Vovy sets up the 1Password CLI, moves your secrets into a vault, and swaps your .env values for op:// references that load only at run time.
Move my .env secrets into 1Password and load them when I run the app
How it works
- Install the 1Password CLI: Vovy installs the op command with Homebrew and checks it runs. This works alongside the 1Password app you already use.
- Turn on app integration: Vovy opens 1Password Settings, Developer and turns on Integrate with 1Password CLI, so you unlock with Touch ID instead of typing a password.
- Move secrets into a vault: Vovy creates a Dev vault item per project and stores each key there, reading them from your current .env file.
- Swap values for references: Vovy replaces real keys with op://Dev/project/field references, which are safe to share because they are only pointers.
- Run the app with op run: Vovy starts your app with op run --env-file, so secrets are injected only while it runs, and shows a card of every mapped key.
What you provide
- A 1Password account and app
- Your current .env file
What you get
- No plain-text secrets on disk
- Touch ID unlock for dev keys
- An .env file safe to share
- One command to run with secrets
FAQ
Do I need a paid 1Password plan?
The CLI works with any 1Password account, which is a paid subscription after the trial.
What happens if 1Password is locked?
op run prompts for Touch ID. If you cancel, the app does not start, so secrets never leak into a half-configured run.
Can my cofounder use the same setup?
Yes. Put the item in a shared vault and they run the same command with their own 1Password login.
Related tasks
All tasks