All apps · 0 apps
lantern
Docker app from sjcobs' Repository
Overview
Readme
View on GitHub
Lantern
A guiding light for when you go dark. Automatically passes your chosen secrets to family members, inside 1Password.
Lantern talks to 1Password only through the official CLI (op) and the official SDK (@1password/sdk). It is free, self-hosted, and open source.
It works by using a 1Password service account token with Create vaults access only; it should not have access to your other vaults. Each POST /run creates a special vault for every family member if they do not already have one (default title Lantern). The clock is 1Password login time (last_auth_at), not a timer this app stores, and not an email/SMS check-in. If they are overdue and that vault has items, Lantern grants view-only access to every family member, renames it to Lantern plus their first name (for example Lantern - Ember), and creates a new empty Lantern vault for the inactive person.
Instructions
- Host the Docker image on your local network. The image needs to always be running and NEVER be reverse proxied or exposed to the public. If you use Unraid, install Lantern from Community Applications.
- Log in to your 1Password dashboard on the web to create a service account. Navigate to Developer → Directory → Service Account.
- Create a new service account named Lantern (or anything you choose). IMPORTANT: Only give your service account the
Allow creation of new vaultspermission. Do NOT give it access to any vaults. - Save your service account token and set
OP_SERVICE_ACCOUNT_TOKEN. - Generate a long random string and set
RUN_TOKEN. You must send this token when callingPOST /run. - Set a scheduler to run
POST /runonce a day, or setAUTO_RUNtotrueto use the built-in scheduler. - Everyone in your family should now have their own personal Lantern vault. That vault is shared with all family members if the owner does not log in to 1Password within the
INACTIVE_AFTER_DAYSyou set.
Endpoint Example:
curl.exe -X POST http://localhost:6346/run -H "Authorization: Bearer <RUN_TOKEN>"
Notifications
You can use n8n (or your preferred workflow scheduler) to notify family members of events by sending emails, SMS, push notifications, a webhook, or even the official Grok Bot. When you call POST /run you will receive a JSON array containing all notify events, or empty [] if none. Each event has notify (warning or shared), email, and name. Warning events also include daysLeft (1–3).
A family with several people can take time to process, so make sure to set your HTTP timeout to a few minutes. Any errors or warnings are printed in the Lantern log.
Return Example:
[
{ "notify": "warning", "email": "ember@example.com", "name": "Ember Voss", "daysLeft": 2 },
{ "notify": "shared", "email": "nix@example.com", "name": "Nix Thorne" }
]
Settings
| Variable | Default | Description |
|---|---|---|
OP_SERVICE_ACCOUNT_TOKEN |
required | 1Password service account token with allow creation of new vaults permission only. |
RUN_TOKEN |
required | Shared secret. Any long random string. You must send this token when calling POST /run. |
VAULT_TITLE |
Lantern |
Name of vaults Lantern will create. |
INACTIVE_AFTER_DAYS |
90 |
Days without a 1Password login before a user's vault is shared. Warnings for the last 3 days. Valid values: 7–365. |
TEST_DAY |
empty (off) | Test the system without waiting. It pretends every member has been idle that many days. Put a dummy item in your Lantern vault. 87 is a warning (3 days left). 90 shares anyone who has items. Leave it empty when you are done. |
PING_URL |
empty (off) | Get notified if the container stops running by settings PING_URL to an external service like healthchecks.io, a successful run pings the URL. Leave empty to skip. |
AUTO_RUN |
true |
Automatically call run on start and every 24 hours. Set false if you only use a scheduler like n8n. No notifications unless something externally calls POST /run. If TEST_DAY is greater or equal to INACTIVE_AFTER_DAYS, or any user is overdue, auto run true will fire immediately on container start and not send notifications. |
PORT |
6346 |
HTTP port to run on. running. |
Dev Environment
npm install
$Env:OP_SERVICE_ACCOUNT_TOKEN = "ops_your-token-here"
$Env:RUN_TOKEN = "a-long-random-string"
npm start
Limitations
An admin can delete anyone's Lantern vault (live or already opened), add themselves or others to it, and change permissions from the 1Password dashboard. View-only grants after a vault is shared do not stop that. Trust your admins, or do not put secrets they can view, edit, or destroy.
Disclaimer
Use at your own risk. This is not a will, a backup, or an official 1Password product. Test it yourself, keep your own copies of anything that matters, and do not rely on it as your only plan. You are responsible for the token, the schedule, and what happens when a vault is shared.
License
MIT.
Support
Bitcoin: bc1qzjrleryk7pmyyhw9xpg9dysvygztstk8u7qehn
Install Lantern on Unraid in a few clicks.
Find Lantern in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.
Requirements
Categories
Related apps
Explore more like this
Explore allDetails
ghcr.io/sjcobs/lantern:latestRuntime arguments
- Web UI
http://[IP]:[PORT:6346]/- Network
bridge- Privileged
- false
Template configuration
- Target
- 6346
- Default
- 6346
1Password service account token with allow creation of new vaults permission only.
- Target
- OP_SERVICE_ACCOUNT_TOKEN
Shared secret. Any long random string. You must send this token when calling POST /run.
- Target
- RUN_TOKEN
Name of vaults Lantern will create.
- Target
- VAULT_TITLE
- Default
- Lantern
Days without a 1Password login before a user's vault is shared. Warnings for the last 3 days. Valid values: 7-365.
- Target
- INACTIVE_AFTER_DAYS
- Default
- 90
Test the system without waiting. It pretends every member has been idle that many days. Put a dummy item in your Lantern vault. 87 is a warning (3 days left). 90 shares anyone who has items. Leave it empty when you are done.
- Target
- TEST_DAY
Get notified if the container stops running by setting PING_URL to an external service like healthchecks.io. A successful run pings the URL. Leave empty to skip.
- Target
- PING_URL
Automatically call run on start and every 24 hours. Set `false` if you only use a scheduler like n8n. No notifications unless something externally calls POST /run.
- Target
- AUTO_RUN
- Default
- true