Sazabi
Sandbox CLIs

1Password

Give the Sazabi agent the 1Password CLI (op) in its sandbox to read secrets and items from your vaults.

About

This CLI connection makes the 1Password CLI (op) available in the Sazabi agent's sandbox. The tool is baked into the sandbox image; connecting it authenticates the already-installed CLI.

Prerequisites

  • A Sazabi project.
  • A 1Password service account token (OP_SERVICE_ACCOUNT_TOKEN), created in your 1Password account under Developer Tools > Service Accounts. Grant the service account read access to the vaults the agent needs.

Set up in the dashboard

Configure the sandbox in the dashboard under Settings > Sandbox CLIs.

Find 1Password in the catalog

In Settings > Sandbox CLIs, find 1Password under Browse sandbox CLIs and choose to connect it.

Provide credentials

Enter the required value: OP_SERVICE_ACCOUNT_TOKEN — your 1Password service account token. Save to store it securely; Sazabi injects it into the sandbox when the agent runs.

Set up with the CLI

You can also configure the 1Password CLI connection with the Sazabi CLI (installed and authenticated — see CLI reference).

sazabi sandbox-clis set --type onepassword --env OP_SERVICE_ACCOUNT_TOKEN=<your-service-account-token>

To validate the credentials without saving, run the same command with test in place of set (the test command also requires the --env flags).

Verify

Ask the agent, in a thread, to run the op CLI (a read-only or status command) and confirm it returns real output. If the command is not found, the CLI connection may not be enabled; if it runs unauthenticated or cannot connect, recheck the credentials.

Troubleshooting

Command not found — Confirm the 1Password CLI connection is enabled for the project under Settings > Sandbox CLIs.

Authentication or connection fails — Recheck the credential/connection values under Settings > Sandbox CLIs.

Further reading