1Password logo
Privacy Security · Security Fraud

1Password

1Password is an end-to-end encrypted password manager and identity security platform built by AgileBits in Toronto. It secures credentials for individuals, families and enterprises, and governs the access granted to employees, machines and AI agents.

Active GDPR compliant Free trial Subscription API available 16+ Verified by Guidaio
Overview

What is 1Password?

1Password is the password manager published by AgileBits Inc., a Toronto company founded in 2005 by Sara Teare and her co-founder, which has grown into a broader identity security platform. The core remains a vault protected by AES 256-bit end-to-end encryption and a two-key model: an account password the user chooses, plus a 128-bit Secret Key generated on the device. Two-Secret Key Derivation combines them, and the Secure Remote Password protocol means the password itself never travels to the server. Even when an organisation signs in through an identity provider, decryption happens locally on a trusted device and the provider never sees the keys.

Around that vault, the 2026 Unified Access platform assembles five products: Enterprise Password Manager, SaaS Manager, Credential Broker, Device Trust and Privileged Access. The AI angle sits in the last three. SaaS Manager surfaces the AI tools employees adopt without telling anyone, and breaks their cost down by team, user and model. Credential Broker verifies AI agents and machine workloads at execution time and releases only the credentials each task is entitled to. Privileged Access frames what an agent may do, checks intent against behaviour and revokes access when the two diverge. A unified audit log records who or what used which credential, when, and under whose authority.

For everyday use, Watchtower raises alerts on breaches and on weak or compromised passwords, and Travel Mode hides selected vaults when crossing a border. Developers get a CLI, SDKs, SSH key and Git commit signing, plus CI/CD, IDE and infrastructure-as-code integrations. Identity integrations cover Okta, Entra ID, Azure AD, OneLogin, Duo, Google Workspace, Rippling and JumpCloud; SIEM output goes to Datadog and Splunk; SaaS Manager, formerly the acquired product Trelica, claims 350 to 400 direct integrations depending on the page.

The company reports more than 200,000 business customers, over 30% of the Fortune 100, two thirds of the Forbes AI 50, 1,400 employees, 1.3 billion secured credentials and 400 million dollars of annual recurring revenue, along with a 2026 Gartner Magic Quadrant Leader position for SaaS Management Platforms. Security claims rest on SOC 2 Type 2, ISO 27001, 27017, 27018 and 27701 certifications, published third-party audits and a HackerOne bug bounty.

What it does

  • Store and autofill passwords, passkeys, one-time codes, payment cards, addresses and documents on every device
  • Generate strong passwords and disposable usernames on demand
  • Share items through shared vaults or expiring links, including with people who do not use 1Password
  • Flag breached, weak and reused credentials through Watchtower
  • Discover shadow IT and undeclared AI tools, and track what they cost
  • Issue credentials to AI agents and machine workloads at runtime, scoped to the task at hand
  • Grant just-in-time privileged access, revoke it automatically, and log every access with full attribution
Audience

When to use 1Password / When not to

A quick filter to help you decide if 1Password is the right fit.

When to use 1Password

  • Security and IT teams that must discover, secure and audit access across employees, machines and AI agents from one console, including the shadow AI their staff adopt unannounced
  • Developers and platform engineers who need secrets management, SSH key and Git commit signing, a command-line interface, SDKs and CI/CD integrations
  • Compliance and risk managers who have to produce evidence: SOC 2 Type 2, ISO 27001, 27017, 27018 and 27701, a signed DPA and a published subprocessor list
  • Small teams and managed service providers: the Teams Starter Pack covers ten members at a flat rate, and the MSP Edition bills on consumption with no minimum licence count
  • Families and individuals who want shared vaults, autofill on every device and breach alerts through Watchtower

When not to use 1Password

  • Anyone looking for a permanently free password manager: there is a 14-day trial and nothing beyond it, apart from the standalone password and username generators
  • Buyers who need public pricing for the whole catalogue, since only the Personal and Business plans carry a listed price while Unified Access, SaaS Manager, Privileged Access, Device Trust and Enterprise are quote-only
  • Organisations required to self-host their credential store: the vault sits with the vendor and the only choice offered is the hosting region
  • Users who cannot commit to safeguarding an Emergency Kit, because losing the account password together with the Secret Key makes the data unrecoverable, including for the vendor
  • Anyone expecting a generative AI assistant: 1Password secures, brokers and audits access, it does not write, summarise or produce content
Get started

How to use 1Password

A typical end-to-end flow, from setup to results.

  1. Pick a plan on the pricing page (Personal, Business, or a quote for the enterprise products) and start the 14-day trial
  2. Create the account on start.1password.com, where the hosting region is chosen: European Union, United States or Canada
  3. Save the Emergency Kit, since the account password and the Secret Key are the only means of decryption and nobody at 1Password can replace them
  4. Install the applications for macOS, Windows, Linux, iOS, Android and watchOS
  5. Add the browser extension for Chrome, Safari, Edge, Firefox or Brave so that credentials are captured and filled automatically
  6. Enrol each new device by scanning a QR code from one already trusted
  7. Import existing credentials from another manager using the guides on support.1password.com
  8. Organise items into vaults, then share them by vault or through an expiring link
  9. For a team rollout, connect the identity provider (Okta, Entra ID, Google Workspace and others) for single sign-on and SCIM provisioning; for development work, wire in the CLI, the SDKs, SSH and Git signing and the CI/CD integrations documented on 1password.dev
  10. Turn on Watchtower for compromise alerts, then run day-to-day administration from the console: role-based permissions, usage reports and audit logs
Quick read

Pros & Cons

Pros

  • Zero-knowledge architecture: the vendor states it has no way to decrypt a vault, and can hand authorities encrypted data only
  • The Secret Key sits alongside the account password, so a server-side breach on its own does not expose vault contents
  • The hosting region is chosen by the customer at account creation: European Union, United States or Canada
  • A complete compliance file: SOC 2 Type 2, ISO 27001, 27017, 27018 and 27701, published third-party audits, a HackerOne bug bounty, a downloadable DPA and a public subprocessor list
  • Device coverage is unusually complete, Linux, watchOS and a command-line interface included
  • Developer tooling that few competitors match: SDKs, SSH key and Git commit signing, CI/CD integrations
  • A single vendor covers human, machine and AI agent identities, with phone, chat, email and community support on Business plans and a 14-day trial on every plan

Cons

  • No permanently free plan, where several competitors offer one; the only free entry point is a 14-day trial
  • Public pricing stops at the Personal and Business plans, leaving Unified Access, SaaS Manager, Privileged Access, Device Trust and Enterprise quote-only
  • The headline rates of USD 2.99 and USD 4.49 apply to the first year only, for new customers on annual billing
  • Losing the Secret Key together with the account password makes the data unrecoverable: that is the design, but it leaves no safety net
  • No self-hosting option; the customer chooses the hosting region and nothing more
  • The catalogue now spans five products, and working out which one covers what takes real effort
  • No support email address is published, so requests go through a chatbot, a form or the community; no Article 27 EU representative is named; and the iOS application requires iOS 18 or iPadOS 18
Pricing

Pricing & Plans

1Password does not offer a permanently free plan. Every plan comes with a 14-day free trial, and two utilities remain free and require no account: the password generator and the username generator. The lowest paid entry point is the Individual plan at USD 3.99 per month on annual billing, that is USD 48 per year, reduced to USD 2.99 per month for the first year for new customers who commit annually. The Families plan covers five members at USD 5.99 per month, or USD 72 per year. The pricing pages quote amounts in US dollars, Canadian dollars or euros.

Individual - USD 3.99 per month on annual billing (USD 2.99 for the first year)
  • password generation
  • autofill
  • sharing
  • unlimited devices and breach alerts
Plan 3
Teams Starter Pack
  • USD 24.95 per month on annual billing
  • ten members included
  • with up to ten additional seats at the per-member rate
Business - USD 8.99 per user per month on annual billing
  • SSO with Okta
  • Entra ID
  • OneLogin and Duo
  • role-based vaults
  • Watchtower
  • and a Families plan offered to every user
Plan 5
Enterprise / Unified Access
  • quote only
  • through the sales team
Plan 6
Enterprise Password Manager
  • quote only
Plan 7
SaaS Manager
  • quote only
Plan 8
Privileged Access
  • quote only
Plan 9
Device Trust
  • quote only
Plan 10
Enterprise Password Manager MSP Edition
  • 14-day trial
  • consumption-based billing
  • no minimum licence count
Plan 11
  • Purchasing is also possible through AWS Marketplace
Special offers — Students: discount available through Student Beans · Non-profit organisations and charities: dedicated programme on the vendor's non-profit page · Journalists: dedicated programme on the vendor's journalism page · Volume pricing for larger organisations, on request from the sales team · New customers on annual billing: 25% off the first year · Every user on a Business account receives a Families plan at no extra cost · Managed service providers: consumption-based billing with no minimum licence count
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how 1Password handles your data.

GDPR overview

Implementation is concrete rather than declarative. The privacy notice in force since 29 December 2025 sets out lawful bases for the EEA, the United Kingdom and Switzerland (contract performance, legitimate interest, consent and legal obligation) and details rights of access, rectification, portability, erasure, objection, restriction, withdrawal of consent and complaint. A data protection officer answers at privacy@1password.com, with a postal Privacy Office in Toronto. Clause 10.1 of the terms binds both parties to Regulation (EU) 2016/679, Directive 2002/58/EC, the CCPA and, where applicable, HIPAA. A DPA is downloadable and signed on request; the subprocessor list is published. Transfers rely on adequacy decisions, EU and UK standard contractual clauses and, where relevant, binding corporate rules, and ISO 27701 certification is claimed. One gap: no Article 27 EU representative is named anywhere on the site.

Who owns the data?

The terms of service state that the customer keeps every right over their data; AgileBits receives only a licence to store, retrieve, back up, restore and copy it so that the service can be delivered. Vault contents, which 1Password calls Secure Data, are encrypted with keys held solely by the account holder or the account administrators, and the vendor states that it never receives a readable copy and cannot decrypt one, including when responding to a lawful demand. In a business deployment the subscribing organisation is the controller of Customer Data and 1Password acts as processor. After termination, data may be kept thirty days for retrieval, then longer only where the law requires it.

Reuse rights

Users add, edit and delete their vault entries at will, and may export a full copy of their Secure Data from the account without asking permission: the vendor states plainly that it will not lock customers out of their own data. Because it cannot decrypt anything, that export depends on the account password and the Secret Key being to hand. Sharing is equally under the user's control, through shared vaults, expiring links, recipients who have no 1Password account, item history and expiry dates, and imports from other managers such as LastPass or Apple Passwords are documented. What remains on the vendor's side is the surrounding telemetry: service and diagnostic data are processed on a legitimate-interest basis, including to develop and train new technology, with a right to object; product usage information is collected only with permission, and that consent can be withdrawn.

Data retention & training

Retention summary
Personal information is kept for as long as the purposes set out in the privacy notice require, unless a longer period is required or permitted by law, or the user asks for deletion. Beyond that, data is de-identified, aggregated or masked for long-term analytics. Deletion is a two-step process: delete the account from an authenticated session, then request expungement; the vendor removes the data from active systems once it has authenticated the request. Copies of modified or deleted data may persist for a time in the systems and in commercial archives, and versions may remain under the retention policy or until they are overwritten. For business contracts, customer data may be kept for thirty days after termination so it can be retrieved, and longer only where the law requires. No figure is published for service or diagnostic data.
Trains on customer data
Unclear
Training opt-out available
Yes
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

AgileBits Inc., based in Toronto, is the controller, which places the vendor under Canadian jurisdiction. Vault contents follow the region chosen by the customer when the account is created: European Union, United States or Canada, with dedicated regional sites at 1password.com, 1password.eu and 1password.ca. One exception is documented: items shared through Item Sharing are stored in the EU for as long as the share remains active. Service data, diagnostic data and other information may be accessed, processed or transferred outside the user's country of residence, and staff reach them from several countries; customer support and email services are hosted mainly in the United States and Canada. Transfers rely on European Commission adequacy decisions, EU and UK standard contractual clauses, binding corporate rules where relevant, and periodic risk assessments. The subprocessor list is published as a PDF in the Legal Center. A technical note for anyone checking: the domain resolves to 172.66.1.143, a Cloudflare anycast node, which says nothing about where data is stored.

Hosting countries
🇨🇦 Canada🇺🇸 United States
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting 1Password.

  • Single point of failure: every credential lives in one vault, and access to it hangs on an account password and a Secret Key
  • Lose both and the data is gone for good, since the vendor is unable to help by design; the printed Emergency Kit is itself a sensitive document that needs physical protection
  • Concentrating personal and professional access with a single vendor creates a dependency that is hard to unwind
  • The zero-knowledge promise rests on third-party audits and a white paper, not on source code the user can read and verify
  • Targeted phishing remains the most likely attack: a convincing fake unlock screen defeats good cryptography
  • Service and diagnostic data are processed on a legitimate-interest basis, including to develop and train new technology, and objecting is a right the user has to exercise personally
  • An expiring share link sent to the wrong person exposes the item until it expires; on business accounts, administrators see usage metadata such as item counts, sign-ins and devices, private vaults included; and automating access for AI agents shifts the risk onto the quality of the written policies
Setup

Setup & Integrations

Technical difficulty

Personal use requires no technical skill: create an account, install the application and the browser extension, add a device by scanning a QR code, and run the assisted import from another manager. The one demanding step is not technical: keeping the Emergency Kit, account password plus Secret Key, somewhere safe. Enterprise deployment is an IT project, with identity provider integration for SSO and SCIM provisioning, vault and role design, and a separately licensed SCIM bridge. Developer use, from the CLI and SDKs to SSH and Git signing and CI/CD, sits at engineer level. Personalised onboarding is included above 100 users.

Deployment

Web appMobile appBrowser extensionDesktop appAPIChrome extensionIOS appAndroid app

Apps stores

Integrations

Okta Entra ID Azure AD OneLogin Duo Google Workspace Rippling JumpCloud Datadog Splunk AWS Marketplace

Supported languages

EnglishGermanSpanishFrenchItalianJapaneseKoreanPortugueseChinese (Simplified)Chinese (Traditional)
Company

Behind 1Password

Company name
AgileBits Inc.
Founded
24/09/2001
Country of origin
🇨🇦 Canada
Headquarters
4711 Yonge Street, 10th Floor, Toronto, Ontario, M2N 6K8, Canada
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇨🇦 Canada

Fundraising

Bootstrapped and profitable for fourteen years before the first outside round in 2019
Series A - USD 200 million in 2019, led by Accel
Series B - USD 100 million in July 2021, at a USD 2 billion valuation
Series C - USD 620 million announced on 19 January 2022 at a USD 6.8 billion valuation, led by ICONIQ Growth with Tiger Global, Lightspeed Venture Partners, Accel, Salesforce Ventures and Backbone Angels
Board members listed by the company: Arun Mathew (Accel), Will Griffith (ICONIQ), founder Sara Teare and executive chair Jeff Shiner
The company reports USD 400 million of annual recurring revenue in 2026

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement 1Password.

L LastPassB BitwardenK KeeperD DashlaneN NordPassR RoboFormE EnpassK KeePassY YubiKeyA Apple Passwords
FAQ

Frequently asked questions

Is there a free plan?
No. 1Password is subscription-only, with a 14-day free trial on every plan. Two tools stay free and need no account at all: the password generator and the username generator.
How much does the cheapest plan cost?
The Individual plan is USD 3.99 per month on annual billing, or USD 48 a year. Families covers five people for USD 72 a year. New customers who commit annually pay a reduced rate for the first year.
Can 1Password read my passwords?
No. Vault contents are end-to-end encrypted with keys the vendor says it never holds, and it states that it cannot decrypt them. Where authorities compel disclosure, only encrypted data can be handed over.
Where is my data hosted?
In the region chosen when the account is created: the European Union, the United States or Canada. One exception applies, since items shared through Item Sharing are stored in the EU for as long as the share stays live.
What happens if I lose my account password?
Recovery relies on the Emergency Kit, which holds the account password and the Secret Key. On a Families plan, a plan administrator can assist with recovery. Without either, nobody can decrypt the data, 1Password included.
Which security certifications does 1Password hold?
SOC 2 Type 2 and ISO 27001, 27017, 27018 and 27701. Third-party security audits are published, and a bug bounty programme runs on HackerOne.
Are a DPA and a subprocessor list available?
Yes. Both are published as PDF documents in the Legal Center, and a signed copy of the DPA can be requested from the sales team.
Which devices are supported?
macOS, Windows, Linux, iOS, iPadOS, Android and watchOS, together with browser extensions for Chrome, Safari, Edge, Firefox and Brave, and a command-line interface.
What does 1Password bring to AI agents?
Three things. SaaS Manager discovers shadow AI and what it costs, Credential Broker issues credentials to agents at runtime scoped to the task, and Privileged Access grants just-in-time rights with guardrails and revocation when behaviour drifts from intent.
Are there discounts, and how can I pay?
Discounts exist for non-profits, journalists and students through Student Beans, with volume pricing on request. Payment is by ACH debit from US bank accounts, by Visa, Mastercard, American Express, Discover, Diners Club, UnionPay or JCB, or with a 1Password gift card.
Conclusion

Should you pick 1Password?

1Password started in 2005 as a password manager and has since become an identity security platform, without abandoning the original product. Its balance point is easy to describe: the cryptography is solid and independently examined, with a two-key model, end-to-end encryption, published third-party audits, SOC 2 Type 2 and ISO 27001, 27017, 27018 and 27701 certifications, a downloadable DPA, a public subprocessor list and a hosting region the customer picks between the EU, the United States and Canada, while the commercial side is far less open: no permanently free plan, and no public price beyond the Personal and Business tiers.

For an AI directory, the interesting part is the agent angle. SaaS Manager exposes the AI tools that appear inside an organisation without anyone approving them, along with what they cost. Credential Broker hands credentials to agents and machine workloads at runtime, scoped to the task rather than granted permanently. Privileged Access sets what an agent may do and withdraws the right when behaviour drifts from stated intent.

Three reservations are worth carrying into a purchasing decision. No Article 27 EU representative is named anywhere on the site, which matters to European buyers. No support email address is published, so every request goes through a chatbot, a form or the community. And the position on model training deserves a direct question to the vendor: vault contents are encrypted and out of reach, but the privacy notice states that contact, service and diagnostic data are processed on a legitimate-interest basis to develop and train new technology, with a right to object that the user has to exercise personally.