New to Claude Skills? Learn how to install them →

nousresearch on GitHub

1Password CLI

Free

Manage secrets securely with 1Password from the command line.

Get this skill

Free · Opens the source repo

What 1Password CLI does

The 1Password CLI skill enables users to securely manage secrets through the 1Password command line interface (CLI). This skill is particularly useful for developers and system administrators who prefer not to store sensitive information in plaintext environment variables or files. By leveraging the 1Password CLI, users can sign in, read secret references, and inject secrets into configuration files or templates seamlessly. This approach enhances security and streamlines workflows by keeping sensitive data out of source control.

To get started, users must have a 1Password account and the 1Password CLI installed. The skill supports multiple authentication methods, including service accounts, desktop app integration, and self-hosted Connect servers. Depending on the chosen method, users can execute commands like op read to retrieve secrets or op inject to embed secrets directly into files. This flexibility makes it suitable for various environments, whether local development or continuous integration (CI) systems.

The skill also emphasizes best practices for handling secrets. It discourages printing raw secrets to the console and recommends using op run or op inject to avoid writing sensitive data to disk. For users who opt for desktop app integration, the skill provides guidance on maintaining authenticated sessions using tmux, ensuring that secret operations remain stable across terminal calls. Overall, this skill is essential for anyone looking to enhance their security posture while managing secrets efficiently in their development workflows.

When to use it

Use this skill when you need to manage secrets securely in your development or CI environment with 1Password.

When not to use it

This skill is not suitable for users who do not have a 1Password account or those who prefer not to use a CLI for secret management.

What you can build with it

Securely Read Secrets

Use the skill to read sensitive secrets from 1Password directly in your terminal, ensuring they are not exposed in plaintext.

Inject Secrets into Configuration

Easily inject secrets into configuration files or templates using the `op inject` command, streamlining your setup process.

Run Commands with Secret Environment Variables

Execute commands that require secret environment variables without hardcoding sensitive information, enhancing security.

How to install 1Password CLI

View source

1. Install with the skills CLI

npx skills add nousresearch/hermes-agent/1password --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by nousresearch

1Password CLI

Use this skill when the user wants secrets managed through 1Password instead of plaintext env vars or files.

Requirements

  • 1Password account
  • 1Password CLI (op) installed
  • One of: desktop app integration, service account token (OP_SERVICE_ACCOUNT_TOKEN), or Connect server
  • tmux available for stable authenticated sessions during Hermes terminal calls (desktop app flow only)

When to Use

  • Install or configure 1Password CLI
  • Sign in with op signin
  • Read secret references like op://Vault/Item/field
  • Inject secrets into config/templates using op inject
  • Run commands with secret env vars via op run

Authentication Methods

Service Account (recommended for Hermes)

Set OP_SERVICE_ACCOUNT_TOKEN in ${HERMES_HOME:-~/.hermes}/.env (the skill will prompt for this on first load). No desktop app needed. Supports op read, op inject, op run.

export OP_SERVICE_ACCOUNT_TOKEN="your-token-here"
op whoami  # verify — should show Type: SERVICE_ACCOUNT

Desktop App Integration (interactive)

  1. Enable in 1Password desktop app: Settings → Developer → Integrate with 1Password CLI
  2. Ensure app is unlocked
  3. Run op signin and approve the biometric prompt

Connect Server (self-hosted)

export OP_CONNECT_HOST="http://localhost:8080"
export OP_CONNECT_TOKEN="your-connect-token"

Setup

  1. Install CLI:
# macOS
brew install 1password-cli

# Linux (official package/install docs)
# See references/get-started.md for distro-specific links.

# Windows (winget)
winget install AgileBits.1Password.CLI
  1. Verify:
op --version
  1. Choose an auth method above and configure it.

Hermes Execution Pattern (desktop app flow)

Hermes terminal commands are non-interactive by default and can lose auth context between calls. For reliable op use with desktop app integration, run sign-in and secret operations inside a dedicated tmux session.

Note: This is NOT needed when using OP_SERVICE_ACCOUNT_TOKEN — the token persists across terminal calls automatically.

SOCKET_DIR="${TMPDIR:-/tmp}/hermes-tmux-sockets"
mkdir -p "$SOCKET_DIR"
SOCKET="$SOCKET_DIR/hermes-op.sock"
SESSION="op-auth-$(date +%Y%m%d-%H%M%S)"

tmux -S "$SOCKET" new -d -s "$SESSION" -n shell

# Sign in (approve in desktop app when prompted)
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "eval \"\$(op signin --account my.1password.com)\"" Enter

# Verify auth
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op whoami" Enter

# Example read
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op read 'op://Private/Npmjs/one-time password?attribute=otp'" Enter

# Capture output when needed
tmux -S "$SOCKET" capture-pane -p -J -t "$SESSION":0.0 -S -200

# Cleanup
tmux -S "$SOCKET" kill-session -t "$SESSION"

Common Operations

Read a secret

op read "op://app-prod/db/password"

Get OTP

op read "op://app-prod/npm/one-time password?attribute=otp"

Inject into template

echo "db_password: {{ op://app-prod/db/password }}" | op inject

Run a command with secret env var

export DB_PASSWORD="op://app-prod/db/password"  # example op:// reference, resolved by `op run`
op run -- sh -c '[ -n "$DB_PASSWORD" ] && echo "DB_PASSWORD is set" || echo "DB_PASSWORD missing"'

Guardrails

  • Never print raw secrets back to user unless they explicitly request the value.
  • Prefer op run / op inject instead of writing secrets into files.
  • If command fails with "account is not signed in", run op signin again in the same tmux session.
  • If desktop app integration is unavailable (headless/CI), use service account token flow.

CI / Headless note

For non-interactive use, authenticate with OP_SERVICE_ACCOUNT_TOKEN and avoid interactive op signin. Service accounts require CLI v2.18.0+.

References

Frequently asked questions about 1Password CLI

Similar skills