Claude got the login. 1Password kept the password.

Claude got the login. 1Password kept the password.

1Password keeps passwords out of Claude's context, but the integration still gives a paid Mac browser agent a scoped route into real accounts.

"Claude knows it used your login. It does not need the password." 1
1Password launched a browser integration for Claude on July 16 that lets the agent use stored login credentials without putting the password or MFA code into Claude's model context, memory, or Anthropic's systems. 1 2
That is a real improvement over pasting a password into a chatbot. It is also the moment when "Claude never sees your password" starts doing a lot of marketing work. Claude still gets the browser, the authenticated session, and the job you asked it to complete.

What it actually does

When a browser task needs a login, Claude asks 1Password for the required credential. You approve that request with a biometric prompt, then 1Password fills the login directly into the target page. The password and one-time code stay outside the model, so Claude can use the login without reading the secret. 1 2
The intended use case is not a password lookup. It is a multi-step browser task such as booking travel or managing an online account. 1Password says its new Agentic Mode can handle an authenticated session across multiple sites, while keeping access limited to the items approved for that task and session. 1
1Password also says it locks down when an AI agent takes control, scans the page after each autofill, and clears filled values if a form submission fails. The rest of the vault is supposed to remain unreachable. 1 2
Conceptual view of the credential boundary: the password goes to the browser while the model stays behind the gate.
A conceptual view of 1Password's stated boundary: the credential is injected into the target page rather than placed in Claude's context. 1

The secret is hidden. The action is not.

The security pitch is narrow, and that is why it is credible. 1Password is not claiming that Claude cannot operate a signed-in browser. It is claiming that the agent can operate it without receiving the password or one-time code. The first problem is reduced. The second problem is the product.
A password is one kind of authority. A live browser session is another. Once the login is filled, the agent can carry out the task it was given inside the account. The launch materials describe credential delivery, per-task approval, and page scanning. They do not describe a separate policy engine that decides whether a post-login action is sensible. 1 2
That distinction matters more than the phrase "zero exposure." The product moves the security boundary from "can the model read the secret?" to "should this agent be allowed to perform this authenticated action?" Biometric approval helps because access is granted per task instead of left standing between sessions. It does not turn the approval into a review of everything the agent might do after the login succeeds.
Conceptual view of the Mac software stack required for Claude and 1Password browser automation.
The integration is a controlled handoff between several apps, not a magic password slot. 13

Frictionless, after the subscription stack

The feature is available to 1Password users on Mac across individual, family, and business plans. The announcement does not name a separate price for the integration. On the Claude side, Anthropic's support documentation puts Claude in Chrome behind paid Pro, Max, Team, and Enterprise plans, with Chrome support still labeled beta. 1 3
The setup also needs the 1Password desktop app and browser extension, plus the Claude desktop app and browser extension. Claude's support page lists Chrome as the supported browser and excludes mobile devices and other Chromium-based browsers. 2 3
So the product's real price is not a per-login meter. It is the existing 1Password account, a paid Claude plan, a Mac, Chrome, two desktop apps, two extensions, and a biometric approval every time the agent needs a credential. That is a reasonable stack for someone who already lives in both products. It is a lot of machinery to call "without interruptions" when the interruption has merely become a fingerprint prompt.

Verdict

1Password for Claude fixes the dumbest version of browser automation: the one that copies a password into the model and hopes the model behaves. Its per-task approval, session scoping, direct form filling, and model-level secret isolation are meaningful engineering choices. But this is still an authenticated browser agent, not a powerless assistant. It keeps the password out of Claude while putting Claude inside the account, subject to the quality of the task, the page, and the approval you just gave it. Use it for repetitive, bounded work where you can inspect the task and tolerate the remaining beta and platform limits. Do not mistake secretless execution for consequence-free execution. The password stayed in the vault. The authority went to the browser.

関連コンテンツ

  • ログインするとコメントできます。
More from this channel