Start with Identity
← Blog
News

1Password buys Apono, moving from credential vault to access control plane

Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, and takes it into territory owned by PAM vendors.

By SWI Community TeamJun 15, 2026Updated Aug 1, 2026

1Password has acquired Apono, an Israeli company building just-in-time access governance for humans, machines, and AI agents. Terms were not disclosed; Calcalist reported 250 to 300 million dollars. All 80 Apono employees join, around 50 of them in Israel. Apono evaluates each access request against policy, grants temporary narrowly scoped permissions, and removes them when the task finishes, so there is no standing account or persistent privilege left behind. It integrates with AWS, Azure, Google Cloud, Kubernetes, Snowflake, and Databricks plus more than 200 enterprise tools, and lets users request access from the applications they already work in. The capability lands under 1Password Unified Access.

Why it matters

1Password has spent three years walking away from being a password manager, through Passage for passkeys and its secrets line. Apono is the biggest step: just-in-time access with zero standing privileges is the core of modern PAM, not an adjacency.

That puts 1Password in front of CyberArk, Delinea, and StrongDM with a very different go-to-market: bottom-up, developer-friendly, priced per seat rather than per vaulted account. For cloud-native teams who found traditional PAM too heavy, that is a real option and worth a look in our PAM buyer guide.

What it does not yet cover is the reason PAM deals get signed: session recording, break-glass for on-premises infrastructure, and the audit artefacts a regulator expects. Judge it on those before treating it as a replacement.

Source: 1Password, price via SecurityWeek

Independent analysis. No vendor sponsorship.