READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

1Password Lets Claude Log Into Your Accounts Without Ever Seeing Your Password

1Password Lets Claude Log Into Your Accounts Without Ever Seeing Your Password
1Password launched a new feature that lets Anthropic's Claude complete tasks like booking travel or checking Stripe transactions using your stored credentials, without the AI model ever seeing your passwords or MFA codes. It's a real fix for a real problem: handing login info to an AI agent is a bad idea, and 1Password built a system where you approve access per task instead of surrendering the keys.

1Password rolled out a new browser integration on Thursday, July 16, that lets Anthropic's Claude complete online tasks using your stored login credentials, without Claude ever actually seeing your passwords, according to 1Password.

The feature is called 1Password for Claude. It works through what 1Password calls a "zero-exposure security framework." When Claude needs to log into a site to complete a task, like booking a flight or checking Stripe payments, it requests access. 1Password then injects the actual username, password, or one-time MFA code directly into the target site through a secure channel. The credential itself never passes through Claude, its memory, or Anthropic's servers, 1Password says.

Users approve each request with a single biometric prompt, according to both 1Password and Engadget's reporting. This replaces the old workaround of pausing an AI agent's work every time it hits a login wall so a human can type in a password.

Why This Matters

Handing an AI agent your raw login credentials is a bad idea. If the model gets compromised, or if it stores that data in memory, your accounts are exposed. ZDNET framed the core problem well: most useful online tasks, whether it's managing Stripe payments, web hosting, or accounting software, sit behind a login. That's the wall that's kept AI agents from doing real, autonomous work.

1Password's fix is scoped and temporary access. Per 1Password's own explanation to ZDNET, "Access is granted per session, scoped to a specific task, and does not carry over. There is no standing access." That means Claude can't check your Stripe dashboard once and then wander back in on its own later. Every task requires a fresh authorization.

1Password also says it locks down the moment an AI agent takes control of a browser, restricting access to only the credentials explicitly granted for that task, and scans every page after autofill to make sure no login data got left exposed in a form field. That's a sensible safeguard given how often AI browser agents make mistakes or get tricked by malicious web pages.

What's Actually Available Right Now

The feature launched for 1Password users on Mac only, across business, family, and individual plans. It requires the 1Password desktop app and browser extension plus the Claude desktop app and browser extension. Windows and mobile support wasn't mentioned in the announcement.

Right now the access is limited to login-related credentials: usernames, passwords, and MFA codes. 1Password says support for payment cards and stored identity details, like your address or ID information, is coming after launch, but gave no specific date.

Alongside the Claude-specific integration, 1Password introduced a broader "Agentic Mode" for all its users. This detects when any AI agent takes control of a browser and automatically restricts vault access to only what's been explicitly granted. For now, 1Password says the mode only works with Claude, but the company says it plans to expand to other AI agents "as the ecosystem grows."

The Honest Trade-Off

There's a legitimate question worth asking before treating this as a solved problem: scoped, session-based access is a real security improvement over just handing an AI your password, but it still means an AI agent is autonomously logging into your financial accounts, and a single biometric tap is the only checkpoint between approval and execution. ZDNET's own reporter raised this directly with 1Password, asking what stops an agent from returning to a sensitive account like Stripe after the first authorized visit. 1Password's answer, that access doesn't carry over and there's no standing access, is a reasonable technical safeguard, but it depends on that system working exactly as designed every time, with no exploitable gap in how sessions are scoped or how the "secure channel" handles credential injection. Neither 1Password nor Anthropic has published independent third-party security audits of this specific framework as of this writing.

The Verge and Engadget's coverage matched 1Password's own framing closely, both outlets largely repeating the company's press materials on the zero-exposure claims without independently verifying how the credential injection is technically implemented. ZDNET was the one outlet that pushed back with a direct question about repeat access, given how much trust this system asks users to place in a black-box handoff between two companies' software.

For now, anyone using this feature is trusting that 1Password's session-scoping holds up under real-world conditions, including on sites designed to phish or manipulate automated browser agents, a risk that's already been documented broadly in AI browser-agent security research. Whether that trust is earned will likely depend on how the feature performs once it's in wider use beyond Mac users on 1Password's individual, family, and business plans.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ZDNET1Password's new Agentic Mode lets Claude log into your accounts without seeing your credentials
center-left
EngadgetYou can now grant Claude access to your 1Password credentials
left
The VergeClaude can now use your 1Password credentials for you