Skip to content
Rush Commerce
AI & Automation3 min read

1Password for Claude: agents log in, never see your secrets

1Password for Claude lets an AI agent use approved logins and TOTP codes without the credential ever reaching the model. Here's the pattern to copy.

Your AI agent needs to log into a website. Until now your options were both bad: paste the password into the chat and hope, or don't automate the task at all. 1Password for Claude, announced July 16, takes a third path — the agent gets to use the credential without ever seeing it. That distinction is the whole story, and it's the pattern worth stealing whether or not you buy the product.

What actually happened

1Password shipped a browser-extension feature that lets Claude complete tasks requiring logins and one-time passcodes. When Claude hits a sign-in wall, 1Password shows you which credential is being requested and why. You approve with biometrics, and 1Password injects the value directly into the page through its own channel. Passwords and TOTP codes never enter Claude's context window, its memory, or Anthropic's infrastructure. After autofill, the extension scans the page and wipes filled values if submission fails.

The other half is Agentic Mode. When a compatible agent takes over the browser, the vault locks down — only the credentials explicitly approved for that task are reachable, and everything else is invisible for the duration. You can see when it's active and cancel it mid-run.

1Password CTO Nancy Wang framed the design goal plainly: the answer isn't handing agents your secrets, it's letting a user grant permission to use a credential without letting the agent see it. It's live on Mac for business, family, and individual plans, requires a paid Claude tier, and Windows support plus payment cards are on the roadmap, per Help Net Security.

Why AI agent credentials matter for your business

Here's the uncomfortable audit. Every browser automation you've built probably authenticates one of three ways: a password sitting in a config file, a session cookie someone exported months ago, or a human who logs in first and hands off. All three fail the same test — you can't answer what did this thing have access to, and when.

The architecture 1Password is selling has three properties you should demand from any agent you deploy, product or homegrown: the secret is scoped to a single task, the grant is visible at the moment it's used, and it's revocable without rotating everything. That's the same lesson we drew from Oak's $60M identity round — agent risk lives in credentials, not models.

You don't need this exact product. You need to stop letting agents hold long-lived secrets in plaintext.

Key takeaways

  • 1Password for Claude launched July 16: agents complete logins and TOTP prompts while credentials stay out of the model's context, memory, and Anthropic's systems
  • Agentic Mode locks the vault when an agent drives the browser — only task-approved credentials are reachable, and the user can cancel anytime
  • Mac only at launch, on business/family/individual plans, requiring a paid Claude tier; Windows and payment cards planned
  • The transferable pattern: agent secrets should be task-scoped, visible at point of use, and revocable without a full rotation

Got automations running on a password in a config file? We build agent workflows with scoped, revocable credentials from day one — because the cleanup after an exposed key costs more than doing it right. See how we build them.

Sources: 1Password press release, Help Net Security.

  • #ai-agents
  • #credentials
  • #security
  • #1password
  • #automation
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.