fidelius vs 1Password CLI for developer secrets

If you already pay for 1Password, need Windows or Linux, or share secrets with a team, use 1Password CLI. If you work on Macs, don't want another subscription and want keys grouped by project with your coding agents set up for you, fidelius fits better.

We make fidelius, so we're not neutral. Every 1Password fact below comes from 1Password's developer docs and pricing page, checked on October 4, 2026.

How each one works

1Password CLI. Your secrets live as items in a 1Password vault. In your project you keep references instead of values, and op run swaps them for the real values while the command runs:

# .env.op
STRIPE_KEY="op://dev/stripe/secret key"
$ op run --env-file=.env.op -- npm test

1Password Environments, marketed as Developer Environments, adds a separate place for project variables, a .env that's mounted through a named pipe instead of written to disk (Mac and Linux), an MCP server that "cannot return secret values", and Claude Code and Cursor plugins, still in beta.

fidelius. Your keys live in your iCloud Keychain, grouped by project in a Mac app. There's no reference file: the project name is the reference.

$ accio myapp npm test

accio adds the keys from project myapp plus a shared project that every project inherits. The same name can have different values per project, like a test STRIPE_KEY in myapp and a live one in billing-api.

Side by side

1Password CLIfidelius
PriceNeeds an account: $3.99/mo billed annually ($2.99 first year for new customers), $4.99 monthly, no free tierFree for the shared project; Pro $24 once for unlimited projects
PlatformsmacOS, Windows, LinuxmacOS 15 or later
Where keys are stored1Password's cloud vaultYour iCloud Keychain, no fidelius server
SyncEvery device with 1PasswordEvery Mac on your Apple ID
Run a commandop run with op:// referencesaccio <project>, no reference file
Output maskingOn by defaultOn when Claude Code or Codex runs it, or with FIDELIUS_MASK=1
AI agent setupMCP server, Claude Code and Cursor plugins (beta), Codex integrationWrites instructions into Claude Code, Codex and Gemini CLI, a prompt for any other agent
MCP serverYesNo
Key files (.p8, .pem)Written out with op read or op injectArrive as a temporary file, deleted when the command ends
Team sharingYes, vaults and permissionsNo
Also keeps logins, cards, passkeysYesNo, developer keys only

Where 1Password is the better choice

  • You already use it. If 1Password is already on your Macs and your team's,op run costs you nothing extra and keeps everything in one place.
  • You work across platforms. The CLI runs on Windows and Linux. fidelius is Mac only and doesn't run in CI.
  • You share secrets. Shared vaults and permissions are 1Password's home ground. fidelius syncs only between your own Macs.
  • You want an MCP server. 1Password has one, and we don't.

Where fidelius is the better choice

  • No subscription. $24 once covers every project on every Mac you use, with every fidelius 1 update. Two years of 1Password Individual billed annually is about $96, or about $84 with the first-year offer for new customers.
  • Projects first. accio picks a project by name, with no op:// reference file to keep in step with your vault. (1Password Environments is 1Password's own way around reference files.) Add a key to a project in the app and accio picks it up.
  • Agents set up in one step. Setup > Add to My Agents Automatically… writes the instructions into Claude Code, Codex and Gemini CLI, shows you each change first and lets you undo it.
  • Nothing beyond Apple. Keys stay in your iCloud Keychain, which Apple end-to-end encrypts. There's no fidelius account. The app goes online only for the Pro license check with Polar (on activation, then at launch if the last check is more than 30 days old) and, if you allow it, a daily check for updates.

Switching

From 1Password to fidelius: export the values you need into a .env, run accio import in the project folder, review the preview in fidelius, then delete the .env. In your scripts, op run --env-file=.env.op -- becomes accio myapp.

You can also keep both: logins and team secrets in 1Password, your own development keys in fidelius.

Related: The best secrets managers for Mac developers in 2026 and A dotenv alternative.