Comparisons and Product ResearchEmergency Access and Recovery

Emergency Access Comparison: Bitwarden, Keeper, NordPass, 1Password, and Lockstep

Bitwarden, Keeper, and NordPass document trusted-contact emergency access. 1Password documents recovery codes, Emergency Kits, and family or team recovery rather than an equivalent individual delayed-access contact workflow. Lockstep does not currently document a shipped trusted-contact emergency-access feature.

Those systems solve related but different problems. “Recovery,” “Emergency Kit,” and “emergency access” should not be treated as interchangeable labels.

Last verified: August 27, 2026. This comparison relies on linked official documentation. Plans, platforms, and behavior can change; verify before purchasing or relying on a feature.

At-a-glance comparison

ProductDelayed trusted-contact accessPermissionsWaiting periodImportant prerequisite or limitation
BitwardenYesView or takeoverUser-selected; minimum one dayOwner must designate and confirm contact in advance
KeeperYesVault access for designated trusted usersConfigurable up to three monthsOwner must designate contacts and choose delay in advance
NordPassYesView passwords after requestSeven days documentedContact needs a NordPass account and prior invitation
1PasswordNo equivalent individual delayed-contact flow found in reviewed docsRecovery code, Emergency Kit, or organizer/admin recovery depending on accountMethod-dependent, not a contact wait timerIndividual recovery code requires email verification; family recovery requires an organizer
LockstepNot currently documented as shippedNot applicableNot applicableDo not rely on a planned or inferred feature

Bitwarden

Bitwarden lets a premium user designate emergency contacts with either:

  • View access, which displays individual-vault items, including passwords and attachments.
  • Takeover access, which allows the contact to establish a new master password and take control after approval.

The owner selects a waiting period with a documented minimum of one day. After a request, the owner may approve or reject it; otherwise access is granted automatically after the period expires.

Bitwarden says emergency access uses asymmetric encryption in its security white paper. Official operational details are in About Emergency Access and Add and Manage Trusted Emergency Contacts.

Strengths

  • Clear distinction between view and takeover
  • Contact-specific waiting period
  • Published zero-knowledge key-sharing explanation
  • Contacts can still request existing grants if the owner's premium features lapse, according to current documentation

Risks and limitations

  • Takeover is extremely powerful.
  • A one-day minimum may be too short for many users.
  • The contact account and contact-verification process become part of the attack surface.
  • Access covers the individual vault, not necessarily every organizational item.

Keeper

Keeper lets users designate trusted emergency contacts and configure a delay for each contact. Keeper's Emergency Access documentation says the delay can be set up to three months.

After the delay, the trusted user can access the owner's vault through their own Keeper account. Current documentation should be checked for plan eligibility, platform availability, and exactly which record types are included.

Strengths

  • Per-contact delay
  • Very long delay available for conservative planning
  • Established trusted-user relationship

Risks and limitations

  • A long maximum is useful only if the user chooses it appropriately.
  • Broad vault access may exceed what a household or business successor needs.
  • The contact's own Keeper security remains critical.

NordPass

NordPass documents a flow in which the owner invites another NordPass user. The contact accepts and may later request to see passwords. The owner can approve or reject the request within seven days; if the owner does nothing, access is granted automatically.

See How to give Emergency Access in NordPass.

Strengths

  • Simple, understandable flow
  • A seven-day delay balances some ordinary absence against urgency
  • Existing grants currently do not require an active subscription during the access period, according to NordPass documentation

Risks and limitations

  • The documented seven-day period is less customizable than contact-specific timers.
  • Access is described as seeing passwords rather than a flexible permission model.
  • The contact must have and secure a NordPass account.

1Password

1Password provides several continuity mechanisms, but they should not be described as the same delayed trusted-contact feature offered by Bitwarden, Keeper, or NordPass.

Emergency Kit

The 1Password Emergency Kit is a PDF containing account details and the Secret Key, with space to record the account password. 1Password recommends storing a printed copy securely and considering what a loved one would need in an emergency.

Anyone who obtains a fully completed kit may have powerful access. Physical storage is therefore part of the security boundary.

Recovery code

Individual and family users can generate a cryptographic recovery code. 1Password says use of the code also requires access to the account email, creates new account credentials, and preserves access to existing data. See Generate and use recovery codes and Recovery code security.

Family or team recovery

Eligible organizers or administrators can help recover other members. The family recovery plan warns that Emergency Kits remain necessary if every capable organizer is locked out.

Strengths

  • Multiple documented recovery paths
  • Cryptographic recovery code
  • Mature family and organizational recovery documentation
  • Emergency Kit supports offline continuity

Risks and limitations

  • A completed Emergency Kit is a concentrated physical secret.
  • Organizer recovery changes the trust model.
  • We did not find an equivalent individual, delayed trusted-contact request workflow in the reviewed official documentation.

Lockstep

Lockstep's current code implements client-side vault encryption, a wrapped vault key, and encrypted exports. Those are relevant foundations for recovery design.

However, as of this review, Lockstep should be listed honestly:

  • No shipped trusted-contact emergency-access workflow was verified.
  • No contact permissions or waiting periods should be advertised.
  • An encrypted export is not automatically a standalone recovery method.
  • Support cannot simply reset a master password and decrypt the existing vault without a separate authorized key path.

This is not a cosmetic disadvantage that content should hide. Recovery is a security feature and must be implemented, tested, documented, and threat-modeled before users rely on it.

See What Happens If You Forget Your Master Password? for Lockstep's current boundary and Threat-Modeling Password Manager Emergency Access for design requirements.

How to choose

Evaluate the behavior, not the checkbox:

  1. Do you need incapacity access, forgotten-password recovery, death planning, or all three?
  2. Should the contact view records or take over the account?
  3. Can you choose a separate delay for each contact?
  4. How are both parties notified?
  5. What secures the contact's account?
  6. Can the owner revoke the grant immediately?
  7. Does access survive subscription lapse?
  8. Which vaults and record types are included?
  9. Does the provider retain any ability to decrypt?
  10. Have you tested the process?

For general setup guidance, read Password Manager Emergency Access.

The bottom line

Bitwarden currently offers the most explicitly documented split between view and takeover access. Keeper offers long configurable delays. NordPass offers a simpler seven-day flow. 1Password emphasizes recovery codes, kits, and account-group recovery. Lockstep does not yet have a verified feature that belongs in the same implemented-capability column.

Choose based on the failure you actually need to survive—and test it before an emergency.

All guides