SecuFocus
PasswordsGetting started & analysis

1Password: a personal vault, with room to share

Secret Keys, family vaults and recovery: understand what you entrust to 1Password, then organise access around everyday needs.

Before you get started

What to expect

1Password organises logins into personal or shared vaults. The Secret Key works alongside the account password to protect the data. Before moving your accounts, keep the Emergency Kit safe and check the recovery options for your plan.

The Wi-Fi password should not be buried in twenty messages

The Wi-Fi password is somewhere in the family messages. An old photo of the label is still circulating, but nobody knows whether it is current. A shared vault gives this kind of information one home, accessible to the people who need it.

1Password is worth considering if you move between your phone and computer or manage access with other people. If your existing manager works well, switching brands need not be a priority. First identify a problem: unclear sharing, reused passwords or a recovery process nobody understands. Buying a different vault will not resolve those choices for you.

What the Secret Key changes

A standard personal account uses an account password and a Secret Key to connect a new device. The latter contributes to the vault’s cryptographic protection, is stored on authorised devices and appears in the Emergency Kit. It does not replace a forgotten password.

Knowing your password may therefore be insufficient to start again on a fresh device. Imagine losing your phone and laptop together. You still need a way to retrieve the sign-in information elsewhere. Keeping the only copy inside the vault it is meant to unlock creates an obvious problem.

Server and device: two different scenarios

1Password documents AES-GCM-256 authenticated encryption and PBKDF2-HMAC-SHA-256 key derivation. The Secret Key contributes 128 bits of entropy and works with the account password. Its particular value concerns a copy of server-held data obtained without that key.

An authorised device stores the Secret Key so you do not enter it on every unlock. Compromising that device is therefore different from stealing a server-side copy. System security, the account password and unlock choices still matter.

We do not turn those specifications into a number of years to “crack 1Password”. Such a figure would require a defined theft scenario, available secrets, parameters and attacker resources. Understanding the model’s boundaries is more useful than a spectacular cracking time.

Create and replace a password correctly

When creating or editing a login item, 1Password lets you generate a password and adjust its options. Use a different secret for each service. For an automatically managed login, we suggest starting with 20 random characters where accepted. A random-word passphrase can be easier to type for a memorised secret.

A common mistake is changing only the vault entry. The website password then stays the same. Change it on the service, verify that the correct value is saved and test a fresh sign-in. That simple check matters more than a green strength indicator.

Avoid selecting the most familiar-looking phrase from ten suggestions. Doing so brings personal habits back into a process intended to depend on randomness. If a keyboard or website constraint matters, configure it before drawing the secret.

The Secret Key and two-factor authentication do different jobs

The Secret Key participates in the encryption model. A second factor controls an authentication step with the service. Confusing them leads to poor recovery planning: finding one does not guarantee that you have the other.

For other accounts, keeping temporary codes in the same manager can simplify use, but also concentrates sign-in capabilities. A separate device or physical security key may suit particularly sensitive accounts, with extra organisation required. Do not keep the only way to recover an inaccessible 1Password account inside that account.

Sharing a vault grants access

With Families, each member has a Private vault and the household has a Shared vault. Additional vaults can be shared with selected people. You do not have to treat the whole household as one account with one password.

Agree on a few rules before adding records. Who can see the router’s administrator login? Who updates a record after changing a password? Does someone still need access after moving out? A few vaults with clear audiences are easier to maintain than a complicated structure nobody understands.

ExampleSuggested arrangement
Personal emailPrivate vault, with personal recovery prepared.
Home Wi-FiA vault shared with the people who need it.
Router administrationA vault restricted to those who maintain it.

Install 1Password and move a few accounts

Evaluate the tasks you actually perform. A desktop sign-in, a phone sign-in, a shared record and a locked vault will tell you more than a feature list. Keep your previous manager available while you make the transition.

Watchtower helps identify weak or reused credentials and accounts associated with breached websites. Review an alert; it does not by itself prove account takeover. Start with your main email account, which often controls recovery for other services.

  1. Install the app and extension through official links, then prepare the Emergency Kit.
  2. Save a secondary account and check autofill on both devices.
  3. Change a reused password on the relevant website, then check the saved record.
  4. Share a low-risk record and check who can access its vault.
  5. Lock the device and vault, and check what reopening them requires.

Prepare account recovery

Individual and family accounts can have a recovery code created in advance. Using it also requires access to the account’s email address; it lets you set a new account password and Secret Key. Two-factor authentication remains enabled. This recovery code is separate from the Secret Key.

Sketch your recovery dependencies: vault, email and second factor. If your email password exists only inside an inaccessible vault, you have found something to fix. Review this arrangement without needlessly initiating recovery on your main account.

  • Retrieve the Emergency Kit from somewhere other than your usual computer.
  • Check that you still control the account’s email address.
  • Prepare a backup for the second factor that does not depend on your current phone.
  • Tell a trusted person where to look if you want them to help in an emergency.

Export data and protect the copy

Desktop exports from 1Password 8 in 1PUX and CSV formats are unencrypted. CSV preserves only some categories and fields. An export is sensitive, and its existence does not establish that a migration will be complete.

When preparing to leave, use protected local storage outside automatically synced folders. Check important records at the destination, including the notes and attachments you rely on. Remove temporary files afterwards and review relevant bins and backups. Normal deletion does not guarantee that every copy has disappeared.

Check passkeys separately: current documentation says their export uses the iOS or Android mobile apps. Do not assume a desktop export includes them. Before leaving a manager, verify another sign-in method for each account or create a passkey in your destination.

Consider sharing and recurring cost

Compare managers using five ordinary tasks: create an account, fill a form, change a password, share access and retrieve a secret on another device. Write down difficulties when they occur instead of relying on a general impression at the end.

Before keeping the subscription, check that everyone can find a login and understands the recovery procedure. Then compare the plan’s recurring cost with the features you use. This analysis is based on documentation; SecuFocus has not run a comparative test on its own devices.

From the provider

1Password

Downloads, compatibility and current terms.

Official website

Frequently asked questions

Practical questions

Does the Secret Key replace two-factor authentication?

No. The Secret Key helps protect the account cryptographically alongside your password. Two-factor authentication controls a sign-in step. They have different roles; prepare recovery methods as well.

Read more: The Secret Key and two-factor authentication do different jobs #Link to this answer

Where should I keep my 1Password Emergency Kit?

Keep it somewhere safe that you can reach even if you lose your phone or vault access. A single copy inside the account you need to recover creates a circular dependency. Also check the recovery options available with your plan.

Read more: Prepare account recovery #Link to this answer

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

  1. 1Password: About your Secret Key ↗support.1password.com ·
  2. 1Password: Export your data ↗support.1password.com ·

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.