The Toms Guide
Menu
Apps & Software

Best Password Managers 2026: We Tested 8, and Two Free Ones Are Genuinely Good

Eight managers, eight weeks, every subscription bought at retail. We migrated a 400-entry vault into each one, broke the autofill on purpose, and read every published security architecture doc. Only one app got a family recommendation without caveats.

Published August 6, 2026
13 min read
Best Password Managers 2026: We Tested 8, and Two Free Ones Are Genuinely Good

We moved a real 400-entry vault through eight password managers, tested autofill against 30 awkward login flows, checked passkey support on iOS, Android, Chrome and Safari, and read each vendor's published encryption architecture. Bitwarden wins overall on the strength of an open-source, audited codebase and a free tier that syncs everywhere. 1Password wins for families and for anyone who wants the polish. Proton Pass wins on privacy posture. We also explain the one migration step almost everyone skips.

Quick answer

Bitwarden is the best password manager for most people in 2026. The reason is not features — it is that the client code is open source, it has been through repeated third-party security audits, and the free tier syncs unlimited entries across unlimited devices without asking for a card. Paid is $10/year, or $40/year for six people.

Two apps beat it in specific lanes. 1Password has the best-built apps in the category and the best family sharing, and it is what we recommend when someone is setting this up for relatives. Proton Pass is the pick if your concern is how much your provider can see about you at all. And if every device in your house has an Apple logo on it, Apple Passwords is already good enough — the honest answer is that you may not need to buy anything.

How we tested

Eight weeks, eight managers, all subscriptions bought at retail. We ran a real 400-entry vault — not a synthetic test set — through every one of them, which surfaced the import bugs that a clean 20-entry demo never will.

The rubric:

  1. Security architecture. Is the vault end-to-end encrypted so the vendor cannot read it? What key-derivation function and iteration count is the default? Has an independent firm audited it, and is the report public? Is the client code inspectable?
  2. Autofill reliability. We built a set of 30 deliberately awkward login flows — multi-step forms, iframed SSO, sites that split username and password across pages, apps with custom keyboards — and counted how many each manager filled correctly without help. This is where price and polish diverge most.
  3. Passkey support. Creation, storage, sync and use across iOS, Android, Chrome and Safari, per the FIDO Alliance specification.
  4. Migration in and out. Import fidelity from a 400-entry CSV, whether attachments and TOTP secrets survived, and how hard it is to leave — an underrated measure of whether a vendor respects you.
  5. What the free tier actually is. After the onboarding funnel finishes trying to upgrade you.

We scored against NIST SP 800-63B for credential-handling expectations rather than vendor marketing claims. Our conflict-of-interest policy is in the editorial standards document.

The ranking at a glance

#ManagerFree tierPaid (individual/yr)Family (yr)Open sourceAutofill (of 30)
1BitwardenUnlimited entries, unlimited devices$10$40 (6)Yes27
21PasswordTrial only$35.88$59.88 (5)No30
3Proton PassUnlimited entries, 1 device type limit$23.88$47.88 (6)Yes26
4Apple PasswordsFree, Apple-onlyFree (Family Sharing)No25 (Apple platforms)
5Dashlane25 entries, 1 device$59.88$89.88 (10)Partial28
6Keeper1 device, no sync$34.99$74.99 (5)No26
7NordPassUnlimited entries, 1 active device$35.88$71.88 (6)Partial25
8Google Password ManagerFree, Chrome/AndroidNo22

Prices are list prices checked on official store pages in July and August 2026. Every vendor in this table runs discounts, and several of the paid tiers are routinely available at half these figures on a first-year promotion — which is also why we score on renewal price, not the introductory one.

1. Bitwarden — best overall

Bitwarden wins on a combination almost nobody else offers: you can read the code, someone independent has checked it, and the free version is not crippled.

The published audit history is the substantive part. Open source alone proves nothing — plenty of inspectable code has never been inspected — but Bitwarden pairs an open client with recurring third-party assessments whose reports are public. When you are handing one company every credential you own, the ability to verify rather than trust is worth more than any feature on a comparison grid.

The free tier syncs unlimited entries across unlimited devices, which is the line the rest of the industry refuses to cross: Dashlane caps you at 25 entries, Keeper and NordPass restrict you to one device, 1Password has no free tier at all. Paid at $10/year adds file attachments, integrated TOTP, emergency access and vault health reports. The six-person family plan at $40/year works out to under $7 per person per year and is the single best value in this roundup.

Autofill handled 27 of our 30 awkward flows, which is very good but not perfect — it stumbled on two multi-step enterprise SSO forms and one banking site that rewrites its DOM after focus. Passkey support is complete across all four platforms we tested.

The catch: the apps look like they were designed by engineers, because they were. Navigation is dense, the settings tree is deep, and the browser extension surfaces more options than a non-technical user wants to see. If you are setting this up for a parent, the polish gap is a real cost and 1Password is the kinder answer.

Best for: anyone comfortable with a slightly utilitarian interface. Cost-conscious families. Anyone who wants an inspectable client.

2. 1Password — best for families and for the polish

1Password filled all 30 of our awkward login flows. Nothing else did. It is the most carefully built software in this category and it shows in the small places: the way it handles two-step forms without you intervening, the way Watchtower explains a problem in a sentence instead of a badge, the way its shared vault model maps onto how a household actually works — one vault for the couple, one for the kids’ school logins, one private per person.

Its security white paper is the most thorough public document any vendor here publishes, and its two-secret key derivation means an attacker with your master password still lacks the device-held secret key. That design is a genuine architectural advantage over the single-secret model most competitors use.

The costs: it is closed source, there is no free tier at all, and $59.88/year for five people is half again what Bitwarden charges for six. For most individuals the value argument does not land. For a household where one person will be doing tech support for everyone else, it does — the polish is what stops the other four people from giving up.

Best for: families. First-time password-manager users. People who will pay for things that just work.

3. Proton Pass — best privacy posture

Proton Pass is the pick when your worry is not just “can they read my vault” but “what can they see about me at all.” Open source clients, end-to-end encryption, and the unusual addition of built-in email aliasing — you can generate a unique throwaway address per site from inside the manager, which decouples your real address from every breach corpus in existence. In practice that is the most useful anti-tracking feature in this entire roundup, and it is the reason to choose Proton over Bitwarden.

It is also the newest codebase here and it feels it. Autofill managed 26 of 30. The free tier is generous on entries but restricts you to one device type, and the aliasing quota on free is low enough that you will hit it. $23.88/year unlocks unlimited aliases and multiple devices; the $47.88 family plan covers six.

Best for: people who want to minimise what any provider learns about them. Anyone who would benefit from per-site email aliases. Existing Proton Mail subscribers, who may already have it bundled.

4. Apple Passwords — good enough if you’re all-Apple

We are including this because the honest answer for a lot of readers is that they do not need to buy anything. Apple Passwords syncs across iPhone, iPad and Mac, creates and stores passkeys properly, flags reused and breached credentials, does verification codes, and supports shared groups with family members. It costs nothing and it is built into the operating system, which means it never asks you to renew.

The two limits are hard ones. It is Apple-only in any practical sense — the Windows and Chrome bridges exist but are second-class. And sharing with someone outside your Apple household is awkward. If either of those describes your life, a dedicated manager earns its price. If neither does, save your money.

Best for: households where every device is Apple and nobody needs to share outward.

5. Dashlane — strong autofill, hard-to-justify price

Dashlane’s autofill is excellent — 28 of 30, second only to 1Password — and it has invested more than anyone in the passwordless direction, with a web-first architecture and a slick automatic password-changer for supported sites. The admin tooling is genuinely good, which is why it does well in business deployments.

The consumer proposition is where it falls apart. $59.88/year individual is the most expensive per-seat price here, the free tier is capped at 25 entries on a single device, which makes it a demo rather than a tier, and the desktop app was retired in favour of the browser extension, which not everyone welcomed.

Best for: business deployments and people who value autofill above all and don’t mind paying for it.

6. Keeper — best security compliance paperwork

Keeper’s differentiator is auditability of the corporate kind: FIPS 140 validated encryption modules, SOC 2 and ISO 27001 certifications, granular enforcement policies, detailed compliance reporting. If you are procuring for an organisation that has to answer questionnaires, this is a serious contender and the paperwork is a real product feature.

For individuals it is less compelling. The free tier is a single device with no sync, which is not usable. Several capabilities you might reasonably expect in the base price — including secure file storage and the dark-web monitoring add-on — are sold separately, so the effective cost lands well above the headline $34.99.

Best for: compliance-driven organisational buyers.

7. NordPass — fine, if you already pay Nord for something else

NordPass is competent and unremarkable. Clean interface, XChaCha20 encryption, unlimited entries on free — but only one active device at a time on the free tier, which means the free version cannot do the one job a password manager exists to do. Autofill managed 25 of 30. Its case is mostly the bundle: if you already subscribe to the wider Nord suite, adding this costs little and consolidates a bill.

Best for: existing Nord subscribers.

8. Google Password Manager — the default you should probably outgrow

Built into Chrome and Android, free, and better than it used to be — it now does passkeys, warns about compromised credentials, and syncs reliably within Google’s world. If the alternative is reusing the same password on 40 sites, this is a large improvement and you should use it.

But it is the weakest autofill in our set outside its home turf at 22 of 30, it is effectively Chrome-and-Android only, and everything lives inside the Google account that is also your email — so an account compromise is a total compromise. Treat it as the floor, not the destination.

Best for: people who will not install anything, as a strictly better option than reuse.

The migration step nearly everyone skips

Switching is easy. Switching safely takes fifteen extra minutes, and this is the part no vendor’s onboarding tells you.

  1. Export from the old manager to CSV, and note exactly where the file lands.
  2. Import into the new one, then verify a count. Our 400-entry vault lost TOTP secrets in two of the eight imports and attachments in three — check the categories you care about rather than trusting the success message.
  3. Run the vault health report and rotate what it flags. An import is the one moment you have every weak and reused credential listed in one place; use it. Cross-check against Have I Been Pwned if your manager doesn’t do breach checking on your tier.
  4. Delete the CSV, then empty the trash. That file is your entire digital life in plaintext. It is the single most dangerous artefact of the whole process and it is sitting in Downloads.
  5. Turn on two-factor for the new account, and set the key-derivation iteration count to the highest option offered. This is what protects your vault if the vendor is ever breached.
  6. Only then close the old account — after two weeks of the new one working, not on day one.

The bottom line

Get Bitwarden if you want the best combination of verifiable security and price. Get 1Password if you want the best software and the easiest family setup, and accept that you are paying for polish. Get Proton Pass if aliasing and metadata minimisation matter to you. Use Apple Passwords and spend nothing if you live entirely inside Apple’s ecosystem.

Whichever you choose, the decision that matters more than the brand is a long unique master passphrase, two-factor on the account, and passkeys wherever a site will let you use them.

More tested app shortlists are in Apps & Software and Best Of.

We re-test this category annually, and out of cycle after any material breach disclosure or pricing change.

best password managerspassword manager 2026bitwarden1passwordproton passdashlanenordpasskeeperpasskeysapple passwordssecurityapp reviews

Frequently asked

What is the best password manager in 2026?

Bitwarden, for most people. Its client code is open source and has been through repeated third-party security audits, its free tier syncs an unlimited number of entries across unlimited devices, and paid plans are $10/year individual or $40/year for a six-person family — roughly a quarter of what the competition charges. 1Password is the better pick if you want the most polished apps and the best family sharing, and Proton Pass is the pick if minimising metadata exposure is your priority.

Are free password managers safe to use?

The good ones are, and the distinction that matters is not free versus paid but audited versus unaudited. Bitwarden's free tier uses the same audited, end-to-end encrypted architecture as its paid tier — the paywall covers sharing, advanced two-factor options and reporting, not the encryption. Apple Passwords and Google Password Manager are also safe and free, but they lock you to one ecosystem. Avoid any free manager that has not published an independent security audit, and avoid browser-only tools that store your vault unencrypted on disk.

Is Apple Passwords good enough, or do I need a password manager?

If every device you own is Apple and you never sign in on a Windows PC or Android phone, Apple Passwords is genuinely sufficient in 2026 — it syncs, it does passkeys properly, it warns you about reused credentials, and it costs nothing. Two things push people off it: cross-platform life, and sharing with someone who isn't in your ecosystem. Both are the exact cases dedicated managers are built for.

What are passkeys and should I use them instead of passwords?

A passkey is a cryptographic key pair that replaces a password: the private half stays in your device or password manager, the site only ever holds the public half, and there is nothing phishable to type. Where a site offers passkeys, use them — they defeat credential-stuffing and most phishing outright. You will still need a password manager for years, because most of your accounts do not support passkeys yet and someone has to hold the ones that don't.

How do I switch password managers without losing everything?

Every manager here exports to CSV and imports from the others, so the mechanical part takes about ten minutes. The step people skip is the cleanup: after importing, run the manager's built-in reused-and-weak-password report and rotate the credentials it flags, then delete the export file from your downloads folder and empty the trash. An unencrypted CSV of your entire vault sitting in Downloads is a worse security problem than the manager you just left.

Should I trust a password manager after the industry breaches?

Yes, with a caveat that changes how you set it up. The breaches that hurt users involved vault data being exfiltrated and then attacked offline, which means your master password strength and the key-derivation settings are what actually protect you. Use a long passphrase you have never used elsewhere, turn on the highest key-derivation setting your manager offers, and enable two-factor authentication on the account. A well-configured manager remains far safer than password reuse, which is the alternative most people default to.

Sources

  1. NIST Special Publication 800-63B — Digital Identity Guidelines, Authentication and Lifecycle Management
  2. FIDO Alliance — passkeys specification and platform support matrix
  3. Bitwarden — published security assessments and third-party audit reports
  4. 1Password — security design white paper
  5. Have I Been Pwned — breach corpus used for credential-reuse checks
  6. Vendor subscription pricing checked on official store pages, July–August 2026

Published August 6, 2026 · Last reviewed August 6, 2026

The dispatch

A weekly read on consumer tech

Independent reporting on the apps, devices, and software that shape how we work and live. One email a week. No tricks.

No spam. Unsubscribe anytime.