Runlayer is a founding partner of 1Password's new agent security platform, alongside Anthropic, OpenAI, Cursor, and Vercel.
If you're still using plaintext .env files or pasting passwords into your agent's chat window, this one's for you.
In 2025, agents acted as extensions of employees. A developer kicked off a task, watched it run, and manually provided credentials when needed. That was fine when agents were glorified copilots.
Now they're autonomous. Agents spin up workflows, access databases, call third-party APIs, and operate across tools without a human in the loop. The credential access model never caught up.
Until now.
Today, 1Password announced Unified Access, a new agent security platform that gives organizations centralized control over how AI agents access credentials, secrets, and sensitive resources. Runlayer is a founding partner alongside Anthropic, Cursor, GitHub, Perplexity, and Vercel.
The problem
Most enterprises manage agent credentials one of three ways: hardcoded in .env files, passed through environment variables at deploy time, or (worst case) pasted directly into agent sessions. All three leave credentials exposed, unaudited, and impossible to rotate at scale.
When an employee leaves the company, their agents don't. Those agents still hold credentials, still access data sources, and still operate with whatever permissions were granted at setup. Security teams have no centralized way to discover, revoke, or audit any of it.
How it works with Runlayer
Runlayer is the control plane for enterprise AI agents, managing how agents connect to tools, resources, and context across your organization. 1Password becomes the credential layer underneath.
When an agent session runs through Runlayer, credentials are retrieved from 1Password vaults in real time. No caching. No plaintext storage. Every credential access is logged with full attribution: which agent, which user delegated access, which credential, when.
The integration fits Runlayer's existing vault abstraction, meaning enterprises can bring 1Password alongside other secret managers without changing how agents are configured or deployed.
What this means for security teams
Unified Access gives security teams three capabilities that didn't exist before for agent workloads:
Discover. See which AI tools and agents are running across endpoints, browsers, and local environments. Identify exposed credentials like unencrypted SSH keys and plaintext .env files. Map AI usage to specific users and devices.
Secure. Vault exposed secrets with one click. Govern human, agent, and machine credentials in a single system. Apply controls to high-risk or shared accounts.
Audit. End-to-end visibility into credential access across human and non-human activity. Clear records of which credential was used, when, by which identity, and under whose authority.
Combined with Runlayer's existing RBAC, ABAC, and approval workflows, this gives enterprises a complete governance stack for agent credential access.
No more plaintext .env files
The shift from copilot to autonomous agent changes the security model fundamentally. Agents aren't just reading code or suggesting edits. They're executing workflows with real credentials against production systems.
1Password's Unified Access Pro is generally available today. Runlayer customers can integrate 1Password to securely inject credentials into every agent session Runlayer manages.
Give your agents secure superpowers.
Check out the 1Password announcement →



