1Password
1Password
Start with meaning, then move to detail.
This lesson explains 1Password as part of operating Hermes with explicit security boundaries. You will learn what it does, when it matters, and the smallest safe test that proves it works.
If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?
For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.
For advanced readers, inspect How it works, Authentication, Bootstrap token, then verify failure modes and version compatibility.
You only need to know which files and accounts the agent may access.
A clear outcome before you read.
- Understand 1Password without assumed prior knowledge.
- Separate the source description from what still needs testing in your environment.
- Read the first command and identify its inputs and outputs before copying it.
What does the source say, and in what order?
- 01How it works
Start here to understand the core idea or structure.
- 02Authentication
Read this after the foundation, then connect it to the previous step.
- 03Bootstrap token
Read this after the foundation, then connect it to the previous step.
- 04Setup
Read this after the foundation, then connect it to the previous step.
- 051. Install and sign in to op
Read this after the foundation, then connect it to the previous step.
- 062. Enable the integration
Read this after the foundation, then connect it to the previous step.
- 073. Map your credentials
Read this after the foundation, then connect it to the previous step.
- 084. Preview and confirm
Read this after the foundation, then connect it to the previous step.
- 09CLI
Read this after the foundation, then connect it to the previous step.
- 10Configuration
Finish here to verify the result and special cases.
Copy only after you understand the effect.
echo 'OP_SERVICE_ACCOUNT_TOKEN=ops_...' > ~/.hermes/.op.env
chmod 600 ~/.hermes/.op.envA token injected this way takes precedence — Hermes detects that `OP_SERVICE_ACCOUNT_TOKEN` is already set and skips loading `.op.env` entirely.
If the token is reachable only through an interactive shell (`op signin`, `OP_SESSION_*` exports in `.bashrc`, etc.), it will **not** be inherited by cron jobs or freshly spawned subprocesses, and those contexts will log a warning and fall back to whatever credentials `.env` already held. Use one of the three options above for any non-interactive workload.
## Setup
### 1. Install and sign in to `op`
Follow the [1Password CLI getting-started guide]### 2. Enable the integrationRead the first command and identify its inputs and outputs before copying it.
Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.