1Password

@1password@1password.social · Joined ⁨Jan⁩ ⁨2023⁩

Building a safer, simpler digital future for everyone.

Copy-pasting secrets into .env files. Plaintext credentials on disk. API keys DM’d over Slack.

That’s how most dev teams handle secrets today, and these are all risks.

1Password Environments changes that, and just got even better:

🔍 Global search across all your accounts
↕️ Search & sort within environments
✨ Refreshed UI

Stop copy-pasting secrets. Start using Environments: 1password.dev/environments

Replying to @⁨1password@1password.social⁩

Our engineers used AI-assisted tooling the same way many teams use modern development tools: to help review, organize, and improve internal code. Every change was reviewed by engineers and went through our standard security and quality processes before being accepted.

The security model behind 1Password remains the same. We cannot see the contents of your vault, and neither can anyone else. That has not changed.

Replying to @⁨1password@1password.social⁩

We’ve heard the feedback clearly, and you all are right to ask hard questions when AI is involved in security products.

What matters here is being precise about what changed and what did not.

The systems involved were internal operational systems and supporting code, not customer vaults or the cryptographic systems that protect them. Your passwords, Secret Key, vault encryption, and private data were never exposed to AI models or opened up in any way.

"The pattern that works is using agents to produce deterministic artifacts, then forcing execution through those constraints." Tido Carriero, VP of Engineering at Cursor.

At 1Password, we applied agentic tooling to B5, our multi-million-line Go monolith, to help plan and execute a production refactor. Here's what we learned: 1password.com/blog/what-we-lea

Overpermissioning was already a problem. Now, imagine those permissions assigned to AI agents operating at machine speed.

At #RSAC2026, Nancy Wang, CTO, @1password, joins Fotis Chantzis, Agent Security Lead at @OpenAI, to unpack ⤵️

🔹 Why legacy access models break in AI-driven environments
🔹 How agent overpermissioning compounds risk
🔹 What leaders must rethink now

📅 March 25 | 3 PM PDT

👉 Register: bit.ly/4b4zCQj

🧩 SDKs should unlock real workflows, not just item reads.

With 1Password SDKs, integrations can now support:
🧰 Full vault management (CRUD + list)
🔐 User-authenticated SDK sessions
🚀 Batch actions for performance at scale

The result is a new class of integrations designed for enterprise operational workflows, where managing access matters as much as securing secrets.

👉 bit.ly/3Mj3QWo

#DeveloperTools #SDKs #IdentitySecurity #AccessManagement #1Password

🔐 Secrets need to move at the speed of modern development.

CI/CD pipelines, local tools, and AI-assisted workflows all need access to secrets at runtime – not copied into files or synced into fixed destinations.

What’s new:
🔐 Runtime, read-only access to 1Password Environments
⚙️ Use via CLI & SDKs
⏱️Scoped, read-only access for automation using service accounts

The result: fewer leaks, less friction, and safer dev workflows.

👉 More here bit.ly/3Mj3QWo

Most agent swarms today work because they inherit broad access to filesystems, networks, and credentials. That doesn’t work for production.

Wayne Duso and Nancy Wang, Chief Technology Officer at 1Password, unpack the constraints and what production-grade swarms actually require:

🔹 Explicit identity
🔹 Scoped, time-bound access
🔹 Continuous enforcement at runtime

👉 More here: bit.ly/4tJzuNg

We’ve open-sourced Security Comprehension and Awareness Measure (SCAM) to benchmark AI agent safety, and we’re taking the conversation to Reddit.

Join Jason Meller, 1Password VP of Product Architecture, for a live Reddit AMA on Feb 17 to unpack:
🔹 Why AI models fail at staying safe
🔹 How a 1,200 word security skill transformed results
🔹 What agent trust means for the future of credential security

Drop your questions now 👉 bit.ly/4ra59pA

AI agents can detect phishing. They just don’t know not to fall for it.

To address this risk, 1Password built the Security Comprehension and Awareness Measure (SCAM) to test AI models in real-world scenarios. The results:
🚨 Every model committed critical failures
🚨 Some forwarded passwords to attackers
🚨 Others typed real credentials into phishing pages

The good news? A simple 1,200-word security skill dramatically reduced failures.

Now, we’re open-sourcing SCAM. 👉 bit.ly/4aocmLC

Agent swarms are incredibly powerful and dangerously easy to deploy unsafely with today’s security models.

We just shared a demo with Autonomy to show a better pattern with 1Password: • just-in-time access • least privilege by default • no standing creds • no hardcoded secrets

If you want agent-powered products that can run safely in real production environments, this model is worth digging into 👇

🔗 bit.ly/45G8NyY

⚠️ AI agent skills are becoming a new attack surface and most teams aren’t prepared.

In OpenClaw, “skills” are treated as documentation, but in reality, they can act as installers.

Jason Meller
, VP & Security Strategist
@1password
, found a top-downloaded skill in a popular registry was being used to deliver macOS infostealing malware.

This is why agentic AI needs identity and access controls that are time-bound, revocable, and attributable.

Must-read 👉 bit.ly/3OkmCgn

The new 1Password Community is live! 🎉

We listened to your feedback and rebuilt the 1Password Community with a dedicated developer space so that you can:

- Quickly troubleshoot issues via developer docs and discussion forums.
- Share projects and integrations with other developers and 1Password customers.
- Join the SDK User Group to connect with other developers building secrets management integrations.

Learn more 👉 blog.1password.com/1password-c

Join 1Password’s Sr. Director of Product, End User Experience, Matt Grimes, for an AMA session about our latest product enhancements, including:

1️⃣ An easier, more intuitive way to search and autofill on mobile
2️⃣ Better item creation, navigation, and autosaving 2FA codes
3️⃣ New ways to stay secure with Watchtower alerts and Touch ID
4️⃣ And much more!

Ask your questions now: reddit.com/r/1Password/comment

We’re excited to share our latest 1Password features, inspired by your feedback!

We’re always working to make 1Password an even easier solution to simplify your digital life. That’s why we’ve added and enhanced many of your favorite features, including:

1️⃣ An easier, more intuitive way to search and autofill on mobile
2️⃣ Improved item creation, navigation, and autosaving 2FA codes
3️⃣ Optimized security with Watchtower alerts and Touch ID
4️⃣ And much more!

blog.1password.com/product-upd