anthropic

1Password fills Claude's logins without showing passwords

Claude News

anthropic

1Password has shipped a Claude connector that lets the assistant sign in to websites on a user's behalf, filling usernames, passwords and one-time codes through a channel the model cannot read. The setup requires a Mac, the Claude desktop app and 1Password 8.12.28 or later, according to 1Password's documentation.

At a glance

  • Every fill starts with an authorization prompt that names the item Claude asked for, and the request can be approved, swapped for a different saved login, or denied outright.
  • While the extension fills the fields, Claude stops reading the page until 1Password reports back, so passwords and one-time codes never reach the model's context, memory or Anthropic's systems.
  • Agentic Mode locks the vault down the moment Claude takes over the browser, leaving only items approved for the current task reachable and disabling inline autofill for everything else.

Credential handling has been the practical ceiling on browser agents: anything behind a login either stayed out of reach or required pasting a password into a context the model could read. Routing the fill through the password manager, with the agent blinded for the duration, reads as an attempt to remove that trade-off rather than manage it. The lockdown of everything not approved for the task likely matters as much as the fill itself.

Setup runs through Customize > Connectors and needs 1Password 8.12.28 or later

The prerequisites are a Mac device, 1Password for Mac at version 8.12.28 or later, the 1Password browser extension at the same version, the Claude desktop app and Claude in Chrome. Both desktop apps have to be running before the connector will pair.

Pairing happens in the Claude desktop app under Customize > Connectors, where the 1Password entry has a Connect button. The 1Password app then asks for Touch ID or the account password to authorize the link, and users signed in to several 1Password accounts can pick which one to connect. Disconnecting uses the same Connectors screen, with a Disconnect button next to the 1Password entry.

Login items, passwords and one-time codes are covered, passkeys are not

1Password's documentation suggests testing the connection in Cowork, opened from +New in the Claude desktop app, with a prompt such as asking Claude to open Amazon, sign in and check the status of a recent order. 1Password then shows an authorization prompt with a suggested Login item, and a drop-down for picking another saved login.

When the saved item signs in through Google or Facebook, Claude requests both the site's Login item and the linked provider item, then completes the sign-in with the provider credentials. Support currently covers usernames, passwords and one-time passwords from Login items; other item types and passkeys are not yet handled.

If the wrong login comes up, 1Password points to a mismatch between the item's website field and the sign-in URL, which can be edited in the desktop app. The authorization prompt also has a search bar for finding an item outside the suggestions.

Agentic Mode triggers even without the connector installed

Agentic Mode engages automatically whenever Claude takes control of the browser, whether or not the connector has been set up. During a session the 1Password extension cannot be used directly, inline autofill suggestions disappear, and logins cannot be filled on other sites; ending it means closing the Claude tab group in the browser.

Business customers need an administrator to switch on agentic autofill on 1Password.com, under Policies, then Manage in the sharing and permissions section. On the Claude side, Team and Enterprise organizations start with the integration off: an Owner has to open Organization settings, then Claude in Chrome, and turn on both team access and password managers.

Passkeys and the Mac requirement

The documentation gives no timeline for passkey support or for item types beyond Login items, and names no platform other than a Mac device. It also does not say whether browsers besides Chrome will be covered. What is documented is the current boundary: usernames, passwords, one-time codes and supported provider sign-ins.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.