Academy → Using HermesOfficial documentation · clear explanation

1Password

1Password

Essential12 minutes3 questions2026-08-09
The idea in one minute

Start with meaning, then move to detail.

This lesson explains 1Password as part of operating Hermes with explicit security boundaries. You will learn what it does, when it matters, and the smallest safe test that proves it works.

If you are new

If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?

For hands-on use

For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.

For specialists

For advanced readers, inspect How it works, Authentication, Bootstrap token, then verify failure modes and version compatibility.

What do you need first?

You only need to know which files and accounts the agent may access.

What will you know?

A clear outcome before you read.

  • Understand 1Password without assumed prior knowledge.
  • Separate the source description from what still needs testing in your environment.
  • Read the first command and identify its inputs and outputs before copying it.
Topic map

What does the source say, and in what order?

  1. 01
    How it works

    Start here to understand the core idea or structure.

  2. 02
    Authentication

    Read this after the foundation, then connect it to the previous step.

  3. 03
    Bootstrap token

    Read this after the foundation, then connect it to the previous step.

  4. 04
    Setup

    Read this after the foundation, then connect it to the previous step.

  5. 05
    1. Install and sign in to op

    Read this after the foundation, then connect it to the previous step.

  6. 06
    2. Enable the integration

    Read this after the foundation, then connect it to the previous step.

  7. 07
    3. Map your credentials

    Read this after the foundation, then connect it to the previous step.

  8. 08
    4. Preview and confirm

    Read this after the foundation, then connect it to the previous step.

  9. 09
    CLI

    Read this after the foundation, then connect it to the previous step.

  10. 10
    Configuration

    Finish here to verify the result and special cases.

Examples from the official page

Copy only after you understand the effect.

echo 'OP_SERVICE_ACCOUNT_TOKEN=ops_...' > ~/.hermes/.op.env chmod 600 ~/.hermes/.op.env
A token injected this way takes precedence — Hermes detects that `OP_SERVICE_ACCOUNT_TOKEN` is already set and skips loading `.op.env` entirely. If the token is reachable only through an interactive shell (`op signin`, `OP_SESSION_*` exports in `.bashrc`, etc.), it will **not** be inherited by cron jobs or freshly spawned subprocesses, and those contexts will log a warning and fall back to whatever credentials `.env` already held. Use one of the three options above for any non-interactive workload. ## Setup ### 1. Install and sign in to `op` Follow the [1Password CLI getting-started guide]
### 2. Enable the integration
Try it now

Read the first command and identify its inputs and outputs before copying it.

Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.

Knowledge check

Three decisions before completion.

1. What is the source of truth when “1Password” changes?
2. What is the best way to apply this lesson?
3. What should happen before a step can modify files or an external account?