Skip to Main Content
Back to blog

1Password + Kiro: Trusted Access for AI-Powered Development

by Dennis Kromhout van der Meer and Scott Lougheed

June 17, 2026 - 4 min

The header image displays the logos for Kiro and 1Password.

Related Categories

AI coding tools such as Kiro are becoming part of how software gets built. They set up projects, manage local environments, and help developers move from an idea to running code. The applications they build still need credentials to connect to APIs, databases, and other services. That creates a practical security problem as coding agents become part of the development lifecycle.

1Password Environments gives developers a secure way to manage those credentials. The 1Password Environments MCP Server extends that capability into Kiro, allowing the agent to help configure project environments without returning secret values, consistent with 1Password’s security model. The principle is simple: agents should help manage access without taking possession of secret value.

Developers can also use Kiro to identify hard-coded credentials and move them into 1Password as part of the development workflow.

A native path for secure project configuration in Kiro

Kiro is a software development agent, available in IDE, CLI, or web experiences, that brings engineering rigor to AI-native coding via spec-driven development and property-based testing. The 1Password Environments MCP Server is now built natively for Kiro, bringing 1Password’s secrets management capabilities into agentic development workflows. 

The integration connects Kiro directly to 1Password Environments through a local MCP server packaged in 1Password developer tools. It gives AI agents a structured way to help developers set up, understand, and manage project configuration while keeping sensitive values securely managed in 1Password. For security teams managing developers, this means supporting AI coding workflows without giving up control of credential management in 1Password.

A screenshot of a developer workflow from within Kiro, in which 1Password is being used to request access to an Inventory Tracker environment.

Here's what happens when a developer asks Kiro to support their workflows:

  1. Start a task in Kiro: For example, ask Kiro to create an app and configure the environment it needs.

  2. Kiro connects to the 1Password Environments MCP Server: The connection lets Kiro discover and invoke the available MCP tools.

  3. Kiro creates and manages the Environment: Kiro can create Environments, list and manage variable names, and prepare project configuration. The MCP server does not return secret values.

  4. Applications use secrets managed in 1Password: Developers can use Kiro to configure and troubleshoot application access while the required secrets remain managed in 1Password. Access remains governed through the 1Password desktop application, while centralized credential management stays intact.

Throughout the workflow, once sensitive values are stored in 1Password and rotated, they remain securely managed moving forward. The MCP server does not return secret values.

The same architecture, a broader surface

When we launched the 1Password Environments MCP Server natively for OpenAI Codex, we called it a proof point for a broader thesis that coding agents are the leading edge of AI agents joining the workforce, and they need real access, governed properly. Kiro is the second proof point, built on the same architecture and the same access model. As AI coding tools evolve, the model stays consistent. 1Password manages sensitive values while integrations help agents work with project configuration.

"Kiro is designed to help developers move from idea to production-ready software with AI assistance grounded in specifications and structured workflow. By bringing secure access to secrets and environment variables directly into Kiro, 1Password is helping developers confidently adopt AI-assisted workflows while keeping credentials secure and under their control."

--Mark Relph, Managing Director, Data & AI Partners at AWS

"Developers shouldn't have to choose between adopting AI-powered tools and strong security practices and neither should their agents. Every place software gets built is now a place an AI agent needs access. Our answer is the same everywhere: credentials stay protected in 1Password and are issued at runtime, scoped to the task, with nothing left in plaintext for a model to see. Kiro extends that model from Codex to another surface where developers actually work, and it's a preview of how we think all agent access will operate."

--Jeff Malnick, VP and GM for AI & Developer at 1Password

Part of a broader collaboration with AWS

This launch is part of a larger integration footprint across AWS. 1Password already secures access across AWS environments through Amazon Nova Act, the MCP Server for 1Password SaaS Manager, the AWS CLI shell plugin, and AWS Secrets Manager sync. Kiro extends that work into the developer’s agentic software development lifecycle.

How to get started

If you’re looking for a way to give AI agents and machine workloads access without creating standing credentials, the 1Password Unified Access Platform brings together Credential Broker and 1Password Privileged Access. Credential Broker authenticates requesters before delivering approved credentials, while Privileged Access governs just-in-time, just-enough access in destination systems.

Explore our Credential Broker public preview.