lantern

lantern

Docker app from sjcobs' Repository

Overview

A guiding light for when you go dark. Automatically passes your chosen secrets to family members, inside 1Password.

Lantern

Lantern

A guiding light for when you go dark. Automatically passes your chosen secrets to family members, inside 1Password.

Lantern talks to 1Password only through the official CLI (op) and the official SDK (@1password/sdk). It is free, self-hosted, and open source.

It works by using a 1Password service account token with Create vaults access only; it should not have access to your other vaults. Each POST /run creates a special vault for every family member if they do not already have one (default title Lantern). The clock is 1Password login time (last_auth_at), not a timer this app stores, and not an email/SMS check-in. If they are overdue and that vault has items, Lantern grants view-only access to every family member, renames it to Lantern plus their first name (for example Lantern - Ember), and creates a new empty Lantern vault for the inactive person.

Instructions

  1. Host the Docker image on your local network. The image needs to always be running and NEVER be reverse proxied or exposed to the public. If you use Unraid, install Lantern from Community Applications.
  2. Log in to your 1Password dashboard on the web to create a service account. Navigate to Developer → Directory → Service Account.
  3. Create a new service account named Lantern (or anything you choose). IMPORTANT: Only give your service account the Allow creation of new vaults permission. Do NOT give it access to any vaults.
  4. Save your service account token and set OP_SERVICE_ACCOUNT_TOKEN.
  5. Generate a long random string and set RUN_TOKEN. You must send this token when calling POST /run.
  6. Set a scheduler to run POST /run once a day, or set AUTO_RUN to true to use the built-in scheduler.
  7. Everyone in your family should now have their own personal Lantern vault. That vault is shared with all family members if the owner does not log in to 1Password within the INACTIVE_AFTER_DAYS you set.

Endpoint Example:

curl.exe -X POST http://localhost:6346/run -H "Authorization: Bearer <RUN_TOKEN>"

Notifications

You can use n8n (or your preferred workflow scheduler) to notify family members of events by sending emails, SMS, push notifications, a webhook, or even the official Grok Bot. When you call POST /run you will receive a JSON array containing all notify events, or empty [] if none. Each event has notify (warning or shared), email, and name. Warning events also include daysLeft (13).

A family with several people can take time to process, so make sure to set your HTTP timeout to a few minutes. Any errors or warnings are printed in the Lantern log.

Return Example:

[
  { "notify": "warning", "email": "ember@example.com", "name": "Ember Voss", "daysLeft": 2 },
  { "notify": "shared", "email": "nix@example.com", "name": "Nix Thorne" }
]

Settings

Variable Default Description
OP_SERVICE_ACCOUNT_TOKEN required 1Password service account token with allow creation of new vaults permission only.
RUN_TOKEN required Shared secret. Any long random string. You must send this token when calling POST /run.
VAULT_TITLE Lantern Name of vaults Lantern will create.
INACTIVE_AFTER_DAYS 90 Days without a 1Password login before a user's vault is shared. Warnings for the last 3 days. Valid values: 7–365.
TEST_DAY empty (off) Test the system without waiting. It pretends every member has been idle that many days. Put a dummy item in your Lantern vault. 87 is a warning (3 days left). 90 shares anyone who has items. Leave it empty when you are done.
PING_URL empty (off) Get notified if the container stops running by settings PING_URL to an external service like healthchecks.io, a successful run pings the URL. Leave empty to skip.
AUTO_RUN true Automatically call run on start and every 24 hours. Set false if you only use a scheduler like n8n. No notifications unless something externally calls POST /run. If TEST_DAY is greater or equal to INACTIVE_AFTER_DAYS, or any user is overdue, auto run true will fire immediately on container start and not send notifications.
PORT 6346 HTTP port to run on. running.

Dev Environment

npm install
$Env:OP_SERVICE_ACCOUNT_TOKEN = "ops_your-token-here"
$Env:RUN_TOKEN = "a-long-random-string"
npm start

Limitations

An admin can delete anyone's Lantern vault (live or already opened), add themselves or others to it, and change permissions from the 1Password dashboard. View-only grants after a vault is shared do not stop that. Trust your admins, or do not put secrets they can view, edit, or destroy.

Disclaimer

Use at your own risk. This is not a will, a backup, or an official 1Password product. Test it yourself, keep your own copies of anything that matters, and do not rely on it as your only plan. You are responsible for the token, the schedule, and what happens when a vault is shared.

License

MIT.

Support

Sponsor sjcobs

Buy me a coffee

Bitcoin: bc1qzjrleryk7pmyyhw9xpg9dysvygztstk8u7qehn

Bitcoin QR

Install Lantern on Unraid in a few clicks.

Find Lantern in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.

Open the Apps tab on your Unraid server Search Community Apps for Lantern Review the template variables and paths Click Install

Requirements

1Password family account and a service account token.

Related apps

Explore more like this

Explore all

Details

Repository
ghcr.io/sjcobs/lantern:latest
Last Updated2026-09-21
First Seen2026-09-21

Runtime arguments

Web UI
http://[IP]:[PORT:6346]/
Network
bridge
Privileged
false

Template configuration

PortPorttcp
Target
6346
Default
6346
TokenVariable

1Password service account token with allow creation of new vaults permission only.

Target
OP_SERVICE_ACCOUNT_TOKEN
Run tokenVariable

Shared secret. Any long random string. You must send this token when calling POST /run.

Target
RUN_TOKEN
Vault titleVariable

Name of vaults Lantern will create.

Target
VAULT_TITLE
Default
Lantern
Inactive after daysVariable

Days without a 1Password login before a user's vault is shared. Warnings for the last 3 days. Valid values: 7-365.

Target
INACTIVE_AFTER_DAYS
Default
90
Test dayVariable

Test the system without waiting. It pretends every member has been idle that many days. Put a dummy item in your Lantern vault. 87 is a warning (3 days left). 90 shares anyone who has items. Leave it empty when you are done.

Target
TEST_DAY
Ping URLVariable

Get notified if the container stops running by setting PING_URL to an external service like healthchecks.io. A successful run pings the URL. Leave empty to skip.

Target
PING_URL
Auto runVariable

Automatically call run on start and every 24 hours. Set `false` if you only use a scheduler like n8n. No notifications unless something externally calls POST /run.

Target
AUTO_RUN
Default
true