Skip to main content
September 12, 2026
Question

op vault create is not idempotent and silently creates duplicate vaults

  • September 12, 2026
  • 0 replies
  • 1 view

Environment: `op` CLI 2.34.1 on Windows 11, Individual account, desktop app integration.

`op vault create <name>` succeeds even when a vault with that exact name already exists,
creating a second vault silently. There is no `--if-not-exists` flag and no warning on stderr.

This breaks the common provisioning pattern of "ensure the vault exists":

    op vault create "My Vault"    # expected: no-op, or an error if it exists
                                  # actual:   creates a SECOND vault named "My Vault"

The failure does not surface at creation time. It surfaces later, in an unrelated command:

    [ERROR] More than one vault matches "My Vault". Try again and specify the vault by its ID:
      * for the vault "My Vault": 5q4gshqd3zm6rhdeufydesasge
      * for the vault "My Vault": zhaytuxho7nbdna6z7mxmvrggm

By then the duplicate already exists and has to be deleted manually from the app.

Steps to reproduce:

1. op vault create "Test Duplicate"
2. op vault create "Test Duplicate"   -- succeeds, no warning
3. op item create --category=Password --title=x --vault "Test Duplicate" --generate-password
   -- fails with the ambiguity error above

What I am asking for:

I am not asking you to forbid duplicate vault names. Vaults are identified by UUID, and
allowing duplicate names is a reasonable design choice. I am asking for three things
in the CLI:

1. `op vault create --if-not-exists <name>`, returning the existing vault instead of
   creating another one.
2. A warning on stderr when `op vault create` creates a vault whose name already exists.
3. An error message at the point of ambiguity that mentions how the duplicate arose.

Without (1), every provisioning script has to reimplement "list -> filter by name -> create
only if absent" by hand. That is the workaround I applied, but the CLI default steers users
into the bug.

Related: https://github.com/1Password/onepassword-sdk-python/issues/218 shows the same
"ambiguity by name, with a message that does not explain the cause" pattern in the Python SDK.