2026-07-20 · 8 min read

How to leave passwords for family when I die

Learn how to leave passwords for family when you die: store instructions not credentials, and compare wills, safe-deposit boxes, Bitwarden, and legacy tools.


Leave instructions and where the keys live — not the passwords themselves. Write down where each account and credential is stored, keep that document separate from your will, and name one trusted person to reach it. Then layer a password manager's emergency access or a platform legacy tool on top, and document your two-factor backup codes and which device each account needs, because a login that demands a 2FA code your family can't reach won't open from a password list alone.

Should I put my passwords in my will?#

No. A will becomes a public record once it is filed with the local probate court, so any password, username, or account number written inside it can be requested and read by anyone — listing that information there means it is made public and risks identity theft.

The split is narrow. Your will should appoint a representative and point to your digital estate plan; the actual access details belong in a document kept separate from the traditional will, with the will simply referencing that plan and naming the person who manages it. Even for crypto the rule holds: mention the asset in the will so it does not fall into your residuary estate, but do not list the private keys, passwords, usernames, or PINs needed to reach it.

Where should I store passwords so family can reach them?#

Every option trades convenience against exposure and delay. Here is how the real methods compare.

MethodWhat it coversMain trade-off
Handwritten list in a safe or safe-deposit boxEverything you choose to write downA sole owner's box stays inaccessible until the estate's representative obtains court-issued letters testamentary — weeks or longer of delay
Password-manager emergency access (e.g. Bitwarden)The full vault, including passwords and attachmentsRequires setup in advance and a paid tier; see the section below
Apple Legacy ContactPhotos, messages, notes, and filesExcludes stored passwords and payment information
Google Inactive Account ManagerData you choose to share, by downloadContacts cannot log in — they only download a copy, after your account is inactive for a set period
Letter of instruction (instructions only)Points to where everything livesRelies on the underlying accounts and 2FA factors still being reachable

A password manager shrinks the problem because you share one master password with survivors rather than a long list. If you go the physical route, mind the safe-deposit-box paradox: with a sole-owned box, the original will can end up locked behind the very probate process it is needed to start — so never store the original will inside it.

Should I write my passwords down, and where is that safe?#

Writing them down is reasonable. Avast recommends writing credentials down, storing the list somewhere secure — possibly a safe-deposit box — stating its location in your will, and designating the specific people who should reach it. The safety comes from where the list lives and who is named, not from the paper. Keep it separate from the will, and remember the access-delay caveat if a bank controls the box.

How does password-manager emergency access work?#

You designate a trusted person ahead of time, and they request access later. With Bitwarden, the account holder adds a trusted contact in advance; when needed, the contact requests access, and you can approve it manually at any time or let it be approved automatically after a wait time you set, if you do not respond. That grace window is the safety property: nothing is handed over now, and you keep the ability to decline.

There are two levels. View grants read access to all vault items including passwords and attachments; Takeover requires the contact to create a new master password for permanent read/write access, replacing your old master password and removing existing two-step login methods. Two setup details matter: the trusted contact must have their own free or Premium Bitwarden account on the same server, and the invitation to become a contact is only valid for five days. For a fuller walkthrough of how these grants work across password managers, see our guide to password-manager emergency access.

What changed with Bitwarden in January 2026?#

Emergency access is no longer free. In January 2026 Bitwarden moved emergency access off the free tier to Premium and raised Premium from 9.99 to 19.80 US dollars per year — its first Premium price increase in about ten years. The pricing page now lists Premium at 19.80 US dollars billed annually, roughly 1.65 a month, with emergency access included. If you set this up before 2026 on the free plan, confirm your emergency contacts are still active.

How do Apple and Google legacy tools work, and what do they miss?#

They cover files and data, not your logins — the most common misunderstanding, so treat them as a supplement.

Apple Legacy Contact. You set it up under Settings, your name, Sign-In and Security, Legacy Contact; it requires two-factor authentication and iOS or iPadOS 15.2, or macOS Monterey 12.1 or later, and you can name more than one contact who does not need an Apple device. After you go silent, the contact needs both the access key and your death certificate to request access, and that access lasts up to three years from when the first request is approved, after which the account is permanently deleted. Crucially, it covers photos, messages, notes, and files, but not the payment information, passwords, and passkeys stored in your iCloud Keychain.

Google Inactive Account Manager. You designate up to 10 people to be notified and optionally receive account data after your account is inactive for a period you choose, from 3 to 18 months, and Google sends reminders to your phone and a recovery email before acting. But the contacts cannot log in — Google emails them a link to download the data you chose to share, and they have three months to download it before the links expire.

How do I share access without handing over live passwords now?#

Build the plan in three layers, ordered so nothing is exposed in the present:

This is where a business-continuity check-in fits. Proceedly runs on a check-in you don't miss: pass a grace window and a person you name confirms — or, on a paid plan, it releases automatically — before your encrypted handoff plan reaches the people who depend on you. It holds your instructions and where the keys live, never the passwords themselves — the same instructions-not-credentials principle these primary sources point to.

Should I give my spouse my master password?#

You can, and Avast's model assumes exactly one master password is shared with survivors after death. But sharing it now exposes the whole vault today. A grace-window emergency-access grant reaches the same outcome without live exposure: Bitwarden lets you approve access manually or automatically after a wait time, so the vault opens only when it needs to.

FAQ#

Can I just list my passwords in my will to be safe? No. A will becomes public once filed with probate, so anything written in it can be read by anyone. Keep credentials in a separate document instead.

Will a safe-deposit box guarantee my family quick access? No. A sole owner's box stays inaccessible until the estate's representative obtains court-issued letters testamentary, which can take weeks or longer.

Does Apple's Legacy Contact give my family my passwords? No. It covers photos, messages, notes, and files, but explicitly not the stored passwords or payment information in your iCloud Keychain.

Can my Google Inactive Account Manager contacts log into my account? No. They receive a download link for the data you chose to share and have three months to use it — they cannot sign in.

Is Bitwarden emergency access still free in 2026? No. As of January 2026 it is a Premium-only feature, and Premium is 19.80 US dollars per year.

What is the single safest overall approach? Leave instructions and where the keys live in a separate secured document, not the credentials themselves in the will, and document your two-factor backup codes and required device, not just passwords.

Sources#