{"slug": "secure-agent-access-in-development-workflows-with-1password-nvidia-openshell", "title": "Secure agent access in development workflows with 1Password + NVIDIA OpenShell", "summary": "1Password released 1Password for NVIDIA OpenShell as a developer preview in its nightly build, letting developers connect a 1Password Environment to the OpenShell runtime so AI agents can reach repositories, APIs and internal services without exposing credential values in the model's context. 1Password transfers credential custody to OpenShell for a defined time to live (TTL) while OpenShell governs which hosts the agent can reach and whether the sandbox can read or write, per 1Password's 2026 Developer survey, which found 65% of developers are expected or encouraged to use AI agents but only 33% say they have a highly secure way to do so, and 91% either use agents today or expect to within two years.", "body_md": "1Password for NVIDIA OpenShell is available now as a developer preview in the [1Password nightly build](https://support.1password.com/betas). Connect a 1Password Environment to the OpenShell runtime and let your agents work with the systems it needs without exposing real credentials to the model.\n\n65% of developers say they’re expected or encouraged to use AI agents, but only 33% say they have a highly secure way to do so, according to 1Password's [__2026 Developer survey__](https://1password.com/blog/survey-ai-agent-adoption-is-outpacing-governance). Developers are leveraging coding agents to handle more of software development, including code debugging, development, documentation, and architecture. In fact, [__91% of developers__](https://1password.com/blog/survey-ai-agent-adoption-is-outpacing-governance) are either using agents today or expect to within the next two years. \n\nAgentic workflows introduce a fundamental security challenge: credentials. An agent needs access to repositories, APIs, and internal services. A long-lived secret gives an agent a broader and longer-lived path than a single task requires, but keeping every credential away from the agent prevents it from completing useful work. Developers need a controlled path between those two extremes.\n\nThe better approach is to make the credential available to the agent only where it is approved and for as long as it’s needed, without exposing the credential values in the agent’s context. That is the problem 1Password for NVIDIA OpenShell is designed to solve.\n\n[__NVIDIA OpenShell__](https://build.nvidia.com/openshell) — part of [__NVIDIA Open Agent Security Platform__](https://nvidianews.nvidia.com/news/open-agent-safety-platform) — is an open, secure runtime for autonomous fleets of agents. It governs how agents execute, what they can see and do, and where inference is routed. Its controls are enforced outside the agent, so the agent cannot change the rules that govern its own access.\n\n1Password for NVIDIA OpenShell extends 1Password’s [__secrets management__](https://www.1password.dev/) workflow to agents. Developers have a secure path to adopt agentic workflows to automate repetitive work, spend more time writing code, and focus attention on the problems that require human judgment. Project variables stay organized, access stays scoped, and the setup fits into existing 1Password and developer workflows. \n\n[__1Password Environments__](https://www.1password.dev/environments) give developers a place to organize the variables an agent needs separately from personal passwords and shared team credentials. With OpenShell, the same model applies: developers create an Environment for a project or agent, specify the destination and expiration, and connect it to an OpenShell sandbox. 1Password manages the credentials, while the OpenShell runtime governs the agent’s behavior and the external services it is permitted to reach. The agent can work with real systems without holding any credentials in its context.\n\nTeams can share access for a task without distributing long-lived secrets through chat, local files, or one-off scripts. Security teams get a clear boundary around which variables an agent can use, which hosts can receive them, whether the sandbox can read or write, and when access ends.\n\nTogether, 1Password and NVIDIA keep different responsibilities in the right place. 1Password transfers custody of the credentials to OpenShell for a defined time to live (TTL), while OpenShell governs where the agent can use them during that window. The developer stays in the loop by reviewing the connection before the agent starts work.\n\nCoding agents should fit into the way developers already work today. Our integration with OpenShell gives agents scoped, time bound access to the systems agents need access to through 1Password workflows developers already use, so they can automate tasks without creating a separate credential process or placing credentials in the agent’s context.”\n\n*• Aashish Tripathi, VP of Product Strategy at 1Password*\n\nThe path from a 1Password Environment to a running OpenShell sandbox is straightforward, but each step controls a different part of the access flow.\n\n**Keep project and agent variables in one place.** The developer creates a 1Password Environment with the secrets and configuration the agent needs. 1Password stores them by reference rather than by value.\n\n**Restrict where credentials work.** Developers can then map the Environment to an OpenShell Provider Profile. A developer can use a built-in profile such as GitHub, or create one with their own host and port it themself. From there, users are able to set the expiration and whether the sandbox can read or write.\n\n**Review and authorize access.** The developer approves the connection after reviewing which values are configuration rather than secrets, as well as the Environment, variables, destinations, and expiration. 1Password creates the provider on OpenShell’s Gateway and provides the necessary commands.\n\n**Temporarily transfer credential custody.** The developer attaches the provider to an OpenShell sandbox. OpenShell owns the sandbox and has custody of the credentials for the configured time to live (TTL), while controlling which services the agent can reach.\n\n**Keep secrets out of context.** Inside the sandbox, the agent sees placeholders rather than real credentials, including a placeholder for its model key.\n\n**Resolve values only on request.** OpenShell Gateway replaces a placeholder with the real value ***only when the agent sends a request to an approved host. After expiration, it stops resolving the reference while the sandbox keeps running***.\n\n1Password for NVIDIA OpenShell is available now as a developer preview in the nightly 1Password build. For detailed instructions on how to set it up, [read our documentation](https://www.1password.dev/security-for-ai/nvidia-openshell).\n\nSet up the integration to give agents the access they need without putting long-lived secrets in their context.\n\nGet started with 1Password and give coding agents controlled access to the systems your development workflows depend on.", "url": "https://wpnews.pro/news/secure-agent-access-in-development-workflows-with-1password-nvidia-openshell", "canonical_source": "https://1password.com/blog/1password-nvidia-openshell", "published_at": "2026-09-28 00:00:00+00:00", "updated_at": "2026-09-28 08:47:12.198155+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools", "developer-tools", "ai-products"], "entities": ["1Password", "NVIDIA OpenShell", "NVIDIA Open Agent Security Platform", "1Password Environments", "1Password nightly build"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/secure-agent-access-in-development-workflows-with-1password-nvidia-openshell", "markdown": "https://wpnews.pro/news/secure-agent-access-in-development-workflows-with-1password-nvidia-openshell.md", "text": "https://wpnews.pro/news/secure-agent-access-in-development-workflows-with-1password-nvidia-openshell.txt", "jsonld": "https://wpnews.pro/news/secure-agent-access-in-development-workflows-with-1password-nvidia-openshell.jsonld"}}