Skip to content

Your password manager has just handed the keys to an AI. Should you be worried?

1Password now lets Claude sign in to your accounts without ever seeing your passwords. The technical solution is elegant. The real question it raises is less so.

Advertisement
The initial paradox 🔑
For an AI to book a ticket, manage an account, or make a purchase on your behalf, it has to log in somewhere. Until now, that meant handing over your credentials, which no sensible person does willingly. Since mid-July 2026, 1Password has offered an ingenious answer: letting the agent use your credentials without ever showing them to it. Here's how, and why it doesn't solve everything.

As AI agents move from conversation to action, a very practical question arises: identity. An assistant that has to carry out a real task on the internet must authenticate itself, and therefore cross the most sensitive barrier in your digital life. The solution proposed by 1Password deserves a closer look, both for what it solves and for what it leaves open.

The mechanism, explained simply

The principle is called a zero-exposure architecture. The idea boils down to one sentence: Claude knows it has logged in, but has never seen with what.

Here's the sequence. When the agent needs to authenticate on a site, it doesn't receive your password. It issues a request, which 1Password displays in its own interface, indicating which credential is being requested and why. You approve, via fingerprint or biometric identification. 1Password then decrypts the credential locally on your machine and injects it directly into the web page, through a secure channel. The password and one-time code never enter the model, its memory, or Anthropic's systems.

Three safeguards complete the setup, and they're well thought out. During filling, the agent is put to sleep: it stops reading and following the page until 1Password has finished, which prevents it from observing the precise moment the secret exists in the page. A credential is only filled on a site matching the one registered for that item, which blocks phishing attempts. And after each fill, the page is re-analysed to check that no secret lingers, with values wiped if submission fails.

Finally, authorisation is limited to the task at hand and doesn't carry over to subsequent sessions. No permanent access granted once and for all.

What's genuinely well done ✅
The design applies a solid security principle: granting permission to use a resource without handing over the resource itself. It's the difference between giving someone your keys and opening the door for them each time they need it. 1Password has also enabled a protection mode by default for all its users, which applies even without configuring the integration and covers agents other than Claude. On the design front, there's little to criticise.

The problem it doesn't solve

And yet. The limit needs to be named clearly, because it's structural and no architecture can make it disappear.

This solution protects your credentials. It doesn't protect your session. Once the agent is logged into your bank account, your email, or your online store, it acts with your rights, in an authenticated session. It doesn't know your password, but it no longer needs it: it's already inside. The most attentive observers of this announcement have noted this, pointing out that the user must remain vigilant about what the agent actually does during the open session.

And that's precisely where the most documented risk lies. Agentjacking, the attack that slips fake instructions into data an agent believes to be legitimate, boasts an 85% success rate. A compromised agent that's already authenticated doesn't need your password to cause damage. Credential theft was one problem. Session abuse is another, and it remains largely open.

The real question, which is broader

This announcement is interesting because it makes visible a transition we're living through without always naming it. We're moving from a computing world where we act, to one where something acts for us. And our entire security edifice—passwords, two-factor authentication, biometrics—was designed to answer a single question: are you really you?

The question that now matters is different: what is acting in your name, with what permission, and can you prove what was done? That's a change in kind. Responsibility shifts too: if an agent authenticated in your name makes a costly mistake, who answers for it?

So should you use this kind of tool? The reasonable answer is neither blanket refusal nor blind adoption. It lies in the scope you grant. Entrusting an agent with managing a subscription or booking a ticket is a measured risk, with repairable consequences. Opening a banking session or access to sensitive professional documents is something else entirely.

The right reflex, as often with AI, is to reason in terms of what you're willing to lose rather than what you hope to gain. 1Password's technology is solid and represents real progress. But no architecture, however elegant, will replace judgement about what you agree to delegate. That decision remains entirely yours—and that's probably for the best.

Advertisement