1Password and Secrets Hygiene for Developers

Learn to store, share, use and rotate passwords, API keys and tokens safely with 1Password, the op CLI and good Git habits.

Start course →

Syllabus

Why Secrets Need Hygiene

  1. What Counts as a Secret
  2. How Secrets Leak
  3. A Simple Threat Model

How a Password Manager Works

  1. How 1Password Protects You
  2. Vaults, Items and Fields
  3. Strong, Unique Passwords

Two-Factor Authentication and Passkeys

  1. One-Time Codes (TOTP)
  2. Passkeys
  3. Spotting Phishing

Sharing Secrets with a Team

  1. Shared Vaults and Groups
  2. Least Privilege for Vault Access
  3. Offboarding and Revocation

The 1Password CLI (op)

  1. Install and Sign In
  2. op read and op run
  3. op inject and Templates

Secrets in the Developer Workflow

  1. .env Files Done Right
  2. SSH Keys and Commit Signing
  3. Secrets in CI/CD

Preventing and Responding to Leaks

  1. Scanning Before You Push
  2. Responding to a Leak
  3. Cleaning Git History

Rotation, Policy and Revision

  1. Rotating Secrets Safely
  2. A Team Secrets Policy
  3. Revision: Cheat Sheet and Self-Check