1Password
Building a safer, simpler digital future for everyone.
AI agents can detect phishing. They just don’t know not to fall for it.
To address this risk, 1Password built the Security Comprehension and Awareness Measure (SCAM) to test AI models in real-world scenarios. The results:
🚨 Every model committed critical failures
🚨 Some forwarded passwords to attackers
🚨 Others typed real credentials into phishing pages
The good news? A simple 1,200-word security skill dramatically reduced failures.
Now, we’re open-sourcing SCAM. 👉 https://bit.ly/4aocmLC
Don’t mind us, just checking out Mastodon.
⚠️ AI agent skills are becoming a new attack surface and most teams aren’t prepared.
In OpenClaw, “skills” are treated as documentation, but in reality, they can act as installers.
Jason Meller
, VP & Security Strategist
@1password@1password.social
, found a top-downloaded skill in a popular registry was being used to deliver macOS infostealing malware.
This is why agentic AI needs identity and access controls that are time-bound, revocable, and attributable.
Must-read 👉 https://bit.ly/3OkmCgn
🔐 Secrets need to move at the speed of modern development.
CI/CD pipelines, local tools, and AI-assisted workflows all need access to secrets at runtime – not copied into files or synced into fixed destinations.
What’s new:
🔐 Runtime, read-only access to 1Password Environments
⚙️ Use via CLI & SDKs
⏱️Scoped, read-only access for automation using service accounts
The result: fewer leaks, less friction, and safer dev workflows.
👉 More here https://bit.ly/3Mj3QWo
🔑 Secrets should move with code, not get copied into files.
We’ve expanded programmatic access to 1Password:
🔹 Runtime read-only secret access from Environments via CLI & SDKs
🔹 Scoped service accounts for safe automation
🔹 Desktop-authenticated SDKs for trusted integrations
Secure access, built into real workflows.
👉 More here https://bit.ly/3Mj3QWo
We’ve open-sourced Security Comprehension and Awareness Measure (SCAM) to benchmark AI agent safety, and we’re taking the conversation to Reddit.
Join Jason Meller, 1Password VP of Product Architecture, for a live Reddit AMA on Feb 17 to unpack:
🔹 Why AI models fail at staying safe
🔹 How a 1,200 word security skill transformed results
🔹 What agent trust means for the future of credential security
Drop your questions now 👉 https://bit.ly/4ra59pA
🧩 SDKs should unlock real workflows, not just item reads.
With 1Password SDKs, integrations can now support:
🧰 Full vault management (CRUD + list)
🔐 User-authenticated SDK sessions
🚀 Batch actions for performance at scale
The result is a new class of integrations designed for enterprise operational workflows, where managing access matters as much as securing secrets.
#DeveloperTools #SDKs #IdentitySecurity #AccessManagement #1Password
Overpermissioning was already a problem. Now, imagine those permissions assigned to AI agents operating at machine speed.
At #RSAC2026, Nancy Wang, CTO, @1password@1password.social, joins Fotis Chantzis, Agent Security Lead at @OpenAI, to unpack ⤵️
🔹 Why legacy access models break in AI-driven environments
🔹 How agent overpermissioning compounds risk
🔹 What leaders must rethink now
📅 March 25 | 3 PM PDT
👉 Register: https://bit.ly/4b4zCQj
Most agent swarms today work because they inherit broad access to filesystems, networks, and credentials. That doesn’t work for production.
Wayne Duso and Nancy Wang, Chief Technology Officer at 1Password, unpack the constraints and what production-grade swarms actually require:
🔹 Explicit identity
🔹 Scoped, time-bound access
🔹 Continuous enforcement at runtime
👉 More here: https://bit.ly/4tJzuNg
A huge thanks to Apple for naming 1Password as the App Store App of the Day! 🎉
1Password makes creating, storing, and protecting strong passwords easier than ever.
With your whole life online, you want the best security possible — download the 1Password app on the Apple AppStore: https://apps.apple.com/story/id1631161034
Agent swarms are incredibly powerful and dangerously easy to deploy unsafely with today’s security models.
We just shared a demo with Autonomy to show a better pattern with 1Password: • just-in-time access • least privilege by default • no standing creds • no hardcoded secrets
If you want agent-powered products that can run safely in real production environments, this model is worth digging into 👇
ISO sets the standards for information security management systems. A security-first approach has always been embedded into 1Password’s DNA, but now we can officially say we meet the highest international standards for information security and privacy. 🏆 🔐
Get all the details: https://blog.1password.com/1password-iso-27001-certified/
We’re introducing the new developer experience in the 1Password Mac, Windows, and Linux apps 🚀
Now it’s easier than ever to discover and set up tools like the 1Password SSH Agent, CLI, and more.
Check out the new developer experience now live across all desktop apps: https://blog.1password.com/new-developer-experience
We’re excited to share our latest 1Password features, inspired by your feedback!
We’re always working to make 1Password an even easier solution to simplify your digital life. That’s why we’ve added and enhanced many of your favorite features, including:
1️⃣ An easier, more intuitive way to search and autofill on mobile
2️⃣ Improved item creation, navigation, and autosaving 2FA codes
3️⃣ Optimized security with Watchtower alerts and Touch ID
4️⃣ And much more!
https://blog.1password.com/product-update-improvements-and-features/
Whether you need to save, find, or access your sensitive data across your devices, 1Password makes it seamless, simple, and secure.
We’ve heard your feedback and we’re excited to share new and updated 1Password features that you’ve been requesting! 🎁
Each of these enhancements helps streamline the many ways you use 1Password, making it easier than ever to manage your digital life. https://blog.1password.com/product-update-features-and-security-q3-2024/
We’ve spent 2024 adding and updating 1Password features, all thanks to your feedback. 🤝
That’s why we’ve added and updated plenty of features you’re going to love, including improved item sharing, recovery codes, autosaving, and more!
👉 Get all the details: https://blog.1password.com/product-update-features-and-security/
The new 1Password Community is live! 🎉
We listened to your feedback and rebuilt the 1Password Community with a dedicated developer space so that you can:
- Quickly troubleshoot issues via developer docs and discussion forums.
- Share projects and integrations with other developers and 1Password customers.
- Join the SDK User Group to connect with other developers building secrets management integrations.
Learn more 👉 https://blog.1password.com/1password-community-launch/
Exciting news! 1Password is now a core member of the Rails Foundation! 🎉
This is more than a membership—it's a commitment to empowering developers. Rails has been instrumental in many success stories, including Kolide, now part of 1Password built with love on Rails.
Let’s make Rails even stronger together!
https://blog.1password.com/1password-joins-rails-foundation/
Join 1Password’s Sr. Director of Product, End User Experience, Matt Grimes, for an AMA session about our latest product enhancements, including:
1️⃣ An easier, more intuitive way to search and autofill on mobile
2️⃣ Better item creation, navigation, and autosaving 2FA codes
3️⃣ New ways to stay secure with Watchtower alerts and Touch ID
4️⃣ And much more!
Ask your questions now: https://www.reddit.com/r/1Password/comments/1i6nvqw/were_the_team_behind_1passwords_latest_product/
Security teams can now help developers find and secure unencrypted SSH keys with 1Password. 🎉
With 1Password Extended Access Management you can secure developer devices, code, and infrastructure.
Get the details on the blog: https://blog.1password.com/extended-access-management-developer-security