1Password SaaS Manager

1Password SaaS Manager MCP Connector for Claude

A+

Govern your 1Password organization for AI agents: catalog SaaS apps, inspect people and teams, read the audit log, and run automation workflows.

8 tools Official Updated Oct 1, 2026 Official Vinkius Partner

Connect your 1Password organization to any AI agent through the 1Password SaaS Manager API. This server governs the organization itself — the SaaS catalog, the people and teams that use it, the audit trail, and the automation workflows — so an agent can reason about access and act on the controls your team has set up.

What you can do

  • SaaS Catalog — List the applications your organization tracks and inspect any one of them in detail
  • People & Teams — See who is in the organization and how the teams are structured
  • Audit Trail — Read the audit log for who did what and when, narrowed by time window
  • Automation — Discover the defined workflows, inspect a specific run, and fire a signal to advance or gate a step

How it works

  1. Create API client credentials for the SaaS Manager in your 1Password organization (choose the US or EU region)
  2. Paste the Client ID and Client Secret into this server's credential fields, and set the base URL to match your region
  3. Ask your agent to reason about the catalog, the people, the audit trail, or the automations — the server signs short-lived tokens on its own

Who is this for?

  • Security & Compliance Teams — keep the SaaS inventory current, surface audit events, and drive the review workflows that gate new access
  • Identity Administrators — check team structure and membership before making access changes
1passwordsaas-managersaas-catalogaudit-logworkflows

8 tools expose this connector's capabilities to your AI agent.

fire_workflow_signal

This is a state-changing operation: only fire it when the user explicitly asks to advance or unblock a run. The activity ID and available signal names come from get_workflow_run; some activities run multiple iterations, in which case iterationId selects one. Fire a signal on an activity of a 1Password workflow run

list_teams

Use when the user asks about team structure, who belongs where, or before reasoning about group-level access. For the team hierarchy, the same endpoint family returns nesting — treat each entry as one team and group by parent fields present in the data. List the teams in the 1Password organization

list_workflows

Use when the user wants to see available automations or find one by name before looking at its runs. The workflow ID from this list is the input for get_workflow_run and fire_workflow_signal. List the automation workflows in 1Password SaaS Manager

get_application

Use after locating an app with list_applications, or when the user names a specific app to inspect. The application ID comes from list results. Read one SaaS application from the 1Password catalog

get_workflow_run

Use when a workflow appears stuck or the user asks what happened in one run. The workflow ID and run ID come from list_workflows and the organization's run history. Inspect one run of a 1Password automation workflow

list_applications

Use when the user asks what SaaS apps the company uses, which are visible or active, or before picking an app to inspect. Page through results by passing the cursor from the previous response as after; cap pages with limit. List the SaaS applications managed in the 1Password organization catalog

list_audit_events

Use for compliance questions: who did what, sign-in anomalies, permission changes. Narrow the window with since/until (ISO dates) to keep pages small; page with after. Read the 1Password audit log

list_people

Use for headcount questions, finding a person, or checking membership status. Pass the cursor from a previous response as after to continue; cap with limit. List people (users) in the 1Password organization

See how to talk to your AI agent using 1Password SaaS Manager.

Which SaaS applications are active in our organization right now?

I listed the tracked applications and filtered to the active ones. You have 14 active SaaS apps: Slack, Confluence, Salesforce, Okta, Datadog, Jira, Linear, Notion, GitHub, AWS, GCP, Zendesk, Intercom and Retool. Want the detail on any of these?

Show me audit log events from the last 48 hours where admin permissions changed.

I read the audit log for the past 48 hours. Three admin-permission events stand out: 2) a service account was granted admin on the Slack app, 4) two people left the 'Security' team, and 1) a new app was added to the catalog by an admin. The service-account grant is the one to review first — do you want me to pull that event in full?

Our onboarding workflow is stuck on step 3. Check that run and tell me what it's waiting for.

I pulled the workflow run. Step 3, the access-grant activity, is waiting on a 'continue' signal — it's gated on a manual confirmation that a manager approves the new person's team access. Nothing has advanced in the last 2 days. Want me to fire the 'continue' signal to unblock it?

The SaaS Manager organization surface: the SaaS application catalog, people, teams, the audit log, and automation workflows. It does not read or manage personal vault items or individual secrets — those are out of scope for this server.

Related Connectors