Reusing the same password across multiple accounts is one of the most consequential security mistakes anyone makes online. When any site is breached — and breaches happen constantly — every account using that same password is immediately vulnerable. The only practical solution is unique, randomly-generated passwords for every account, stored somewhere other than your memory. That’s what 1Password is for. This fits into the wider topic we cover in our Complete Guide to Software and Apps.
This guide covers the complete workflow from first setup to the advanced features — Travel Mode, Watchtower, passkeys, and team sharing — that make 1Password a comprehensive security tool rather than just a password store.
Setting up and understanding the vault
After creating a 1Password account at 1password.com, download the desktop app (Windows or macOS) and the browser extension (Chrome, Firefox, Safari, Edge, Brave). Sign in with account email, Secret Key, and account password — the Secret Key is a 34-character code generated during account creation, required alongside the password for signing in on a new device.
The Secret Key is critical: save it to the Emergency Kit PDF (generated during account creation) and store it somewhere safe — a locked physical location. Losing both the account password and the Secret Key simultaneously makes account recovery impossible. 1Password’s zero-knowledge encryption model means 1Password itself cannot see any data in the vault and cannot assist with recovery without the Secret Key.
Vaults are the encrypted containers holding all items. Every account starts with a default Personal vault; create additional vaults for different categories:
- Personal vault — personal credentials that only you access
- Shared vault (family or team plan) — streaming services, shopping accounts, utility logins that multiple people need
- Work vault — separate from personal if mixing personal and professional on the same account
Vault membership determines who sees which credentials — items in the shared vault are visible to all vault members; items in the personal vault are visible only to the account owner.
Items in 1Password are structured records storing more than username-password pairs. Each login item stores the website URL (for autofill matching), username, password, notes, custom fields, and one-time password (OTP) code if 2FA is enabled. Beyond logins, 1Password stores secure notes, credit cards, bank accounts, identities (name, address, passport details for auto-filling checkout forms), software licences, SSH keys, API credentials, and Wi-Fi passwords.
The browser extension and autofill — daily use
The browser extension is the daily interface. When you navigate to any site’s login page, the extension detects the login fields and displays a suggestion to fill with the matching credential. Click the suggestion — or click the 1Password icon in the toolbar and select the credential — and the username and password fill instantly.
Keyboard shortcut: Ctrl+Shift+X (Windows) or Cmd+Shift+X (Mac) opens the 1Password extension from any browser page.
For sites with unusual login flows where autofill doesn’t trigger automatically (some sites use non-standard field names): click the 1Password icon visible in the focused field, or use the keyboard shortcut to open the extension and select the credential manually.
When creating a new account on any website, 1Password detects the password field and offers to generate and save a new password. Click the suggestion → 1Password generates a strong random password (customisable: length from 8–100 characters, random characters or memorable words, character type inclusion) → “Use Generated Password” → 1Password offers to save the new login with the URL, username, and generated password.
Password strength recommendation: 20+ character random passwords with mixed case, numbers, and symbols are the standard for most accounts. Memorable word-based passwords are appropriate for accounts where the password must occasionally be entered manually — device passwords, Wi-Fi passwords.
Saving items — step by step
- Save from the browser: navigate to a site → sign in → when 1Password offers to save, click “Save” → confirm item name and vault → added to the vault and available across all devices immediately.
- Add manually: 1Password app → “+” → choose item type (Login, Credit Card, Secure Note, Bank Account, Identity, etc.) → fill fields → save. Use this for non-web credentials — database passwords, server credentials, software licence keys, SSH passphrases.
- Import from another password manager: File → Import → choose the source format (LastPass, Bitwarden, Dashlane, Chrome, Firefox, CSV) → upload the exported file. All credentials import in a single operation. Verify the import is complete and correct before deleting credentials from the old tool.
- Add one-time passwords (OTP) for 2FA: open any login item → edit → “Add one-time password” → scan the QR code displayed during the site’s 2FA setup. Once added, 1Password generates the six-digit TOTP code for that site and includes it in autofill — username, password, and 2FA code all fill in a single interaction.
Security trade-off to understand: storing 2FA codes in 1Password combines both authentication factors in one tool — anyone with access to the 1Password vault has both factors. For most accounts this is an acceptable trade-off. For the most critical accounts (primary email, financial, identity), keeping 2FA in a separate authenticator app maintains the strictest factor separation.
- Store secure notes and documents: “+” → Secure Note → write or paste sensitive information (API keys, server details, security questions and answers, software activation codes). Attach documents or images to any item — scans of government IDs, insurance cards, passport copies — encrypted and accessible from any device.
Watchtower — the security audit dashboard
Watchtower is accessible from the left sidebar of the 1Password app. It continuously monitors the vault for risk categories:
- Compromised passwords: uses the Have I Been Pwned database of breached credentials — flags any stored passwords appearing in known breaches
- Weak passwords: short, common, or low-entropy passwords
- Reused passwords: the same password used across multiple sites
- Sites supporting 2FA: accounts in the vault where 2FA is available but not yet set up
Work through Watchtower findings starting with the Compromised category — accounts with compromised passwords should be changed immediately. Then address weak and reused passwords, starting with the most sensitive accounts (email, banking, work). A methodical Watchtower review once a month or quarter is one of the highest-impact security maintenance activities available.
Travel Mode — 1Password’s most distinctive feature
When Travel Mode is enabled, any vaults not marked “Safe for travel” become temporarily invisible — they disappear from the app entirely as if they don’t exist, and reappear when Travel Mode is disabled.
Before crossing a border where devices may be inspected or searched: enable Travel Mode. If asked to unlock a device and 1Password is opened by an inspector, only the Safe for travel vault is visible. Work credentials, sensitive client information, and private documents are not visible even if the app is unlocked — because they genuinely don’t exist on the device while Travel Mode is active. This is one of the most thoughtfully designed security features in any consumer product, addressing the specific threat of border security compelled access without requiring any deception.
Family sharing and emergency access
The 1Password Families plan (up to 5 family members on one subscription) gives each person their own private vault alongside access to shared family vaults — private credentials other family members cannot see, plus shared credentials everyone can access.
Create a “Family” shared vault for logins multiple people use (streaming services, shared email, utilities, home network passwords). Keep individual private vaults for personal banking, work, and private accounts. The shared vault becomes the single source of truth for any credential a family member might need to find independently.
Emergency access in 1Password Families is handled through the Family Organiser role — a designated account with access to the recovery process for other family members’ vaults. The Organiser can recover a family member’s vault access through the admin console at start.1password.com using account recovery keys, without knowing the individual’s master password. This recovery capability is the critical distinguishing feature: it prevents the scenario where one person’s vault becomes permanently inaccessible if they are incapacitated — a scenario with no solution in many other password managers.
Passkeys — the forward-looking feature
1Password stores passkeys — the FIDO2-based passwordless authentication credentials supported by Google, Apple, Microsoft, GitHub, and many other major services — alongside traditional passwords in the vault. When a site offers to create a passkey, 1Password detects it and offers to save it. The passkey is then available for autofill on any device where 1Password is installed.
1Password’s cross-platform passkey support (iOS, Android, Windows, macOS, Linux) is particularly valuable for users working across both Apple and non-Apple devices — a single, vendor-neutral passkey store that works everywhere rather than being locked into Apple’s Keychain or Google’s Password Manager. As more services adopt passkey authentication, having them stored in 1Password means the passwordless transition doesn’t require platform lock-in. You might also run into Disable Chrome Password Manager.
1Password for development teams
The Business plan adds managed vaults, guest accounts, and the 1Password CLI for developer workflows. The CLI allows accessing vault items in scripts, CI/CD pipelines, and automated workflows — loading API keys, database passwords, and deployment credentials directly from 1Password without storing them in environment files or code repositories. Related: How to Use a Password Manager.
Configure the 1Password CLI on each developer’s machine, store all project secrets in a shared team vault, and reference them in scripts using the CLI rather than hardcoding or using .env files that get accidentally committed to version control. For organisations running the CLI integration, 1Password becomes the source of truth for every secret used in automated systems — a meaningful security improvement over the typical practice of copying secrets into configuration files. For 1Password’s official documentation on the CLI setup and the complete item type reference, 1Password’s developer documentation covers the CLI, the API, and the passkey integration in technical detail. If this sounds familiar, Chrome Password Manager is worth a look.







