惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
S
Securelist
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
Martin Fowler
Martin Fowler
量子位
D
Docker
G
Google Developers Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
U
Unit 42
S
Secure Thoughts
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
K
Kaspersky official blog
NISL@THU
NISL@THU
T
Tailwind CSS Blog
I
Intezer
T
Threat Research - Cisco Blogs
P
Privacy & Cybersecurity Law Blog
D
DataBreaches.Net
Engineering at Meta
Engineering at Meta
C
Cyber Attacks, Cyber Crime and Cyber Security
F
Full Disclosure
Microsoft Security Blog
Microsoft Security Blog
Cisco Talos Blog
Cisco Talos Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Simon Willison's Weblog
Simon Willison's Weblog
Vercel News
Vercel News
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
F
Fortinet All Blogs
W
WeLiveSecurity
C
Cisco Blogs
Security Latest
Security Latest
PCI Perspectives
PCI Perspectives
L
LangChain Blog
P
Palo Alto Networks Blog
IT之家
IT之家
aimingoo的专栏
aimingoo的专栏
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale
Help Net Security
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
Project Zero
Project Zero
G
GRAHAM CLULEY
Recent Commits to openclaw:main
Recent Commits to openclaw:main
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
Lohrmann on Cybersecurity
Cloudbric
Cloudbric
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password Expanding Programmatic Access to 1Password | 1Password Zero knowledge vs. a malicious server: A look at ETH Zurich’s research | 1Password Agents are making filesystems cool again | 1Password Black History Month employee spotlight: Joseph Ojelade | 1Password 1Password's new benchmark teaches AI agents how not to get scammed | 1Password Streamlining SaaS onboarding and offboarding | 1Password 3 common SaaS Management challenges and how to avoid them | 1Password How 1Password Is Evolving Its Partner Ecosystem | 1Password How to build secure agent swarms that power production-grade autonomous systems | 1Password From magic to malware: How OpenClaw's agent skills become an attack surface | 1Password Solving the unsanctioned SaaS problem | 1Password 1Password and 60 Day Hustle: cybersecurity for small businesses | 1Password Security advisory for AI-assisted browsing interactions with the 1Password browser extension | 1Password It’s incredible. It’s terrifying. It’s OpenClaw. | 1Password Managing the risks of social logins | 1Password What’s the first security tool your small business should buy? | 1Password As AI Supercharges Phishing Scams, 1Password Introduces Built-In Protection | 1Password How to interview with confidence at 1Password | 1Password Five tips for successful SaaS Management | 1Password SaaS Manager | 1Password Why SaaS License Waste Is a Cost and Security Problem | 1Password AI is changing the IDE. With 1Password, security keeps up | 1Password How IT teams can get a handle on shadow IT | 1Password Bringing secure, just-in-time secrets to Cursor with 1Password | 1Password The Chasing Entropy Podcast Season One is in the Books | 1Password Now available via QBS Software: 1Password Enterprise Password Manager – MSP Edition | 1Password The role of credentials in the AI espionage campaign reported by Anthropic | 1Password The hidden offboarding step draining your budget | 1Password AWS and 1Password: Innovation in AI and beyond | 1Password Simplifying credential security on OpenAI Atlas | 1Password From Social Work to Social Impact: Growing at 1Password | 1Password Improving in-page notifications in the 1Password browser extension | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password Now available via Renaissance: 1Password Enterprise Password Manager – MSP Edition | 1Password Behind the wheel at Oracle Red Bull Racing | 1Password Securing MCP servers with 1Password: Stop credential exposure in your agent configurations | 1Password What’s new in 1Password Enterprise Password Manager - Q4, 2025 | 1Password Belonging as a catalyst for high performance | 1Password Password habits are worsening, but leaders see a path to passwordless | 1Password A simpler, faster way to unlock 1Password | 1Password Oracle Red Bull Racing Episode 4, CIO Matt Cadieux | 1Password 70% of IT and security pros say SSO is falling short | 1Password 1Password's Phishing Survey: Avoid Holiday Phishing Scams | 1Password Securing the Win | 1Password SaaS optimization: How to maximize value and reduce costs | 1Password The enterprise AI crisis: Unsanctioned tools and unenforced policies | 1Password An Identity Security taxonomy for Agentic AI | 1Password Speed and security: Mark Hazelton on protecting Oracle Red Bull Racing’s most valuable asset – its data | 1Password 1Password for Good: Giving back during cybersecurity awareness month | 1Password Utah Mammoth and Utah Jazz score with identity security | 1Password Oracle Red Bull Racing CEO and Team Principal | 1Password Three signs you need a SaaS Management Platform | 1Password Closing the credential risk gap for AI agents using a browser | 1Password Microsoft and Dropbox password managers are sunsetting: What it means and what to do next | 1Password From hackathon nerves to internship wins: Kavya’s journey at 1Password | 1Password 1Password now available in Comet, the AI-powered browser by Perplexity | 1Password 1Password announces new integration with Zscaler | 1Password Breaking the mold: Why more women should consider a career in sales | 1Password What security leaders need to know about mergers and acquisitions | 1Password Clickjacking: What it means for 1Password users | 1Password AI and security at Black Hat: 5 key takeaways from a security expert panel | 1Password Blog | 1Password Do any CISOs feel lucky? | 1Password How to lead with confidence in the AI era: a conversation with Nancy Wang, VP, Engineering | 1Password New Device Trust Check makes browser extension enforcement easier | 1Password Purpose, performance, and trust: Inside the culture powering 1Password’s next chapter | 1Password Now available on Pax8 Marketplace: 1Password Enterprise Password Manager - MSP Edition | 1Password The security principles guiding 1Password’s approach to AI | 1Password Choosing the right SaaS management platform for your business | 1Password Simplify access reviews with 1Password SaaS Manager | 1Password How great usability tripled Duke University's password manager adoption | 1Password
Introducing new .env file support in 1Password environments | 1Password
info@1password.com (Francine Boulanger) · 2025-10-29 · via Blog on 1Password Blog

The new .env destination in 1Password environments makes it easy for developers to use and collaborate on .env files securely, right from the desktop app.

1Password environments provide a secure workspace to store, organize, and manage project secrets – the same credentials you would normally handle as environment variables. Each environment acts as a dedicated space for a project or app, helping teams manage and maintain consistent credentials.

With the new .env file destination, you can use those secrets – stored securely and locally – in your usual workflows. We launched this functionality in beta earlier this month, and have already had some rave reviews:

“Just wanted to drop some feedback after playing around with the new Environments Beta in 1Password. Honestly, I’m loving it so far. The local .env file mounting is just brilliant. Secrets are easy to access without having to run extra commands, but still secure – exactly what I want. Makes switching between machines seamless, too.”

This new integration lets you keep your familiar .env workflow while solving its largest flaws: insecure storage and messy collaboration. Secure storage and access are integrated directly into the 1Password desktop app, meaning no command-line setup, infrastructure changes, or plaintext secrets stored on disk. You and your team can share and update environment variables safely without insecurely passing files or copying secrets into chat.

1Password environments also integrates with AWS Secrets Manager, allowing teams to securely sync and use secrets in production today. Local .env file mounting is now available to everyone using our desktop password manager on Mac and Linux as part of the 1Password environments public beta.

Where .env files fall short

Many developers rely on .env files in development environments to store and load app credentials like API keys, database URLs, and access tokens. The idea traces back to The Twelve-Factor App, which popularized storing configuration in environment variables instead of code or config files. This approach was a major improvement – it moved secrets out of source files – but led to the challenge of .env files storing credentials in plaintext.

Plaintext storage might be manageable for a single developer, but it becomes riskier in a team setting. While developers have tried various methods to simplify this process, from shared folders to dedicated secrets-management tools, these approaches often introduce additional setup time, complexity, and overhead.

Every developer knows the trade-off – .env files are simple but fragile:

  • Secrets are stored in plaintext on disk.

  • It’s easy to forget to add .env to .gitignore and expose credentials in commits.

  • Syncing changes across machines and teammates is laborious.

  • Onboarding new developers often means chasing secrets through chats or internal docs.

These problems slow down teams and increase the chance of sensitive data leaks.

Meet 1Password environments: a secure, familiar way to work with .env files without complicating your workflow

1Password environments brings the same trusted protection developers rely on for SSH keys and personal credentials to their .env files. Built directly into our desktop password manager, it lets your apps read the variables they need without secrets being written to disk. When your app requests access, 1Password retrieves the secrets securely. Once they’re read, they’re gone until you need them again.

A screenshot of Environments in 1Password.

It’s a simple example of one of our core principles: making the secure thing the easy thing. Developers get the same workflow they already know – just safer, faster, and built into the tools they already use.

Simplify your workflow

1Password environments work with your existing .env tools and libraries – no need to rewrite code or change how you load environment variables.

Instant setup

Create an environment, import your variables, mount your file, and invite your colleagues to collaborate. No admin setup or account-level configuration required.

Zero plaintext

Secrets are not written to disk so won’t appear in your Git history. You can’t accidentally commit them.

Offline access

No more getting blocked when your connection drops: you can now access cached secrets even when offline, a long-standing request from our users.

Built for collaboration

Version history, access control, and automatic updates all live in one place so everyone can stay synced without juggling files.

What’s happening behind the scenes

Here’s how this new functionality works: 1Password environments mounts a .env file at the path you choose. Once you approve access, 1Password passes the data directly to your app through a UNIX pipe. Your applications can read the file as if it were a regular .env file but the file contents are never written to disk.

The mounted file remains available as long as 1Password is running and locks automatically when 1Password is locked. Because the file is mounted virtually, it won’t be tracked by Git, meaning your secrets can’t be staged, committed, or pushed.

This setup allows your apps to interact with a .env file as they normally would without ever exposing or persisting secrets. Everything works as expected, just far more securely.

Get started

Setting up 1Password environments takes just a minute:

  1. In the 1Password desktop app, head to the Developer section in the sidebar. (If you haven’t already, you’ll need to enable the 1Password Developer experience in Settings.)

  2. Create or open an environment.

  3. Import your existing .env file.

  4. Under Destinations, choose Local .env file.

  5. Select the file path where you want to mount it.

  6. Authorize access when prompted.

  7. Run your app as usual. 1Password provides your secrets securely when needed.

  8. Delete your old .env file if you haven’t done so already.

A screenshot of Applications within Environments.

1Password environments works out of the box with existing dotenv libraries. You can disable or re-enable mounted .env files anytime from the Destinations tab.

What’s next

1Password environments already integrates with AWS Secrets Manager, making it easy for teams to use it in production. More destinations are on the way.

Looking ahead, we’re focused on expanding support to more developer workflows while continuing to refine the experience based on beta feedback. We’re also exploring options to bring this experience to Windows. (Stay tuned for updates!)

If you’re trying 1Password environments during beta, we’d love your feedback. Join the discussion in the 1Password Community or subscribe to our developer newsletter for updates.

Try 1Password environments today

Get started in the 1Password desktop app and experience a simpler, safer way to work with .env files.