1Password and Anthropic launched 1Password for Claude, a browser integration that lets Claude access accounts protected by credentials stored in 1Password without exposing passwords or MFA codes to the AI model. The system requires the agent to request access for a specific task, after which the user must approve the request—reportedly including biometric confirmation in some flows—and 1Password injects the credentials directly into the destination site through a secure channel outside the model’s view.
The companies said the feature uses a per-session, task-scoped authorization model with no standing access, forcing Claude to request approval again for later attempts. 1Password also introduced a broader Agentic Mode that automatically locks down vault access when a recognized AI agent controls the browser, limiting the agent to only the explicitly approved credentials for the current task. The Claude integration is launching first, with availability on Mac for 1Password business, family, and individual plans, and broader support for other browser-based agents planned later.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
1Password and Anthropic announced 1Password for Claude, a browser integration that lets Claude use credentials stored in 1Password vaults without exposing passwords or MFA codes to the model. The launch also introduced Agentic Mode, which restricts browser credential access to user-approved, task-scoped sessions when an AI agent is controlling the browser.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcehelpnetsecurity.com
Open sourceitpro.com
Open sourcezdnet.com
Open sourcemacrumors.com
Open source1password.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.