Password managers compared: which one fits how you live
Three questions decide this, and none of them is about features. Answer them here and get a straight recommendation, with the reasoning shown.
Some links on this page are commercial. If you buy through them we may earn a commission, at no extra cost to you. It never changes what we recommend or what we write — see our disclosure and editorial policy.
Every password manager will store your passwords. That part is solved, and it is why feature tables are so unhelpful here: they compare the part that no longer differs.
What still differs is what happens when you cannot get in — and which answer suits you depends less on the software than on two things about you: whether you will really keep a piece of paper safe, and whether you will really pay.
So we built the decision as a decision. The selector above asks the three questions that actually separate these products; the rest of this page explains why those are the three.
Why these three questions
They are not arbitrary. Each one maps to a real structural difference documented by the vendors themselves, covered in full in our guide on what happens when you lose access.
The paper question exists because 1Password derives your encryption key from two secrets: your password and a 34-character Secret Key generated on your device. 1Password states plainly that it has "no record of your Secret Key and can't recover it". That is excellent security and an unforgiving failure mode. If the Emergency Kit will end up in a downloads folder, this is not your tool.
The free question exists because Bitwarden's free tier is genuinely usable — but Emergency Access, the recovery feature most likely to save you, sits behind the paid plan. "Free Bitwarden" and "Bitwarden" are not the same product where it matters most.
The trusted-contact question exists because it is the only recovery path that does not depend on an object you have to keep. If there is someone, Bitwarden's model gets considerably stronger.
The short version, if you would rather just read it
| You are | Pick | The catch to know about |
|---|---|---|
| Willing to print and store a kit, and to pay | 1Password | Lose either half of the key and there is no recovery. None. |
| Wanting free, with someone to trust | Bitwarden | Emergency Access is a paid feature. Free plus no trusted contact means your only net is an export. |
| Unwilling to depend on paper | Proton Pass | Resetting by email returns the account with the vault still encrypted. Keep the 12-word phrase. |
| Would rather trust a phone than paper or a phrase | LastPass | Recovery needs a device you were already logged in on, set up in advance. Lose every device and there is nothing left to recover from. |
A fourth option, outside the three questions
LastPass answers "what happens when you cannot get in" differently from the other three, and differently enough that it does not fit the selector above. 1Password, Bitwarden and Proton Pass all recover through something you store: a printed kit, an export plus a trusted contact, a twelve-word phrase. LastPass recovers through something you already have logged in — a device, tied to email, SMS or biometrics, configured before you need it.
That is a real trade-off, not a lesser one. A phone you carry every day is harder to lose than a sheet of paper you filed away three years ago. But the artifact-based approach travels; the device-based one does not — wipe or lose every device you have ever authenticated from, and LastPass has nothing left to recover from either, same as the others.
LastPass also disclosed a significant security incident in 2022: an attacker exfiltrated a backup copy of customer vault data, including some fields that were not encrypted (such as website URLs) alongside fields that were. No plaintext password was exposed — the encryption held — but it is the most consequential incident among the four products compared here, and worth knowing before you choose.
What none of them save you from
Whichever you pick: export your vault today and store the file offline. Every failure described above ends well if you have an export and badly if you do not. It costs five minutes and makes the rest of this page academic.
How we reached this
Everything here comes from each vendor's own documentation, quoted rather than paraphrased, with sources listed in the full guide. The detailed breakdown of each option, including current pricing and the specification table, follows below.
Which one fits you
Three questions, one answer. Nothing is sent anywhere — this runs entirely in your browser.
Answer the questions above and the recommendation appears here, with the reasoning shown.
Side by side
| 1PasswordAgileBits | BitwardenBitwarden, Inc. | Proton PassProton AG | LastPassLastPass | |
|---|---|---|---|---|
| What derives the key | Password + Secret Key | Password only | Password, with key backup | Master password only |
| Artifact you must keep | Emergency Kit (PDF) | Export, plus a trusted contact | 12-word recovery phrase | A trusted device or phone number, set up in advance |
| Vendor can restore access | No | No | Account yes, data no | No |
| Trusted-person recovery | Family organiser | Emergency Access | — | Not offered |
| Free tier | No | Yes | Yes | Yes, limited to one device type |
| Worst realistic outcome | Total loss | Total loss — delete and start over | Account restored, vault lost | Total loss — no trusted device, phone or channel left |
| Price | Individual US$48.00/yr Family (up to 5) US$72.00/yr Checked 5 Aug 2026 | Free Free Premium US$10.00/yr Family (up to 6) US$40.00/yr Checked 5 Aug 2026 | Free Free Pass Plus US$23.88/yr Checked 5 Aug 2026 | — |
Who each one is for
1Password
People willing to print and store an Emergency Kit, and to pay for it.
Catch: Lose either half of the key and there is no recovery. None.
Bitwarden
People who want a real free tier and have someone to name as a trusted contact.
Catch: Emergency Access is a paid feature. Free, with no trusted contact, means your only net is an offline export.
Proton Pass
People unwilling to depend on a piece of paper staying safe for years.
Catch: Resetting by email returns the account with the vault still encrypted. Keep the twelve-word phrase.
LastPass
People who would rather rely on a phone they already carry than a printed kit or a memorised phrase.
Catch: Recovery needs a device you were already logged in on. Lose every device and there is nothing left to recover from.
Visit LastPass →1Password
Derives the encryption key from two secrets — your password and a 34-character Secret Key generated on your own device.
What works
- The Secret Key adds entropy no human memorises, which defends against a server breach in a way single-secret models do not.
- The vendor never held the Secret Key, so there is no copy to compel or leak.
- Family organiser can reset an individual member's account.
What to watch
- Lose either half and there is no recovery. The Secret Key does not rescue you from a forgotten password, and the password does not rescue you from a lost Secret Key.
- No free tier — a 14-day trial only.
- The Emergency Kit is handed to you at signup and is easy to treat as onboarding paperwork.
Bitwarden
Derives everything from the master password alone, which makes the model simpler to explain and simpler to lose.
What works
- The free tier is genuinely usable for storing and syncing passwords.
- Emergency Access lets a trusted contact take over, which is the only recovery path that does not depend on keeping an object safe.
- Open source, with a published account-recovery model.
What to watch
- Emergency Access — the recovery feature most likely to save you — is a paid feature. Free Bitwarden and Bitwarden are not the same product where it matters most.
- Administrator-driven account recovery is an organisation feature, not a personal one.
- The documented last resort is to delete the account and create a new one.
Proton Pass
Splits recovery into two outcomes that can happen separately — you can get the account back without getting the vault back.
What works
- The recovery phrase encrypts a backup copy of your key, so resetting with it keeps everything.
- Recovery does not depend on keeping a physical document safe.
- Free tier with unlimited logins and devices.
What to watch
- Resetting by email or SMS returns the account with the data still encrypted — you log in successfully and the vault is unreadable.
- The email reset behaves unlike email resets everywhere else on the internet, which is exactly what makes it a trap.
- The third path, activating a recovery file from a previously trusted device, requires having such a device to hand.
LastPass
Recovery runs through a device you already trust — email, SMS or biometrics — set up before you need it, not a portable artifact like a printed kit or a phrase.
What works
- Zero-knowledge architecture — LastPass states it has no record of your master password and cannot recover or reset it on your behalf.
- Three separate recovery channels if configured in advance: an email-triggered local recovery on a trusted device, SMS, or mobile biometrics.
- Free plan exists, with no trusted-contact or paid step required to enable basic account recovery.
What to watch
- Recovery depends on still holding a device you used before — not a portable artifact you can store somewhere safe. Lose every device you were ever logged in on and the built-in channels have nothing to recover from.
- The free plan restricts you to one device type (computers only, or mobile only), which is narrower than Bitwarden's free tier.
- Disclosed a significant 2022 security incident: an attacker exfiltrated a backup copy of customer vault data, including some unencrypted fields (such as website URLs) alongside the still-encrypted vault contents. No plaintext passwords were exposed, but it is the most consequential incident among the four products on this page.
What we compared, and why
- What happens on the day you cannot get in
- It is the only event where these products behave differently in kind rather than in degree, and it is the one you will experience once, badly, and possibly permanently.
- What you have to keep, and where
- Every recovery model depends on an artifact you had to store in advance. Whether that artifact is paper, a phrase or a person is the choice you are actually making.
- What the free tier excludes
- In this category the paywall tends to sit in front of recovery rather than in front of storage, so the free version and the paid version differ most where it matters most.
What we have not tested yet
Everything here comes from each vendor's own documentation, quoted rather than paraphrased, with sources listed in the full guide. We have not yet run each recovery flow end to end on a live account. When we do, this page gets updated and the change log will say what changed.
Questions
Do I actually need a password manager?
If you reuse passwords anywhere, yes, and the reason is not the strength of any individual password but the blast radius of a single breach. The choice between these three is a smaller decision than the choice to use one at all.
Which is safest?
All three are zero-knowledge, meaning the vendor never holds anything that can decrypt your vault. On cryptographic story alone 1Password is the strongest, because the Secret Key defends against a class of server-side attack the others do not. That is a different question from which is safest for you, which depends on whether you will keep the Emergency Kit.
What if I choose wrong and want to switch later?
All three export your vault, so switching is possible and not especially painful. That is another reason the recovery model matters more than the feature list: features you can change your mind about, a lost vault you cannot.