1Password and GitHub
The two logins everything else builds on, an SSH key in 1Password, signed commits, and the GitHub CLI.
1Password holds every secret dot uses: SSH keys and API tokens. The private
key never leaves 1Password and is used after Touch ID. Every item dot
creates or uses (not your logins) is tagged dotfiles, so
op item list --tags dotfiles shows them all.
One SSH key does two jobs:
- Authentication:
git pushandgit pullto GitHub. - Commit signing: GitHub shows your commits as Verified.
The app and its CLI, op, come from dot apply. The first steps are yours,
because they involve your account.
1. Sign in and turn on the developer features
Open 1Password, sign in, and in Settings → Developer turn on:
- Use the SSH agent: SSH and git get keys from 1Password.
- Integrate with 1Password CLI:
opuses the app’s session and Touch ID.
If 1Password offers to update ~/.ssh/config, either answer works; dot adds
the same block if it’s missing. To check:
op vault list # Touch ID, then your vaults
ls ~/Library/Group\ Containers/2BUA8C4S2C.com.1password/t/agent.sock
The second command must print the path: that file is the agent’s socket.
2. Create an SSH key
An Ed25519 key, in your built-in personal vault: “Personal” on
individual and family accounts, “Private” on business ones. By default the
SSH agent only offers keys from that vault, and op uses it when no
--vault is given. Tag it dotfiles. One key per Mac is fine; GitHub
accepts several.
-
In the app: + New Item → SSH Key → Add Private Key → Generate a New Key → Ed25519. Title it
GitHuband add the tagdotfiles. -
In the terminal:
op item create --category "SSH Key" --title "GitHub" --tags dotfiles --ssh-generate-key ed25519The CLI can’t edit SSH keys yet, so to tag an existing key, edit it in the app.
3. Log in to GitHub
Connect the GitHub CLI, gh, to a token in 1Password, so no token is ever
saved on disk: GitHub. It
takes about ten minutes once, and under a minute on each later Mac.
4. Use the key
In dot.toml, ssh_key is the key’s title in 1Password, and user
under [github] your GitHub username:
ssh_key = "GitHub"
[github]
user = "your-username"
dot apply ssh # ssh agent 1password
dot apply git # git signing-key $ssh_key
dot apply github # github ssh-key $github.user $ssh_key
ssh agent 1passwordadds aHost *block to~/.ssh/configthat points at the agent. The rest of the file stays yours.git signing-keymakes git sign every commit and tag with the key (op-ssh-sign), and writes~/.config/git/allowed_signersso git can verify signatures locally.github ssh-keyadds the public key to your GitHub account twice, as an authentication key and as a signing key, titled after the hostname.
dot check needs no Touch ID: the public key comes from the agent, and
GitHub’s public key lists show what your account has. Signing a commit asks
for Touch ID, and so does dot apply github, which adds keys through gh.
5. Check it
ssh -T git@github.com # "Hi <you>! You've successfully authenticated"
git log --show-signature -1 # in a repo with a new commit: Good "git" signature
dot auth status # every login dot uses
Commits made before signing was on aren’t signed. If they aren’t pushed
yet, git rebase --root --force-rebase re-signs them.