Notes ·
AI Agents Need Their Own Keys
In 1Password Lets Claude Use Credentials Without Exposing Passwords, Slashdot looks at a new way to let Claude sign in to websites using credentials stored in 1Password.
“Once Claude is authenticated, it may still be able to view private data, change settings, place orders, or perform other actions available inside the account.”
This feels like the wrong direction.
APIs have existed for a long time so computers can communicate with other computers. Give an AI its own revocable token with limited permissions instead of letting it operate through my full user account.
The AI should have access only to the specific actions and data it needs. My password and personal session should remain mine.
Read the full Slashdot story.