1Password adds Codex MCP server for runtime secret access

1Password has released an MCP server for OpenAI’s Codex coding agent that lets secrets be accessed at runtime without exposing them in prompts, code or model context. The company said the integration uses just-in-time credentials and is part of its broader push to secure agentic development.

1Password adds Codex MCP server for runtime secret access

1Password LLC has expanded its collaboration with OpenAI Group PBC with a new Model Context Protocol, or MCP, server for Codex. The 1Password Environments MCP Server for Codex is designed to let the coding agent pull credentials from 1Password vaults at runtime, while keeping those values out of prompts, code, terminals and the model’s context window.

The company said the setup creates a secure runtime environment where secrets are mounted, used and then discarded. User authentication is required at the moment of access, so developers can reference vaulted credentials inside Codex without the actual values being exposed to the agent or written into the surrounding workflow.

⚡ New to this?

This matters because AI coding agents need access to secrets such as database passwords, API keys and deployment credentials to do useful work. MCP, or Model Context Protocol, is a standard way for tools to connect to AI agents, and 1Password is using it to keep those secrets out of prompts and code.

For non-experts, the big issue is simple: if a password gets pasted into a file or prompt, it can be copied later and used in a breach. 1Password and OpenAI are trying to reduce that risk by making credentials temporary and controlled at the moment the agent needs them.

🦞 OpenClaw angle

If you run self-hosted agents, stop treating secrets as prompt input or .env file content. Put credential access behind a broker that issues short-lived secrets at task time, and make the agent reference a vault entry instead of the raw value.

Also audit any repositories where tokens or API keys are still hardcoded and replace them with vaulted references. For agent workflows that touch databases or deployment systems, require user authentication at the moment of access and discard credentials after the job finishes.

The release extends a strategy 1Password has been building over the past year. The company has already shipped similar integrations for Cursor, Browserbase and Perplexity AI Inc.’s Comet browser, all based on the same just-in-time credential pattern. In each case, the goal is the same: provide agents with access only when they need it, and avoid leaving long-lived secrets sitting in code or files.

That problem is a familiar one for teams using AI coding tools. Codex and other coding agents often need access to databases, application programming interfaces, or deployment pipelines to do real work. In practice, that access is often granted by pasting credentials into local files, dropping them into prompts, or hardcoding them into repositories.

According to 1Password, those habits create avoidable risk because credentials can be copied, leaked or exfiltrated later. The company said hardcoded secrets in repositories and other long-lived credential storage have been the root cause of multiple high-profile breaches.

1Password said the new MCP server addresses the issue in three ways. First, Codex can be told to use 1Password to store any credentials it needs to create or handle. Second, developers can reference vaulted secrets inside Codex without those values appearing in code, terminals or model context. Third, hardcoded credentials in existing projects can be replaced with vaulted references, moving secrets out of repositories.

The company’s CTO, Nancy Wang, said the question for teams adopting coding agents is not whether to give them access, but how. “A credential that persists is already compromised,” Wang said. “That’s why just-in-time credentials are the only viable security model for AI-native development.”

OpenAI described the integration as a way to keep agent speed from getting ahead of enterprise security controls. Nick Steele, who works on agent security at OpenAI, said secure access to credentials is critical as developers bring coding agents into real software workflows. He said 1Password’s MCP server for Codex helps teams give agents runtime access without copying secrets into prompts, local files or repositories.

1Password said the Codex integration fits into its broader Unified Access platform, which it introduced in March. The platform is intended to govern access for human users, machine identities and AI agents through a single identity-first model.

The company also pointed to the scale of its enterprise vault. According to 1Password, it protects more than 1.3 billion credentials and is used by more than 1 million developers and 180,000 businesses, including Asana Inc., Figma Inc., GitHub Inc., Stripe Inc. and Wiz Inc.

The new Codex integration is the latest step in 1Password’s effort to position itself as an access layer for agentic development, with credentials issued at the moment they are needed and discarded once the task is complete.

Source: SiliconANGLE ↗

More from Security News