Files

2.0 KiB

SSH Key Storage in 1Password — Reference

Session: 2026-06-26 (Hermes Agent)

Problem

1Password's native "SSH Key" item category (category: SSH_KEY, field type SSHKEY) does not correctly persist the private_key field when created via op item create. The field is silently dropped from the created item.

Workaround

Use SECURE_NOTE with a CONCEALED field labeled private key. This stores the key securely, hides it from casual view, and makes it retrievable via op read or op item get --reveal.

Pattern

  1. Generate key locally (Ed25519 preferred):

    ssh-keygen -t ed25519 -C "hermes-agent@proxmox" -f ~/.ssh/id_ed25519_proxmox -N ""
    
  2. Build JSON template from file (never pass private key on CLI):

    python3 -c "
    import json
    pk = open('~/.ssh/id_ed25519_proxmox').read().strip()
    puk = open('~/.ssh/id_ed25519_proxmox.pub').read().strip()
    template = {
        'title': 'hermes-agent Proxmox SSH Key',
        'category': 'SECURE_NOTE',
        'fields': [
            {'id': 'notesPlain', 'type': 'STRING', 'purpose': 'NOTES',
             'label': 'notesPlain', 'value': f'Public key:\\n{puk}'},
            {'id': 'private_key', 'type': 'CONCEALED',
             'label': 'private key', 'value': pk}
        ]
    }
    json.dump(template, open('/tmp/op_template.json', 'w'))
    "
    
  3. Create and verify:

    cat /tmp/op_template.json | op item create - --vault Hermes
    # Verify
    op item get "hermes-agent Proxmox SSH Key" --vault Hermes --reveal
    

Retrieval in Scripts

pk=$(op read 'op://Hermes/hermes-agent Proxmox SSH Key/private key')
tmpkey=$(mktemp)
echo "$pk" > "$tmpkey"
chmod 600 "$tmpkey"
ssh -i "$tmpkey" root@10.0.20.91 "hostname"
rm -f "$tmpkey"

Note on Service Accounts

Hermes' OP_SERVICE_ACCOUNT_TOKEN is scoped to specific vaults. If op vault list shows only "Hermes", that's the only vault accessible. To add access to other vaults, update the 1Password integration's vault grants in the 1Password admin console.