once executes a command in your current directory, prints its stdout and keeps it in memory in a small per-user background daemon. Repeated calls with the same command, directory and tenant key are answered from memory until the entry expires. The daemon stops by itself once its last entry has expired.
The typical use case: reading secrets from 1Password without approving every single read with your fingerprint.
The first call asks for your fingerprint, every further call within 8 hours with the same tenant key does not.
This is the place to start: it lists every option and command (once help and -h work too). For more verbose documentation keep reading.




