Lesson 5 / 24
Vaults, Items and Fields
Organise logins, secure notes and API credentials into vaults and items.
A simple structure
A vault is a container, an item is one thing inside it (a login, an API credential, a secure note), and an item has fields such as username and password. Permissions are set per vault, so separate vaults for Personal, Team and Production.
Secret references
Every field can be addressed by a reference of the form op://vault/item/field. Scripts and config files use this reference instead of the real value.
op://Production/Postgres/password
op://Production/Stripe/secret-keyName things clearly
Use consistent item names like "Stripe (production)" and put the environment in the name. Mixing staging and production keys in one vault is how the wrong key gets used.
Quick check: What does `op://Dev/Database/password` point to?
- The password field of the item "Database" in vault "Dev"
- A website URL
- A Git branch
- A local file path
Answer
The password field of the item "Database" in vault "Dev" — The format is vault, then item, then field.