{"slug": "the-1password-environments-mcp-server-is-now-on-cursor-marketplace", "title": "The 1Password Environments MCP Server is now on Cursor Marketplace", "summary": "1Password Environments MCP Server is now available on the Cursor Marketplace, enabling developers to securely manage credentials for AI agents operating on production APIs and infrastructure. The integration keeps secrets out of agent context windows by injecting them at runtime through the local MCP server, with user approval prompts and scoped access. Travis McPeak, Head of Security at Cursor, said the tool lets developers \"move fast without creating risk for their teams.", "body_md": "AI agents are doing more than just generating code. Increasingly, they are working autonomously on complex coding challenges, touching production APIs, databases, and infrastructure across development environments, often without thorough human review. To perform these operations and access multiple systems, agents rely on developer secrets and non-human identities (NHI). But often, developers lack a secure way to share these secrets, leading to overprivileged, invisible access. The growth in autonomous agentic workflows changes what secure credential management needs to look like.\n\nThe problem posed by hardcoded secrets is not new. Developers have managed API keys in .env files, tokens committed to repos, and credentials sitting in plain text across codebases for decades. The conventional response has typically been reactive: rotate *after* an incident, clean up *after* a review, catch secrets *when* you find them.\n\nThat approach was built for workflows where a human reviews each step, but the model breaks when agents are involved.\n\nWhen an AI agent runs code containing a hardcoded credential, that credential can pass through an AI agent’s context window and be logged, cached, or forwarded downstream, making tracking and governance extremely difficult. The potential security impact of a plaintext secret expands disproportionately once an agent accesses it.\n\n[ Cursor](https://cursor.com/) is a multi-modal AI coding platform helping developers and engineering teams build software across complex codebases. Cursor allows developers to use an agent for complex coding tasks involving production APIs, services, and infrastructure. 1Password Environments MCP Server is designed so developers can take advantage of this increased velocity without compromising on security.\n\nThe [ existing 1Password plugin on Cursor Marketplace](https://cursor.com/marketplace/1password) now makes\n\nWhen agents are running code against production APIs and real infrastructure, security can't be bolted on afterward. The Cursor Marketplace exists to give developers the tools they need to build confidently with AI, and that includes getting the security layer right. With the 1Password Environments MCP Server, credentials stay out of the model context, allowing developers using Cursor to move fast without creating risk for their teams.\"\n\n-Travis McPeak, Head of Security, Cursor\n\nCursor can identify plaintext values that need to be moved out of a codebase or .env file. Since those values already exist in plaintext, the agent may read them during migration. Developers should rotate credentials that were previously exposed in source code or agent context.\n\nCursor authenticates through the local 1Password Environments MCP server. The 1Password desktop app remains the trust boundary for account access and approvals. Authentication or first use of an Environment may trigger an approval prompt.\n\nCursor can list, create, and rename Environments; append variables; list variable names; and create or inspect local .env destinations.\n\nOnce values are stored in 1Password, list operations return names, not secret values. A local .env destination makes those values available to the application through FIFO at runtime.\n\nOnce secured in 1Password, the MCP server does not read or return secret values to the agent, and any access is issued only at runtime, scoped to the task. This is the design principle for our MCP server that reflects [ 1Password’s approach to MCP and agentic workflows](https://1password.com/blog/where-mcp-fits-and-where-it-doesnt). Secrets are securely injected at runtime for an authorized process and users must explicitly authorize access for the scoped task. MCP works best when access is scoped, user-approved, and keeps credentials out of the agent context.\n\nAI agents are moving from suggesting code to operating inside the development workflow. The security question is not whether they can help, but what they can access and where credentials live. By making 1Password Environments natively available through Cursor Agent, developers can move plaintext .env values into 1Password, manage the environment from Cursor, and let applications receive those values at runtime. Once a secret is in 1Password, the MCP server returns names, not values. That is the boundary developers should be able to trust.”\n\n-Nancy Wang, CTO, 1Password\n\nThis integration is designed to fit into how Cursor users already work, while reducing the need to handle secrets directly or copy them into local files, repositories, or configuration.\n\nWith this integration, developers can:\n\nAsk Cursor to create and configure your development environment, with secrets managed by 1Password. Run your application with credentials injected at runtime rather than stored in plaintext .env files, all without leaving Cursor.\n\nBootstrap new projects with 1Password-managed environments so you do not have to create or share .env files.\n\nLet Cursor create and update environment configurations so your code runs with the right setup, while underlying secrets stay in 1Password.\n\nStay in control of every access, since each interaction with 1Password through Cursor requires explicit user approval via a local auth prompt.\n\n*Currently available for macOS and Linux only.*\n\nCursor Marketplace joins the growing list of places where developers can find the 1Password Environments MCP Server, with more to come. Each AI-native platform 1Password expands into is another proof point that secure, scoped credential access is how agentic development should work. As more AI-native development tools become central to how software gets built, 1Password will continue to meet developers where they are.\n\nExplore [ ourdocumentation](https://www.1password.dev/environments/mcp-server) to configure the MCP server and start building securely with Cursor today.\n\n**For developers already using Cursor and 1Password:** Find the 1Password Environments MCP Server on [ 1Password Marketplace](https://marketplace.1password.com/integration/mcp-server-for-cursor) and the\n\n**New to 1Password?:**[ Start a free trial](https://1password.com/pricing/password-manager) to get access to 1Password Password Manager, 1Password Environments, and the 1Password Environments MCP Server.", "url": "https://wpnews.pro/news/the-1password-environments-mcp-server-is-now-on-cursor-marketplace", "canonical_source": "https://1password.com/blog/the-1password-environments-mcp-server-is-now-on-cursor-marketplace", "published_at": "2026-07-30 00:00:00+00:00", "updated_at": "2026-07-30 16:24:20.598948+00:00", "lang": "en", "topics": ["ai-agents", "developer-tools", "ai-safety", "ai-infrastructure"], "entities": ["1Password", "Cursor", "Cursor Marketplace", "1Password Environments MCP Server", "Travis McPeak"], "alternates": {"html": "https://wpnews.pro/news/the-1password-environments-mcp-server-is-now-on-cursor-marketplace", "markdown": "https://wpnews.pro/news/the-1password-environments-mcp-server-is-now-on-cursor-marketplace.md", "text": "https://wpnews.pro/news/the-1password-environments-mcp-server-is-now-on-cursor-marketplace.txt", "jsonld": "https://wpnews.pro/news/the-1password-environments-mcp-server-is-now-on-cursor-marketplace.jsonld"}}