Skip to content

1Password

lazyenv can use 1Password as a secret store (via the 1Password SDK).

Terminal window
export OP_SERVICE_ACCOUNT_TOKEN="your-service-account-token"

Optional:

Terminal window
export OP_INTEGRATION_NAME="lazyenv"
export OP_INTEGRATION_VERSION="dev"

1Password does not have native “environments”. lazyenv encodes environments into Vault names:

  • .lazyenv/config.json projectId is the base project name (example: acme)
  • each environment becomes a vault named {projectId}-{env} (example: acme-dev, acme-prod)

At the moment, vault creation is not supported via the SDK. Create the vaults in 1Password first.

1Password vault items are flat by title, so lazyenv uses a key prefix for folders:

  • folder / uses no prefix
  • folder /apps/web uses WEB__
  • If you get “Vault not found”, create {projectId}-{env} in 1Password and retry.
  • If you’re migrating from another store, use lazyenv migrate --to onepassword.