Let an AI Agent Log In For You (Without the Password)

Quick answer

Yes, you can now let an AI agent log into your accounts safely. As of 16 July 2026, 1Password for Claude lets Anthropic's Claude sign into a site and finish a real task, pull your Stripe numbers, book a slot, update a record, without ever seeing your password or one-time code. You approve each login with your fingerprint, 1Password injects the credential straight into the page, and the agent only gets that access for that one task. It removes the last reason most small-business owners never let an agent actually do the work.

You did not hold back because the agent was not smart enough. You held back because saying yes meant handing over your passwords.

It is 7 a.m. In Lisbon. Leo opens the laptop before the shop does. He runs a four-person outdoor-gear store: two staff on the floor, one packing online orders, and him doing everything else.

He wants one thing before the coffee lands. Yesterday's numbers. Sales on Shopify. Money that actually settled in Stripe. Anything odd.

He has an AI agent that could pull all of it in seconds. Claude, sitting right there in his browser.

So why does he still do it by hand?

Because pulling those numbers means logging into Stripe. And logging into Stripe means either typing the password himself or pasting it somewhere the AI can read it. He is not about to hand his payments dashboard to a model that keeps everything it is told. So every morning he logs in by hand. The smartest tool he owns sits there, waiting, one password away from the job.

That wall came down today.

What actually changed today?

Today, 1Password shipped a way for Claude to log into your accounts without ever seeing the password.

It is called 1Password for Claude, and it went live on 16 July 2026 for Mac, on business, family, and individual plans. The idea is simple to say and hard to build. You let Claude finish a task that needs a login, and 1Password hands over the credential at the last second, straight into the web page, so the password and the one-time code never touch the model, its memory, or Anthropic's systems.

You stay in control the whole time. When Claude reaches a login, 1Password shows you which credential it wants and why. You approve with your fingerprint. The access is scoped to that one task and ends when the task ends. Anthropic and 1Password first sketched this partnership in March. Today it is a shipping feature you can turn on.

Why has "let the agent do it" never worked before?

Because the login was always the wall.

Your agent can already do the easy half of the job. It can read a page, summarise a dashboard, draft the email, compare two suppliers. Watch what happens the moment real work needs an account:

  • It can read your Stripe summary, if you are already logged in. It cannot log in.
  • It can draft the reply to a supplier, but it cannot open your email to send it.
  • It can tell you what to change in your booking system. It cannot open the door.

So you were left with two bad options. Type every password yourself, which defeats the point of having an agent. Or paste your passwords into the agent, which no sensible owner does with a Stripe or a bank login.

Read that back. The reason your agent never did the work was not intelligence. It was access. You were the login.

From an agent that talks to an agent that finishes the job

A chatbot answers. An agent finishes.

That is the whole shift, and a login is where the difference used to die. Here is Leo's morning now, start to finish.

He types one line: "Log into Stripe and tell me yesterday's revenue, refunds, and anything unusual." Claude opens the Stripe dashboard in Chrome. It hits the login. Instead of stopping, it asks 1Password for the Stripe credential. Leo gets a prompt on his Mac showing exactly what is being requested. He presses his finger to the sensor. 1Password fills the login and the one-time code straight into the page. Claude reads the numbers, spots a refund spike on one product, and writes Leo three lines.

He never typed a password. Claude never saw one. The job that used to need him now needs one fingerprint.

1Password can even carry him across more than one site in a single task, so a workflow that touches three logins does not stop three times to ask.

How can an AI agent log in without seeing the password?

It works because the password is injected into the web page at the moment of use, not handed to the AI. The credential lives in one encrypted place, and the agent only ever gets the result of the login, never the secret behind it.

Engineers have a name for the pattern underneath this: a credential vault. As one security teardown put it this week, a credential vault is an encrypted store that lets a system use a key it never holds. Store the secret once. Inject it at the instant of the call. The thing making the call, your agent, never touches it.

There is one question that sorts the safe designs from the risky ones: at the moment of use, who is holding the password in plain text? Paste it into the agent, and the answer is the model, sitting in a context window that can be tricked into repeating it. With 1Password for Claude, the answer is the web page, for a few milliseconds, and then it is gone. As that same teardown said, an agent that never holds a key can never leak one.

Five-step flow: you ask the agent to do a task, the agent hits a login wall, you approve with your fingerprint, the password manager injects the login into the page, the agent finishes the task. The password never enters the AI.
How a secure agent login runs. The password is injected into the page at the moment of use, so it never enters the model.
0passwords or one-time codes that enter the model, its memory, or Anthropic's systems, according to 1Password.

Isn't this just a security hole with extra steps?

No. It is closer to the opposite. It shrinks what a confused agent can leak.

Be clear-eyed here. Prompt injection, where a booby-trapped web page tries to hijack an agent, is still an unsolved problem. Anyone who tells you their agent cannot be confused is selling something. What this design changes is the blast radius. If an agent gets tricked, the first thing an attacker hunts for is credentials, and this agent's pockets are empty. No password in the context window. No one-time code in memory. Nothing to find, so nothing to leak.

1Password added a second guardrail called Agentic Mode. When a browser agent takes control of a browser where 1Password is installed, the extension locks itself down. It hides its own interface and will only release the specific logins you approved for the current task. You can see when it is active and cancel at any time. After each autofill, 1Password checks the page to confirm the secret was not exposed, and if a form submission fails, it wipes the filled values before handing control back. For qualifying businesses, staff using 1Password at work get this protection automatically, with nothing new to set up.

 The old way: paste the passwordThe new way: approve, then inject
What you doType or paste the password into the agentApprove one login with your fingerprint
What the agent seesThe full password and 2FA codeOnly that the login worked
If the agent is trickedThe secret is right there to stealThere is no secret in reach to steal
To cut off accessChange the password everywhere it livesEnd the task; the access is already gone

It is early, and worth saying plainly. This is Mac first, it needs the 1Password app and browser extension plus the Claude desktop app and extension, and support for payment cards and identity details is coming later. Start small and it earns your trust fast.

How to try it this week, in about 20 minutes

You do not need a project. You need one login and one small task.

  1. Check the kit. A Mac, 1Password with its browser extension, and the Claude desktop app with its browser extension. Turn on the 1Password for Claude integration in 1Password.
  2. Put one login in 1Password. Pick something useful but not scary. Your Stripe or Shopify dashboard, your booking tool, your supplier portal. Not your bank on day one.
  3. Choose a read-only task. Something that looks, not touches. "Log into Stripe and tell me yesterday's revenue and any refunds." Never start with "pay this invoice."
  4. Run it and approve. When Claude hits the login, your fingerprint prompt appears. Approve it. Watch Claude finish the job and report back.
  5. Check the receipt. The task is done, and you never typed or pasted a password. That feeling, that is the point.

Once you trust the read-only version, widen it slowly. Let it pull a weekly summary from three tools instead of one. Keep it reading before it starts writing. This is the same careful path we walk clients through in the Sprint: one workflow, proven, before you scale it. If you have not yet, this pairs well with giving your agent a way to quote every lead in minutes, and it sits right next to the trust question we raised in our note on AI voice scams.

What you have after this

In a week, your agent pulls your morning numbers while the kettle boils, and you approve it with a thumb.

In a month, the small logins-and-lookups you never bothered to delegate are just gone. The supplier portal check. The revenue glance. The "did that payment land" question.

In six months, the line between "the AI can suggest it" and "the AI can do it" has quietly moved, and not one of your passwords moved with it.

Same agent. Same accounts. It just got the keys to the building, without ever holding the keys.

What is 1Password for Claude?

It is an integration, launched 16 July 2026 for Mac, that lets Anthropic's Claude log into websites and finish tasks that need an account, without the password or one-time code ever entering the model. You approve each login with your fingerprint, and 1Password injects the credential directly into the page.

Can Claude see my password or my 2FA code?

No. 1Password says the password, one-time code, and other secrets never enter Claude's context, memory, or Anthropic's systems. Claude only learns that the login worked. The credential is delivered through a secure channel straight into the web page.

Is it available on Windows, and what do I need?

At launch it is Mac only, on business, family, and individual plans. You need the 1Password desktop app and browser extension, plus the Claude desktop app and browser extension. Support for payment cards and identity details is planned for later.

Can the agent spend money, or only read things?

It can complete logins and actions anywhere Claude can act in Chrome, which includes purchases and account changes. But you approve every login and can cancel at any time, so the safe way to start is read-only tasks, like pulling a revenue summary, before you let it change or pay anything.

Does this stop prompt injection?

No, and be wary of anyone who claims otherwise. Prompt injection is unsolved. What this design does is shrink the damage: because the agent never holds the password, a tricked agent has no credential to leak, and 1Password's Agentic Mode locks the vault down while a browser agent is in control.

Find your first high-payback workflow.

See the Sprint

Sources

HN

Editorial responsibility
Notma Intelligence publishes practical guidance using named sources and visible dates. AI tools may assist research or drafting; a named human remains responsible for factual review before publication.
Read the editorial policy → · Meet founder Hammton Ndeke →

Find your first high-payback workflow.

Book a free conversation or start with the fixed-fee Sprint.

See the Sprint

Keep reading