Comparisons and Product ResearchEmergency Access and Recovery
Emergency Access Comparison: Bitwarden, Keeper, NordPass, 1Password, and Lockstep
Bitwarden, Keeper, and NordPass document trusted-contact emergency access. 1Password documents recovery codes, Emergency Kits, and family or team recovery rather than an equivalent individual delayed-access contact workflow. Lockstep does not currently document a shipped trusted-contact emergency-access feature.
Those systems solve related but different problems. “Recovery,” “Emergency Kit,” and “emergency access” should not be treated as interchangeable labels.
Last verified: August 27, 2026. This comparison relies on linked official documentation. Plans, platforms, and behavior can change; verify before purchasing or relying on a feature.
At-a-glance comparison
| Product | Delayed trusted-contact access | Permissions | Waiting period | Important prerequisite or limitation |
|---|---|---|---|---|
| Bitwarden | Yes | View or takeover | User-selected; minimum one day | Owner must designate and confirm contact in advance |
| Keeper | Yes | Vault access for designated trusted users | Configurable up to three months | Owner must designate contacts and choose delay in advance |
| NordPass | Yes | View passwords after request | Seven days documented | Contact needs a NordPass account and prior invitation |
| 1Password | No equivalent individual delayed-contact flow found in reviewed docs | Recovery code, Emergency Kit, or organizer/admin recovery depending on account | Method-dependent, not a contact wait timer | Individual recovery code requires email verification; family recovery requires an organizer |
| Lockstep | Not currently documented as shipped | Not applicable | Not applicable | Do not rely on a planned or inferred feature |
Bitwarden
Bitwarden lets a premium user designate emergency contacts with either:
- View access, which displays individual-vault items, including passwords and attachments.
- Takeover access, which allows the contact to establish a new master password and take control after approval.
The owner selects a waiting period with a documented minimum of one day. After a request, the owner may approve or reject it; otherwise access is granted automatically after the period expires.
Bitwarden says emergency access uses asymmetric encryption in its security white paper. Official operational details are in About Emergency Access and Add and Manage Trusted Emergency Contacts.
Strengths
- Clear distinction between view and takeover
- Contact-specific waiting period
- Published zero-knowledge key-sharing explanation
- Contacts can still request existing grants if the owner's premium features lapse, according to current documentation
Risks and limitations
- Takeover is extremely powerful.
- A one-day minimum may be too short for many users.
- The contact account and contact-verification process become part of the attack surface.
- Access covers the individual vault, not necessarily every organizational item.
Keeper
Keeper lets users designate trusted emergency contacts and configure a delay for each contact. Keeper's Emergency Access documentation says the delay can be set up to three months.
After the delay, the trusted user can access the owner's vault through their own Keeper account. Current documentation should be checked for plan eligibility, platform availability, and exactly which record types are included.
Strengths
- Per-contact delay
- Very long delay available for conservative planning
- Established trusted-user relationship
Risks and limitations
- A long maximum is useful only if the user chooses it appropriately.
- Broad vault access may exceed what a household or business successor needs.
- The contact's own Keeper security remains critical.
NordPass
NordPass documents a flow in which the owner invites another NordPass user. The contact accepts and may later request to see passwords. The owner can approve or reject the request within seven days; if the owner does nothing, access is granted automatically.
See How to give Emergency Access in NordPass.
Strengths
- Simple, understandable flow
- A seven-day delay balances some ordinary absence against urgency
- Existing grants currently do not require an active subscription during the access period, according to NordPass documentation
Risks and limitations
- The documented seven-day period is less customizable than contact-specific timers.
- Access is described as seeing passwords rather than a flexible permission model.
- The contact must have and secure a NordPass account.
1Password
1Password provides several continuity mechanisms, but they should not be described as the same delayed trusted-contact feature offered by Bitwarden, Keeper, or NordPass.
Emergency Kit
The 1Password Emergency Kit is a PDF containing account details and the Secret Key, with space to record the account password. 1Password recommends storing a printed copy securely and considering what a loved one would need in an emergency.
Anyone who obtains a fully completed kit may have powerful access. Physical storage is therefore part of the security boundary.
Recovery code
Individual and family users can generate a cryptographic recovery code. 1Password says use of the code also requires access to the account email, creates new account credentials, and preserves access to existing data. See Generate and use recovery codes and Recovery code security.
Family or team recovery
Eligible organizers or administrators can help recover other members. The family recovery plan warns that Emergency Kits remain necessary if every capable organizer is locked out.
Strengths
- Multiple documented recovery paths
- Cryptographic recovery code
- Mature family and organizational recovery documentation
- Emergency Kit supports offline continuity
Risks and limitations
- A completed Emergency Kit is a concentrated physical secret.
- Organizer recovery changes the trust model.
- We did not find an equivalent individual, delayed trusted-contact request workflow in the reviewed official documentation.
Lockstep
Lockstep's current code implements client-side vault encryption, a wrapped vault key, and encrypted exports. Those are relevant foundations for recovery design.
However, as of this review, Lockstep should be listed honestly:
- No shipped trusted-contact emergency-access workflow was verified.
- No contact permissions or waiting periods should be advertised.
- An encrypted export is not automatically a standalone recovery method.
- Support cannot simply reset a master password and decrypt the existing vault without a separate authorized key path.
This is not a cosmetic disadvantage that content should hide. Recovery is a security feature and must be implemented, tested, documented, and threat-modeled before users rely on it.
See What Happens If You Forget Your Master Password? for Lockstep's current boundary and Threat-Modeling Password Manager Emergency Access for design requirements.
How to choose
Evaluate the behavior, not the checkbox:
- Do you need incapacity access, forgotten-password recovery, death planning, or all three?
- Should the contact view records or take over the account?
- Can you choose a separate delay for each contact?
- How are both parties notified?
- What secures the contact's account?
- Can the owner revoke the grant immediately?
- Does access survive subscription lapse?
- Which vaults and record types are included?
- Does the provider retain any ability to decrypt?
- Have you tested the process?
For general setup guidance, read Password Manager Emergency Access.
The bottom line
Bitwarden currently offers the most explicitly documented split between view and takeover access. Keeper offers long configurable delays. NordPass offers a simpler seven-day flow. 1Password emphasizes recovery codes, kits, and account-group recovery. Lockstep does not yet have a verified feature that belongs in the same implemented-capability column.
Choose based on the failure you actually need to survive—and test it before an emergency.