{"slug": "secure-developer-secrets-with-1password", "title": "Secure developer secrets with 1Password", "summary": "1Password launched 1Password Environments and Developer Watchtower to help teams find and secure improperly stored developer credentials, addressing a 34% year-over-year increase in leaked secrets on GitHub reported by GitGuardian. The tools identify plaintext credentials on local devices, provide admin visibility into credential risk, and give developers a secure place to store API keys, tokens, and environment variables without writing secrets to disk.", "body_md": "No developer wants to be responsible for causing a catastrophic breach. But security best practices are often incompatible with the expectation that developers constantly write and ship code, and that velocity is massively accelerating thanks to AI adoption. Developers trying to work fast need convenience, but the easiest place to put a developer secret can sometimes be the riskiest place to leave it. For many developers, that place is a local .env file: fast, familiar, and supported by the tools they already use, but often stored in plaintext on disk. Even when developers are given discrete tools for managing secrets, they can be complex, time-consuming, and disconnected from their workflows. So when someone needs to get an app up and running, the fastest path can be the familiar path: put a credential in a plaintext file on your local disk.\n\nThese habits create a visibility gap for IT and security leaders and contribute to secret sprawl. [ GitGuardian’s 2026 State of Secrets Sprawl](https://www.gitguardian.com/state-of-secrets-sprawl-report-2026) report found 28.65 million new secrets in public GitHub commits in 2025, up 34% from the previous year. The same report found the number of leaked secrets for AI services had grown by 81% in a single year.\n\nWhen credentials are stored in plaintext on a local device, IT and security teams may not know they exist, which means they cannot monitor them, revoke them, rotate them, or understand what else depends on them.\n\nThat is the gap 1Password is closing with the launch of 1Password Environments and Developer Watchtower: helping teams find improperly stored developer credentials, secure them in the place employees already trust, and let developers keep using them without slowing down the work.\n\n**Developer Watchtower **identifies plaintext developer credentials on local devices and guides users to import them into 1Password.\n\n**Developer credential visibility for admins** provides a clearer view of credential risk across their organization, with reporting and remediation workflows to help employees secure exposed credentials.\n\n**1Password Environments** gives developers a secure place to store, share, and use the secrets behind apps, services, automations, and AI-assisted workflows.\n\nTogether, these capabilities give developers a safer way to use the credentials their work depends on, while giving IT and security teams the visibility and control they need to manage risk before those credentials spread.\n\n1Password Environments gives developers a secure place to store and use the secrets their apps depend on, including API keys, access tokens, database passwords, cloud credentials, and environment variables.\n\nBuilt directly into our desktop password manager, it lets your apps read the variables they need without secrets being written to disk. When your app requests access, 1Password retrieves the secrets securely. Once they’re read, they’re gone until you need them again. It feels like the same, one-click flow that makes .env files so appealing, but backed up by 1Password’s security.\n\nNow, we’ve made it easier for teams to adopt and manage environments at scale. Environments can now be shared with 1Password groups, not just individuals, so Teams and Business customers can manage access through the same admin model they already use for vaults. Admins also get account-level controls to govern whether 1Password Environments can be used across the organization, with enforcement across the desktop app, CLI, and SDKs.\n\nWe’ve also improved the day-to-day experience for developers and teams. Users can manage access more easily from the Environments detail view, search and sort environments and variables, find environments across their account with global search, and work in a cleaner interface. We’ve also made reliability and infrastructure improvements to make Environments a more dependable part of everyday development workflows.\n\nThe result is a secure workflow that doesn’t slow down development. Developers can import an existing .env file or add variables manually, organize secrets by app, service, project, or stage, share access with teammates or groups, and keep using environment variables without leaving plaintext secret values on disk. They can also access secrets through the 1Password CLI and SDKs, use local desktop authentication such as biometrics where available, support automation with service accounts, and make secrets available to AI coding workflows through 1Password’s MCP Server without exposing the values to the model context.\n\nDeveloper Watchtower already helps developers identify plaintext SSH keys on their device. With this launch, it now extends that protection to .env files, one of the most common places developer secrets can end up during local development.\n\nThat makes Developer Watchtower and 1Password Environments work together in a much more complete way. Watchtower helps find plaintext credentials where they already live, and Environments gives developers a secure place to put them.\n\nWhen 1Password identifies credentials in a local .env file, the user gets a Watchtower alert that explains the risk and guides them to import those secrets into 1Password Environments. Instead of simply warning that a secret exists, 1Password helps the user take action and move it into their vault in one click.\n\nFor developers, this means they can clean up exposed local credentials without rebuilding the way they work. For IT and security teams, it means credentials that may have been invisible on local devices can be brought into 1Password, where they are easier to manage, share, govern, and remediate. Admins will see a new report – Local disk exposure – where they can review plaintext .env files and SSH keys found on local disks by the 1Password desktop app.\n\n*Learn how to set up these features in 1Password's developer docs**.*", "url": "https://wpnews.pro/news/secure-developer-secrets-with-1password", "canonical_source": "https://1password.com/blog/secure-developer-secrets-with-1password", "published_at": "2026-07-28 00:00:00+00:00", "updated_at": "2026-07-28 12:54:20.064935+00:00", "lang": "en", "topics": ["developer-tools", "ai-infrastructure", "ai-safety"], "entities": ["1Password", "GitGuardian", "1Password Environments", "Developer Watchtower"], "alternates": {"html": "https://wpnews.pro/news/secure-developer-secrets-with-1password", "markdown": "https://wpnews.pro/news/secure-developer-secrets-with-1password.md", "text": "https://wpnews.pro/news/secure-developer-secrets-with-1password.txt", "jsonld": "https://wpnews.pro/news/secure-developer-secrets-with-1password.jsonld"}}