<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>1password on Nico Carusso - Security Thoughts</title>
    <link>https://nicocarusso.pages.dev/tags/1password/</link>
    <description>Recent content in 1password on Nico Carusso - Security Thoughts</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 28 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://nicocarusso.pages.dev/tags/1password/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Secrets in the shell &amp; how to avoid them: 1Password CLI</title>
      <link>https://nicocarusso.pages.dev/articles/secrets-shell-1-pass/</link>
      <pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://nicocarusso.pages.dev/articles/secrets-shell-1-pass/</guid>
      <description>&lt;p&gt;We use passwords, API keys/tokens, secrets in general. We use them locally to test more frequently than we would like to admit. We store them in shell environment variables and tell ourselves we will clean them up afterwards. But that is not what always happens, is it?&lt;/p&gt;
&lt;p&gt;The idea of this post is to present you an alternative: I will show you how to stop storing secrets locally by using the 1Password CLI to retrieve them at runtime, including a small trick for MCP servers, so you never have to paste tokens into plain JSON config files again.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
