Skip to main content

diff

Compare 1Password with the live platform state. diff never writes.

env-sync diff (--service <name> | --all) --env <env> [--format text|json]
FlagMeaning
--service <name>One service key from the manifest's services: map.
--allEvery service in the manifest, in manifest order. Mutually exclusive with --service.
--env <env>Required. Selects the 1Password item (<source>/<env>) and is passed to every adapter.
--format text|jsonOutput format. The default is text.

Text output​

Each target gets one line. Values are compared by fingerprint (a truncated SHA-256), so raw secrets never appear:

[web] vercel:myapp-web[development,preview]: drift on [API_KEY, DATABASE_URL]
[web] dotenv:apps/web/.env.local: no drift
[api] ssm:/myapp/api: LEGACY_TOKEN: MISSING_FROM_1PASSWORD
  • drift on [...]: the value differs, or the key is absent on the platform.
  • MISSING_FROM_1PASSWORD: the platform has a key that 1Password no longer has.

GitHub Actions secrets are write-only, so they cannot be fingerprinted. github-actions targets use presence mode instead:

[api] github-actions:myorg/myapp:dev: DATABASE_URL: present, value unverifiable; API_KEY: MISSING_FROM_GITHUB

JSON output​

--format json prints one JSON document for scripts and dashboards:

{
"schemaVersion": 1,
"generatedAt": "2026-09-28T12:00:00.000Z",
"env": "dev",
"services": {
"api": {
"targets": [
{
"target": "ssm:/myapp/api",
"platform": "ssm",
"diffMode": "fingerprint",
"status": "ok",
"keys": [
{ "key": "API_KEY", "status": "DRIFT", "expectedFingerprint": "3f9a1c0e7b2d", "actualFingerprint": "a81d44f0c9e3" },
{ "key": "DATABASE_URL", "status": "MATCH", "expectedFingerprint": "0c5e9b12aa47", "actualFingerprint": "0c5e9b12aa47" }
]
}
]
}
}
}

Key statuses are stable machine tokens: MATCH, DRIFT, MISSING_FROM_1PASSWORD (fingerprint mode), PRESENCE_PRESENT, PRESENCE_MISSING (presence mode), and NON_DIFFABLE (listed in the target's non_diffable, not compared). If one target fails, it gets "status": "error" and an error string. Its sibling targets still run. Any change to these tokens bumps schemaVersion.

Exit codes​

Mode01
textNo drift anywhere.Drift or a platform-only key on any target, any service error, a usage error, or a manifest schema error.
jsonThe document is complete. It can still report drift or errors, as data.Do not trust stdout: usage error, schema error, or neither --service nor --all.