Load Environment Variables from 1Password
Fetches environment variables from a 1Password item and writes them to .env.local in the current project.
Prerequisites
1Password desktop app installed (download from 1password.com)
1Password CLI installed:
brew install --cask 1password-cliEnable desktop app integration:
- Open 1Password app → Settings → Developer
- Enable "Connect with 1Password CLI"
- Restart the 1Password app after enabling (important!)
- This allows the CLI to use your existing 1Password session
Verify CLI access:
op whoamiShould show your account details if integration is working.
Troubleshooting: If you see "couldn't connect to desktop app":
- Make sure 1Password app is running
- Restart the 1Password app
- Update to latest version if needed
Environment variables stored in 1Password as a Secure Note with the env vars in the notes field
How It Works
Check for multiple accounts (if user has more than one):
op account listIf multiple accounts exist, you'll need to specify
--accountflag in subsequent commands.List available 1Password items to help user identify the right one:
# Single account: op item list | grep -i "env" # Multiple accounts (specify which one): op item list --account=my.1password.com | grep -i "env"Ask the user which item contains their environment variables (by name or ID)
Fetch the item and extract fields:
op item get "$ITEM_NAME" --format=jsonParse fields and write to
.env.local:- For Secure Notes: Extract from
fieldsarray wheretypeis notCONCEALED(skip password fields) - For each field:
label=valueformat - Common patterns:
- Field with
labelandvalueproperties - Sections with multiple fields
- Handle notesPlain for multi-line env content
- Field with
- For Secure Notes: Extract from
Write to
.env.local:# From notes field (recommended - simpler format) op item get "$ITEM_NAME" --account=ACCOUNT_NAME --fields label=notesPlain | tr -d '"' > .env.localOr for structured fields:
op item get "$ITEM_NAME" --account=ACCOUNT_NAME --format=json | jq -r '.fields[] | select(.value != null) | "\(.label)=\(.value)"' > .env.localNote: The
tr -d '"'removes surrounding quotes thatopadds to field values.
Example Workflow
# 1. Check if you have multiple accounts
op account list
# 2. List items to find the right one
op item list --account=my.1password.com | grep -i "env"
# 3. Get env vars from 1Password (from notes field - recommended)
op item get "Dev Environment" --account=my.1password.com --fields label=notesPlain | tr -d '"' > .env.local
# 4. Confirm
cat .env.local
1Password Item Format
Option 1: Secure Note with plain text
Store all env vars in the notes field:
DATABASE_URL=postgresql://postgres:postgres@localhost:5432/mydb
REDIS_URL=redis://localhost:6379
STRIPE_SECRET_KEY=sk_test_...
NEXT_PUBLIC_APP_URL=http://localhost:3000
Option 2: Structured fields
Create fields for each env var:
- Field: DATABASE_URL, Value: postgresql://...
- Field: REDIS_URL, Value: redis://...
- Field: STRIPE_SECRET_KEY, Type: password/concealed, Value: sk_test_...
What This Creates
.env.localfile with all environment variables from 1Password- Preserves formatting and comments if using notes field
- Filters out non-value fields if using structured format
Available Keys
The following environment variables are available in 1Password:
| Variable | Purpose |
|---|---|
FAL_KEY |
Fal.ai media generation API |
AI_GATEWAY_API_KEY |
AI Gateway routing |
EXA_API_KEY |
Exa search API |
BLOB_READ_WRITE_TOKEN |
Vercel Blob storage |
RESEND_API_KEY |
Resend email API |
NEXT_PUBLIC_LIVEBLOCKS_PUBLIC_KEY |
Liveblocks client-side key |
LIVEBLOCKS_SECRET_KEY |
Liveblocks server-side key |
REPLICATE_API_TOKEN |
Replicate AI models |
BETTER_AUTH_SECRET |
Better Auth session signing |
PAYLOAD_SECRET |
Payload CMS secret |
STRIPE_SECRET_KEY |
Stripe payments |
Security Notes
.env.localshould be in.gitignore(Next.js does this by default)- Never commit
.env.localto version control - Rotate secrets if accidentally committed
- Use separate 1Password items for different environments (dev/staging/prod)
Next Steps
After loading env vars:
Review the file:
cat .env.localAdd any project-specific overrides manually
Run the app:
bun dev
Tips
- Multiple environments: Create separate 1Password items for dev/staging/prod
- Team sharing: Share the 1Password vault with your team
- Updates: Re-run this skill to refresh
.env.localwhen secrets change - Validation: Use with
/env-configskill for type-safe env validation