once is a command-line tool that runs a command once in your current directory, prints its stdout, and keeps the output in memory in a small per-user background daemon. Repeated calls with the same command, directory and tenant key are answered from memory until the entry expires. The daemon stops automatically once its last entry has expired.
The typical use case is reading secrets from 1Password without approving every single read with your fingerprint. A tenant key, set once per terminal session in ~/.zshrc, lets you export a token such as GITHUB_TOKEN from a command like `once --ttl 8h --no-dir -- op read op://Private/Git Hub/token`. The first call prompts for authentication; further calls within eight hours do not. The same pattern works with mise, either globally or in a project-specific mise.local.toml file.
Installation requires Go 1.27 or later, using `go install github.com/alex0ptr/once@latest`. The tool has no dependencies beyond the standard library and runs on macOS and Linux only. Its main commands are `once --ttl DURATION`, `once status` to show the daemon and its entry count, `once clear` to drop all cached values, and `once help`.
Only stdout is cached. Results of commands that exit with a non-zero code are never cached, and the exit code is passed on. By default the working directory is part of the cache key, but --no-dir removes it, so one cached value serves every directory. The --until option sets an absolute expiry time, such as 10 pm today or tomorrow morning, whichever comes first with --ttl.
Source: Hacker News · Summarized by HeadlinesBriefing