1Password Review: Features, Pricing, and Who It Suits

Password Review

1Password is the password manager people recommend when they do not know what you need. That is mostly deserved — it is the most polished product in the category — but it also has two characteristics that make it wrong for a meaningful number of buyers.

There is no free tier, and there is no self-hosting. If either is a requirement, stop reading and look elsewhere. If neither is, this is probably the best product available.

This review is based on 1Password’s documented features and published security architecture rather than on independent testing, and it says so plainly where that matters.

What Makes It Architecturally Different

Most password managers encrypt your vault with a key derived from your master password. If an attacker steals the encrypted vaults from the vendor’s servers, the only thing standing between them and your data is how good your master password was.

1Password adds a second factor to the encryption itself: the Secret Key. This is a 128-bit key generated on your device during setup, never transmitted to 1Password, and combined with your master password to derive the encryption key.

The practical consequence is significant. A server-side breach does not give an attacker something they can brute-force offline, because they are missing a high-entropy key that never existed on 1Password’s infrastructure. Authentication also uses SRP, so the master password itself is never sent over the network even during login.

This is a genuine design advantage, and few competitors replicate it. It is the strongest argument for the product.

The trade-off: you must keep the Secret Key. Lose both it and your signed-in devices, and 1Password cannot recover your vault. That is the correct behaviour for a zero-knowledge system, and it catches people out.

Core Features

Vault organisation

Items are organised into vaults, which can be personal or shared. Shared vaults are how families and teams distribute credentials without messaging them around, and the permission model on business plans is granular enough to be useful.

The item types go well beyond logins: secure notes, credit cards, identities, software licences, SSH keys, API credentials, documents.

Watchtower

Monitors your vault for reused passwords, weak passwords, credentials appearing in known breaches, sites that support two-factor you have not enabled, and expiring items. It surfaces this as a prioritised list rather than a wall of warnings, which is why people act on it.

This is the feature most likely to materially improve your security in the first week.

Travel Mode

Temporarily removes vaults you have not marked as travel-safe from your devices, so a border inspection cannot reveal them. Genuinely useful for journalists, lawyers and anyone crossing borders with sensitive client data; irrelevant for most people.

Passkey support

1Password supports storing and using passkeys, and was early to it. As more services adopt passkeys, having them in the same vault as your passwords rather than locked to one device ecosystem is a real convenience.

Integrations for developers

The CLI, SSH agent and secrets-injection tooling are unusually good, and a genuine reason engineering teams pick 1Password over cheaper options.

Apps and Usability

This is where 1Password separates from the field. The desktop and mobile apps are fast, coherent and pleasant, browser autofill is reliable, and setup is guided well enough that non-technical family members manage it.

That matters more than it sounds. A password manager only works if people use it. The most secure product that your team abandons after a month provides nothing.

Pricing

1Password is subscription-only across individual, family, and business tiers. It moved away from one-time licences years ago and has not returned, which remains a live objection for some long-time users.

There is a free trial but no permanently free tier — a meaningful gap given that Bitwarden’s free tier covers unlimited passwords on unlimited devices.

Pricing changes periodically and varies by region and plan, so verify current pricing on 1Password’s own page rather than relying on figures quoted in reviews.

What It Does Not Do

Being direct about the limits:

  • No free tier. Trial only.
  • No self-hosting. Your encrypted vault lives on 1Password’s infrastructure. The encryption model means they cannot read it, but if hosting your own data is a policy requirement, this is disqualifying.
  • Not open source. The clients are not open for public audit. 1Password publishes a detailed security white paper and commissions external audits, which is a reasonable substitute, but it is not the same as source availability.
  • No one-time purchase. Subscription or nothing.

Who It Suits

Families. The shared vault model and the quality of the apps make it the one non-technical relatives will actually adopt.

Small businesses without dedicated IT. Straightforward admin, good onboarding, sensible defaults.

Development teams. The CLI, SSH agent and secrets tooling are best-in-class.

Anyone crossing borders with sensitive data. Travel Mode has no real equivalent elsewhere.

Who Should Look Elsewhere

Anyone who needs free. Bitwarden, and it is not a compromise.

Anyone who must self-host. Bitwarden’s self-hosted server or Vaultwarden.

Anyone who objects to subscriptions. Enpass still offers a one-time purchase.

Anyone who requires open-source clients. Bitwarden or KeePassXC.

Common Mistakes to Avoid

  • Not saving the Emergency Kit. It contains your Secret Key. Print it, store it somewhere physical and safe. Without it and without a signed-in device, your vault is unrecoverable — by design, and 1Password cannot help.
  • Storing the Emergency Kit in the vault. People genuinely do this. If you are locked out, you cannot open the thing containing the key to open it.
  • Reusing your master password anywhere. It is the one credential not protected by the vault.
  • Ignoring Watchtower after week one. It keeps finding things. Check it monthly.
  • Not adding a family recovery contact. On family plans, an organiser can help recover an account. A one-person account has no such path.
  • Assuming Travel Mode hides everything. It removes vaults not marked travel-safe. Verify what remains before you travel, not after.

FAQs

Is 1Password worth paying for when Bitwarden is free?

It depends what you value. Bitwarden’s free tier is genuinely capable and open source. 1Password gives you the Secret Key architecture, better apps, Watchtower and Travel Mode. If polish and adoption across a family or team matter, the subscription is defensible. If not, Bitwarden is not a downgrade in security terms.

What happens if I lose my Secret Key?

If you also lose access to every device already signed in, your vault cannot be recovered — not by you and not by 1Password. This is a consequence of the zero-knowledge design. Save the Emergency Kit somewhere physical.

Has 1Password ever been breached?

1Password disclosed a security incident in 2023 affecting an internal system, and reported that customer vault data was not compromised. The Secret Key architecture is specifically designed so that a server-side compromise does not expose vault contents. Check their published incident reports for current detail.

Can I use 1Password for free?

No. There is a trial, but no permanently free tier. If free is a requirement, Bitwarden is the standard recommendation.

Does 1Password support passkeys?

Yes, for both storing and using them, and it was an early adopter. Keeping passkeys in a cross-platform vault avoids being locked into a single device ecosystem.

Is 1Password good for businesses?

Yes, particularly small businesses without dedicated IT and development teams that will use the CLI and secrets tooling. Organisations with heavy compliance reporting requirements may find Keeper’s admin controls a better fit.

Verdict

1Password is the best-executed password manager available, and the Secret Key architecture is a real security advantage rather than marketing. The apps are good enough that people who resist password managers will actually use it, which is the property that determines whether one works at all.

The two hard limits are the absence of a free tier and the absence of self-hosting. Neither is a flaw so much as a product decision, but both disqualify it for specific buyers.

If you can pay and do not need to self-host, this is the one to beat.

Key Takeaways

  • The Secret Key means a server breach cannot expose your vault to offline brute-forcing.
  • Save the Emergency Kit physically. Lose it and your devices, and nothing recovers the vault.
  • Watchtower is the feature most likely to improve your security immediately.
  • No free tier, no self-hosting, no one-time licence, not open source.
  • App quality drives adoption, and adoption is what makes a password manager work.

If any of those limits rule it out for you, our guide to the best 1Password alternatives covers what to use instead and how to migrate without leaving a plaintext copy of every credential on your desktop.