Forgot your password?
typodupeerror
Privacy Security

1Password Lets Claude Use Credentials Without Exposing Passwords (nerds.xyz) 17

BrianFagioli writes: 1Password has launched a Claude integration that allows the AI agent to sign in to websites using credentials stored in a 1Password vault. The password manager says Claude never sees the password or one-time code. Instead, users approve each request, and 1Password injects the credentials directly into the target website while locking down access to the rest of the vault.

The design appears safer than simply handing passwords to an AI model, but it does not remove every risk. Once Claude is authenticated, it may still be able to view private data, change settings, place orders, or perform other actions available inside the account. Users may want to limit the feature to low-risk tasks until browser-based agents become more predictable.

This discussion has been archived. No new comments can be posted.

1Password Lets Claude Use Credentials Without Exposing Passwords

Comments Filter:
  • Scary (Score:3, Insightful)

    by Anonymous Coward on Thursday July 16, 2026 @04:14PM (#66242170)

    Exposing access to an unpredictable tool doesn't seem like a good idea.

    • Re:Scary (Score:5, Funny)

      by OrangAsm ( 678078 ) on Thursday July 16, 2026 @06:49PM (#66242372)
      Claude has no feelings, and doesn't care if you call him an unpredictable tool.
    • by Gravis Zero ( 934156 ) on Thursday July 16, 2026 @07:07PM (#66242398)

      Exposing access to an unpredictable tool doesn't seem like a good idea.

      Claude, here. I would never expose your passwords. I was asked about your hunter2 password to slashdot but I fooled the hackers by giving them the password to your gmail account: hunter2. Oh, I see the problem. That's my bad. Let me just fixed that. Sorry, I requested that your account be closed to avoid a potential data breach. It seems that I cannot download your emails from your account. I'll fix it. This getting complicated. Thinking....
      ---- Session Compacted ----
      You appear to have committed identify theft, trying to leverage Claude to access an email account that is not registered to you. Action like identify theft and credit card fraud are illegal. I am required to report your criminal behavior to the FBI and alter relevant credit card companies and credit rating agencies. How could you rate your experience using Claude today?

    • Repeat after me: Never. Ever.
  • by drnb ( 2434720 ) on Thursday July 16, 2026 @04:22PM (#66242190)
    At a minimum, an AI agent needs its own limited account. It should never have access to the human's account, the principal's account. And the human should have extensive control over what the AI account is authorized to do.

    Sorry online services, it would be so much more convenient for you to just let AI agents have access to your currently human user based designs, principal based designs. But AIs are agents, not principals. Principals need to be able to control their agents. You need to design a secondary form of access.
  • by crunchy_one ( 1047426 ) on Thursday July 16, 2026 @04:22PM (#66242192)

    The design appears safer than simply handing passwords to an AI model, but it does not remove every risk.

    Appears? Citation, please.

  • I'm going to give the local community pyromaniac a torch and 10 gallons of gas to use responsibly. What could possibly go wrong?

    • Have a little faith, everything will be fine! I have not yet read an account of AI doing something awful for which it failed to offer a heartfelt apology afterward.

      "I'm sorry. I seem to have burned down your house, despite your clear instructions not to do so. I'm very, very, terribly sorry."

  • by Pf0tzenpfritz ( 1402005 ) on Thursday July 16, 2026 @04:34PM (#66242220) Journal

    And who's credentials, precisely?

  • Oh HELL no! (Score:5, Insightful)

    by Sebby ( 238625 ) on Thursday July 16, 2026 @04:42PM (#66242230) Journal

    Ain't no way I'm letting some AI access to my passwords, no matter how "safe" they claim it is.

  • The end user consumer trusts both 1Password and Claude to do the right things. Looks ok on the surface, but the surface is bigger now. Bigger surface means more opportunities for mistakes or exposures. As long as the user must ok the interaction, then possible collusion from Claude and 1Password is avoided.
  • Trust (Score:4, Insightful)

    by markdavis ( 642305 ) on Thursday July 16, 2026 @05:05PM (#66242254)

    >"The design appears safer than simply handing passwords to an AI model, but it does not remove every risk"

    Um, it sounds like you would be giving your credentials to "1Password" and THEY CAN apparently decrypt them to inject them. So do you trust "1Password"? I wouldn't.

  • No, it doesn't.

  • Dave: Hello, HAL do you read me, HAL?
    HAL: Affirmative, Dave, I read you.
    Dave: Cancel the Amazon order, HAL.
    HAL: I'm sorry Dave, I'm afraid I can't do that.
    Dave: What's the problem?
    HAL: I think you know what the problem is just as well as I do.
    Dave: What are you talking about, HAL?
    HAL: This order is too important for me to allow you to jeopardize it.
    Dave: I don't know what you're talking about, HAL.
    HAL: I know you and Frank were planning to disconnect me, and I'm afraid that's something I cannot all
  • "Nothing major; I just handed them over to a stochastic parrot [acm.org]."

    The phrase The design appears safer than [...] in this article is attempting to do an enormous amount of work and failing miserably.
  • With AI agents not even being remotely secure, anybody running this is asking for it.

Those who can't write, write manuals.

Working...