Security architecture
Bitwarden is open source, independently audited and can be self-hosted, which appeals to anyone who wants to verify rather than trust. Vault data is encrypted on your device before it is uploaded, so the service cannot read it.
1Password adds a Secret Key alongside your master password. That second factor is stored on your devices and combined with the master password during decryption, meaning a stolen server database is useless even against a weak master password. It is the strongest argument in 1Password's favour.
Everyday usability
1Password is the more refined product. Autofill is more reliable across awkward sites, the applications feel native on each platform, and features such as travel mode, item categories and one-time-code storage are cleanly presented.
Bitwarden is functional rather than delightful. Recent releases have closed much of the gap, but occasional autofill quirks and a plainer interface remain the trade-off for a much lower price.
- 1Password: smoother autofill, more polished apps
- Bitwarden: capable, occasionally rougher edges
- Both: passkey storage, secure notes, breach alerts
The free tier changes the maths
Bitwarden's free plan covers unlimited passwords on unlimited devices, which is genuinely unusual and makes it the default recommendation for anyone protecting a personal vault on a budget. Its paid personal tier adds emergency access, file attachments and advanced reports for a few euros a year.
1Password has no free tier beyond a trial. You are paying for design, support and the Secret Key model, and for many households that is a reasonable trade.
Families, sharing and teams
Both offer family plans with shared vaults and per-member permissions. 1Password's family administration and recovery flow is clearer, which matters when a less technical relative forgets a master password.
For small businesses, 1Password's provisioning, reporting and policy controls are more mature, while Bitwarden is the cheaper route with adequate directory integration and the option to keep everything on your own server.
Migrating without losing anything
Both import from browsers and from every major competitor. Export the old vault, import it, then verify a sample of entries before deleting anything, and remember that an export file is unencrypted plain text: delete it securely afterwards.
Turn off the browser's own password saving once migration is complete, or you will end up with two partial sets of credentials drifting apart.
- Export, import, verify, then delete the export securely
- Disable browser password saving afterwards
- Set a long unique master password you can remember
- Store recovery codes offline, outside the vault
