Lesson 13 / 24

Install and Sign In

Install the op CLI, connect it to the desktop app and sign in.

Use the desktop app integration

The easiest and safest way to sign in locally is the desktop app integration: turn it on in 1Password settings (Developer) and the CLI asks for approval with your fingerprint or system password. You do not type the master password into a terminal.

Reference in, value out, never on disk

Your scripts keep only references. The op CLI resolves them to real values at the moment a command runs.

Four stages: reference, authenticate, resolve, run.
Figure 5.1 — Reference, authenticate, resolve, run.

Check it works

Verify the install, then list your vaults. The first command that needs access triggers an approval prompt.

op --version
op vault list

Do not export your password

Avoid putting a master password or session token in shell history or environment files. Use biometric approval locally and a service account (covered later) for automation.

Quick check: What is the recommended way to sign in to op on your own laptop?

  • Type the master password in every script
  • Commit a token to the repo
  • Email yourself the Secret Key
  • Desktop app integration with biometric approval
Answer

Desktop app integration with biometric approval — It keeps the master password out of the terminal and files.