fidelius vs 1Password CLI for developer secrets
By Maria Otworowska,
We make fidelius, so we're not neutral. Every 1Password fact below comes from 1Password's developer docs and pricing page, checked on October 4, 2026.
How each one works
1Password CLI. Your secrets live as items in a 1Password vault. In your project you keep references instead of values, and op run swaps them for the real values while the command runs:
# .env.op
STRIPE_KEY="op://dev/stripe/secret key"$ op run --env-file=.env.op -- npm test1Password Environments, marketed as Developer Environments, adds a separate place for project variables, a .env that's mounted through a named pipe instead of written to disk (Mac and Linux), an MCP server that "cannot return secret values", and Claude Code and Cursor plugins, still in beta.
fidelius. Your keys live in your iCloud Keychain, grouped by project in a Mac app. There's no reference file: the project name is the reference.
$ accio myapp npm testaccio adds the keys from project myapp plus a shared project that every project inherits. The same name can have different values per project, like a test STRIPE_KEY in myapp and a live one in billing-api.
Side by side
| 1Password CLI | fidelius | |
|---|---|---|
| Price | Needs an account: $3.99/mo billed annually ($2.99 first year for new customers), $4.99 monthly, no free tier | Free for the shared project; Pro $24 once for unlimited projects |
| Platforms | macOS, Windows, Linux | macOS 15 or later |
| Where keys are stored | 1Password's cloud vault | Your iCloud Keychain, no fidelius server |
| Sync | Every device with 1Password | Every Mac on your Apple ID |
| Run a command | op run with op:// references | accio <project>, no reference file |
| Output masking | On by default | On when Claude Code or Codex runs it, or with FIDELIUS_MASK=1 |
| AI agent setup | MCP server, Claude Code and Cursor plugins (beta), Codex integration | Writes instructions into Claude Code, Codex and Gemini CLI, a prompt for any other agent |
| MCP server | Yes | No |
| Key files (.p8, .pem) | Written out with op read or op inject | Arrive as a temporary file, deleted when the command ends |
| Team sharing | Yes, vaults and permissions | No |
| Also keeps logins, cards, passkeys | Yes | No, developer keys only |
Where 1Password is the better choice
- You already use it. If 1Password is already on your Macs and your team's,op run costs you nothing extra and keeps everything in one place.
- You work across platforms. The CLI runs on Windows and Linux. fidelius is Mac only and doesn't run in CI.
- You share secrets. Shared vaults and permissions are 1Password's home ground. fidelius syncs only between your own Macs.
- You want an MCP server. 1Password has one, and we don't.
Where fidelius is the better choice
- No subscription. $24 once covers every project on every Mac you use, with every fidelius 1 update. Two years of 1Password Individual billed annually is about $96, or about $84 with the first-year offer for new customers.
- Projects first. accio picks a project by name, with no op:// reference file to keep in step with your vault. (1Password Environments is 1Password's own way around reference files.) Add a key to a project in the app and accio picks it up.
- Agents set up in one step. Setup > Add to My Agents Automatically… writes the instructions into Claude Code, Codex and Gemini CLI, shows you each change first and lets you undo it.
- Nothing beyond Apple. Keys stay in your iCloud Keychain, which Apple end-to-end encrypts. There's no fidelius account. The app goes online only for the Pro license check with Polar (on activation, then at launch if the last check is more than 30 days old) and, if you allow it, a daily check for updates.
Switching
From 1Password to fidelius: export the values you need into a .env, run accio import in the project folder, review the preview in fidelius, then delete the .env. In your scripts, op run --env-file=.env.op -- becomes accio myapp.
You can also keep both: logins and team secrets in 1Password, your own development keys in fidelius.
Related: The best secrets managers for Mac developers in 2026 and A dotenv alternative.