Financial institutions rolling out AI agents for customer and back-office tasks face a blunt tradeoff: give the agent standing access to logins, or block it from doing anything useful. 1Password and Anthropic have shipped an alternative. The new integration, 1Password for Claude, lets a Claude agent complete a login-gated task, checking a small business owner’s Stripe dashboard, for instance, without the agent ever seeing the password.
When Claude hits a login screen, it requests a credential from 1Password’s vault. The user approves with a biometric prompt, and 1Password fills the password directly into the page. The model never receives the credential in a form it could read or repeat, and access clears once the task ends. A companion feature, Agentic Mode, locks 1Password’s own interface whenever an agent drives the browser. “The answer isn’t handing agents your secrets,” said Nancy Wang, 1Password’s chief technology officer. “It is to let a user give an agent permission to use a credential without letting the agent see it.”
Banks, payment platforms and fintechs are the accounts with the most to lose from a leaked credential, and they are also among the first movers on customer-facing agents, which is why the announcement leads with a Stripe-dashboard scenario rather than a generic productivity use case.
The sharper point is architectural: most enterprise AI security still focuses on monitoring what an agent does once it has access. This model instead removes the secret from the agent’s reach entirely, the same instinct behind FIS turning frontier AI on its own core banking security. For risk teams vetting agent vendors, the question is no longer whether an agent can be watched, but whether it can be denied the secret and still finish the job.
Source: 1Password