are active in our organization right now?
```

**Response:** 
```
I found 14 active SaaS apps: Slack, Confluence, Salesforce, Okta, Datadog, Jira, Linear, Notion, GitHub, AWS, GCP, Zendesk, Intercom, and Retool. Do you need details on any of them?
```

**Prompt:** 
```
Show me audit log events from the last 48 hours where admin permissions changed.
```

**Response:** 
```
I checked the audit log for the last 48 hours. Three admin permission events occurred: a service account was granted admin on Slack, two people left the Security team, and an admin added a new app to the catalog. Should I pull the full details for the service account grant?
```

**Prompt:** 
```
Our onboarding workflow is stuck on step 3. Check that run and tell me what it's waiting for.
```

**Response:** 
```
The workflow run is stuck at the access-grant activity in step 3. It is waiting for a manual 'continue' signal because a manager needs to approve the new person's team access. Do you want me to fire the signal to unblock it?
```

## Capabilities

### SaaS Inventory Management
Your agent can list and inspect every application tracked in your 1Password catalog.

### Identity Auditing
Your agent can pull audit logs to track user actions and permission changes.

### Team Oversight
Your agent can map out your organization's team structure and user memberships.

### Workflow Control
Your agent can monitor automation runs and trigger signals to advance them.

## Use Cases

### Automated Compliance Audits
Ask your agent to find all permission changes that happened over the weekend.

### SaaS Inventory Checks
Quickly verify which software applications are currently active in your organization.

### Workflow Troubleshooting
Identify exactly why an onboarding or offboarding automation has stalled.

### Team Membership Verification
Confirm if a user belongs to a specific team before granting them new access.

## Benefits

- Reduces manual clicks by letting your agent query the SaaS catalog directly.
- Speeds up troubleshooting stuck automations by inspecting workflow runs.
- Simplifies compliance checks by pulling filtered audit logs via natural language.
- Enables direct interaction with 1Password workflows through signal firing.

## How It Works

Setting up the connection is a straightforward process through the 1Password SaaS Manager API.

1. Generate API client credentials in your 1Password organization.
2. Select your specific region, such as US or EU.
3. Enter your Client ID and Client Secret into the Vinkius credential fields.
4. Set the base URL to match your chosen region.
5. Connect your preferred MCP-compatible client to start using the tools.

## Frequently Asked Questions

**How do I connect this MCP to my 1Password account?**
You need to create API client credentials in your 1Password SaaS Manager settings. Once you have the Client ID and Secret, you provide them to Vinkius, and you can connect your AI client immediately.

**Can my AI agent actually change things in 1Password?**
Yes, specifically through the fire_workflow_signal tool. This allows your agent to advance or unblock specific steps in an automation workflow when you tell it to.

**Does this work with any AI client?**
It works with any MCP-compatible client, including Claude, Cursor, Windsurf, and VS Code.

**How does the agent handle large lists of users or apps?**
The tools use pagination and cursors. Your agent can request specific limits or use the 'after' parameter to move through large datasets without overwhelming the context.

**Is my data secure?**
The MCP uses short-lived tokens generated by the server to interact with the 1Password API, ensuring your credentials remain protected.

**Which parts of 1Password does this manage?**
The SaaS Manager organization surface: the SaaS application catalog, people, teams, the audit log, and automation workflows. It does not read or manage personal vault items or individual secrets — those are out of scope for this server.

**How does authentication work?**
Machine-to-machine OAuth 2.0 client-credentials. The server exchanges your Client ID and Client Secret for a short-lived bearer token and signs its own requests — no human login, no user session. The base URL selects the region: app.trelica.com (US) or eu.trelica.com (EU).

**Can it change the organization, or only read it?**
Mostly read. The read tools cover the catalog, people, teams, audit log, workflow definitions, and runs. The one state-changing tool is fire_workflow_signal, which advances or gates a step of an automation run — use it only when explicitly asked.
