Skip to content

Credentials & secrets

How the team stores and shares credentials. adunopay uses 1Password as the single source of truth for shared secrets.

The team account lives at checksum.1password.eu (the .eu domain — 1Password's EU-hosted region). Sign in there for the web vault, or add it as an account in the 1Password desktop/browser apps.

Never commit secrets to git

This page documents where credentials live and how to get access — not the credentials themselves. Passwords, API keys, and tokens belong in 1Password, never in this repo (even though it's private), in code, or in chat. If a secret is ever committed, treat it as compromised and rotate it.

Vaults

Getting access

A new joiner is invited to the checksum.1password.eu account and granted the relevant vaults. Access is administered by the CIO, Thomas Ziegler (thomas.ziegler@checksum.ch) — contact him to be added or to request a vault.

Conventions

Offboarding