TL;DR: As coding agents move into developer workflows, teams are under pressure to stop copying secrets into files or keeping long-lived credentials in local environments; 1Password’s demo argues that runtime injection, read-only access, and per-environment targeting reduce risk while preserving speed. The governance shift is real because least privilege has to be enforced at execution time, not after the secret has already been exposed.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Demo On Demand Secure agentic development: Just-in-time secrets as the new default”.
Key questions
Q: How should security teams handle secrets for coding agents?
A: Security teams should move from static secret placement to runtime delivery, using just-in-time injection, narrow scoping, and task-specific access.
Q: When does just-in-time secrets management matter most in agentic development?
A: It matters most when agents need real credentials to call APIs, run code, or reach production-like systems, because those are the moments when durable secret storage creates the largest exposure window.
Practitioner guidance
- Use just-in-time secret issuance Deliver credentials only at execution time so coding agents never receive a reusable secret in a persistent location.
- Enforce read-only agent access Scope credentials so the agent can perform the task but cannot modify systems or expand access beyond the intended action.
- Target secrets by environment Issue different credentials for development, test, and production-like environments so a single secret cannot cross boundaries.
Bottom line: Coding agents force teams to treat secret delivery as a runtime control problem rather than a storage problem.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Just-in-time secrets are now a governance control, not a developer convenience. Coding agents require secrets at execution time, which means the traditional assumption that credentials can be safely staged ahead of use is already under pressure. The important shift is not tooling preference but control timing, because durable secret placement creates unnecessary exposure in agentic workflows. Practitioners should treat execution-time issuance as the control boundary for agent-assisted development.
A few things that frame the scale:
- Claude Code-assisted commits leaked secrets at a rate of 3.2%, more than double the human-only baseline of 1.5%, with peaks reaching 31 secrets per 1,000 commits in August 2025, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How do security teams keep agent speed and enterprise governance in the same workflow?
A: Build the policy into runtime access so the secure path is also the fastest one. If developers must choose between speed and protection, the process is already misaligned. The goal is to make short-lived, scoped access the default way agents obtain credentials.
👉 Read our full editorial: Just-in-time secrets for agentic development are now the default