1Password — Set up op CLI, sign in, and read or inject secrets
1Password — Set up op CLI, sign in, and read or inject secrets
Start with meaning, then move to detail.
This lesson explains 1Password — Set up op CLI, sign in, and read or inject secrets as part of operating Hermes with explicit security boundaries. You will learn what it does, when it matters, and the smallest safe test that proves it works.
If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?
For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.
For advanced readers, inspect Skill metadata, Reference: full SKILL.md, Requirements, then verify failure modes and version compatibility.
You only need to know which files and accounts the agent may access.
A clear outcome before you read.
- Understand 1Password — Set up op CLI, sign in, and read or inject secrets without assumed prior knowledge.
- Separate the source description from what still needs testing in your environment.
- Read the first command and identify its inputs and outputs before copying it.
Short definitions before the details.
- Skill
- An instruction bundle that teaches Hermes a repeatable workflow without necessarily adding an external service.
Set up op CLI, sign in, and read or inject secrets
What does the source say, and in what order?
- 01Skill metadata
Start here to understand the core idea or structure.
- 02Reference: full SKILL.md
Read this after the foundation, then connect it to the previous step.
- 03Requirements
Read this after the foundation, then connect it to the previous step.
- 04When to Use
Read this after the foundation, then connect it to the previous step.
- 05Authentication Methods
Read this after the foundation, then connect it to the previous step.
- 06Service Account (recommended for Hermes)
Read this after the foundation, then connect it to the previous step.
- 07Desktop App Integration (interactive)
Read this after the foundation, then connect it to the previous step.
- 08Connect Server (self-hosted)
Read this after the foundation, then connect it to the previous step.
- 09Setup
Read this after the foundation, then connect it to the previous step.
- 10Hermes Execution Pattern (desktop app flow)
Finish here to verify the result and special cases.
Copy only after you understand the effect.
export OP_SERVICE_ACCOUNT_TOKEN="your-token-here"
op whoami # verify — should show Type: SERVICE_ACCOUNTexport OP_CONNECT_HOST="http://localhost:8080"
export OP_CONNECT_TOKEN="your-connect-token"# macOS
brew install 1password-cli
# Linux (official package/install docs)
# See references/get-started.md for distro-specific links.
# Windows (winget)
winget install AgileBits.1Password.CLIRead the first command and identify its inputs and outputs before copying it.
Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.