Log in with your 1Password SSH key
Keep the key devmachine logs in with inside 1Password, instead of a file on your disk. 1Password’s SSH agent hands the key over when devmachine needs it, and asks you to approve with Touch ID or your password.
If you do not already keep SSH keys in 1Password, you do not need this: the
key setup makes for devmachine is simpler, and just as safe.
You need: a VPS (tested on Debian and Ubuntu), 1Password 8 on your computer, and an SSH key saved in 1Password.
Before you start: machine, skills, workspace
Do steps 1 to 3 below first. setup needs the agent running to offer its
keys.
curl -fsSL https://mydevmachine.sh/install.sh | sh
devmachine setup
devmachine skills add
devmachine workspaces new acme
devmachine sync
Already have a machine? See step 3 for moving it to the 1Password key. See getting started for what each command does.
By hand
1. Turn on the 1Password SSH agent
In 1Password, open Settings → Developer and turn on Use the SSH agent.
2. Point your terminal at it
Add one line to ~/.zshrc (or ~/.bashrc), then open a new terminal.
On macOS:
export SSH_AUTH_SOCK=~/Library/Group\ Containers/2BUA8C4S2C.com.1password/t/agent.sock
On Linux:
export SSH_AUTH_SOCK=~/.1password/agent.sock
ssh-add -l now lists the keys 1Password offers.
3. Choose the key in setup
devmachine setup
When it asks how the CLI should log in, pick the line that ends in
(from the SSH agent) with your key’s fingerprint. setup installs that
key on the server, proves it works, and turns password logins off, as usual.
It records the key’s public half as agent_key: in config.yml, and that
is what tells devmachine to ask the agent for that one key from then on —
never every key in the vault.
For a machine you already set up with another key: add the 1Password
key’s public half to the server’s /root/.ssh/authorized_keys, then
delete the machine’s key: line from config.yml and replace it with
agent_key:, set to that same public key line.
4. Optional: limit what the agent offers everywhere else
Step 3 is enough for devmachine itself. Plain ssh and anything else on
your computer still ask 1Password for every key in the vault, one after
another, and a vault with many keys can hit the server’s limit — the
error says “Too many authentication failures”.
Tell 1Password which key to offer, in ~/.config/1Password/ssh/agent.toml:
[[ssh-keys]]
item = "devmachine"
vault = "Private"
item is the key’s name in 1Password, vault the vault it is in. Add one
[[ssh-keys]] block per key you still want the agent to offer, such as
your GitHub key. Skip this if devmachine (ssh, mosh, run) is the
only thing you use this key for — it already offers only the one key.
5. Use it
devmachine ssh acme
1Password asks you to approve, and the session opens. devmachine ssh and
mosh run the system ssh, which reads the same SSH_AUTH_SOCK.
devmachine run keeps its connection open for five minutes, so a few
commands in a row ask only once.
A program you open from the Dock or a launcher does not read your
~/.zshrc. If it calls devmachine for you, it has to set SSH_AUTH_SOCK
to the path in step 2 itself.
With your agent
Steps 1 and 4 happen in 1Password, and step 3’s choice is yours, so do those
by hand. Then, in a new Claude Code or Codex session on your computer
(devmachine skills add taught it the CLI):
Check that devmachine logs in with my 1Password SSH key: run
devmachine doctor and tell me what it says.
The agent runs devmachine doctor. 1Password asks you to approve, and every
line should pass. If one says the login was refused, the agent can list
the agent’s keys with ssh-add -l and compare them with the key setup
installed.
Check it: devmachine doctor passes, and 1Password showed an approval
prompt for it.
Source: 1Password — SSH agent, 1Password — advanced use, 1Password — agent config file
Where to go next
- Get started
Your first devmachine, explained
Install devmachine, connect a server and open your first workspace, one command at a time.
Beginner
- Security
Logins and secrets
See what a workspace is missing, then sign in and hand over tokens with credentials, login and secrets.
Beginner
- Networking
SSH or mosh?
When to use ssh and when to use mosh, and the one firewall setting mosh needs.
Beginner