anthropic
Logins get filled through a channel Claude can't see
Promtime
anthropic1Password has documented 1Password for Claude, a connector that lets Claude sign in to websites on a user's behalf while the passwords are filled over a channel the agent cannot read. The setup instructions, published in 1Password's support documentation, cover a Mac-only configuration built around the Claude desktop app and Claude in Chrome.
At a glance
- During a fill, Claude stops reading and tracking the page until 1Password reports back, so the credentials have already been submitted and are gone from view when the model looks again.
- Setup requires a Mac, 1Password for Mac and its browser extension at version 8.12.28 or later, the Claude desktop app and Claude in Chrome, plus authorizing the connector with Touch ID or the account password.
- Coverage stops at Login items: usernames, passwords, one-time codes and supported sign-in providers such as Google or Facebook are filled, while passkeys and every other item type remain unsupported.
Credential handling has been the sharpest unresolved problem for browser agents: a model that can click through a checkout can also read whatever the page and the password manager expose to it. The design here appears to answer that by making the fill invisible to the agent rather than by trusting it, which shifts the security question from model behaviour to the boundary between two desktop applications. The lockdown of everything outside the approved item reads as an acceptance that an agent session is a hostile environment for a vault.
Claude only learns which login item it used, never the password
When a task hits a sign-in wall, Claude sends a request to 1Password, which shows the item being asked for. The user can approve it, pick a different saved login, or deny the request outright. On approval, the browser extension fills the credentials directly on the site through a secure channel outside the agent's view.
Claude stops reading and tracking the website for the duration of the fill and resumes only after 1Password reports back, by which point the credentials have been submitted and are no longer visible. Passwords and one-time codes never enter the model's context, memory, or Anthropic's systems; Claude retains only the identity of the login item.
Agentic Mode cuts off the 1Password extension while Claude drives the browser
Agentic Mode engages automatically as soon as Claude takes control of the browser, whether or not the 1Password connector has been set up. While it is active, only the items approved for the current task remain reachable, and nothing else in the vault is reachable.
The restrictions during that window are broad: no interaction with the 1Password browser extension, no inline autofill suggestions, and no using 1Password to sign in to other websites. 1Password describes the mode as a built-in security feature. Ending that state means closing the Claude tab group in the browser, which is also the documented way to cancel an Agentic Mode session.
Connecting the two apps requires version 8.12.28 on both 1Password components
The requirements list a Mac device, 1Password for Mac and the 1Password browser extension at version 8.12.28 or later, the Claude desktop app, and Claude in Chrome. Connecting runs through Customize > Connectors in the Claude desktop app, where the 1Password connector is authorized with Touch ID or the 1Password account password.
1Password suggests testing the link in Cowork, opened from +New in the Claude desktop app, with a prompt such as checking the status of a recent Amazon order. Users signed in to several 1Password accounts choose which one to connect from a dropdown, and disconnecting uses the same Connectors screen.
If the suggested login is wrong, the item's stored website must exactly match the sign-in URL; the authorization prompt also has a search bar for picking another item. For sites behind Google or Facebook, Claude requests both the site's Login item and the linked provider item, then signs in with the provider.
What administrators must switch on 1Password Business accounts need an administrator to enable "Allow AI agents to autofill for users" under Policies > Sharing and permissions on 1Password.com. On Claude Team and Enterprise plans the feature is off by default until an Owner turns on Claude in Chrome for the team and enables password managers. No timeline is given for passkey support or for anything beyond macOS.
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
We only use your name and avatar from Google. We never store your email address.
