# The 1Password Environments MCP Server is now on Cursor Marketplace

> Source: <https://1password.com/blog/the-1password-environments-mcp-server-is-now-on-cursor-marketplace>
> Published: 2026-07-30 00:00:00+00:00

AI agents are doing more than just generating code. Increasingly, they are working autonomously on complex coding challenges, touching production APIs, databases, and infrastructure across development environments, often without thorough human review. To perform these operations and access multiple systems, agents rely on developer secrets and non-human identities (NHI). But often, developers lack a secure way to share these secrets, leading to overprivileged, invisible access. The growth in autonomous agentic workflows changes what secure credential management needs to look like.

The problem posed by hardcoded secrets is not new. Developers have managed API keys in .env files, tokens committed to repos, and credentials sitting in plain text across codebases for decades. The conventional response has typically been reactive: rotate *after* an incident, clean up *after* a review, catch secrets *when* you find them.

That approach was built for workflows where a human reviews each step, but the model breaks when agents are involved.

When an AI agent runs code containing a hardcoded credential, that credential can pass through an AI agent’s context window and be logged, cached, or forwarded downstream, making tracking and governance extremely difficult. The potential security impact of a plaintext secret expands disproportionately once an agent accesses it.

[ Cursor](https://cursor.com/) is a multi-modal AI coding platform helping developers and engineering teams build software across complex codebases. Cursor allows developers to use an agent for complex coding tasks involving production APIs, services, and infrastructure. 1Password Environments MCP Server is designed so developers can take advantage of this increased velocity without compromising on security.

The [ existing 1Password plugin on Cursor Marketplace](https://cursor.com/marketplace/1password) now makes

When agents are running code against production APIs and real infrastructure, security can't be bolted on afterward. The Cursor Marketplace exists to give developers the tools they need to build confidently with AI, and that includes getting the security layer right. With the 1Password Environments MCP Server, credentials stay out of the model context, allowing developers using Cursor to move fast without creating risk for their teams."

-Travis McPeak, Head of Security, Cursor

Cursor can identify plaintext values that need to be moved out of a codebase or .env file. Since those values already exist in plaintext, the agent may read them during migration. Developers should rotate credentials that were previously exposed in source code or agent context.

Cursor authenticates through the local 1Password Environments MCP server. The 1Password desktop app remains the trust boundary for account access and approvals. Authentication or first use of an Environment may trigger an approval prompt.

Cursor can list, create, and rename Environments; append variables; list variable names; and create or inspect local .env destinations.

Once values are stored in 1Password, list operations return names, not secret values. A local .env destination makes those values available to the application through FIFO at runtime.

Once secured in 1Password, the MCP server does not read or return secret values to the agent, and any access is issued only at runtime, scoped to the task. This is the design principle for our MCP server that reflects [ 1Password’s approach to MCP and agentic workflows](https://1password.com/blog/where-mcp-fits-and-where-it-doesnt). Secrets are securely injected at runtime for an authorized process and users must explicitly authorize access for the scoped task. MCP works best when access is scoped, user-approved, and keeps credentials out of the agent context.

AI agents are moving from suggesting code to operating inside the development workflow. The security question is not whether they can help, but what they can access and where credentials live. By making 1Password Environments natively available through Cursor Agent, developers can move plaintext .env values into 1Password, manage the environment from Cursor, and let applications receive those values at runtime. Once a secret is in 1Password, the MCP server returns names, not values. That is the boundary developers should be able to trust.”

-Nancy Wang, CTO, 1Password

This integration is designed to fit into how Cursor users already work, while reducing the need to handle secrets directly or copy them into local files, repositories, or configuration.

With this integration, developers can:

Ask Cursor to create and configure your development environment, with secrets managed by 1Password. Run your application with credentials injected at runtime rather than stored in plaintext .env files, all without leaving Cursor.

Bootstrap new projects with 1Password-managed environments so you do not have to create or share .env files.

Let Cursor create and update environment configurations so your code runs with the right setup, while underlying secrets stay in 1Password.

Stay in control of every access, since each interaction with 1Password through Cursor requires explicit user approval via a local auth prompt.

*Currently available for macOS and Linux only.*

Cursor Marketplace joins the growing list of places where developers can find the 1Password Environments MCP Server, with more to come. Each AI-native platform 1Password expands into is another proof point that secure, scoped credential access is how agentic development should work. As more AI-native development tools become central to how software gets built, 1Password will continue to meet developers where they are.

Explore [ ourdocumentation](https://www.1password.dev/environments/mcp-server) to configure the MCP server and start building securely with Cursor today.

**For developers already using Cursor and 1Password:** Find the 1Password Environments MCP Server on [ 1Password Marketplace](https://marketplace.1password.com/integration/mcp-server-for-cursor) and the

**New to 1Password?:**[ Start a free trial](https://1password.com/pricing/password-manager) to get access to 1Password Password Manager, 1Password Environments, and the 1Password Environments MCP Server.
