Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Enterprise AI

1Password Secures Coding Agents with OpenAI Codex


1Password Secures Coding Agents with OpenAI Codex
  • by: Business Wire
  • |
  • May 20, 2026

1Password has expanded its collaboration with OpenAI to secure credential access for Codex coding agents. The new 1Password Environments MCP Server for Codex allows developers to grant secure, just-in-time access to credentials directly within their coding workflows without exposing secrets.

Quick Intel

  • 1Password introduces Environments MCP Server for OpenAI Codex to secure credential access for coding agents.
  • Secrets are injected at runtime and never enter prompts, code, or the model’s context window.
  • Credentials remain in 1Password and are not written to disk or hardcoded in repositories.
  • Supports just-in-time access after user authentication or approval for enhanced security.
  • Enables Codex to reference vaulted credentials without exposing their values.
  • Strengthens unified access control for both human users and AI agents in development environments.

As coding agents like Codex take on larger roles in software development, secure and controlled access to credentials for databases, APIs, and deployment pipelines has become essential.

Trusted Access Built Into Developer Workflows

Traditional methods of managing credentials — such as copying them into files, prompts, or hardcoding them — create significant security risks. The new integration addresses these challenges by ensuring secrets never leave the 1Password vault.

Developers can prompt Codex to use the 1Password MCP server to retrieve and apply credentials. Secrets are injected only at runtime into authorized processes and are available only for the duration of the session or execution.

Key Security Capabilities

- Catch secrets at the source by having Codex store and use credentials through 1Password. - Use secrets without seeing them, allowing references inside Codex without exposing values in code or terminals. - Keep secrets outside of code by replacing hardcoded credentials with vaulted references.

“As coding agents take on more of the software development lifecycle, the question isn't whether to give them access, but how,” said Nancy Wang, CTO of 1Password. “A credential that persists is already compromised. That’s why just-in-time credentials are the only viable security model for AI-native development.”

“As developers bring coding agents into real software workflows, secure access to credentials is critical,” said Nick Steele, Agent Security at OpenAI. “1Password's MCP server for Codex helps teams give agents the access they need at runtime, without copying credentials into prompts, local files, or repositories. That’s the kind of security that simplifies agentic development, empowering teams to ship faster while keeping sensitive credentials protected.”

This integration advances 1Password’s Unified Access platform, providing a single source of truth for governing access for both humans and AI agents.

About 1Password

1Password is redefining identity security for how people and AI agents work today. The 1Password® Unified Access platform discovers and secures identities and credentials, authorizes just-in-time access, and audits actions across human and AI agents. 1Password SaaS Manager helps organizations discover and secure access to SaaS applications while optimizing spend. 1Password’s enterprise vault protects more than 1.3 billion credentials and secrets and is trusted by more than 1 million developers and over 180,000 businesses, including Asana, Canva, Cresta, Dust, Figma, GitHub, HackerOne, Hugging Face, MongoDB, Notion, Salesforce, SandboxAQ, Stripe, and Wiz.

  • Open AIAI SecurityDev Sec Ops
News Disclaimer
  • Share