People leave 1Password for three reasons, and knowing which one is yours narrows the field immediately.
Some want a free option, because 1Password has no free tier. Some want to self-host, because 1Password is cloud-only by design. And some left when 1Password moved from a one-time licence to subscription-only and never made peace with it.
Each of those points at a different replacement. Below are the alternatives worth considering, what each genuinely does better, and what you give up.
First, What You Are Actually Replacing
1Password is a strong product, and it is worth being clear about what you lose when you leave.
Its Secret Key architecture is unusual: your vault is encrypted with both your master password and a 128-bit key generated on your device and never sent to the server. That means a breach of 1Password’s servers does not expose vaults to brute-forcing the way a password-only design would. Few competitors match this specific design.
You also lose Watchtower (breach and weak-password monitoring), Travel Mode, and what is generally considered the most polished apps in the category.
If none of those matter to you, the alternatives below are genuinely competitive.
The Alternatives Worth Considering
Bitwarden — the default recommendation
The one most people should try first. Bitwarden is open source, and its free tier is genuinely usable rather than a crippled trial: unlimited passwords across unlimited devices, which is more than most paid competitors’ entry tiers.
Its documented feature set covers all major platforms, browser extensions, secure sharing on paid tiers, and — importantly — the option to self-host the server, either the official server or the lighter community-built Vaultwarden.
Bitwarden commissions regular third-party security audits and publishes them, which is meaningful for a product whose entire value is trust.
Choose it if: you want free, open source, self-hosting, or all three. Give up: some interface polish. Bitwarden’s apps are functional rather than delightful.
Proton Pass — best if you already use Proton
Part of the Proton ecosystem alongside Proton Mail and Proton VPN, with a free tier and Swiss jurisdiction. Documented features include hide-my-email aliases, which are genuinely useful for reducing spam and limiting breach exposure.
Choose it if: you already pay for Proton, or email aliasing appeals. Give up: maturity — it is the newest product here.
Dashlane — closest on polish
The alternative that feels most like 1Password in terms of interface quality. Documented features include a built-in VPN on some plans and dark web monitoring.
Choose it if: polish matters and you do not need free or self-hosting. Give up: Dashlane discontinued its standalone desktop apps in favour of a browser-based experience, which some users dislike.
Keeper — strongest for compliance
Aimed at business and enterprise, with documented compliance certifications, granular admin controls, and detailed audit reporting.
Choose it if: you have compliance obligations or need fine-grained admin control. Give up: simplicity, and add-ons are priced separately.
NordPass — simple and cheap
From the Nord family. Uses XChaCha20 encryption, has a free tier, and is straightforward.
Choose it if: you want cheap and simple, or already buy NordVPN. Give up: the free tier historically limited active devices — check current terms.
KeePassXC — no cloud at all
Fully local, open source, free. Your vault is a file. You control where it lives; sync it yourself with Dropbox, Syncthing or nothing.
Choose it if: you want zero cloud dependency and full control. Give up: convenience entirely. No managed sync, no easy family sharing, mobile requires third-party apps. This suits technical users and nobody else.
Enpass — one-time payment
The closest thing to the old 1Password licensing model. Enpass offers a one-time purchase option and stores your vault in your own cloud storage rather than the vendor’s.
Choose it if: subscription is the specific thing you object to. Give up: vendor-managed sync reliability, since sync is your storage provider’s job.
How They Compare
| Product | Free tier | Self-host | Open source | Best for |
|---|---|---|---|---|
| Bitwarden | Yes, generous | Yes | Yes | Most people |
| Proton Pass | Yes | No | Yes | Proton users, aliasing |
| Dashlane | Limited | No | No | Interface polish |
| Keeper | Limited | No | No | Compliance, admin control |
| NordPass | Yes, limited | No | Partially | Simplicity, low cost |
| KeePassXC | Free entirely | N/A, local | Yes | Full local control |
| Enpass | Limited | Your cloud | No | Avoiding subscriptions |
Pricing in this category changes frequently and varies by individual, family and business tiers. Verify current pricing on each vendor’s page before deciding.
How to Actually Switch
Migration is more straightforward than people expect, and the risky part is not the import.
1. Export from 1Password. It supports exporting to a portable format from the desktop app.
2. Import into the new manager. Every product here has a documented 1Password importer.
3. Verify before deleting anything. Check that logins, secure notes, credit cards and TOTP codes all came across. Attachments and some custom field types are the usual casualties.
4. Re-enrol your two-factor codes if TOTP did not migrate cleanly. Do this before you lose access to 1Password.
5. Securely delete the export file. This is the step people skip. Your export is an unencrypted plaintext file containing every credential you own. Do not leave it in Downloads.
6. Keep the 1Password subscription for a fortnight as a fallback, then cancel.
Common Mistakes to Avoid
- Leaving the plaintext export on disk. The single most dangerous moment in any password manager migration is the hour your entire vault exists as an unencrypted file.
- Assuming TOTP codes migrated. They often do not transfer cleanly. Verify each one before cancelling your old account.
- Choosing self-hosting without a backup plan. Self-hosting means you own recovery. If your server dies and you have no backup, the vault is gone.
- Picking free without checking device limits. Several free tiers restrict active devices. Bitwarden’s does not, which is why it is the usual recommendation.
- Switching for cost alone. The annual difference is typically small. Switch for a capability you actually need.
- Forgetting shared vaults. If family or team members share credentials, migrate and re-verify their access too, not just your own.
FAQs
What is the best free alternative to 1Password?
Bitwarden. Its free tier covers unlimited passwords on unlimited devices, which is more generous than most paid entry tiers elsewhere. It is also open source and independently audited.
Is 1Password worth paying for?
For many people, yes. The Secret Key architecture is a genuine security advantage, and the apps are the most polished in the category. The honest question is whether you need those things more than you need free or self-hosting.
Can I self-host a password manager?
Yes, with Bitwarden’s self-hosted server or the lighter community Vaultwarden. Understand that you then own backups, updates and uptime. If you lose the server and have no backup, you lose the vault.
Is it safe to switch password managers?
Yes, if you handle the export carefully. The export is unencrypted plaintext containing everything. Import it, verify it, then securely delete it — and do not put it in cloud-synced folders in the meantime.
Will my two-factor codes transfer?
Sometimes, and not reliably. TOTP secrets are the most common migration casualty. Check every one before you cancel your old subscription, and be ready to re-enrol from each service.
Does 1Password still offer a one-time licence?
No. 1Password moved to a subscription model, which is precisely why Enpass — which retains a one-time purchase option — appears on lists like this one.
Key Takeaways
- Identify your reason for leaving first: free, self-hosting, or subscription objection. Each points somewhere different.
- Bitwarden is the right first try for most people — free, open source, self-hostable, audited.
- 1Password’s Secret Key design is a real advantage you are giving up. Know that going in.
- The dangerous moment in migration is the plaintext export file. Delete it securely.
- Verify TOTP codes before cancelling anything.
Where to Start
Install Bitwarden’s free tier alongside 1Password and import a copy of your vault. Live with both for a week. If you do not miss anything, cancel — and if you do, you have lost nothing but an evening.
For the other side of this decision, our 1Password review covers what it does well in detail, and our antivirus guide covers the adjacent layer most small businesses get wrong.
