On July 16, 2026, password management giant 1Password (AgileBits) and AI developer Anthropic announced a new feature called “1Password for Claude,” which allows AI agents to log in without directly knowing users’ credentials. This collaboration adopts a “zero-exposure architecture” that structurally eliminates security risks when AI operates websites on behalf of the individual.
- Key Points of Historic Partnerships and Events in July 2026
- Why is “delegation of authentication to AI” important now?
- Five steps to get people to use passwords without revealing them
- Introduction of ‘Agentic Mode’ to protect browsers from AI
- A turning point where the unit of authorization shifts from “app” to “task”
- Risks to be resolved and risks that still remain ‘after the operation’
- Passkey Support and Integrated Management of ‘All Secrets’
- Outlook for AI Governance Toward 2027
Key Points of Historic Partnerships and Events in July 2026
On July 16, 2026, AgileBits released a new feature called “1Password for Claude,” which integrates with Anthropic’s AI “Claude” to log in to websites on behalf of users without revealing their passwords to the AI. This feature is designed to safely bypass the biggest barrier for browser-operated AI agents in web tasks such as booking airline tickets, checking order status, and changing account settings—the “login” process.
In traditional AI utilization, there were extremely dangerous scenarios where users would directly paste passwords into chat screens or prompts to delegate web operations to agents. However, with the introduction of this feature, credentials are strictly managed on the 1Password side without being sent to AI model context, memory, or Anthropic systems.
As of July 2026, the terms for offering are as follows.
-
Supported OS: Mac only
-
1Password Eligible Plans: Business, Families, Individual plans
-
Claude Eligible Plans: Pro, Max, Team, Enterprise plans
-
Required components: 1Password and Claude desktop apps, plus browser extensions for both (4 items in total)
The diagram below illustrates the concept of automated login by AI agents.

Why is “delegation of authentication to AI” important now?
This is because the role of AI is shifting from simply “assisting with thinking” to “acting agents,” completing complex tasks on behalf of users. Between 2025 and 2026, highly autonomous tools like “Claude Code” have become widespread, but when AI encounters website login screens, the only options until now are extremely inefficient or risky: “manually log in” or “hand over the password to AI.”
Empowering AI agents with operational authority dramatically boosts productivity while exposing new risks that disrupt traditional IT governance. For example, incidents such as unintended database deletions and credential retention in logs due to AI models’ indeterminate inference processes have been reported worldwide.
1Password defines AI agents as a “third identity class” after humans and machines, and advocates for the need for a dedicated new security model. Rather than “handing” passwords to AI, the system that grants users permission to use them without revealing secrets is the starting point of trust in ID management in the AI agent era.
How “Zero Exposure” Works to Avoid Exposing Secrets
Five steps to get people to use passwords without revealing them
At the core of 1Password for Claude is the company’s proprietary design, which it calls the zero-exposure architecture. With this mechanism, AI can complete the login process without knowing the password “value” at all. The specific process proceeds in the following five steps.
-
Step 1 (Request): Claude determines that logging in to the website is necessary and sends a request to 1Password.
-
Step 2 (Presentation): 1Password displays on the user’s screen which credentials are requested and for what purpose.
-
Step 3 (Approval): The user reviews the details and completes the approval using biometric authentication such as Touch ID or the master password for 1Password.
-
Step 4 (Injection): Approved credentials are automatically auto-fed directly to the web page through a secure channel outside the AI’s visual range.
-
Step 5 (Revoked): This access is limited during the execution of the task and expires upon completion. Permanent access rights do not remain with AI.
After injection, 1Password automatically checks whether secret information is exposed on web pages, and if submission fails, it immediately deletes the values entered in the form and returns control to Claude, implementing a thorough defense measure. This minimizes the risk of passwords being stolen by malicious prompts.
Introduction of ‘Agentic Mode’ to protect browsers from AI
Announced alongside the integration of 1Password for Claude, “Agentic Mode” is a powerful protection feature that activates while the AI agent controls the browser. This is automatically activated the moment the corresponding AI agent starts operating the browser, even without any specific integration settings.
When Agentic Mode is enabled, the following restrictions apply to the 1Password extension.
-
The user interface (UI) of extensions is hidden.
-
Inline autofill candidates are no longer displayed.
-
Agents can only access login information explicitly approved for that task.
-
Other items in the Vault will no longer be accessible to the AI.
The significance of this feature lies in structurally eliminating the risk that AI agents might accidentally touch unauthorized accounts through autofill candidate menus and similar means. For corporate Business accounts, unless administrators enable the “agentic autofill” setting, employees are controlled so that they cannot start using this feature without permission, and the information systems department is designed to maintain control.
Please refer to the diagram below.

New Security Boundaries and Challenges in the AI Agent Era
A turning point where the unit of authorization shifts from “app” to “task”
The innovation demonstrated by 1Password for Claude holds the potential to fundamentally change the nature of SaaS governance. Traditional identity management focused on static authorization of “who can access which apps.” However, this collaboration adopts a runtime-based dynamic authorization model that asks which credentials to use only at runtime for which tasks.
This is an extremely effective approach in environments where AI agents work across multiple SaaS services. In AI governance in 2026, one of the top priorities is not granting AI excessive authority (Excessive Agency). This 1Password model embodies the principle of assigning the Least Privilege on a per-task basis.
For IT officers, this news is not just about improving convenience; it means that the scope of ID governance has begun to expand from “humans” to “AI agents.” Going forward, it will be necessary to rethink agent privilege design as a unified whole, including authorization controls for tool connections via MCP (Model Context Protocol).
Risks to be resolved and risks that still remain ‘after the operation’
This technology greatly reduces the risk of leaks originating from “shadow AI,” where employees intentionally paste passwords into AI chat. By providing a safe alternative, the internal rule of “prohibiting direct input into AI” will only become effective.
However, it is important to note that zero-exposure design only addresses “credential leakage,” and the “risk of AI-driven actions” still remains.
-
Operational error: The risk that AI may make wrong judgments and unintentionally purchase products or delete settings.
-
Approval fatigue: There is concern that “approval fatigue,” where frequent biometric authentication requests are pressed without scrutinizing the content, will become established.
-
Destination terms: May violate the web service terms that prohibit automated AI agent operations.
Currently, only “login” information and “One-Time Passcode (TOTP)” are eligible, and credit card information or passkey authentication is not supported. There are still technical and institutional hurdles for AI to fully autonomously overcome all payments and advanced authentications.
Future Developments: Standardization of AI Authentication Infrastructure and Ecosystem Expansion
Passkey Support and Integrated Management of ‘All Secrets’
1Password has announced that it will expand its integration targets beyond login information in the future. One particularly anticipated feature is support for passkeys. As of March 2026, major services such as Google, GitHub, and Amazon support passkeys, but there is ongoing industry-wide debate about how AI agents can autonomously pass this “device + biometic” authentication assumption.
1Password’s strategy is to evolve into a platform that centrally manages all aspects of “authentication and access,” including passwords, passkeys, SSH keys, API keys, and credit card information. In secret management for AI agents, the company has clearly aimed to target the de facto standard by enclosing the developer community through the provision of SDKs and MCP servers.
Competitors Bitwarden and Dashlane are also announcing MCP support and agent-specific features one after another in 2026. The key management domain for AI agents is shifting from the dominance of 1Password to competition among multiple vendors, expanding users’ choices while also demanding the organization’s ability to select technologies.
Outlook for AI Governance Toward 2027
In March 2026, Japan’s “AI Operator Guidelines” were revised to explicitly state the requirement that “human judgment is mandatory (Human-in-the-Loop)” before AI agents perform operations that influence external parties. The process of “human authentication via biometric verification” at 1Password for Claude aligns perfectly with the current trends in these regulations and guidelines.
Going forward, integration is expected to go beyond single tool integration with SaaS management platforms (such as Admina) that visualize AI usage across the organization, as well as with dedicated guardrail technologies that monitor AI agent behavior. Looking ahead to 2027, when AI agents transition from “experiments” to “backbone of practice,” the authorization model presented by 1Password is expected to serve as an important reference for future AI security.
[#1Password #Claude #AIエージェント #サイバーセキュリティ #ID管理 #ゼロエクスポージャー #Anthropic #2026年最新技術]


コメント