1Password
1Password is an end-to-end encrypted password manager and identity security platform built by AgileBits in Toronto. It secures credentials for individuals, families and enterprises, and governs the access granted to employees, machines and AI agents.
What is 1Password?
1Password is the password manager published by AgileBits Inc., a Toronto company founded in 2005 by Sara Teare and her co-founder, which has grown into a broader identity security platform. The core remains a vault protected by AES 256-bit end-to-end encryption and a two-key model: an account password the user chooses, plus a 128-bit Secret Key generated on the device. Two-Secret Key Derivation combines them, and the Secure Remote Password protocol means the password itself never travels to the server. Even when an organisation signs in through an identity provider, decryption happens locally on a trusted device and the provider never sees the keys.
Around that vault, the 2026 Unified Access platform assembles five products: Enterprise Password Manager, SaaS Manager, Credential Broker, Device Trust and Privileged Access. The AI angle sits in the last three. SaaS Manager surfaces the AI tools employees adopt without telling anyone, and breaks their cost down by team, user and model. Credential Broker verifies AI agents and machine workloads at execution time and releases only the credentials each task is entitled to. Privileged Access frames what an agent may do, checks intent against behaviour and revokes access when the two diverge. A unified audit log records who or what used which credential, when, and under whose authority.
For everyday use, Watchtower raises alerts on breaches and on weak or compromised passwords, and Travel Mode hides selected vaults when crossing a border. Developers get a CLI, SDKs, SSH key and Git commit signing, plus CI/CD, IDE and infrastructure-as-code integrations. Identity integrations cover Okta, Entra ID, Azure AD, OneLogin, Duo, Google Workspace, Rippling and JumpCloud; SIEM output goes to Datadog and Splunk; SaaS Manager, formerly the acquired product Trelica, claims 350 to 400 direct integrations depending on the page.
The company reports more than 200,000 business customers, over 30% of the Fortune 100, two thirds of the Forbes AI 50, 1,400 employees, 1.3 billion secured credentials and 400 million dollars of annual recurring revenue, along with a 2026 Gartner Magic Quadrant Leader position for SaaS Management Platforms. Security claims rest on SOC 2 Type 2, ISO 27001, 27017, 27018 and 27701 certifications, published third-party audits and a HackerOne bug bounty.
What it does
- Store and autofill passwords, passkeys, one-time codes, payment cards, addresses and documents on every device
- Generate strong passwords and disposable usernames on demand
- Share items through shared vaults or expiring links, including with people who do not use 1Password
- Flag breached, weak and reused credentials through Watchtower
- Discover shadow IT and undeclared AI tools, and track what they cost
- Issue credentials to AI agents and machine workloads at runtime, scoped to the task at hand
- Grant just-in-time privileged access, revoke it automatically, and log every access with full attribution
When to use 1Password / When not to
A quick filter to help you decide if 1Password is the right fit.
When to use 1Password
- Security and IT teams that must discover, secure and audit access across employees, machines and AI agents from one console, including the shadow AI their staff adopt unannounced
- Developers and platform engineers who need secrets management, SSH key and Git commit signing, a command-line interface, SDKs and CI/CD integrations
- Compliance and risk managers who have to produce evidence: SOC 2 Type 2, ISO 27001, 27017, 27018 and 27701, a signed DPA and a published subprocessor list
- Small teams and managed service providers: the Teams Starter Pack covers ten members at a flat rate, and the MSP Edition bills on consumption with no minimum licence count
- Families and individuals who want shared vaults, autofill on every device and breach alerts through Watchtower
When not to use 1Password
- Anyone looking for a permanently free password manager: there is a 14-day trial and nothing beyond it, apart from the standalone password and username generators
- Buyers who need public pricing for the whole catalogue, since only the Personal and Business plans carry a listed price while Unified Access, SaaS Manager, Privileged Access, Device Trust and Enterprise are quote-only
- Organisations required to self-host their credential store: the vault sits with the vendor and the only choice offered is the hosting region
- Users who cannot commit to safeguarding an Emergency Kit, because losing the account password together with the Secret Key makes the data unrecoverable, including for the vendor
- Anyone expecting a generative AI assistant: 1Password secures, brokers and audits access, it does not write, summarise or produce content
How to use 1Password
A typical end-to-end flow, from setup to results.
- Pick a plan on the pricing page (Personal, Business, or a quote for the enterprise products) and start the 14-day trial
- Create the account on start.1password.com, where the hosting region is chosen: European Union, United States or Canada
- Save the Emergency Kit, since the account password and the Secret Key are the only means of decryption and nobody at 1Password can replace them
- Install the applications for macOS, Windows, Linux, iOS, Android and watchOS
- Add the browser extension for Chrome, Safari, Edge, Firefox or Brave so that credentials are captured and filled automatically
- Enrol each new device by scanning a QR code from one already trusted
- Import existing credentials from another manager using the guides on support.1password.com
- Organise items into vaults, then share them by vault or through an expiring link
- For a team rollout, connect the identity provider (Okta, Entra ID, Google Workspace and others) for single sign-on and SCIM provisioning; for development work, wire in the CLI, the SDKs, SSH and Git signing and the CI/CD integrations documented on 1password.dev
- Turn on Watchtower for compromise alerts, then run day-to-day administration from the console: role-based permissions, usage reports and audit logs
Pros & Cons
Pros
- Zero-knowledge architecture: the vendor states it has no way to decrypt a vault, and can hand authorities encrypted data only
- The Secret Key sits alongside the account password, so a server-side breach on its own does not expose vault contents
- The hosting region is chosen by the customer at account creation: European Union, United States or Canada
- A complete compliance file: SOC 2 Type 2, ISO 27001, 27017, 27018 and 27701, published third-party audits, a HackerOne bug bounty, a downloadable DPA and a public subprocessor list
- Device coverage is unusually complete, Linux, watchOS and a command-line interface included
- Developer tooling that few competitors match: SDKs, SSH key and Git commit signing, CI/CD integrations
- A single vendor covers human, machine and AI agent identities, with phone, chat, email and community support on Business plans and a 14-day trial on every plan
Cons
- No permanently free plan, where several competitors offer one; the only free entry point is a 14-day trial
- Public pricing stops at the Personal and Business plans, leaving Unified Access, SaaS Manager, Privileged Access, Device Trust and Enterprise quote-only
- The headline rates of USD 2.99 and USD 4.49 apply to the first year only, for new customers on annual billing
- Losing the Secret Key together with the account password makes the data unrecoverable: that is the design, but it leaves no safety net
- No self-hosting option; the customer chooses the hosting region and nothing more
- The catalogue now spans five products, and working out which one covers what takes real effort
- No support email address is published, so requests go through a chatbot, a form or the community; no Article 27 EU representative is named; and the iOS application requires iOS 18 or iPadOS 18
Pricing & Plans
1Password does not offer a permanently free plan. Every plan comes with a 14-day free trial, and two utilities remain free and require no account: the password generator and the username generator. The lowest paid entry point is the Individual plan at USD 3.99 per month on annual billing, that is USD 48 per year, reduced to USD 2.99 per month for the first year for new customers who commit annually. The Families plan covers five members at USD 5.99 per month, or USD 72 per year. The pricing pages quote amounts in US dollars, Canadian dollars or euros.
- password generation
- autofill
- sharing
- unlimited devices and breach alerts
- up to five members
- unlimited shared vaults and administrative controls
- USD 24.95 per month on annual billing
- ten members included
- with up to ten additional seats at the per-member rate
- SSO with Okta
- Entra ID
- OneLogin and Duo
- role-based vaults
- Watchtower
- and a Families plan offered to every user
- quote only
- through the sales team
- quote only
- quote only
- quote only
- quote only
- 14-day trial
- consumption-based billing
- no minimum licence count
- Purchasing is also possible through AWS Marketplace
Data, GDPR & hosting
A consolidated view of how 1Password handles your data.
GDPR overview
Implementation is concrete rather than declarative. The privacy notice in force since 29 December 2025 sets out lawful bases for the EEA, the United Kingdom and Switzerland (contract performance, legitimate interest, consent and legal obligation) and details rights of access, rectification, portability, erasure, objection, restriction, withdrawal of consent and complaint. A data protection officer answers at privacy@1password.com, with a postal Privacy Office in Toronto. Clause 10.1 of the terms binds both parties to Regulation (EU) 2016/679, Directive 2002/58/EC, the CCPA and, where applicable, HIPAA. A DPA is downloadable and signed on request; the subprocessor list is published. Transfers rely on adequacy decisions, EU and UK standard contractual clauses and, where relevant, binding corporate rules, and ISO 27701 certification is claimed. One gap: no Article 27 EU representative is named anywhere on the site.
Who owns the data?
The terms of service state that the customer keeps every right over their data; AgileBits receives only a licence to store, retrieve, back up, restore and copy it so that the service can be delivered. Vault contents, which 1Password calls Secure Data, are encrypted with keys held solely by the account holder or the account administrators, and the vendor states that it never receives a readable copy and cannot decrypt one, including when responding to a lawful demand. In a business deployment the subscribing organisation is the controller of Customer Data and 1Password acts as processor. After termination, data may be kept thirty days for retrieval, then longer only where the law requires it.
Reuse rights
Users add, edit and delete their vault entries at will, and may export a full copy of their Secure Data from the account without asking permission: the vendor states plainly that it will not lock customers out of their own data. Because it cannot decrypt anything, that export depends on the account password and the Secret Key being to hand. Sharing is equally under the user's control, through shared vaults, expiring links, recipients who have no 1Password account, item history and expiry dates, and imports from other managers such as LastPass or Apple Passwords are documented. What remains on the vendor's side is the surrounding telemetry: service and diagnostic data are processed on a legitimate-interest basis, including to develop and train new technology, with a right to object; product usage information is collected only with permission, and that consent can be withdrawn.
Data retention & training
Hosting summary
AgileBits Inc., based in Toronto, is the controller, which places the vendor under Canadian jurisdiction. Vault contents follow the region chosen by the customer when the account is created: European Union, United States or Canada, with dedicated regional sites at 1password.com, 1password.eu and 1password.ca. One exception is documented: items shared through Item Sharing are stored in the EU for as long as the share remains active. Service data, diagnostic data and other information may be accessed, processed or transferred outside the user's country of residence, and staff reach them from several countries; customer support and email services are hosted mainly in the United States and Canada. Transfers rely on European Commission adequacy decisions, EU and UK standard contractual clauses, binding corporate rules where relevant, and periodic risk assessments. The subprocessor list is published as a PDF in the Legal Center. A technical note for anyone checking: the domain resolves to 172.66.1.143, a Cloudflare anycast node, which says nothing about where data is stored.
Things to keep in mind
Risks and trade-offs to weigh before adopting 1Password.
- Single point of failure: every credential lives in one vault, and access to it hangs on an account password and a Secret Key
- Lose both and the data is gone for good, since the vendor is unable to help by design; the printed Emergency Kit is itself a sensitive document that needs physical protection
- Concentrating personal and professional access with a single vendor creates a dependency that is hard to unwind
- The zero-knowledge promise rests on third-party audits and a white paper, not on source code the user can read and verify
- Targeted phishing remains the most likely attack: a convincing fake unlock screen defeats good cryptography
- Service and diagnostic data are processed on a legitimate-interest basis, including to develop and train new technology, and objecting is a right the user has to exercise personally
- An expiring share link sent to the wrong person exposes the item until it expires; on business accounts, administrators see usage metadata such as item counts, sign-ins and devices, private vaults included; and automating access for AI agents shifts the risk onto the quality of the written policies
Setup & Integrations
Technical difficulty
Personal use requires no technical skill: create an account, install the application and the browser extension, add a device by scanning a QR code, and run the assisted import from another manager. The one demanding step is not technical: keeping the Emergency Kit, account password plus Secret Key, somewhere safe. Enterprise deployment is an IT project, with identity provider integration for SSO and SCIM provisioning, vault and role design, and a separately licensed SCIM bridge. Developer use, from the CLI and SDKs to SSH and Git signing and CI/CD, sits at engineer level. Personalised onboarding is included above 100 users.
Deployment
Apps stores
Integrations
Supported languages
Behind 1Password
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement 1Password.
Frequently asked questions
Is there a free plan?
How much does the cheapest plan cost?
Can 1Password read my passwords?
Where is my data hosted?
What happens if I lose my account password?
Which security certifications does 1Password hold?
Are a DPA and a subprocessor list available?
Which devices are supported?
What does 1Password bring to AI agents?
Are there discounts, and how can I pay?
Should you pick 1Password?
1Password started in 2005 as a password manager and has since become an identity security platform, without abandoning the original product. Its balance point is easy to describe: the cryptography is solid and independently examined, with a two-key model, end-to-end encryption, published third-party audits, SOC 2 Type 2 and ISO 27001, 27017, 27018 and 27701 certifications, a downloadable DPA, a public subprocessor list and a hosting region the customer picks between the EU, the United States and Canada, while the commercial side is far less open: no permanently free plan, and no public price beyond the Personal and Business tiers.
For an AI directory, the interesting part is the agent angle. SaaS Manager exposes the AI tools that appear inside an organisation without anyone approving them, along with what they cost. Credential Broker hands credentials to agents and machine workloads at runtime, scoped to the task rather than granted permanently. Privileged Access sets what an agent may do and withdraws the right when behaviour drifts from stated intent.
Three reservations are worth carrying into a purchasing decision. No Article 27 EU representative is named anywhere on the site, which matters to European buyers. No support email address is published, so every request goes through a chatbot, a form or the community. And the position on model training deserves a direct question to the vendor: vault contents are encrypted and out of reach, but the privacy notice states that contact, service and diagnostic data are processed on a legitimate-interest basis to develop and train new technology, with a right to object that the user has to exercise personally.
- Choosing a selection results in a full page refresh.
- Opens in a new window.