Every password manager with emergency access, compared
Which password manager with emergency access is worth paying for? Bitwarden, Proton, Keeper, LastPass and NordPass compared on price, wait time and access.
Five mainstream password managers ship a real emergency-access feature: Bitwarden, Proton, Keeper, LastPass and NordPass. In all five, granting access sits behind a paid tier — the cheapest at list price is Bitwarden Premium at $19.80 a year — while the trusted contact can usually stay on a free account. 1Password ships no equivalent, Dashlane dropped its emergency contact along with its desktop app, Norton Password Manager never had one, and neither Google's nor Apple's legacy tools hand over your saved passwords.
Which password managers actually have emergency access?#
These five, and the gaps between them are wide: read-only viewing versus a takeover that resets your master password, a fixed 7-day wait versus anything from zero to three months, and $19.80 a year versus $42.99.
Four names people expect on that list are missing, each for a different reason:
- 1Password ships nothing like it. In a pinned February 2024 forum reply, a staff member wrote that "we don't have anything new to share about an emergency access feature right now," explaining that such access would need keys 1Password itself does not hold. The request is open, not shipped — what 1Password offers instead, and how to work around it, is a plan you assemble yourself.
- Dashlane had one and dropped it. Its support page says the old emergency contact lived only in the desktop app, which Dashlane no longer offers, and points users at a manual export instead.
- Norton Password Manager's official feature list covers passwordless unlock, a Safety Dashboard, a generator, imports, sync and encrypted storage — no emergency access, no legacy contact, no sharing.
- Google and Apple run account-level legacy tools that stop at the vault door. Details below.
Is there a free password manager with emergency access?#
No — not for the person granting it. Every implementation above requires a paid plan on the grantor's side, and NordPass is why this question keeps getting answered wrongly. Its plan-comparison page lists "Emergency Access" as a feature line, but its support article is explicit: you need a NordPass Premium subscription — individual Premium or Family — to give Emergency Access, while it can be granted to any NordPass user, including Free users. Free users can receive, never give.
Receiving is the cheap half. Bitwarden's contact needs only a free or premium account on the same Bitwarden server, and NordPass notes that no active subscription is required during the emergency access period. So the cheapest working setup is one paid seat — $19.80 a year on Bitwarden, or $1.99 a month on Proton Pass Plus — plus a free account for the person you name.
How does Bitwarden emergency access work, end to end?#
Bitwarden is the most documented of the five, and the flow has five stages:
- You invite. Adding a trusted contact is available to premium users, including members of paid organizations — Families, Teams or Enterprise.
- They accept. The contact needs a free or premium Bitwarden account on the same server, and the invitation is valid for only five days.
- They request. You can approve immediately or reject the request — and rejecting "will not remove the grantee from being a trusted emergency contact or prevent them from making access requests in the future."
- The clock runs out. The minimum wait you can set is one day. Silence past it releases access.
- They get View or Takeover. View grants "view/read access to all items in your individual vault, including login items' passwords and attachments." With Takeover, the contact "must create a master password for permanent read/write access to your vault" — which replaces your previous master password and removes any two-step login methods. The choice between the two is the whole decision, and View vs Takeover, step by step walks through it.
Two limits are easy to miss. Emergency access covers only your individual vault, so organization-owned items are excluded. And if an organization you belong to has the Automatic confirmation policy turned on, "emergency access is not available for your account."
The cryptography holds up: the scheme uses public key exchange, with your symmetric key encrypted using the grantee's RSA public key, so Bitwarden itself never holds usable access. One pricing note — Bitwarden Premium roughly doubled to $1.65/mo, billed annually at $19.80, in early 2026, up from $9.99 a year. Older comparison posts still quote the $9.99 figure.
Does Proton have emergency access?#
Yes, since 28 August 2025 — recently enough that most comparison posts have not caught up. It is also the widest in scope of the five: once granted, "your trusted contacts will be able to securely access your Proton data, including emails, passwords, and files," rather than a single vault. You configure it at mail.proton.me under Settings, then Recovery, then Emergency access.
Three details decide whether Proton's version does what you assume:
- The contact needs a Proton Mail address, not just any email. The launch blog says contacts "will also need to have a Proton Account"; the support page is stricter — "Both you and your contact must have a Proton Mail email address."
- The maximum wait is 30 days, not "months." The blog describes waits "ranging from days to months", but the documented dropdown offers 30, 14, 7, 3, 2 or 1 day, or no wait time.
- It is a full sign-in, not a read-only copy. An approved contact clicks "Access account", then switches into your account and operates it. You are notified whenever a request is made, so you "can deny the request if it's not a real emergency," and a contact you remove loses access.
Proton Pass's pricing page lists Emergency Access as a Pass Plus feature, and "all paid plans qualify."
What do 1Password, Keeper and LastPass do differently?#
1Password substitutes two things for emergency access, and neither is delegated access. The Emergency Kit is "a PDF document with your account details and a place to write your 1Password account password" — a sign-in aid you have to print, store and protect yourself. Account recovery lets a family organizer, a team administrator or owner, or a custom group with the Recover Accounts permission restore your access: the recovered person gets a new Secret Key, creates a new account password and has two-factor authentication reset. The recoverer never gains sight of the vault.
Keeper is the most conservative on access level and the most generous on delay. Contacts "can view what they need, but they can't edit, move, delete or export anything from your vault," and you can name up to five with a waiting period "from immediately up to three months" each — a countdown that begins the moment the trusted user attempts to log in. The feature is available only for consumer accounts, not Business or Enterprise, and it is the most expensive route here at $42.99/yr for Unlimited or $91.99/yr for Family, after a 30-day trial.
LastPass gates the feature to Premium and Families, not Free, grants reach to "passwords, accounts, and secure notes," and runs on a customizable wait time — "the window between your access request and when it's approved (account access is granted if the request is not denied within the time window)." Premium is $3/mo and Families $4/mo for six accounts, billed annually; the setup flow and its zero-knowledge claim are unpacked in how LastPass emergency access works.
Do Google and Apple pass on saved passwords?#
Neither does, and this is where plans quietly fail.
Google's mechanism is Inactive Account Manager, not a password-manager feature. It shares selected data after a chosen period of inactivity with up to 10 people, warns that "some information can't be shared," and its examples are products like Blogger, Drive, Mail and YouTube — not saved passwords. The trigger is passive, judged from "your last sign-ins, your recent activity in My Activity, usage of Gmail (e.g., the Gmail app on your phone), and Android check-ins," and each contact must supply a phone number "for the sole purpose of ensuring that only the trusted contact can actually download your data." Google Password Manager's only delegation is sharing individual passwords with members of a Google family group, copied into their own manager, with no emergency trigger at all.
Apple is blunter. A Legacy Contact receives "photos, messages, notes, files, device backups, and more", but Apple's inaccessible-data list explicitly names "data stored in your iCloud Keychain (payment information, passwords, and passkeys)." Your passwords are the one thing a Legacy Contact does not get.
Is emergency access safe to turn on?#
The cryptography is sound — Bitwarden's key exchange keeps secrets out of the service's reach — so the real risks are about people and access levels, not encryption.
The sharpest trade-off is Bitwarden's Takeover: because it replaces your master password and removes your two-step login methods, a contact who is compromised, careless or hostile can lock you out of your own vault permanently. Keeper's read-only model and NordPass's view-only model cannot do that; Proton's full account sign-in can do rather more. Match the level to the job — a contact who only needs to read records never needs Takeover.
The wait window is your defence against a premature request. Bitwarden lets you reject the request before the clock runs out, Proton notifies you so you can deny a request that is not a real emergency, Keeper notifies the owner when a trusted contact attempts to log in, and NordPass gives you 7 days to accept or decline before access is granted automatically. Every one of those protections assumes you are well enough to read your email — which is exactly the case where the feature matters least.
What does emergency access not cover?#
Run this checklist against whichever manager you pick. Every item is a gap the feature itself does not close:
- The contact already has an account on the same service. Bitwarden needs a free or premium account on the same server, Proton a Proton Mail address, Keeper a Keeper account, NordPass a NordPass account, LastPass a LastPass user. None of it can be arranged after you go silent.
- The invitation is actually accepted. Bitwarden's is valid for only five days, so an unopened invite expires into nothing.
- Shared and work items are handled separately. Bitwarden covers only your individual vault; Keeper's feature is consumer-only.
- Accounts outside the vault are written down. Anything never saved to the manager — a domain registrar under a personal email, a bank that requires a hardware key, a client's billing portal — stays invisible to the feature.
- The contact knows what to do with access. No manager here ships instructions. A read-only vault answers "what is the password," never "which client to call first, and what have you promised them."
- Dashlane users have a re-export routine. Dashlane's replacement is manual: export an encrypted DASH file, store it somewhere your person can reach, and share the export password separately. The file does not update itself, so you repeat the export every time your data changes — it is stale the day after you make it.
The last two items are the ones a password manager will never close, because they are not password problems. The platform-level versions of the same trade-off — Bitwarden, 1Password, Google and Apple side by side — are laid out in how emergency access works across password managers. For the instructions layer — which handoff goes to whom, in what order, and where keys physically live — Proceedly is a business-continuity check-in: miss it past a grace window and a person you name confirms (or, on a paid plan, it releases automatically) before your encrypted handoff plan reaches the people who depend on you. It holds the instructions and the locations, never the passwords. Bitwarden, Proton or Keeper keeps those.
FAQ#
Which password manager has the cheapest emergency access? Bitwarden Premium, at $1.65/mo billed annually — $19.80 a year. Proton Pass Plus at $1.99/mo on annual billing costs a few dollars more and unlocks emergency access across your whole Proton Account rather than one vault.
Does 1Password have a legacy contact or emergency access? No. A 1Password staff member confirmed in the company's forum, in a pinned February 2024 reply, that there is "nothing new to share about an emergency access feature right now". The substitutes are the Emergency Kit PDF and family or team account recovery, which restores your own access rather than granting someone else sight of your vault.
Is NordPass emergency access free? Only to receive. Granting it requires a NordPass Premium or Family subscription, even though the plan-comparison page lists the feature without that caveat.
Can my trusted contact read my vault without telling me? Not silently, in any of the five. Bitwarden lets you reject the request during the wait window, Proton notifies you so you can deny a request that is not a real emergency, NordPass gives you 7 days, and Keeper notifies the owner when the contact attempts to log in. The wait only protects you while you can still read your email.
What is the longest wait time I can set? Three months with Keeper. Proton's documented maximum is 30 days, despite the launch blog's mention of months, and NordPass is fixed at 7 days.
Will my contact get my passwords from Apple or Google? No. Apple excludes "data stored in your iCloud Keychain (payment information, passwords, and passkeys)" from Legacy Contact access, and Google's Inactive Account Manager shares products such as Drive, Mail and YouTube while warning that some information cannot be shared.
How many trusted contacts can I name? Up to five on Proton, up to five on Keeper, and no stated limit on Bitwarden. LastPass and NordPass do not publish a number.
Sources#
- Proton: Emergency Access launch — 28 August 2025 launch, whole-account scope, five contacts, "all paid plans qualify".
- Proton support: Emergency access — Proton Mail address requirement, the 1-to-30-day wait dropdown, setup path, denying requests.
- Proton Pass pricing and Proton Pass price change — Pass Plus gating and the $1.99/mo annual price.
- Bitwarden help: emergency access — eligibility, five-day invitations, same-server requirement, individual-vault scope, rejection behaviour, key exchange, Automatic confirmation policy.
- Bitwarden help: add and manage trusted emergency contacts — View vs Takeover, one-day minimum wait.
- Bitwarden personal plans and Thurrott on the 2026 price increase — current pricing and the early-2026 change.
- 1Password community thread, Emergency Kit, account recovery — why there is no feature and what stands in for it.
- Keeper docs: emergency access, Keeper feature page, Keeper pricing KB — contacts, delays, read-only limits, prices.
- LastPass pricing and LastPass emergency access — plan gating and wait-time mechanics.
- NordPass support: how to give Emergency Access, NordPass: introducing Emergency Access and NordPass plans — the Premium-to-grant rule, 7-day window, view-only scope.
- Dashlane: share your data with a trusted person — feature removal and the DASH export workaround.
- Norton Password Manager features — the absence of emergency access.
- Google: Inactive Account Manager and How-To Geek on Google Password Manager family sharing — inactivity triggers, contact verification, and what is shared.
- Apple: what a Legacy Contact can access — the iCloud Keychain exclusion.