# op read and op run — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/op-read-run

> Fetch a single value with op read and run a command with secrets injected as environment variables.

## Resolve at the last moment

`op read` prints one field. `op run` is better for apps: it scans environment variables for `op://` references, replaces them with real values for that process only, and masks them in the output. Nothing is written to disk.

## A .env that holds only references

This `.env.1p` file is safe to commit because it has no real secret. `op run` fills the values in when starting the app.

```bash
# .env.1p
DATABASE_URL=op://Dev/Postgres/url
STRIPE_KEY=op://Dev/Stripe/secret-key

# run the app with real values only in its environment
op run --env-file=.env.1p -- npm start

# read a single field
op read "op://Dev/Postgres/password"
```

## Do not echo secrets

Avoid `echo $(op read ...)` and logging environment variables. `op run` masks values it knows about, but your own code can still print them, so never log whole environments.

**Quiz:** What does `op run --env-file=.env.1p -- npm start` do?

- [ ] Uploads .env.1p to GitHub
- [x] Resolves op:// references and starts the app with real values in its environment
- [ ] Deletes the vault
- [ ] Prints all secrets to the terminal

*Answer:* Resolves op:// references and starts the app with real values in its environment. The values exist only in the child process environment while it runs.
