There’s a problem that grows with every agent you run: how does the thing sign in anywhere? Until now you had exactly two choices. Dump your credentials into the context — where the model can read them. Or interrupt the agent at every login and type them yourself.
1Password for Claude launched yesterday and turns that into a third option.
How it works
Credentials are injected straight into the target site through a channel that 1Password controls. The password and any multi-factor one-time code stay outside the model, outside its memory, and outside Anthropic’s systems.
Access is granted per session and scoped to an approved set of items. It doesn’t carry into other sessions and leaves no standing access behind. Claude requests the credentials it needs for a given task — you approve or deny each request with a single biometric prompt.
CTO Nancy Wang sums up the idea in one line:
“The answer isn’t handing agents your secrets. It is to let a user give an agent permission to use a credential without letting the agent see it.”
Agentic Mode
1Password is also introducing Agentic Mode for all users. The moment a compatible agent takes control of the browser, the vault locks down. Only the credentials granted for the current task stay reachable. Nothing else.
The mode turns itself on and stays active while the agent works. You can see it running in the browser extension and switch it off whenever you want.
Two more details I like:
- 1Password brokers credential access across multiple sites within a single task — so Claude can move through multi-step workflows without asking for logins again.
- After every autofill, the page is scanned and filled values are wiped if the form submission fails. That closes a common way for secrets to linger on screen.
Availability
1Password for Claude is available now to 1Password users on Mac, across business, family and individual plans. It requires the 1Password desktop app and browser extensions plus the Claude desktop app and browser extensions. Support for payment cards and personal details like names and addresses is due after launch.
Agentic Mode starts with Claude but is built to extend to other browser-based agents.
My take
This is the right direction of thinking. We’ve built a whole class of tools that act for us in the browser — while treating authentication as if it were a solved problem. It isn’t. A password in the context window is a password that can end up in a transcript, a log, or a prompt injection attack.
The catch: Mac only, and it assumes you’re in the 1Password ecosystem. But the principle — permission instead of secret — is exactly what agents need. I hope it becomes a standard rather than a differentiator.
Sources: