2.0 KiB
SSH Key Storage in 1Password — Reference
Session: 2026-06-26 (Hermes Agent)
Problem
1Password's native "SSH Key" item category (category: SSH_KEY, field type SSHKEY) does not correctly persist the private_key field when created via op item create. The field is silently dropped from the created item.
Workaround
Use SECURE_NOTE with a CONCEALED field labeled private key. This stores the key securely, hides it from casual view, and makes it retrievable via op read or op item get --reveal.
Pattern
-
Generate key locally (Ed25519 preferred):
ssh-keygen -t ed25519 -C "hermes-agent@proxmox" -f ~/.ssh/id_ed25519_proxmox -N "" -
Build JSON template from file (never pass private key on CLI):
python3 -c " import json pk = open('~/.ssh/id_ed25519_proxmox').read().strip() puk = open('~/.ssh/id_ed25519_proxmox.pub').read().strip() template = { 'title': 'hermes-agent Proxmox SSH Key', 'category': 'SECURE_NOTE', 'fields': [ {'id': 'notesPlain', 'type': 'STRING', 'purpose': 'NOTES', 'label': 'notesPlain', 'value': f'Public key:\\n{puk}'}, {'id': 'private_key', 'type': 'CONCEALED', 'label': 'private key', 'value': pk} ] } json.dump(template, open('/tmp/op_template.json', 'w')) " -
Create and verify:
cat /tmp/op_template.json | op item create - --vault Hermes # Verify op item get "hermes-agent Proxmox SSH Key" --vault Hermes --reveal
Retrieval in Scripts
pk=$(op read 'op://Hermes/hermes-agent Proxmox SSH Key/private key')
tmpkey=$(mktemp)
echo "$pk" > "$tmpkey"
chmod 600 "$tmpkey"
ssh -i "$tmpkey" root@10.0.20.91 "hostname"
rm -f "$tmpkey"
Note on Service Accounts
Hermes' OP_SERVICE_ACCOUNT_TOKEN is scoped to specific vaults. If op vault list shows only "Hermes", that's the only vault accessible. To add access to other vaults, update the 1Password integration's vault grants in the 1Password admin console.