---
url: https://docs.mochiexec.io/guides/vault-presets.md
description: >-
  Tested configurations that connect flow vaults to 1Password, pass, and AWS SSM
  Parameter Store, read-only.
---

# Vault Presets

flow can store secrets in its own encrypted vaults, or read them from a secret manager you
already use. Presets are tested configurations for that second case, so you don't have to
write one by hand.

A vault created from a preset **reads through** to the provider: it holds links to secrets
that already exist there and never writes to them.

| Preset | Provider | Requires |
|---|---|---|
| `1password` | 1Password | `op`, `jq` |
| `pass` | pass (GPG) | `pass` |
| `aws-ssm` | AWS Systems Manager Parameter Store | `aws` |

## Set one up

```sh
mochi vault preset list                           # available presets
mochi vault preset preflight --preset 1password   # is the provider installed and usable?
mochi vault preset connect --preset 1password     # run the provider's sign-in step
mochi vault preset render op --preset 1password --out op-vault.json
mochi vault create op --type external --config op-vault.json
```

Provider options such as the 1Password vault or the AWS region are passed with
`--set key=value`.

`mochi vault preset browse` lists what a provider holds, to help you find secrets worth
linking.

flow docs: [Secrets & vaults](https://flowexec.io/guides/secrets)

How flow vaults work, and how executables read secrets from them.
