{"slug": "your-env-file-wasnt-built-for-ai-agents-1password-has-a-better-way", "title": "Your .env File Wasn’t Built for AI Agents. 1Password Has a Better Way.", "summary": "At the Raise Summit in Paris, Richard Kirby, Office of the CTO at 1Password, discussed the company's shift toward passkeys and AI credential management, noting that passwords remain prevalent but the focus is moving to managing credentials for AI agents. 1Password launched a feature using FIFO pipes to keep credentials off local disks and .env files, and it allows users to approve AI agent access to credentials without exposing raw secrets, a mechanism Kirby calls 'Securing the Stay.'", "body_md": "# Your .env File Wasn’t Built for AI Agents. 1Password Has a Better Way.\n\nAt the Raise Summit in Paris, I caught up with **Richard Kirby**, Office of the CTO at 1Password.\n\nWe sat down to discuss **why passwords haven’t disappeared**, where passkeys still stall in practice, how engineering teams should approach service accounts and AI agents requesting tool access, and what building secure, developer-friendly secrets management actually looks like today.\n\n## Passkeys are replacing passwords?!\n\nWe’re seeing the cybersecurity world gradually move **from old-school passwords to passkeys**. That shift is exactly why I asked Richard how 1Password (a company built around password management) is approaching the change and adapting its broader strategy.\n\nThe company is actively pushing that transition: a few years ago, 1Password acquired Passage specifically to speed up passkey adoption. Today, the platform supports both passwords and passkeys, though Richard expects the shift to happen slowly:\n\nPasswords are not going away. In some ways, we would love passwords to go away because passkeys are obviously a more secure option. However, passwords remain so prevalent that every system still relies on them.\n\nHe says this change affects credentials overall, not just user passwords. “In the age of AI, managing credentials has become very important. AI doesn’t use a passkey itself, but it still needs credentials to access certain resources”.\n\nThat’s why 1Password sees passkeys as an important part of the modern tech stack. Passwords are still here, but the **focus is shifting more toward AI and managing credentials for AI agents**.\n\n## Software vendors are slowing passkey adoption\n\nWhen I asked what technical hurdles are preventing passkeys from becoming the new standard, Kirby said platform vendors first have to rewrite how they handle authentication:\n\nIntroducing passkey technology requires people to go back and retrofit their existing platforms, which creates the biggest hurdle.\n\nFrom a user’s perspective, passkey setup can be confusing because **vendors handle it so differently**: some require multiple passkeys, others replace passwords entirely, and some do both. That inconsistency is still slowing down wider passkey adoption.\n\nAs engineering teams automate more infrastructure, I wanted to understand how they should think about non-human identities, like service accounts and AI agents.\n\nRichard was especially excited about a feature his team recently launched: a **dedicated part of the product that helps developers manage local secrets safely**:\n\nInitially we built the 1Password Environments feature to help developers keep credentials out of local disks and .env files. It uses FIFO pipes, which lets us avoid writing credentials to disk.\n\nThis setup also solves a big security problem for AI. You should never give raw credentials directly to an autonomous AI agent, since they can end up in logs or other places you can’t control. This feature lets apps access credentials securely while keeping you in control:\n\nWhen an agent wants to use plugins for Cursor, Claude, or other major platforms, 1Password notifies me and says, “An agent wants access to data.” I approve the request, and 1Password supplies the credential to the authorized application so it can complete the sign-in, without exposing the raw secret to the agent. That’s a huge step forward. We don’t see this as the end goal, but it is an extremely valuable tool for working with AI agents in a secure environment.\n\n## What happens when you invite an AI Agent “into the house”?\n\nRichard calls this mechanism **“Securing the Stay,”** and sees it as a major breakthrough in connecting cybersecurity and AI.\n\nBut that raises a new question: once the agent is inside, what can it do, who approved it, and how much can it do on its own? That’s why **these systems need governance, policy, and oversight**.\n\nNo one has solved it fully yet, but the whole industry is moving in that direction.\n\nWe see the biggest transformation for users right there: Securing the Stay and establishing full compliance to provide complete control and guarantees over what an agent can access.\n\n## Keep things simple!\n\n1Password tries to keep its user experience simple, and its Director of Product Management strongly believes in that approach:\n\nI have always believed that if you make someone’s job easier, they will do it. The cybersecurity industry as a whole holds a reputation for overcomplicating things. People often perceive passkeys as overly complex, so they run away from them.\n\nFor Richard, being developer-friendly means helping people get things done quickly and simply, without extra complexity. As a developer himself, he values tools that reduce friction and work reliably.\n\n## Least privilege is key to good security\n\nTo wrap up our interview, I asked Richard Kirby which identity primitive he would prioritize first if he had to design an access management layer for a startup today.\n\nWithout hesitation, Richard chose** least-privilege access**.\n\nThe principle of least privilege has always underpinned good security, but teams have always struggled to apply it. Returning to my previous point: if you make it simple, users will reap massive benefits.", "url": "https://wpnews.pro/news/your-env-file-wasnt-built-for-ai-agents-1password-has-a-better-way", "canonical_source": "https://shiftmag.dev/stop-leaking-env-keys-1password-secrets-management-10881/", "published_at": "2026-08-13 12:14:18+00:00", "updated_at": "2026-08-13 12:18:43.167574+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy"], "entities": ["1Password", "Richard Kirby", "Passage", "Raise Summit"], "alternates": {"html": "https://wpnews.pro/news/your-env-file-wasnt-built-for-ai-agents-1password-has-a-better-way", "markdown": "https://wpnews.pro/news/your-env-file-wasnt-built-for-ai-agents-1password-has-a-better-way.md", "text": "https://wpnews.pro/news/your-env-file-wasnt-built-for-ai-agents-1password-has-a-better-way.txt", "jsonld": "https://wpnews.pro/news/your-env-file-wasnt-built-for-ai-agents-1password-has-a-better-way.jsonld"}}